Privacy Policy of Epassi Deutschland GmbH

Effective: August 2026

We are pleased that you use our online and digital services. Below, we wish to inform you about how we handle your personal data, the purposes of processing, and your rights under the General Data Protection Regulation (GDPR) in connection with the services we provide.
Epassi Deutschland GmbH (also referred to as “Epassi”, “we” or “us”) is a group company of Epassi Group (“Epassi Group”). We respect your privacy and are committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR). This Privacy Policy describes how we process personal data, what types of data we collect, for what purposes they are used, and to which parties data may be disclosed. This Privacy Policy applies to all customers and users of Epassi services, including visitors to our websites and mobile applications.
We believe you should know how we use your personal data and how you can control the collection and use of your personal data. If you have questions about data processing or wish to exercise your rights, please contact us using the contact details provided in Section 1. Please note that our services may contain links to external websites or third-party services over whose content we have no control. This Privacy Policy does not apply to the use of third-party content.

1. Controller and Contact Details

Controller: Epassi Deutschland GmbH
Address: Hanseatenhof 8, 28195 Bremen
Website: www.epassi.de
Email: datenschutz@epassi.com
Data Protection Officer: Ms Taika Pöntinen — dpo@epassi.com

2. Types, Purposes, Data Categories, Legal Bases and Retention Periods

Purpose of Processing Categories of Data Processed Legal Basis Retention Period
Service provision by Epassi including account management, enabling the use of merchant/Epassi Sport partner services, offering products and services to the user, billing of the employer Name, company, transaction information, purchase history, access logs, user device information, email address, personal identification code, phone number, postal code, user balance, selected benefits, date and time of check-in and check-out, Type of membership, tariff, history, contract start and end, membership number, selected venue, cancellation or suspension period Contract performance, legitimate interest (depending on service type) For as long as the end user uses the services + 2 years; 10 years for transaction and financial information
User communication, location-based, personalization and marketing Name, email address, phone number, user settings, user balance, company, geographic location, user interactions via cookies Consent, legitimate interest (user communication) For as long as the end user is a contractual partner of Epassi and/or a marketing opt-in has not been withdrawn
Website analytics and cookies IP address, user settings, user device, app version, app language, status of Google Services, other information collected via cookies Consent, legitimate interest Maximum 2 years or until withdrawal
Verification with partners Name, company, date of birth, photo Contract performance, legitimate interest, legal obligation Until withdrawal of membership
App registration and terms of use Email address, alias (display name), date of birth, check-in and check-out data, language setting; where registration via generic invitation link: additionally first name, last name, email address; optional: gender, profile photo Contract performance For the pre-contractual relationship and the duration of the terms of use
Authentication and access management (login) Email address, login history, device information, role and permission data (RBAC) Contract performance, legitimate interest For as long as the end user uses the services + 2 years
Payment processing (SEPA direct debit mandate) SEPA mandate data, tokenised payment data (no IBAN stored) Contract performance, legal obligation Contract duration and statutory retention periods (billing purposes)
Registration for online courses with network partners First name, last name, employer Consent Shared with third parties for the stated purpose; course participations are treated as check-ins and stored accordingly until the consent is removed
Interface use (identity/authorisation verification with partners) Name, company, date of birth, photo Contract performance, legitimate interest, legal obligation Until withdrawal of membership
App registration and terms of use Email address, alias (display name), date of birth, language setting; where registration via generic invitation link: additionally first name, last name, email address; optional: gender (mandatory for Activity Rewards), profile photo (mandatory for Fitness Network) Contract performance For the pre-contractual relationship and the duration of the terms of use
Authentication and access management (login) Email address, login history, device information, role and permission data (RBAC) Contract performance, legitimate interest For as long as the end user uses the services + 2 years
Payment processing (SEPA direct debit mandate) SEPA mandate data, tokenised payment data (no IBAN stored) Contract performance Contract duration and statutory retention periods (billing purposes)
Registration for online courses with network partners First name, last name, email address Contract performance Shared with third parties for the stated purpose; course participations are treated as check-ins and stored accordingly; statutory retention periods apply
Customer support First name, last name, email address, date of birth, email, contact details, company, membership status, salutation, free text field content, phone number, call recordings/transcipts Contract performance, legitimate interest 24 Months after the resolution of support case; compliance with statutory obligations
Personal preferences to customize app Studio favourites, preferred sports, training goals, height, weight (voluntary) Consent Until deletion by the user or termination of the contractual relationship
Fraud detection IP address, member ID, device type/ID, browser type, geolocation, pages visited, links clicked Legitimate interest Until no longer required for security purposes, subject to statutory retention periods
Service Development and Analytics Data generated from end-user service usage Legitimate interest Epassi uses service usage data to analyze functionalities and improve the service. Analysis helps us develop the service according to your needs and preferences. Epassi strives to process personal data as minimally as possible relative to the purpose and legitimate interest.
Data is retained for up to two years or until the data category is deleted earlier.
Prize draws Name, date of birth, email, contact details, company, membership status, salutation Consent For the duration of the prize draw + 4 months after the prize draw, subject to statutory retention periods
Accessibility Feedback As specified in the accessibility statement Legal obligation Data is retained for three years from the response to each feedback submission

3. Sources of Data

We collect personal data:

  • Directly from you (e.g. when registering in the app, entering into a contract, or communicating with Customer Service)
  • From your employer (via registration by the employer)
  • Automatically via our websites and applications (e.g. cookies, device information)
  • From other sources, e.g. updated address data from delivery service providers or public registers

4. Disclosure, Recipients and Processors

We carefully review any disclosure of personal data and ensure that partners and sub-processors have committed to compliance with applicable data protection laws prior to receiving personal data, for example by entering into appropriate data processing agreements.

Disclosure to Epassi Sports Partners (Epassi Sports)
Personal data is not shared with third parties for commercial purposes without your consent. We share personal data with our Epassi Sports Partners to the extent necessary to grant you access to their facilities.
At check-in, the following data is transmitted to the partner for identity verification and authorisation: full name, photo, employer’s company name, check-in and check-out timestamps, check-in type, and duration of stay. The photo serves fraud prevention purposes; the company name ensures continuity of use after contract expiry. Timestamps and duration of stay are required for retrospective identification in the event of a reported rule violation. The partner is not permitted to use the photo for any purpose beyond identifying the member during their visit.
The Merchants also have access to check-in history, subscription information, and voluntarily provided information on training goals, sport preferences, and physical characteristics of users of the facility. The Merchant Portal’s check-in history shows only abbreviated usernames or hashed IDs, the member ID, and the last check-in timestamp. Exports do not contain names, photos, email addresses, or company names. Data in the Merchant Portal is automatically deleted upon termination of the Epassi membership, or at the latest 6 months after the last check-in.

Unsolicited personal data
If personal data is transmitted to us that we have not requested — in particular health data that users or employers voluntarily disclose in support requests, document submissions, or other communications — we will not process such data and will delete it without undue delay to the extent technically possible. We kindly ask that you do not transmit data beyond the scope required for the respective purpose.

List of Processors and Further Recipients
Personal data may, when necessary, be disclosed for the processing purposes referred to in this privacy policy to the following third parties:

  • To Epassi’s merchants, for financial and payment-processing purposes necessary in connection with the use of the services.
  • To a financing service provider or other service providers, for the financing of products included in Epassi’s product range.
  • To Epassi’s employer clients, as described above in Section 3, “Sources of Data.”
  • To Epassi’s service providers, such as web-hosting providers, where and to the extent that the processing of personal data is necessary for the implementation of the Epassi service.
  • To Epassi’s group companies, on the basis of a data processing agreement concluded with them, to the extent that they carry out any part of the Epassi service or its support functions.

Epassi may further share personal data in connection with a possible merger, sale of our assets, financing or sale of all or part of our business, and in connection with other similar arrangements.

Personal data will also be disclosed to third parties where this is required by applicable legislation governing the processing of personal data or by an order issued by a competent authority, and for the purpose of investigating any infringing use of the products or services and ensuring the safety and usability of Epassi’s products and services.

In order for Epassi to provide the agreed services, the following processors of personal data on behalf of Epassi also process personal data. List of personal data processors and other recipients of data:

  • ABlyft (A/B testing tool for website optimisation)
  • Amazon Web Services (hosting of the Customer Portal and other products, including database and storage services, location/geocoding services for studio search, and message queues for the Epassi app)
  • Adyen N.V. (financial tool; payment service provider – SEPA direct debit)
  • Auth0 (Okta) (identity and access management / login)
  • Brevo (transactional emails and push notifications)
  • Consent Manager (consent management tool on the website: further information: https://www.consentmanager.de/datenschutz/)
  • Colony Labs, Inc. / Scribe (documentation tool)
  • Datev eG (financial tool)
  • Dealfront (Leadfeeder – lead generation and analytics tool)
  • DocuSign (signing tool)
  • eMotivo GmbH (support tool)
  • Google (marketing tools: Google Ads, DoubleClick, Tag Manager, YouTube, Maps (Google Ireland Limited as processor, Art. 28 GDPR). Where consent is given, cookies are set and pseudonymous usage profiles are created (Art. 6(1)(a) GDPR); without consent, GA4 sends only cookieless pings without user attribution for statistical modelling.)
  • gridscale GmbH (web hosting tool)
  • Honeycomb (observability/tracing tool for technical fault diagnosis: diagnostic data may in individual cases contain personal data. Log data is stored for 21 days. Legal basis: Art. 6(1)(f) GDPR.)
  • HubSpot (customer service and marketing tool)
  • IMEDIAPP SA / Batch.com (user communication: further information: https://batch.com/de/privacy-policy)
  • Kombo Technologies GmbH (HR interface tool for simplified registration)
  • LinkedIn, Inc. (marketing tools: LinkedIn Ads and Analytics)
  • LoyJoy GmbH, Kapuzinerstr. 20, 48149 Münster (chatbot platform)
  • Lucanet (financial tool)
  • Matomo (app analytics tool: further information: https://matomo.org/privacy-policy/)
  • Meta Platforms, Inc. (marketing tools)
  • Microsoft (M365 products)
  • Network Partners (identity and authorisation verification)
  • New Relic, Inc. (performance monitoring)
  • Oracle NetSuite (CRM tool)
  • Pimcore (financial tools)
  • Podscribe (marketing tool)
  • PostHog (product analytics, user surveys, and feature flag system: PostHog processes only pseudonymised user IDs; re-identification by PostHog is not possible. EU Cloud hosting active.)
  • Spotify Ad Analytics (marketing tool)
  • The UK Trade Desk Ltd (marketing tool)
  • Vimeo.com, Inc. (marketing tool)
  • Zendesk GmbH, c/o TaylorWessing, Neue Schönhauser Str. 3–5, 10178 Berlin (chatbot / customer support tool: the chatbot does not actively request personal data. Voluntarily entered personal data is deleted where no legitimate basis for processing exists.)

5. Data Transfers Outside the EU/EEA

In exceptional cases, services provided by our processors may be performed outside the EU/EEA. In such cases, we ensure that:

  • an adequate level of data protection exists by virtue of an adequacy decision of the European Commission, or
  • Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR are used, supplemented by appropriate safeguards.

6. Security Measures

Ensuring the confidentiality, integrity, and availability of personal data is important to Epassi. Epassi’s security management system is based on legal, regulatory, and contractual requirements. The Epassi service and IT systems are certified according to the ISO27001 information security standard. The security management system consists of appropriate technical, administrative, and organizational measures to protect personal data from unauthorized access, disclosure, destruction, and processing.

Administrative and organizational measures:

  • Epassi services are implemented and personal data stored in two separate EU-based data centers certified to internationally recognized security standards
  • Role-based access control
  • Technical segregation of personal data
  • Supplier and system monitoring in accordance with ISO27001

Technical measures:

  • Geo-redundant server locations within the EU
  • Access and authorisation concepts (role-based)
  • Firewall and encryption technologies
  • Backup and recovery systems
  • HTTPS connectionsFor website visitors: To protect your data against unauthorised access as comprehensively as possible, we implement technical and organisational measures. We use an encryption procedure on our websites. Your data is transmitted between your device and our server via TLS encryption.

7. Rights of Data Subjects

Under applicable data protection laws, you have certain rights regarding the processing of personal data.

a. Right of Access
You have the right to obtain confirmation as to whether personal data concerning you is being processed, and to access that data.

b. Right to Rectification and Erasure
You have the right to rectification of inaccurate personal data and to erasure of personal data. Please note that certain data must be retained due to statutory obligations.

c. Right to Data Portability
Where applicable, you have the right to receive your data in a structured, commonly used, and machine-readable format.

d. Right to Restriction of Processing
Under the conditions set out by law, you have the right to request the restriction of processing of your personal data.

e. Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis.

f. Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time.

g. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with the State Commissioner for Data Protection: https://www.datenschutz.bremen.de/wir-ueber-uns/online-meldungen/beschwerdeformular-15253

8. Exercising Your Rights & Identity Verification

Please direct your requests by email to: datenschutz@epassi.com. To verify your identity, we reserve the right to request additional information. Your request will be responded to within one month. In certain cases (e.g. statutory retention obligations), erasure may not be possible. For repeated requests, a reasonable processing fee may be charged.

9. Cookies

We use cookies on our websites. Cookies are small text files that are stored on and can be read from your device. A distinction is made between session cookies, which are deleted once you close your browser, and persistent cookies, which are stored beyond the individual session.

10. Third-Party Content

10.1 Embedded Videos 

We embed videos from third-party providers in our app and on our websites. For such content, the respective third-party provider is responsible under data protection law and identifies such content accordingly.

11. Use of Artificial Intelligence

Epassi uses tools that employ artificial intelligence (AI) in the provision of its services, including large language models and machine learning models. However, Epassi’s use of AI is subject to strict limitations imposed by contractual agreements, technical restrictions, and internal policies, to ensure that personal data is never shared with AI models in a manner that could compromise data protection, for example by training the AI. The use of these tools and applications at Epassi does not impair or hinder the exercise of data subjects’ rights. You have the right to object at any time to the processing of your personal data by AI.

12. Changes to this Privacy Policy

This Privacy Policy may be amended at any time. The current version is available on our website (https://epassi.de/datenschutz/). Please note the effective date stated above and check this page regularly to stay informed about any changes.

13. Language

This Privacy Policy is provided in German and English. In the event of any discrepancy between the language versions, the German version shall prevail.