Privacy policy
1. Controller
The controller within the meaning of the GDPR is Henning Haist, Klingsorstraße 3, 81927 Munich, Germany. Email: fitnessover41@gmail.com.
No data protection officer has been appointed, as this is not required under the statutory criteria (Art. 37 GDPR, § 38 BDSG).
2. In brief
This website is deliberately built to collect as little data as possible: it sets no cookies, uses no analytics, tracking or advertising services, embeds no third-party content (fonts, videos, maps, social media plugins) and has no forms, accounts or newsletters. Personal data arises only when the site is accessed (server log files), when you email us, when you buy through Digistore24 and when you visit our social media profiles.
3. Cookies and storage on your device
We do not set cookies on this website and do not store any information in your browser (no local storage, session storage or IndexedDB). Because no information is stored on or read from your device, no consent is required under § 25 TDDDG (the German telemedia privacy act) – which is why this website has no cookie banner. Should we use services in the future that rely on cookies or similar technologies, we will obtain your consent beforehand and update this notice.
The language version is chosen solely from your browser’s language setting on your first visit; nothing is stored.
4. Hosting and server log files
This website is hosted by [add hosting provider]. When a page is requested, the server automatically processes technically necessary data: IP address, date and time, requested file/URL, amount of data transferred, status code, referrer URL and browser and operating system details (user agent). This processing is necessary to deliver the page, to ensure its stability and security and to fend off attacks; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation). We do not combine this data with other data and do not use it for marketing. Log files are kept only as long as necessary for these purposes (usually a few days to weeks) and are then deleted or anonymised.
A data processing agreement under Art. 28 GDPR is in place with the hosting provider. Where the provider processes data in a country outside the EU/EEA (e.g. the USA), this is based on an adequacy decision of the European Commission (EU-US Data Privacy Framework) or on standard contractual clauses (Art. 44 et seq. GDPR).
5. Fonts, images and videos
All fonts, images and video clips are served from our own server. No connection is made to Google Fonts, YouTube, Instagram or other third-party servers unless you actively click a link to them. The video clips play through your device’s standard browser player; no usage behaviour is recorded.
6. Contact by email
If you email us, we process your email address, the content of your message and metadata (time) to handle your request (Art. 6(1)(b) GDPR where it concerns a contract or a pre-contractual enquiry, otherwise Art. 6(1)(f) GDPR). We keep the correspondence until the matter is resolved and no statutory retention duty applies; business letters are kept for up to six years (§ 257 HGB, § 147 AO). Our mailbox is operated with Google (Gmail; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); Google processes the data on our behalf, and a transfer to the USA may take place on the basis of the EU-US Data Privacy Framework or standard contractual clauses. Please do not send us sensitive health data by email.
7. Purchase via Digistore24
Our digital guidebooks are sold through the platform Digistore24. When you click “Buy now”, you leave our website and reach the Digistore24 checkout (Digistore24 GmbH, Munich). Ordering, payment, invoicing and delivery of the download take place there; for the data processed in the course of that, Digistore24 is itself responsible under its own privacy policy. We receive from Digistore24 only the data needed for contract handling, for meeting tax and commercial-law obligations and – if you contact us – for customer support (Art. 6(1)(b) and (c) GDPR). We retain this data in line with statutory periods (generally up to ten years, § 147 AO, § 257 HGB). For more information, see Digistore24’s privacy policy in the checkout.
8. External links and social networks
Our website contains links to our profiles on Instagram and possibly other social networks. These are simple links, not embedded plugins: a connection to the respective provider is established only when you click a link (e.g. Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland). From then on the provider’s privacy terms and cookie settings apply, and we have no influence on the data processing there. When you visit our profile or interact with our posts, the provider processes data about you (e.g. usage and reach statistics); we and the provider may be jointly responsible for this (Art. 26 GDPR). The legal basis for the linking itself is our legitimate interest in informing about our offer (Art. 6(1)(f) GDPR).
9. Recipients, third-country transfers, automated decisions
Depending on the occasion, recipients of your data are the hosting provider (processor), the email service provider (processor), Digistore24 and tax advisers and tax authorities where legally required. Data is transferred to third countries only as described above and only on the basis of an adequacy decision or appropriate safeguards (Art. 44 et seq. GDPR). There is no automated decision-making including profiling (Art. 22 GDPR). You are not obliged to provide personal data; without the server log data the website cannot technically be delivered, and without the purchase data no purchase can be processed.
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3)). Right to object: where we process data on the basis of legitimate interests (Art. 6(1)(f)), you may object at any time on grounds relating to your particular situation. Simply email us at the address above.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
11. Data security
Data between your browser and our website is transmitted in encrypted form via HTTPS (TLS), which you can recognise by the lock symbol in the address bar. Complete security of data transmission over the internet can nevertheless not be guaranteed.
12. Updates and changes
As of: October 2026. We update this notice when our website, the services we use or the legal situation change. The version published here applies.