Privacy Policy

Note: Translation for reference only. The German original is the legally binding version.

We are very pleased about your interest in Tanz mit der Schwester. The protection of your personal data is of particular importance to our management. You can use our websites without disclosing any personal data to us. However, if you wish to use more specific services via our websites, other online presences, applications and social media pages, we may have to process your personal data. If we wish to process data about you and cannot rely on any other legal basis, we will always ask for your consent first (for example before you submit a form to us).

When handling your personal data (such as name, address, email address or telephone number) we always comply with the applicable data protection laws. With this privacy policy we inform you about which data we process. This privacy policy also explains which data subject rights you have.

We have taken various technical and organizational measures to protect your data on our websites as effectively as possible. Nevertheless, there are always risks on the internet, and complete protection is not possible. You are therefore free to transmit your personal data to us by other means, for example by telephone, if you prefer.

This privacy policy serves not only to fulfil the obligations arising from the GDPR and to comply with the law of the member states of the European Union (EU) and the European Economic Area (EEA). It is also intended to comply with, and to be interpreted in accordance with, legal provisions such as those of the United Kingdom (UK GDPR), the Swiss Federal Act on Data Protection and the Swiss Data Protection Ordinance (DSG, DSV), the California Consumer Privacy Act (CCPA/CPRA), China's Personal Information Protection Law (PIPL), and other US state and global data protection laws. It is to be construed for each country and state in such a way that the terms and legal bases used correspond to those applicable in the respective state.

1. Definitions

We use specific terms from various data protection laws in this privacy policy. So that our statement is easy to understand, we explain those terms in advance. Where necessary for the application of the law in an individual case, the following definitions are to be interpreted or extended in accordance with the case law of the General Court of the European Union, the Court of Justice of the European Union, the Swiss Federal Supreme Court, the Supreme Court of the United Kingdom, or national data protection laws and national case law, including judge-made law and common law.

2. Name and Address of the Controller

The controller within the meaning of the General Data Protection Regulation, of other data protection laws applicable in the member states of the European Union and the European Economic Area, of the British data protection laws, of the Swiss data protection laws (DSG, DSV), of the Californian data protection laws (CCPA/CPRA), of Chinese data protection law (PIPL), as well as of international laws and other provisions of a data protection nature is:

Rahel Zelenkowits (Tanz mit der Schwester) Hörwarthstraße 92 80804 Munich Germany Phone: +49 175 9646927 Email: info@tanzmitderschwester.de Website: www.tanzmitderschwester.de

3. Collection of General Data and Information

Each visit to our websites by a data subject or an automated system records a range of general data and information, which is stored in the log files of the respective server. This may include (1) browser types and versions used, (2) the operating system of the accessing system, (3) the website from which an accessing system reaches our websites (referrer), (4) the sub-pages accessed, (5) the date and time of access, (6) an Internet Protocol address (IP address), (7) the internet service provider of the accessing system, and (8) other similar data and information used to avert danger in the event of attacks on our information technology systems.

When using this general data and information, we draw no conclusions about the data subject. This information is needed instead in order to (1) deliver the content of our websites correctly, (2) optimize the content of our websites and the advertising for them, (3) ensure the continued functioning of our information technology systems and of the technology of our websites, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. This anonymously collected data and information is therefore evaluated by us statistically and with the aim of increasing data protection and data security, in order ultimately to ensure an optimal level of protection for the personal data we process. Server log file data is stored separately from all personal data provided by a data subject.

The purpose of the processing is to avert danger and ensure IT security, as well as the purposes mentioned above. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems. The log files are deleted once the stated purposes have been achieved.

4. Contact Options via the Website and Other Data Transmissions, and Your Consent

Our websites contain information that enables quick electronic contact with us and direct communication with us, which also includes a general address for electronic mail (email address) and, where applicable, a telephone number. If a data subject contacts us by email, via a contact form, via an input form, or by other means, the personal data transmitted by the data subject is stored automatically. Such personal data transmitted to us on a voluntary basis is processed for the purposes of handling the matter or contacting the data subject.

For the transmission, storage and processing of your contact details and enquiries, and for contacting you, we obtain your consent pursuant to Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:

By transmitting your personal data, you voluntarily consent to the processing of the personal data you have entered or transmitted for the purposes of handling your enquiry and of contacting you. By transmitting your data to us, you also voluntarily give your express consent pursuant to Art. 49 (1) (1) (a) GDPR to transfers of data to third countries, to and by the companies named in this privacy policy and for the purposes named therein, in particular to such transfers to third countries for which an adequacy decision of the EU/EEA does or does not exist, as well as to companies or other bodies that are not covered by an existing adequacy decision on the basis of a self-certification or other accession criteria, and in or for which significant risks exist and no appropriate safeguards for the protection of your personal data are in place (e.g. because of Section 702 FISA, Executive Order EO 12333 and the CloudAct in the USA). When giving your voluntary and express consent, you were aware that an adequate level of data protection may not exist in third countries and that your data subject rights may not be enforceable. You may withdraw your data protection consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal. With a single action (entry and transmission) you give several consents. These are consents under EU/EEA data protection law as well as under the CCPA/CPRA, ePrivacy and telemedia law, and other international legal provisions which are required, among other things, as a legal basis for further planned processing of your personal data. By your action you also confirm that you have read and taken note of this privacy policy.

5. Routine Erasure and Restriction of Personal Data

We process and store personal data for the period necessary to achieve the purpose of the processing, or where this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or for as long as a legal basis for the processing exists.

If the purpose of the processing ceases to apply, if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the processing ceases to apply, the personal data is routinely restricted or erased in accordance with the statutory provisions.

6. Rights of the Data Subject under the GDPR

To exercise any of these rights, the data subject may contact us at any time.

7. General Purpose of Processing, Categories of Data Processed and Categories of Recipients

The general purpose of processing personal data is to handle all matters concerning the controller, customers, prospective customers, business partners, or other contractual or pre-contractual relationships between those groups (in the broadest sense), or legal obligations of the controller. This general purpose applies where no more specific purposes are stated for a particular processing operation.

The categories of personal data we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of personal data are public bodies, external bodies, internal processing, intra-group processing and other bodies.

A list of our processors and of the data recipients in third countries, as well as of international organizations where applicable, is either published on our website or can be requested from us free of charge.

8. Legal Bases for Processing

Art. 6 (1) (a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific purpose. Where processing is necessary for the performance of a contract to which the data subject is party — as is the case, for example, for processing operations necessary for the supply of goods or the provision of another service — the processing is based on Art. 6 (1) (b) GDPR. The same applies to processing operations necessary to carry out pre-contractual measures, for example in the case of enquiries about our services. Where we are subject to a legal obligation requiring the processing of personal data, such as the fulfilment of tax obligations, the processing is based on Art. 6 (1) (c) GDPR.

In rare cases, processing personal data may be necessary to protect the vital interests of the data subject or of another natural person — for example if a visitor to our premises were injured and their name, age, health insurance data or other vital information had to be passed to a doctor, hospital or other third party. The processing would then be based on Art. 6 (1) (d) GDPR.

Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the legal basis is Art. 6 (1) (e) GDPR.

Finally, processing operations may be based on Art. 6 (1) (f) GDPR. This legal basis covers processing operations not covered by any of the above legal bases, where processing is necessary for the purposes of a legitimate interest pursued by us or by a third party, provided that the interests and fundamental rights and freedoms of the data subject do not override those interests. The European legislator considered that a legitimate interest could be assumed, for example, where the data subject is a client of the controller (Recital 47, sentence 2 GDPR).

9. Legitimate Interests Pursued by the Controller or a Third Party, and Direct Marketing

Where the processing of personal data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the conduct of our business activities for the benefit of the well-being of our staff and shareholders.

We may send you direct marketing about our own goods or services that are similar to the goods or services you have enquired about, ordered or purchased. You may object to direct marketing at any time (for example by email). No costs arise for you other than transmission costs at the basic rates. The processing of personal data for direct marketing purposes is based on Art. 6 (1) (f) GDPR; the legitimate interest is direct marketing.

Our messages and newsletters may also constitute communication for direct marketing purposes within the meaning of Art. 13 (2) of EU Directive 2002/58 (ePrivacy Directive) and the national law resulting from that directive, provided that we obtained your electronic and other contact details in the context of the sale of a service or product — which includes the creation of a free user account granting access to free content on our websites and to publications (newsletters, etc.) — and provided that the direct marketing promotes similar products or services, so that the direct marketing is permitted even without consent (cf. CJEU, judgment of 13 November 2025, Case C-654/23). In such cases you may refuse the use of your contact details at any time free of charge.

10. Storage Period for Personal Data

The criterion for the duration of storage of personal data is the respective statutory retention period. Where no statutory retention period exists, the criterion is the contractual or internal retention period. After the period expires, the corresponding data is routinely erased, provided it is no longer required for the performance or initiation of a contract. This applies in particular to all processing operations for which no more specific criteria have been defined.

11. Statutory or Contractual Requirements to Provide Personal Data; Necessity for Entering into a Contract; Consequences of Failure to Provide

We inform you that the provision of personal data is partly required by law (for example tax regulations) or may also result from contractual provisions (for example details of the contracting party). It may be necessary for the conclusion of a contract that a data subject provides us with personal data which we subsequently have to process. A data subject is, for example, obliged to provide us with personal data when our organization concludes a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject must contact us. We inform the data subject on a case-by-case basis whether the provision of the personal data is required by law or by contract or is necessary for the conclusion of a contract, whether there is an obligation to provide the personal data, and what the consequences of failing to provide it would be.

12. Existence of Automated Decision-Making

As a responsible organization, we normally refrain from automated decision-making and profiling. If we carry out automated decision-making or profiling in exceptional cases, we inform the data subject either separately or via a sub-item in this privacy policy (here on our website). In that case, the following applies:

Automated decision-making, including profiling, may occur where this is (1) necessary for entering into or the performance of a contract between the data subject and us, or (2) permitted by Union or member state law to which we are subject and that law lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject, or (3) based on the data subject's explicit consent.

In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we implement suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject. In those cases you have the right to obtain human intervention on our part, to express your point of view and to contest the decision.

Meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject, will be set out in this privacy policy where applicable.

13. Recipients in a Third Country, Appropriate or Suitable Safeguards, and How to Obtain a Copy of Them or Where They Are Available

Under Art. 46 (1) GDPR, the controller or a processor may transfer personal data to a third country only if the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Appropriate safeguards may be provided by standard data protection clauses without requiring any specific authorization from a supervisory authority, Art. 46 (2) (c) GDPR.

Standard contractual clauses of the EU or other appropriate safeguards are agreed with all recipients in third countries before personal data is transferred for the first time, or the transfers are based on adequacy decisions. It is therefore ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all processing of personal data. Every data subject can obtain a copy of the standard data protection clauses or adequacy decisions from us. They are also available in the Official Journal of the European Union.

Art. 45 (3) GDPR empowers the European Commission to decide, by means of an implementing act, that a non-EU country ensures an adequate level of protection — that is, a level of protection for personal data essentially equivalent to that within the EU. Adequacy decisions mean that personal data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar rules apply to the United Kingdom, Switzerland and some other states.

In all cases in which the European Commission, or a government or competent authority of another state, has decided that a third country ensures an adequate level of protection and/or that a valid framework exists (for example the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, or the UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to members of such frameworks (for example self-certified entities) are based exclusively on that entity's membership of the respective framework or on the respective adequacy decisions. Every data subject can obtain a copy of the frameworks from us; they are also available in the Official Journal of the European Union, in published legislative materials, or on the websites of data protection supervisory authorities or other authorities or institutions.

14. Right to Lodge a Complaint with a Data Protection Supervisory Authority

As the controller, we are obliged to inform data subjects of the existence of a right to lodge a complaint with a supervisory authority. This right is governed by Art. 77 (1) GDPR. Under that provision, every data subject has the right, without prejudice to any other administrative or judicial remedy, to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or place of the alleged infringement, if they consider that the processing of personal data relating to them infringes the General Data Protection Regulation. The EU legislator limited this right only to the extent that it may be exercised in respect of a single supervisory authority (Recital 141, sentence 1 GDPR). This rule is intended to avoid duplicate complaints in the same matter by the same data subject. If a data subject wishes to complain about us, we therefore ask that only one supervisory authority be contacted.

15. Registration or Completion of Input Forms on Our Website, and Your Consent

You have the option of registering on our websites by providing personal data and/or of completing input forms. Which personal data is transmitted to us in doing so is determined by the respective input form used for the registration or entry. The personal data you enter is processed exclusively for internal use by us and for our own purposes. We may, however, pass your personal data to one or more processors, who likewise use your personal data exclusively for purposes attributable to us as the controller. Data may also be passed on if you have instructed us to do so; the legal basis is then Art. 6 (1) (b) GDPR.

Specifically, we offer a registration and contact form on our website. Entries from this form are received on our own webspace at our hosting provider (see section 16) and are forwarded exclusively by email to our mailbox info@tanzmitderschwester.de. No database and no file containing your entries is created on the server, and no data is passed on to any further third party.

Registering or entering data on our website may additionally result in the storage of the IP address assigned by your internet service provider, together with the date and time of the registration or entry. This data is stored on the basis that only in this way can misuse of our services be prevented, and that this data makes it possible, if necessary, to investigate criminal offences committed. Storage of this data is therefore necessary for our protection. The purpose of this processing is to avert danger, detect misuse and investigate criminal offences, as well as the purposes mentioned above. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems and the investigation of criminal offences. This data is not passed on to third parties as a matter of principle, unless there is a legal obligation to do so or the disclosure serves criminal prosecution.

Registering, entering and transmitting your personal data also enables us to offer you content or services which, by their nature, can only be offered to registered or known persons. You are free to have the personal data provided during registration amended at any time, or erased entirely from our records. The purposes of the processing are the receipt of the data by us and the use of your data for further processing, for communication with you, and for mapping or implementing the registration or the purposes of the entry. The legal basis is your consent under Art. 6 (1) (a) GDPR and/or Art. 49 (1) (1) (a) GDPR.

By entering and transmitting your data, you voluntarily consent to the processing of the personal data you have entered. By entering your data and transmitting it to us, you also voluntarily give your express consent pursuant to Art. 49 (1) (1) (a) GDPR to transfers of data to third countries, to and by the companies named in this privacy policy and for the purposes named therein, in particular to such transfers to third countries for which an adequacy decision of the EU/EEA does or does not exist, as well as to companies or other bodies that are not covered by an existing adequacy decision on the basis of a self-certification or other accession criteria, and in or for which significant risks exist and no appropriate safeguards for the protection of your personal data are in place (e.g. because of Section 702 FISA, Executive Order EO 12333 and the CloudAct in the USA). When giving your voluntary and express consent, you were aware that an adequate level of data protection may not exist in third countries and that your data subject rights may not be enforceable. You may withdraw your data protection consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal. With a single action (entry and transmission) you give several consents. These are consents under EU/EEA data protection law as well as under the CCPA/CPRA, ePrivacy and telemedia law, and other international legal provisions which are required, among other things, as a legal basis for further planned processing of your personal data. By your action you also confirm that you have read and taken note of this privacy policy.

We provide every data subject, at any time on request, with information about which personal data is stored about them. Furthermore, we rectify or erase personal data at the request or on the indication of the data subject, provided that no statutory retention obligations or other grounds justifying the processing conflict with this. All of our staff are available to you as contacts in this regard.

16. Data Protection Provisions on the Use of STRATO

STRATO is a provider of web hosting services, domain registrations, cloud storage, online shops and other internet-based services. With an extensive portfolio of products, STRATO supports both private individuals and businesses in designing and managing their online presence effectively. STRATO's services are designed to offer users reliable, secure and user-friendly solutions for their web projects.

When STRATO services are used, personal data such as names, addresses, email addresses, telephone numbers, payment information and usage data of the services offered is processed. This information is necessary in order to provide the services, manage user accounts, handle support requests and ensure the security of user data.

The operating company of the service, and therefore the recipient of the personal data, is: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany.

Purposes for which the personal data is processed, and the legal basis for the processing: the purpose of the data processing is the use of the web hosting services and the other products offered. The processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR to which the data subject is party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as improving our services, ensuring network and information security, and the use of external hosting.

The criteria for determining the period for which the personal data is processed are the contractual relationship between us and the operating company of the service, or statutory or contractual retention periods. The provision of the personal data is neither required by law or by contract nor necessary for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If it is not provided, however, our services or those of the operating company may not be available.

Further information and the applicable data protection provisions of STRATO can be found at https://www.strato.de.

17. Cookies and Local Storage in the Browser

This website does not use cookies. No files enabling recognition of visitors are stored on their devices. Only the language setting (German/English) chosen by the data subject is stored locally in the browser (localStorage) so that the site is displayed in the desired language on the next visit. This storage is necessary for the service explicitly requested by the data subject (Section 25 (2) No. 2 TDDDG) and contains no personal data. A cookie banner is therefore not required.

18. Anonymous Reach Measurement (cookie-free)

To improve our services, we collect anonymous visit statistics on our own server. Only aggregated daily counters are stored: number of page views per page, language version (German/English), traffic source (e.g. search engine or direct visit), device category (mobile/tablet/desktop), operating system category (e.g. iOS/Android), average time spent per page, country of origin, and the number of clicks on contact and sign-up links. No cookies are set, no IP addresses are stored, no individual usage profiles are created, and no data is transferred to third parties; identifying individual persons is not possible. The legal basis is our legitimate interest in the statistical analysis of the use of our services (Art. 6 (1) (f) GDPR).

19. Instagram

This website contains a simple link to our Instagram profile. No Instagram components (e.g. embedded content or plugins) are integrated; merely visiting our website therefore does not transfer any data to Instagram. Only when the data subject clicks the link do they reach Instagram's pages (operator: Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland); from that point on, Instagram's privacy policy applies: https://privacycenter.instagram.com/policy.


Last updated: July 2026

The privacy policy above was created with the support of a generator developed by lawyers for digital law, data protection consultants and the ISO 9001 certification body.

Contact

Tanz mit der Schwester · München

Phone: +491759646927 · info@tanzmitderschwester.de · Instagram