Legal
Platform privacy information
Information for users of the application app.numara.works and for members, leads and guests of studios that use numara.
Last updated:
This English version is provided for convenience. The German version is legally binding.
Who is responsible?
numara is software that gyms, boutique studios and coaching providers (each a “studio”) use to run their business. Who is responsible for a processing operation depends on the data concerned:
- Data of a studio’s members, leads, guests and coaching clients: the respective studio is the controller. Numara Works UG (haftungsbeschränkt) processes this data on the studio’s behalf as a processor under a data processing agreement (Art. 28 GDPR) and only on the studio’s instructions. Please refer to your studio’s privacy policy to find out which data it collects and for what purposes.
- Accounts of studio staff, contract handling and billing with studios, security and abuse prevention: Numara Works UG (haftungsbeschränkt) is the controller.
If you are a member of a studio, please direct requests about your data to your studio first. We support the studio in responding. If your request reaches us directly, we forward it to the studio concerned.
This information describes how the platform works technically. The website numara.works is covered by the website privacy policy.
Contact
Numara Works UG (haftungsbeschränkt)Kolonnenstraße 8
10827 Berlin
Germany
Email: mail@numara.works
Represented by the managing directors Simon Schmidt and Benedikt Rapp. No data protection officer has been designated; please send questions about data protection to the email address above.
Accounts for studio staff
Studio staff sign in without a password, using a sign-in link sent by email. Sign-in is handled by Firebase Authentication, a Google service. We process:
- email address and name,
- role in the studio and assigned locations,
- a session cookie
__session(httpOnly, Secure, SameSite=Lax, valid for 5 days), -
an entry
auth_email_for_sign_inin the browser’s local storage so that sign-in can be completed after clicking the link.
The legal basis is Art. 6(1)(b) GDPR (provision of the contractually agreed software). The account exists until the studio removes the access or the contract with the studio ends.
Member area and booking portal
Studios can provide a booking portal to their members. Sign-in there also works via a link sent by email, which is
valid for one day. After sign-in, the platform sets the session cookie __session_member (httpOnly,
Secure, SameSite=Lax); the session expires after 35 days.
Bookings, waitlist places and credits (such as class packs) are processed in the member area. This processing is carried out on the studio’s behalf; the legal basis is usually your contract with the studio.
Technically necessary storage
The platform only stores information on your device that is strictly necessary for the service you have expressly requested (§ 25(2) No. 2 TDDDG). No consent is required for this. We do not use analytics or advertising cookies.
| Name | Type | Purpose | Duration |
|---|---|---|---|
__session |
Cookie | Session of studio staff | 5 days |
__session_member |
Cookie | Session in the member area | 35 days |
auth_email_for_sign_in |
Local storage | Completing sign-in via email link | until sign-in is completed |
numara-theme |
Local storage | Chosen appearance (light or dark) | until deleted in the browser |
numara_checkin_client_id, numara_rating_client_id |
Local storage | Random device IDs for QR check-in and class ratings; prevent duplicate submissions | until deleted in the browser |
| Booking-attempt keys | Local storage | Prevent double bookings when a form is submitted again | until deleted in the browser |
| Table column preferences | Local storage | Remember the chosen table view | until deleted in the browser |
| Source of the first visit | Session storage | UTM parameters and cleaned referrer address; only transmitted when you submit a form, so that the studio knows where an enquiry came from | only for the open browser tab |
Usage measurement
In the staff area only, we measure how quickly and reliably the application works. We record the pattern of the route visited with the studio identifier removed, the type of navigation, load timings and a flag indicating whether an error occurred. No user, studio or content data is included. The measurements are written to the server logs. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a stable and fast application.
Email sending and consent
All emails from the platform are sent via the service Resend (Resend, Inc., USA) acting as a processor: sign-in links, booking and waitlist notifications, and studios’ campaigns and automated flows. Resend reports delivery events back (delivered and, where available, opened or bounced). We store these events for 90 days.
Double opt-in: Sign-ups via a studio’s forms are verified with a confirmation link. By default the link is valid for 72 hours; the studio can set a validity of between 24 and 168 hours. As proof of consent we store the time, IP address, user agent and consent text for as long as the consent is relevant as evidence. Unconfirmed sign-ups are deleted 30 days after the link expires.
Unsubscribing: Every marketing email contains an unsubscribe link and a one-click unsubscribe header. After an unsubscribe or erasure, only a one-way hash (SHA-256) of the email address is kept so that the unsubscribe remains effective.
Payments
Only if a studio has activated online sales are payments processed via Stripe. The provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. The studio is the merchant. You enter card data directly with Stripe; it never reaches numara. Stripe acts in part as an independent controller, for example for fraud prevention and to comply with legal obligations. For details, see Stripe’s privacy policy.
Bank data in the finance module
Only if a studio connects its business account does the finance module process transaction data of that account:
- if activated: finAPI GmbH, Adams-Lehmann-Straße 44, 80797 Munich, Germany, an account information service licensed by BaFin.
For the studio, we store the counterparty, payment reference, amount and date of transactions. Such transactions may contain personal data, for example the name of a paying member. Bank transactions and orders are retained in accordance with German tax law (§ 147 AO, up to 10 years).
AI functions
For AI functions we use Google Vertex AI (Gemini) via Google Cloud EMEA Limited. Requests are processed via Google’s global endpoint, so processing may also take place outside the EU. The safeguards are Google Cloud’s data processing agreement, the EU-US Data Privacy Framework and the Standard Contractual Clauses. Under the Google Cloud service terms, Google does not use the data to train its models.
What is sent to the model:
- Dashboards, insights and schedule suggestions: only aggregated figures, never names, email addresses, IDs or IBANs.
- Categorisation of bank transactions: counterparty name and payment reference, after email addresses, IBANs and phone numbers have been removed.
- Coaching message drafts: the client’s first name, a redacted summary of their goal, training figures for the last 30 days, redacted excerpts of previous contact and the coach’s brief. Last name, email address, phone number and IDs are not sent. Drafts are only sent after the coach has reviewed them.
- Analysis of other providers’ class schedules: publicly accessible web page text only.
AI run records are deleted after 90 days.
Partner platforms
Only if a studio activates them does numara process bookings and check-ins of users of the partner platforms Urban Sports Club and EGYM Wellpass at that studio. For Urban Sports Club we store only a salted hash of the customer ID and a display name. The partner platforms are independent controllers for their users’ data.
Only if a studio activates the feature (it is not yet generally available) are messages sent via the WhatsApp Business Platform. The parties involved are Twilio Ireland Limited, 25–28 North Wall Quay, Dublin 1, Ireland, and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. Separate consent of the recipient is required. Conversations are deleted 180 days after the last message.
Sub-processors
| Provider | Service | Place of processing | Safeguards |
|---|---|---|---|
| Google Cloud EMEA Limited, Dublin, Ireland | Hosting (Cloud Run, Firestore, BigQuery, Cloud Storage, Secret Manager, Cloud Scheduler), Firebase Authentication, Vertex AI | Netherlands (europe-west4); Vertex AI global | Data processing agreement, EU-US Data Privacy Framework, Standard Contractual Clauses |
| Resend, Inc., San Francisco, USA | Email sending | USA | Data processing agreement, Standard Contractual Clauses |
| Stripe Payments Europe, Limited, Dublin, Ireland (if activated) | Payment processing | EU; transfers to the USA possible | In part independent controller; see Stripe’s privacy policy |
| finAPI GmbH, Munich (if activated) | Account information service | Germany | GDPR directly applicable |
| Twilio Ireland Limited, Dublin, Ireland (if activated) | Sending WhatsApp messages | EU; transfers to the USA possible | Standard Contractual Clauses |
| Meta Platforms Ireland Limited, Dublin, Ireland (if activated) | WhatsApp Business Platform | EU; transfers to the USA possible | EU-US Data Privacy Framework, Standard Contractual Clauses |
We use Open-Meteo for weather data; no personal data is transmitted in the process.
Transfers to third countries
The platform is operated in the EU. Data is transferred to third countries, in particular the USA, when emails are sent via Resend, for AI functions via Google Vertex AI’s global endpoint, and possibly through access by the US parent companies of our service providers. Such transfers are safeguarded by the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the recipient is certified, by the EU-US Data Privacy Framework (Art. 45 GDPR).
Retention periods
| Data | Retention period |
|---|---|
| Audit and log entries | 400 days |
| Unconfirmed double opt-in sign-ups | 30 days after the confirmation link expires |
| Coaching messages and notes | 730 days |
| AI run records | 90 days |
| WhatsApp conversations | 180 days after the last message |
| Email delivery events | 90 days |
| Waitlist entries and partner-platform bookings | 30 days after the class |
| Payment notification events (webhooks) | 90 days |
| Orders, entitlements (such as memberships and credits) and bank transactions | per statutory retention periods, up to 10 years (§ 147 AO, § 257 HGB) |
| Other studio data | for the term of the contract with the studio, then deleted or returned in accordance with the data processing agreement |
| Backups | daily backups 7 days, weekly backups 4 weeks; analytics warehouse with a 7-day recovery window |
Erasure
Studios can erase members and leads in the application. The personal fields are anonymised; the record remains for statistics without any reference to the person. An unsubscribe from marketing emails is kept as a hash so that no further emails are sent.
Data security
- Each studio’s data is strictly separated from that of other studios.
- All data in transit is TLS-encrypted.
- Stored data is encrypted by Google Cloud.
- Access is restricted based on roles.
- Sign-in works without passwords, via a link sent to the registered email address.
Your rights
If you are a member, lead or guest of a studio, please direct requests to your studio first, as it is responsible for your data. For the processing for which Numara Works UG (haftungsbeschränkt) is the controller, you have the following rights towards us:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR).
You may withdraw consent at any time with effect for the future (Art. 7(3) GDPR), for example via the unsubscribe link in every marketing email. This does not affect the lawfulness of processing carried out before the withdrawal.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). The data will then no longer be processed unless there are demonstrable compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for direct marketing at any time without giving reasons (Art. 21(2) GDPR).
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for Numara Works UG (haftungsbeschränkt) is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit(Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61
10555 Berlin, Germany
numara does not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR. AI drafts for coaching messages are reviewed by the coach before they are sent.
Changes
We update this information when platform features, our service providers or the legal situation change. The version published on this page applies.