Privacy Policy for the B42 App
Last updated on July 13, 2026
This privacy policy applies to the B42 app (iOS and Android). For our websites b-42.com, elite.b-42.com, pro.b-42.com, and prevention.b-42.com, the separate privacy policy for B42 websites applies. For B42 CoachZone (teams.b-42.com) applies the separate privacy policy for the CoachZone.
1. Data protection at a glance
General Information
The following information provides a simple overview of what happens to your personal data when you use our app. Personal data refers to any data that can be used to personally identify you. For detailed information, please refer to our full privacy policy below.
Who is responsible for data collection in this app?
Data processing is carried out by the app operator. You can find contact details in Section 2.2.
How do we collect your data?
Some of your data is collected when you provide it to us, for example, by entering information during registration or while using the app. Other data is automatically recorded by our IT systems when the app is running (e.g., device information, operating system, time of app launch).
What data do we collect and why?
Some data is collected to ensure the app functions correctly. Other data may be used to analyze user behavior. Please refer to the following sections for details.
Analysis tools and third-party tools
When using the app, your usage behavior may be statistically analyzed. This is done using analysis tools, which we describe in detail in Section 4. This analysis only takes place after you have given your express consent when starting the app for the first time.
2. General information and mandatory disclosures
2.1. Data protection
The operators of this app take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
Please note that data transmission over the internet may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible. Communication between the app and our servers is exclusively encrypted via SSL/TLS.
2.2. Data controller
The party responsible for data processing in this app is:
SFY GmbH
IndustriestraĂźe 15
84149 Velden
Germany
Phone: +49 1590 4864277
Email: info@b-42.com
Represented by the Managing Director, Andreas Gschaider.
2.3. Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You may revoke your consent at any time — either directly in the app settings (Profile tab → icon in the top right) or by emailing us. The legality of the data processing carried out prior to the revocation remains unaffected.
2.4. Right to lodge a complaint with the competent supervisory authority
In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority. The competent authority is the State Data Protection Commissioner for the federal state in which our company is based. A list of supervisory authorities can be found at: www.bfdi.bund.de.
2.5. Right to data portability
You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.
2.6. Access, rectification, and erasure
Under applicable legal provisions, you have the right to obtain information free of charge at any time regarding your stored personal data, its origin, recipients, and the purpose of data processing, as well as a right to rectification or erasure where applicable. Please contact info@b-42.com at any time for this purpose.
2.7. Transfers to third countries
Some of the services used in this app are based in the USA. Where we transfer data to the USA, this is done on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework (DPF) of July 10, 2023, provided the respective provider is certified under the DPF. Otherwise, we base the transfer on standard contractual clauses in accordance with Art. 46(2)(c) GDPR. The respective legal bases are specified for each individual service.
3. Data collection in the app
3.1. Data categories collected
We process the following categories of personal data:
Identity data
First and last name, date of birth, email address, gender, and information transmitted to us via your Meta or Google account. We use this data to verify your identity and provide your account. This data is stored for the duration of the contractual relationship and for 3 years after its termination.
Contact details
Email address and other communication channels you have used to contact us. We use this data to contact you if necessary. Retention period: 3 years after the last contact.
Profile picture
Users may voluntarily upload a profile picture. This is displayed on your public profile and is visible to other B42 users (see "Behavioral and profile information" section below). The profile picture is stored for the duration of the contractual relationship and can be changed or deleted at any time in the app settings. The legal basis is Art. 6(1)(a) GDPR (consent via voluntary upload).
Body and training information
Height, weight, fitness level, training focus, and playing position (e.g., center-back). We use this data to better tailor our training plans and product recommendations to your needs. Retention period: for the duration of the contractual relationship.
Location data
The B42 app offers GPS tracking for running sessions, provided you have granted the app the necessary permission. Processing is based on your age:
- Users under 16: GPS coordinates are displayed in real time exclusively during an active session. Individual GPS points are not stored.
- Users aged 16 and over: GPS data is stored to evaluate and visualize your running performance. The data is automatically deleted after 24 months; aggregated evaluations are retained for the duration of the contractual relationship. The legal basis is Art. 6(1)(a) GDPR (explicit consent).
Marketing communication
Marketing-related emails and in-app communications (e.g., product news, offers) are sent exclusively to users aged 16 and over. The legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time in the app settings or by emailing info@b-42.com.
Purchase information
Payment service provider, duration of your B42 subscription, price, currency, VAT, and the payment number assigned by the payment service provider (e.g., Apple, Google). We do not store credit card information ourselves. Payment data is subject to statutory retention requirements and is stored for 10 years (§§ 146, 147 AO).
Behavioral and profile information
Your usage behavior within the app. We use this data to improve our products and provide you with relevant content. Retention period: 12 months, after which it is anonymized.
The information in your public profile is what you present to others in the B42 app. Other users can see your first and last name (if provided), your profile picture, your completed workouts, and your performance test results. Your B42 Player Card is also visible to other users. To help motivate other users through your achievements and progress, you agree to the use of your B42 Player Card on other SFY GmbH communication channels.
Social media information
Information we receive through your interactions with us on social media such as Facebook, Instagram, or Google, including publicly available information like your social media handles and public posts. We receive this information directly from social networks or through third-party agencies with whom we have entered into appropriate agreements.
Device information
Information about your device, including IP address, date and time of app usage, device identifiers, device type, operating system and version, and browser type (for the web view). This data is required for network security and error diagnostics. Retention period: 30 days.
Activity information
Fitness data such as your chosen training program, start and end times of workouts, and completed activities. We use this data to operate our products, support your performance goals, and provide relevant product recommendations. Completed workouts and your full training history are stored permanently so you can track your progress at any time — they remain until you actively delete your account (see Section 11.1). The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
3.2. Account and profile data
To use the app to its full extent, you need an account, which can be created via the registration function or by logging in with Meta, Google, or Apple. The email address required for this is stored on our server and used exclusively for login functionality and sending important transactional emails (e.g., password resets, order confirmations). The legal basis is Art. 6(1)(b) GDPR.
3.3. Age-dependent processing
After registration, users provide their date of birth in the app. Based on this information, certain functions and processing activities are managed according to age:
- GPS storage of running sessions, health integrations (Apple Health, Fitbit, Polar, Garmin), and marketing communications are available exclusively to users aged 16 and over (cf. §7 BDSG).
- For users under 16 years of age, the corresponding consents are not obtained; the functions remain disabled.
The date of birth is stored for the duration of the contractual relationship. The legal basis is Art. 6(1)(b) GDPR (performance of a contract, as age-dependent function control is part of the user agreement).
4. Analytics tools
4.1. PostHog
This app uses PostHog, a product and analytics tool from PostHog Inc. We use the EU cloud version of PostHog; all data is processed and stored exclusively on servers within the European Union (Frankfurt, Germany). No personal data is transferred to third countries.
PostHog allows us to analyze how users interact with the app (e.g., screens viewed, click paths, session duration) in order to make targeted improvements. Furthermore, we use PostHog for error analysis to identify and resolve issues in the user flow (e.g., drop-offs during specific actions, faulty screens). The data is processed in a pseudonymized form.
In addition, we use PostHog Workflows to trigger automated actions based on user behavior (e.g., context-sensitive in-app notifications). This processing also takes place exclusively on PostHog's EU servers.
PostHog is only used after your explicit consent upon the first app launch. The legal basis is Art. 6(1)(a) GDPR. You can revoke your consent at any time in the app settings. The collected usage data is automatically deleted after 12 months.
We have concluded a data processing agreement with PostHog. Further information: posthog.com/privacy.
4.2. Automated processing and personalized content
PostHog Workflows analyzes your usage behavior and can automatically trigger context-sensitive in-app notifications or content based on it (e.g., reminders for incomplete training sessions). This processing serves exclusively to improve your app experience.
There is no automated decision-making within the meaning of Art. 22 GDPR—i.e., no decisions with legal or similarly significant effects on you are made solely by automated means (e.g., no automatic termination, account blocking, or credit checks). The legal basis is Art. 6(1)(a) GDPR (consent).
5. Stability and troubleshooting
5.1. Firebase / Google Crashlytics
To detect and fix app errors and crashes, we use Firebase Crashlytics, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
If an error occurs in the app, the following data is automatically transmitted to Firebase:
- Anonymized user ID (randomly generated, no way to identify you)
- Device type, operating system, and app version
- Time of error
- Error logs and stack traces
- Geographic location (country only)
This data is used exclusively for diagnosing and fixing errors. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable app operation). Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is certified under the DPF. Crash data is automatically deleted after 90 days.
We have entered into a data processing agreement with Google. Further information: firebase.google.com/support/privacy.
5.2. Sentry
In addition to Firebase Crashlytics, we use Sentry for error tracking and performance monitoring. The provider is Sentry, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Sentry collects the following data in the event of an error:
- Anonymized user ID
- Device type, operating system, and app version
- Time and type of error
- Error logs and stack traces
- Performance metrics (e.g., load times)
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable app operation). We use Sentry in the EU region; all data is processed and stored exclusively on servers within the European Union. No personal data is transferred to third countries. Error data is automatically deleted after 90 days.
We have entered into a data processing agreement with Sentry. Further information: sentry.io/privacy.
6. Communication
6.1. Mailgun
We use Mailgun to send transactional emails (e.g., password resets, order confirmations, important account information). The provider is Mailgun Technologies, Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA.
Mailgun processes your email address and the content of the respective email. This data is not used for marketing purposes. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). We use Mailgun in the EU region; all data is processed and stored exclusively on servers within the European Union. No personal data is transferred to third countries. Email log data is deleted after 30 days.
We have entered into a data processing agreement with Mailgun. Further information: mailgun.com/legal/privacy-policy.
6.2. Push notifications
With your consent, the B42 app sends push notifications to your device (e.g., training reminders, important app updates). You will be prompted via your operating system's native permission dialog when you first launch the app.
The following services are used for delivery:
- iOS: Apple Push Notification Service (APNs) — Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (DPF certified)
- Android: Firebase Cloud Messaging (FCM) — Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (DPF certified)
In this process, a device-specific push token (anonymized device identifier) is transmitted to the respective service, which does not allow for your personal identification. The legal basis is Art. 6(1)(a) GDPR (consent). You can disable push notifications at any time in your device's system settings. Upon deactivation or deletion of your account, the push token is deleted immediately.
7. Payment
7.1. RevenueCat
We use RevenueCat to manage in-app subscriptions and purchases. The provider is RevenueCat, Inc., 633 Tasman Drive, San Jose, CA 95134, USA.
RevenueCat processes data regarding your subscription status, purchase time, selected plan, and an anonymized user ID. Credit card or bank account details are not transmitted to RevenueCat; these remain with the respective payment provider (App Store or Google Play).
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in reliable subscription management). Transfers to the USA are based on standard contractual clauses in accordance with Art. 46(2)(c) GDPR. Subscription data is stored for the duration of the contractual relationship and for 3 years thereafter.
We have entered into a data processing agreement with RevenueCat. Further information: revenuecat.com/privacy.
8. Login with third-party providers
8.1. Login with Meta (Facebook)
The B42 app offers the option to sign in using your Meta account (formerly Facebook). The provider is Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA.
When using the Meta login, your name and email address are retrieved from Meta following your express consent. This data is used exclusively for creating and managing your B42 account. Data is only transmitted to Meta after you explicitly click the "Continue with Facebook" button.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) for account creation and Art. 6(1)(a) GDPR (consent) for data transfer to Meta. Transfers to the USA are based on the EU-US Data Privacy Framework; Meta Platforms is DPF-certified.
Further information on data protection at Meta: facebook.com/privacy/policy.
8.2. Login with Google
The B42 app offers the option to sign in using your Google account. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When using the Google login, your name and email address are retrieved from Google after your explicit consent. This data is used exclusively for creating and managing your B42 account. Data is only transmitted to Google after you explicitly click the "Continue with Google" button.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) for account creation and Art. 6(1)(a) GDPR (consent) for data transfer to Google. The transfer to the USA is based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.
Further information on data protection at Google: policies.google.com/privacy.
8.3. Sign in with Apple
The B42 app offers the option to sign in using your Apple ID. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
When using "Sign in with Apple," Apple transfers your name and email address to the B42 app upon your consent. Apple offers the optional ability to provide an anonymized relay email address so that your actual email address is not transmitted to SFY GmbH. In this case, B42 will communicate with you exclusively via the forwarding address provided by Apple.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) for account creation and Art. 6(1)(a) GDPR (consent) for data transfer to Apple. The transfer to the USA is based on the EU-US Data Privacy Framework; Apple Inc. is DPF-certified.
Further information on data protection at Apple: apple.com/legal/privacy.
9. Teams function (CoachZone)
The B42 app includes a Teams area where coaches and clubs can manage their athletes, share training plans, and view performance data. This area is technically connected to the B42 CoachZone (teams.b-42.com) and accesses the same platform.
9.1. Special role structure
The data protection situation in the Teams area differs from the other app functions:
- Athletes use the Teams area to receive content from their coach and share their own training data. SFY GmbH is the controller for this data.
- Coaches and club administrators, who collect, manage, or analyze athlete data via the app, are themselves controllers for this processing under the GDPR. In this context, SFY GmbH processes athlete data exclusively as a data processor in accordance with Art. 28 GDPR.
Athletes who wish to access or request the deletion of their data stored in the Teams area should contact their respective coach or club. SFY GmbH supports the fulfillment of data subject rights upon request from the controller and can be reached at info@b-42.com.
9.2. Data processed in the Teams section
The following data may be processed in the Teams section of the app:
- Athlete name, playing position, and profile picture
- Training results, performance data, and test results
- Attendance and training history
- Internal team communication (e.g., announcements, lineups)
The legal basis for processing by SFY GmbH as a data processor is Art. 6(1)(b) GDPR (performance of a contract with coaches/clubs). Athlete data is deleted no later than 30 days after the termination of the contractual relationship with the respective coach/club.
The full privacy policy for the CoachZone platform, including the tools used and further details, is available at teams.b-42.com/datenschutz.
10. Health Integrations
The B42 app allows you to sync runs and activities via external health and fitness platforms. This feature is available exclusively to users aged 16 and over. Data from these integrations is considered health data under Art. 9 GDPR (special categories of personal data). Processing is based solely on your explicit consent pursuant to Art. 9(2)(a) GDPR. You can disconnect the integration at any time in the app settings.
10.1. Apple Health
On iOS devices, you can grant the B42 app access to your Apple Health data. The provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
When you enable the integration, the app only reads the data from Apple Health that you have explicitly authorized (e.g., running distance, step count, heart rate, calories burned). The data is transferred only to the B42 app and used there to display and analyze your activities. It is not shared with third parties.
Data is transferred to the USA based on the EU-US Data Privacy Framework; Apple Inc. is DPF-certified. Further information: apple.com/legal/privacy.
10.2. Fitbit / Google
B42 offers integration with Fitbit devices and services. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Fitbit is a Google product).
When you enable the Fitbit integration, activity data such as completed runs, distance, heart rate, and calories burned are retrieved via the Fitbit Web API. The legal basis is Art. 9(2)(a) GDPR (explicit consent). Data is transferred to the USA based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.
We have entered into a data processing agreement with Google. Further information: fitbit.com/legal/privacy-policy.
10.3. Polar
B42 offers integration with Polar watches and the Polar Flow service. The provider is Polar Electro Oy, Professorintie 5, 90440 Kempele, Finland.
When you activate the Polar integration, training data such as completed activities, GPS routes, heart rate, and calorie consumption are retrieved via the Polar Accesslink API. Since Polar Electro Oy is based in Finland (EU/EEA), no third-country transfer takes place. The legal basis is Art. 9 (2) (a) GDPR (explicit consent).
We have concluded a data processing agreement with Polar Electro Oy. Further information: polar.com/de/legal/privacy-policy.
10.4. Garmin
B42 offers an integration with Garmin devices and the Garmin Connect service. The provider is Garmin International, Inc., 1200 E. 151st Street, Olathe, KS 66062, USA.
When you activate the Garmin integration, activity data such as completed runs, GPS routes, heart rate, and calorie consumption are retrieved via the Garmin Connect API. The legal basis is Art. 9 (2) (a) GDPR (explicit consent). Data transfer to the USA takes place on the basis of the EU-US Data Privacy Framework, provided Garmin International is certified under the DPF; otherwise, it is based on standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.
We have concluded a data processing agreement with Garmin. Further information: garmin.com/de-DE/privacy.
10.5. Storage period for health data
Activity data imported from health integrations is stored for the duration of the contractual relationship. After disconnecting the respective integration or deleting your account, the imported data will be deleted immediately.
11. User rights
11.1. Account deletion
You can delete your B42 account and all associated personal data directly in the app: Profile → Settings (icon at the top right) → Delete account. Deletion includes all stored profile, training, health, and activity data. Data subject to statutory retention requirements (e.g., payment receipts under § 147 AO) will only be deleted after the respective period has expired. You will receive a confirmation email after confirming the deletion.
11.2. Data subject rights
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR): You may request information about the personal data processed concerning you.
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request the deletion of your data under certain conditions.
- Right to restriction of processing (Art. 18 GDPR): You may request the restriction of the processing of your data.
- Right to data portability (Art. 20 GDPR): You may receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR): You may object to the processing of your data.
The right of access and the right to erasure are subject to the restrictions set out in Sections 34 and 35 of the German Federal Data Protection Act (BDSG).
11.3. Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection supervisory authority regarding our processing of your personal data.
11.4. Withdrawal of consent
You may withdraw your consent at any time with future effect, either directly in the app settings or by sending an email to info@b-42.com. Processing that took place prior to the withdrawal remains unaffected.
11.5. Right to object to direct marketing
In accordance with Art. 21 (2) GDPR, you have the right to object at any time to the processing of your personal data for the purpose of direct marketing. Once you have objected, we will no longer process your data for this purpose.
11.6. Links to other websites
The app may contain links to services provided by other companies. This privacy policy applies exclusively to the B42 app from SFY GmbH. We have no influence over the data protection practices of other providers.
11.7. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time in compliance with applicable data protection regulations. The current version is available at b-42.com/datenschutzerklaerung-app.
11.8. Contact
If you have any questions regarding the collection, processing, or use of your personal data, please contact:
SFY GmbH
IndustriestraĂźe 15
84149 Velden
Germany
Email: info@b-42.com
‍
Data Policy for B42: Pro Soccer Training
Last updated on October 17, 2023
1. Data protection at a glance
General notes
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy listed below this text.
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy listed below this text.
Who is responsible for data collection in this app?
Data processing is carried out by the app operator. See point 2 for contact details.
How do we collect your information?
On the one hand, your data is collected when you provide it to us. For example, this could be data that you enter into a form. Other data is automatically collected by our IT systems when you visit the app. In particular, this includes technical data (e.g. Internet browser, operating system or time of page access). This data is collected automatically as soon as you enter our website.
What data do we collect and what do we use it for?
Some of the data is collected to ensure error-free provision of the app. Other data can be used to analyze your user behavior. We process personal data that you provide to us as a user of the products, e.g. through the use of our products, and those that others provide to us. We collect the following categories of personal information about you, directly or indirectly. This includes the following data points:
identity data: First and last name, date of birth, email address, gender, social media identification, and information that is forwarded to us via your Facebook or Google account. We use this information to verify your identity.
contact details: Phone number, email address, messenger ID, social media handle, other communication channels that you have used to request more information from us. We use this information to contact you — depending on the purpose — for various reasons.
Body and training information: Body size, weight, fitness level, desired training priorities, playing position (e.g. central defender). We use this data to better adapt our products to your needs.
Purchase information: Payment service provider, duration of your B42 subscription, price, currency, VAT. We use payment service providers to process payments. Even though we do not store any credit card information ourselves, we store a payment number that the respective service provider assigns (e.g. Apple, Google) and which can be assigned to you. We use this information to process your payments.
Behavioral and profile information: Your user behavior on the app. We use this data to get to know you better as a consumer so that we can send you marketing messages about products and services that we think may be of interest to you.
Social media information: Information that we obtain through your interaction with us on various social media such as Facebook, Instagram or Google, including any social media information that is publicly available, such as your social media handles, social media interactions and public postings, your “likes” and other reactions, your social media contacts, your photos that have been published or that you send to us by mentioning us or following our social media posts using “handles” or “hashtags.” We receive this information from social networks (e.g. Facebook, Instagram) either directly or through third-party agencies with whom we have agreements.
Device information: Information about your device or browser that gives us information about your browsing behavior or device usage. Your device information is collected via our app and your browser information is collected through our cookies, tags, and pixels. These are often required for network security. This information includes, for example: IP address, date and time of visit, how long you stayed on our app, the amount of data transferred, the referral URL (if you came to our website from another website or an ad), the pages visited on our website, your browser type (including the language and version of the browser software) and add-ons, device identifiers and features, device type, versions, and operating system.
Activity information: Fitness data such as selected training program, start and end of training, activities. We use this data to operate our products, improve your performance goals and user experience, and find out which products would be best for you based on your training pattern.
What data do we collect and what do we use it for?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request that this data be corrected, blocked or deleted. You can contact us at any time at the address given in the legal notice if you have any further questions about data protection. You also have the right to lodge a complaint with the competent supervisory authority.
Analysis tools and third-party tools
When you visit our app, your surfing behavior can be statistically evaluated. This is done primarily with cookies and so-called analysis programs. Your surfing behavior is usually analyzed anonymously; surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information can be found in the following privacy policy.
You can disagree with this analysis. We will inform you about the options for objection in this privacy policy.
2. General information and mandatory information
data protection
The operators of this app take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
When you use this app, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission on the Internet (e.g. when communicating by e-mail) may have security gaps. Complete protection of data against access by third parties is not possible.
Note on the responsible body
The responsible body for the data processing of this app is:
SFY GmbH
Industriestrasse 15
84149 Velden
Telephone: +49 160 97978139
email: andi@b-42.com
The responsible body is the natural or legal person who alone or together with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.).
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke any consent you have already given at any time. All you need to do is send us an informal email message. The legality of the data processing carried out up to the time of revocation remains unaffected by the revocation.
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of data protection law, the person concerned has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the following link:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to data portability
You have the right to have data that we process automatically based on your consent or in fulfilment of a contract handed over to you or to a third party in a standard, machine-readable format. If you request the direct transfer of data to another person responsible, this will only be done if it is technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the operator, this app uses SSL or TLS encryption. If SSL or TLS encryption is activated, the data that you send to us cannot be read by third parties. By default, this encryption is always enabled.
Information, blocking, deletion
Within the framework of the applicable legal provisions, you have the right to obtain free information about your stored personal data, its origin and recipient and the purpose of data processing and, if applicable, the right to correct, block or delete this data at any time. You can contact us at any time at the address given in the legal notice if you have any further questions about personal data.
Objection to promotional emails
The use of contact details published as part of the legal notice obligation to send unsolicited advertising and information material is hereby rejected. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
3. Data collection in our app
cookies
This app sometimes uses so-called cookies. Cookies do not cause any damage to your computer and do not contain any viruses. Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored and stored on your device.
Most of the cookies we use are so-called “session cookies.” They are automatically deleted at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser the next time you visit.
Cookies that are necessary to carry out the electronic communication process or to provide certain functions you request (e.g. shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f DSGVO. The app operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g. cookies to analyse your surfing behavior) are stored, these are treated separately in this privacy policy.
server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
If you want
- Browser type and version
- operating system used
- Referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not combined with other data sources.
Profile data
The prerequisite for full use of the app is, among other things, an account that can be created, for example, using the registration function. The email address required for this is stored on our server and is only used for login functionality and the sending of requested and important emails (e.g. password reset, order confirmation).
Login with Facebook
This app uses the option of logging in via Facebook, Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). When using the login with Facebook, the name and email address are retrieved from Facebook after explicit consent. This data is used in the same way as in the “Profile data” section. Data is only transmitted to Facebook after you have explicitly clicked on the “Continue with Facebook” button.
legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can withdraw this consent at any time. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
4. Analysis tools
Google Analytics
This app uses features of the Google Analytics web analysis service. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses so-called “cookies.” These are text files that are stored on your device and which enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. Google Analytics cookies are stored on the basis of Art. 6 para. 1 lit. f DSGVO. The app operator has a legitimate interest in analyzing user behavior in order to optimize both its range of services and its advertising.
IP anonymization
We have activated the IP anonymization function in this app. As a result, your IP address will be shortened by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this app, Google will use this information to evaluate your use of Aoo, to compile reports on activities and to provide other services related to app usage and Internet usage to the app operator. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google.
Objection to data collection
You can prevent Google Analytics from collecting your data by refusing participation in the usability improvement program when you first start the app or revoking your consent subsequently in the app settings (“Profile” tab -> click on icon in the top right corner). More information about how Google Analytics handles user data can be found in Google's privacy policy:
https://support.google.com/analytics/answer/6004245?hl=de.
Order data processing
We have concluded a contract with Google for order data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographics in Google Analytics
This app uses the “demographic characteristics” feature of Google Analytics. This allows reports to be created that contain statements about the age, gender and interests of site visitors. This data comes from interest-based advertising from Google and from visitor data from third-party providers. This data cannot be attributed to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section “Objection to data collection.”
Hotjar
This app uses Hotjar, an analysis software from Hotjar Ltd. (“Hotjar”) (
http://www.hotjar.com, 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta, Europe). Hotjar makes it possible to measure and evaluate the usage behavior of the app in the form of clicks, mouse movements, scroll heights, etc. This information is transmitted to the Hotjar server in Ireland and stored there.
The following information is collected:
- The IP address of your device (anonymized)
- Your email address including your first and last name, as far as they can be viewed in our app
- Your device's screen size
- Device type and browser information
- Geographical position (country only)
- The preferred language to display our website
Hotjar uses this information to evaluate and analyze your use of our app in order to enable the app operator to improve its range of services. Hotjar also uses services from third-party companies, such as Google Analytics and Optimizely, to provide services. These third-party companies may store information that your browser sends as part of your website visit, such as cookies or IP requests. For more information on how Google Analytics and Optimizely store and use data, please refer to their corresponding privacy policies.
For more information on Hotjar's privacy policy, please visit
Hotjar's privacy policy remove.
You can prevent Hotjar from collecting data by declining participation in the usability improvement program when you first start the app or revoking your consent subsequently in the app settings (“Profile” tab -> click on icon at the top right).
5. Additional tools
Bugsnag
In order to identify and fix errors and problems with this app, this app uses the Bugsnag analysis service. The provider is Bugsnag Inc., 939 Harrison Street, San Francisco, California 94107, USA.
The app contains code from Bugsnag, which anonymously sends a “log” of the error and further data to Bugsnag's servers when errors occur. The following data is collected in this process:
- Anonymized user ID (randomly generated unique ID that does not allow Bugsnag to draw any conclusions about the user's identity)
- Type of device, operating system and browser type
- Geographic location (country only)
- Time of transmission
- Log and stack trace of the error that occurred
The above data is only transmitted to Bugsnag if an error occurs in the app and is only used to correct this error. Data processing is based on your consent (Art. 6 para. 1 lit. a DSGVO).
Bugsnag is certified according to the “EU-US Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA.
For more information about Bugsnag's privacy policy, please see Bugsnag's privacy policy:
 https://docs.bugsnag.com/legal/privacy-policy/Facebook Connect
Facebook Connect from the social network Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA is integrated into our pages. With Facebook Connect, you can create a new B42 account via your Facebook account or log into it. If you create an account with the app operator using Facebook Connect or log in with Facebook Connect, the app operator receives access to your public profile and email address. This information is used to create your account or log into your account. The legal basis for this is Art. 6 para. 1 lit. b GDPR, as your Facebook data is used to create an account with B42. The data is stored and processed as described in point 3.
Mailgun
To send important emails, such as password reset and order confirmation, etc., this app uses the Mailgun service infrastructure (MailGun Inc., 620 Folsom St, Ste 100, San Francisco, CA 94107, USA).
MailGun Inc. is certified under the EU-US Privacy Shield and is therefore committed to maintaining a data protection standard comparable to the European data protection standard. For more information, please refer to MailGun Inc.'s privacy policy:
https://www.mailgun.com/privacy-policy The legal basis for this is Art. 6 para. 1 lit. f DSGVO, as the app operator has a legitimate interest in doing so.
Adjust
To analyze and optimize our marketing activities regarding app usage, we use the Adjust app analysis service from Adjust GmbH, Saarbrücker Str. 37A, 10405 Berlin (hereinafter “Adjust”). The data collected via Adjust provides information, for example, about the download of the B42 app, the online advertising channel that generated the download, the time the app was opened, the duration of app use and specially used app functions (in particular for successful registration). Adjust uses users' IP and Mac addresses for analysis, which, however, are anonymized (hashed) after collection and are used exclusively in pseudonymized form by Adjust. As a result, it is not possible for us to identify a natural person or a device. For more information about Adjust, visit the website:
https://www.adjust.com/Clevertap
Our app uses Clevertap, a combination of analysis and marketing solution in one system. Clevertap enables the operator of the app to collect data about the use of the app and to individualize marketing activities. The operating company of Clevertap is WizRocket Inc., 440 N Wolfe Rd, Sunnyvale, CA 94085, USA.
Every time you access our app, Clevertap collects and stores data for marketing and optimization purposes. User profiles are created using the data obtained. The user profiles are used for the purpose of analyzing visitor behavior and the targeted orientation of marketing activities and enable us to improve our range of apps.
We use Clevertap to use the data and information obtained via our app to evaluate your user behavior. The data is also used to create reports on user activity and to provide other services related to the use of our app.
You can withdraw your consent to the use of Clevertap through our app at any time by uninstalling our app.
Clevertap's applicable privacy policy can be found at clevertap.com/privacy-policy/.
UXcam
With UXcam, a service provided by UXCam Inc., (6250 Cypress Avenue, El Cerrito, CA, 94530, USA), (“UXCam”), we use to analyze user experience, which helps us understand how the user interface of the B42 app is used. For this purpose, technical usage data that is generated when using the app and user interactions are collected and then evaluated in order to further optimize the user interface. The collected usage data is only processed pseudonymized. No contact details, passwords or other directly identifying personal information are collected when using the B42 app via this service. The pseudonymous information about interaction with the app is usually transferred to a server in the USA and processed there. UXcam expressly contractually assures us of compliance with European data protection regulations, and UXCam is also certified under the EU-US Privacy Shield. The applicable data protection regulations of UXcam can be found at
https://help.uxcam.com/hc/en-us/articles/360004158171 be retrieved. You can withdraw your consent to the use of UXcam through our app at any time by uninstalling our app.
6. Rights of the user
Information on the rights of data subjects
Every data subject has the right to information under Article 15 GDPR, the right to rectification under Article 16 GDPR, the right to erasure under Article 17 GDPR, the right to restrict processing under Article 18 GDPR, the right to object under Article 21 GDPR and the right to data portability under Article 20 GDPR. The restrictions set out in Sections 34 and 35 BDSG apply to the right of information and the right of deletion.
Information on the right of appeal
You also have the right to complain to the competent data protection supervisory authority about the processing of your personal data by us.
Instructions for revocation in case of consent
You can revoke your consent to the processing of personal data at any time by contacting us. This also applies to the revocation of declarations of consent that were given to us before the General Data Protection Regulation came into force. Please note that the revocation only takes effect for the future. Processing that took place before the revocation is not affected.
Right in the event of data processing for direct marketing
In accordance with Article 21 Paragraph 2 GDPR, you have the right to object to the processing of personal data concerning you at any time. In the event of your objection to processing for direct marketing purposes, we will no longer process your personal data for these purposes. Please note that the objection is only effective for the future. Processing that took place before the objection was lodged is not affected.
Reference to the right of objection when balancing interests
Insofar as we base the processing of your personal data on a balance of interests, you can object to the processing. If you exercise such an objection, please explain the reasons why we should not process your personal data as described by us. In the event of your justified objection, we will review the situation and will either stop or adjust the data processing or explain our compelling legitimate reasons to you.
Links to other websites
Our app may contain links to other websites or apps from other providers. We would like to point out that this privacy policy applies exclusively to B42 websites. We have no influence on and do not control that other providers comply with the applicable data protection regulations.
Changes to the privacy policy
We reserve the right to change or adapt this privacy policy at any time in compliance with applicable data protection regulations.
Responsible person and data protection officer
You can contact us at any time if you have any questions about the collection, processing or use of your personal data, or if you wish to provide information, correct, block or delete data.
Responsible person for data processing
SFY GmbH
Industriestrasse 15
84149 Velden
germany
email: info@b-42.com
represented by managing director Andreas Gschaider
Data collection in our app
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
Text link
Bold text
Emphasis
Superscript
Subscript