Déclaration de protection des données (version 16.05.2018)

Marco Abels, Alter Hohlweg 7, 58093 Hagen, Germany, is the developer, founder and operator of the website my-crossbox.com (.eu and .de), will be referred to as my-crossbox in the following. my-crossbox is a management software for the planning, administration and analysis of a course-led sports organisation (so-called box). It is possible to manage and organize course units, members, interested athletes and coaches. Through the Box-Community data contents can be planned, shared and carried out between different boxes.

With this privacy policy my-crossbox wants to show which rights the user has when using the offer, how the data is processed and which data is collected for which purpose. The subject of data protection should be dealt with openly and completely transparently.

This data protection declaration applies to the website www.my-crossbox.de (https://www.my-crossbox.de), www.my-crossbox.com (https://www.my-crossbox.com) and www.my-crossbox.eu (https://www.my-crossbox.eu); When URLs with the suffixes .eu or .de are called up, they are forwarded to .com.

What is personal data?

Personal data is all information relating to an identifiable natural person. Personal data in connection with the use of this web service includes, for example, name, gender, date of birth and e-mail address.

Processing and use of personal data for general access to my-crossbox (logoff area)

In the logoff area, i.e. without user registration on my-crossbox, no personal data is required. A contact form is available for contacting my-crossbox. The contact form can be found at www.my-crossbox.com/impressum . Alternatively, my-crossbox can be contacted at the e-mail address [email protected] . When calling the homepage my-crossbox.com, a link to the social media provider facebook is integrated. Here it is only checked whether the calling user "liked" the fan page of my-crossbox on facebook.

Processing and use of personal data in the context of my-crossbox (login area)

>In order to provide and use the contents on my-crossbox, both as owner, member or guest, a registration with the following minimum details is required:

- First name, surname, e-mail address, password, consent to the data protection declaration

The principle of data economy is followed here, d.h. only those data are collected which are necessary for the fulfilment of the underlying purpose. The user must agree to the data protection declaration before initiating the registration process. The data protection declaration must be accessed via a link. If the link is not opened to view the data protection declaration, consent to data protection cannot be given. This is to prevent the consent from being given without having opened the contents of the data protection declaration. Following registration, the e-mail address must be confirmed by means of a verification e-mail. An automated e-mail will be sent to the user from [email protected] . The verification serves the security of the person concerned and is intended to ensure that the e-mail address used is in the possession of the registrant.

When visiting the website in the protected area, i.e. after logging in, the connection data of the requesting computer, the page menu called up, the date of the page call and the identification data of the browser used are stored as standard for the purpose of user friendliness, improvement of the service offered and system security.The stored IP address is shortened by the last three digits.

In the basic settings of a new user, the visibility is reduced to a minimum (opt-in). In order to be able to use further contents of my-crossbox or to increase the visibility in individual areas, the setting in the respective user account must be made independently by the user.

Participation in tournaments

In the user menu "Tournament" the user is offered internal as well as public tournaments or the user can create a tournament independently. Before participating in a tournament, the user is shown the type of tournament. In the tournament leaderboard the names of the participating users as well as the box membership are displayed. The user always has the possibility to change the display of his last name in the tournament settings. By default the last name is shortened to the first letter. The setting can be changed so that the last name is displayed completely. Please note that in a public tournament the Leaderboard can also be viewed without a user account.

Authorization of differentiated user types

Usertype "Box-owner/owner"

Special features of a user account of type "Box-owner/owner":
  • Insight into the full name of all registered users of the own box as well as of users registered as guests
  • Insight into the e-mails of all registered users.Mail address for non-verified users of their own box
  • Can delete user from system
  • Can change the user type of a user account
  • Can view the participation of members in a course (full name) incl. the participation of guests. For participants from other registered boxes only the first name + first letter of the last name is displayed
  • Sight the registration and deregistration process of the course participants with complete name (also for guests)
  • Further settings of visibility can be made in the user settings

  • User type "Trainer/ Coach"

    Special abilities of a user account of type "Trainer/ Coach":
  • May see the participation of members in a course (first name + first letter of surname) incl. of guests and members of other boxes
  • Sight the registration and deregistration process of the course participants
  • More visibility settings can be made in the user settings
  • In the contact list only those users will be suggested who have given the corresponding permission in the user settings (default off)

  • User type "Member/User"

    Special features of a user account of type "Member/User":
  • May see the participation of members in a course (first name + first letter of last name), if the setting of the logged in user allows this, incl. the participation of guests and members of other boxes.
  • More visibility settings can be made in the user settings
  • In the contact list only those users are suggested who have given permission in the user settings (default off)

  • user type "Guest"

    guests/interested persons, who submit a request for participation in a trial training/ drop-in, get a "slimmed down" user account. If a guest's request is accepted for trial training, his first name will be displayed in the registration list. The last name is only displayed completely for the box owner. All other user types can only see the first letter of the last name. As an indication of a guest, the consecutive numbering of the deposited guests is shown in brackets (e.g. guest1).

    Personal rights of the person concerned according to the Basic Data Protection Regulation (GDPR)
    Ab/ Since 25.05.2018, the new regulation of the Basic Data Protection Regulation has been in force within the EU. This regulation is intended to strengthen the personal rights of the data subject. This section is intended to draw the attention of the data subject to his or her claims under the GDPR. In particular, it is necessary to refer to the claims for information (Art. 15 GDPR), rectification (Art. 16 GDPR) and deletion (Art. 17 GDPR) of personal data.

    information:
    In accordance with Art. 12 para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the claim for information. Under the conditions of Art. 15 GDPR, the person responsible may be requested to provide information on the nature and scope of the personal data collected, stored and processed. In addition, as a user you have a right to be informed of the information referred to in Art. 15 GDPR, in particular about the existence of a right of appeal to a supervisory authority and the duration of the storage. The correct identity of the person concerned must be established before information is provided. Information claims are processed exclusively via the e-mail address stored in the system. For the purpose of providing information, the data subject will be provided with a tabular list of his/her personal data by e-mail within the time limit.

    correction:
    In accordance with Art. 12 para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the information claim. Under the conditions of Art. 16 GDPR, the data controller may be required to rectify the personal data concerned, which are incorrect or incomplete. Before the rectification is carried out, the correct identity of the data subject must be established. Correction claims will be processed exclusively via the e-mail address stored in the system.

    deletion:
    In accordance with Art. 12 para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the claim for information. Under the conditions of Art. 17 GDPR, the deletion of personal data may be requested from the person responsible. Before the deletion is carried out, the correct identity of the data subject must be established. Deletion claims are processed exclusively via the e-mail address stored in the system. The determined data records must then be checked to determine whether the claim for deletion is in conflict with legitimate interests. It must be checked whether longer retention periods result from mandatory statutory provisions or from the requirement of proof even after the exchange of services has taken place due to statutory warranty periods, as well as limitation periods (from §§195 et seq. BGB). If there is no justified interest for further storage in contradicting the claim for deletion, the personal data to be deleted shall be prepared in tabular form. The personal data must then be deleted or made unrecognisable. The anonymisation/deletion must be sent to the person concerned by e-mail, enclosing the tabular overview of the data. Here the data subject receives an overview of which data is anonymised for the purpose of booking history and evaluation statistics and which data is completely deleted. Subsequently, the tabular processing of the personal data (including the contact e-mail address), if stored, must also be deleted or made unrecognisable.

    Contradiction:
    In accordance with Art. 12 Para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the claim for information. Under the conditions of Art. 21 GDPR, an objection may be raised against the processing of personal data. The correct identity of the data subject must be established before the objection is executed. Objection claims are processed exclusively via the e-mail address stored in the system.

    restriction:
    In accordance with Art. 12 para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the information claim. Under the conditions of Art. 18 GDPR, the data controller may be required to restrict the processing of personal data. Before the restriction is implemented, the correct identity of the data subject must be established. Claims for limitation are processed exclusively via the e-mail address stored in the system.

    Forwarding:
    In accordance with Art. 12 para. 3 GDPR, a period of one month after receipt of the claim must be observed for compliance with the claim for information. Under the conditions of Art. 20 GDPR, the responsible person may be required to transfer personal data to another responsible person. Before the transfer is carried out, the correct identity of the data subject must be established. Claims for transfer are processed exclusively via the e-mail address stored in the system.

    integration facebook:
    >On the start page (in the logoff area), a facebook plug-in for displaying the like status of a facebook user and for sharing the facebook fan page of my-crossbox is stored in the footer. If the calling user is already logged in to facebook at the current time on the same device, facebook can be able to determine the user name and if necessary even the real name of the user from the transmitted data and assign this information to the personal user account. You can opt out of this assignment to your personal account by logging out of your facebook account. In the login area, the user types "Owner" and "Coach" have the possibility to share the workouts planned for one day on facebook. The content to be shared is done via the facebook user account of the respective user. The contribution is related to my-crossbox. If a facebook user clicks on the shared post, he will be redirected to my-crossbox.com and has access to the workout description of the shared weekday.

    contact form:
    To contact us, you can use the contact form my-crossbox.com/impressum. To use the contact form we need the following information:
  • E-Mail address and message content

  • Alternatively to the contact form you can also contact us via the e-mail address [email protected].

    Use of Cookies:
    When you open the page, cookies are stored. The storage is necessary in order to be able to use access to the website as barrier-free as possible. The function of "stay logged in" is controlled with the help of a cookie. A (hash) encrypted character string is stored here. Personal data is not stored in the cookie. However, a connection to the user can be established via the character string, which is absolutely necessary for the functionality of this cookie. Another cookie uses a character string to share content on facebook. This code is only active in the login area.

    iFrame integration of my-crossbox:
    With an iFrame integration, contents of my-crossbox can be stored on external websites. Only the box-owner and tournament administrators have access to the source code for the integration of corresponding content from my-crossbox. Below are listed the areas that can be included on foreign pages:
    contents without insight into personal data:
  • view of the course week of a box. No personal data is displayed here. The box owner can take the iFrame programming line from the box settings and store it in an external website.

  • contents which may contain personal data:
  • leaderboard for a tournament. The tournament administrator has the possibility to display a link for the iFrame programming line. With this line it is possible to embed the Leaderboard on a foreign website.



  • Inappropriate use of my-crossbox:
    If the use of my-crossbox should not take place according to the actual purpose (see the introduction of this privacy policy) or if radical, inhuman, sexual and/or offensive contents are spread with the help of the portal, my-crossbox reserves the right to stop the use with immediate effect and to delete the affected user accounts if necessary. Serious violations will be reported.

    Questions on data protection:
    Questions on data protection regarding my-crossbox can be directed at any time to the following contacts:
    Marco Abels
    Alter Hohlweg 7
    58093 Hagen
    Germany

    E-Mail: [email protected]
    Phone: +49 151 289 305 82