Privacy policy
This privacy policy informs you, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), which personal data we process when you visit this website, for what purpose and on what legal basis. It applies to this website only, not to external sites reachable via links.
Last updated: August 2026.
1. Controller
The controller within the meaning of the GDPR is:
Dolomiti Athletic Center Srl Kampill Center, Innsbruckerstraße 31 39100 Bolzano (BZ), Italy VAT no. 03314200217
E-mail: info@dolomiti-athletic-center.com Telephone: +39 0471 180 5290
We have not appointed a Data Protection Officer, as there is no obligation to do so under Article 37 GDPR. For any data protection matter please contact us at the address above.
2. Principles
We process personal data only where this is necessary to provide a functioning website and our services, or where you have given consent. We do not sell your data and do not use it for advertising or profiling.
Depending on the processing, the legal bases are:
- Art. 6(1)(a) GDPR – your consent
- Art. 6(1)(b) GDPR – performance of a contract or pre-contractual steps
- Art. 6(1)(c) GDPR – compliance with a legal obligation
- Art. 6(1)(f) GDPR – our legitimate interest in the secure, functioning operation of the website
- Art. 9(2)(a) GDPR – your explicit consent, where health data is involved
3. Hosting and technical provision
This website runs on a server operated by Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany. The server is located in a data centre in France and therefore within the European Union. Hosting does not involve any transfer to a third country. Processing takes place on the basis of Art. 6(1)(f) GDPR and a data processing agreement under Art. 28 GDPR.
4. Server logs
We do not keep permanent access logs of visitors to this website. Our web server writes no classic access logs containing IP addresses.
For technical reasons the application produces short-lived operational logs (for example error messages). These are capped at 30 MB in total, are continuously overwritten automatically and are discarded in full each time the website is updated. They are not analysed to observe user behaviour.
Independently of this, the hosting provider processes the connection data technically required to operate the network. The services named under points 6, 9 and 10 also process your IP address, as this is technically necessary for any internet connection.
5. Cookies and similar technologies
This website sets no advertising, marketing or tracking cookies and builds no user profiles.
Technically necessary cookies are set by our authentication service Clerk (see point 9), which is loaded on all pages in order to provide the protected login area:
- __client, __client_uat – recognition of an existing login session
- __cf_bm, _cfuvid – cookies of the upstream security provider Cloudflare, used to defend against automated attacks
For signed-in staff, editing mode additionally uses the edit_session cookie, which identifies the active editing session.
The legal basis is Art. 6(1)(f) GDPR (secure operation and provision of the login area). You can delete or block cookies in your browser settings at any time; the public part of the website remains fully usable.
6. Audience measurement with Plausible
To measure page views we use Plausible, a service of Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible is designed to be privacy-friendly:
- it sets no cookies
- it stores no personal data and no IP addresses
- it performs no cross-device recognition and no profiling
- data is processed exclusively within the EU
Only aggregated figures are recorded, such as the page visited, referrer, device type and country. We cannot trace these back to individuals. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in privacy-preserving statistics).
7. Appointment request
The "Appointment request" form lets you request an appointment without obligation. In doing so we process:
- name, telephone number and e-mail address
- the service and location you are interested in
- optionally the affected body region, a preferred time frame and your message
- optionally files you upload (images or PDF, max. 8 files and 15 MB)
This data is not stored in any database of this website. It is transmitted solely by e-mail to our reception and processed in the practice's mailbox. Delivery and storage run on a mail server operated on the clinic’s own hardware, on its premises. No external e-mail provider (such as Microsoft 365 or Google Workspace) is involved — your enquiry does not leave the clinic’s own infrastructure and is not transferred to a third country.
Note on health data: details of the affected body region, your message and in particular any findings or images you upload may constitute health data within the meaning of Art. 9 GDPR. We process these special categories of personal data exclusively on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you give when submitting the form, and for pre-contractual steps under Art. 6(1)(b) GDPR. Please submit only the information genuinely required for your request.
Your enquiry is retained for as long as needed to deal with it; if treatment follows, the statutory retention periods for health records apply. You may object to further processing and request erasure at any time.
8. Contact by e-mail and telephone
If you contact us by e-mail or telephone, we process your details in order to answer your enquiry. Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR. Please note that unencrypted e-mail does not offer complete protection against access by third parties; please do not send us sensitive health data by ordinary e-mail unprompted.
9. User accounts and sign-in (Clerk)
For the protected area (staff and patients) we use the authentication service Clerk, provided by Clerk, Inc., 660 King Street, San Francisco, CA 94107, USA. Clerk processes username, e-mail address, password (only as a cryptographic hash) and session information.
Because Clerk is loaded on all pages in order to detect an existing sign-in, the cookies named under point 5 are set even when you are not signed in. In this process your IP address is transmitted to Clerk and to the upstream provider Cloudflare.
Clerk is a company based in the USA. The transfer takes place on the basis of the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and a data processing agreement. Legal basis: Art. 6(1)(b) GDPR (provision of the user account) and Art. 6(1)(f) GDPR (secure operation).
10. Google Maps
On the detail pages of our locations we embed maps from Google Maps, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open a location page, the map is loaded directly from Google. In this process your IP address and technical details of your browser are transmitted to Google; processing in the USA by Google LLC cannot be ruled out. Google may under certain circumstances associate this data with your Google account if you are signed in there at the same time. We have no influence over Google's further processing.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in convenient directions). The transfer to the USA is based on the Standard Contractual Clauses and on Google LLC's certification under the EU-US Data Privacy Framework.
If you wish to avoid this transfer, please do not open the location detail pages; the addresses and opening hours of all locations are also available on the overview page, which contains no embedded map. Further information: policies.google.com/privacy
11. Patient area
For patients to whom we grant access, we provide a protected area with individual training and exercise plans. The data processed there (name, contact details, assigned exercise plans and training content) constitutes health data within the meaning of Art. 9 GDPR. It is processed solely for the purpose of your care, on the basis of Art. 9(2)(h) GDPR (health care) in conjunction with Art. 6(1)(b) GDPR. Access is password-protected and visible only to you and the treating team. The data is stored on the EU server named under point 3.
12. Recipients of your data
We pass on your data only where this is necessary to provide our services or where we are legally obliged to do so. Recipients are:
- Contabo GmbH (Germany) – hosting and server operation, data centre in France
- Plausible Insights OÜ (Estonia) – anonymous audience measurement
- Clerk, Inc. (USA) and Cloudflare, Inc. (USA) – authentication and attack mitigation
- Google Ireland Limited (Ireland) – map display on the location pages
- Dolomiti Sportclinic – the clinic group’s e-mail infrastructure, operated on its own hardware on site
- treating doctors and therapists in our network, insofar as this is necessary for your care
Agreements under Art. 28 GDPR are in place with all service providers acting as processors. No data is passed on for advertising purposes.
13. Transfers to third countries
With the exception of the services named under points 9 and 10, no transfer of your data takes place to countries outside the EU or the EEA. Appropriate safeguards under Chapter V GDPR are in place for those transfers (the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework).
14. Retention periods
We store personal data only for as long as necessary for the stated purposes:
- appointment requests: until your enquiry has been dealt with
- treatment-related records: in accordance with the statutory retention periods for health records
- user accounts: for the duration of the access, after which they are deleted
- operational logs: on a rolling basis, maximum 30 MB, discarded at each update
15. Your rights
You have the right at any time to:
- access the data held about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent you have given, with effect for the future (Art. 7(3) GDPR)
An informal message to info@dolomiti-athletic-center.com is sufficient to exercise these rights.
You also have the right to lodge a complaint with the supervisory authority:
Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Rome, Italy E-mail: garante@gpdp.it — Website: www.garanteprivacy.it
16. Data security
Transmission takes place exclusively in encrypted form via HTTPS (TLS). We take technical and organisational measures under Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access, in particular access restrictions, encrypted password storage and regular backups. Complete protection against every conceivable attack is not technically possible when transmitting data over the internet.
17. Changes to this privacy policy
We update this privacy policy whenever our website or the services we use change. The version published on this page applies.
