Privacy Policy
We are pleased that you are using our BLACKROLL mobile app (hereinafter“App”), which is available for download from the Apple and Google app stores, and we thank you for your interest in our company and our services. Protecting your privacy while you use our App is important to us.
We would like to inform you about the processing of your personal data and your rights as a data subject in connection with the use of our App,
BLACKROLL AG
Hauptstraße 17
CH-8598 Bottighofen
Switzerland
Phone: +41 (0)715085779
Email: [email protected]
(hereinafter also“we” or“BLACKROLL”)
as the data controller within the meaning of data protection law and, at the same time, as a service provider, would like to provide you with the following information.
The processing of your personal data is carried out exclusively in accordance with the legal provisions of Swiss data protection law, taking into account the data protection laws of the European Union, in particular the EU General Data Protection Regulation (GDPR), as well as other legal provisions regarding data protection.
This privacy policy applies only to our app. It does not apply to our online store (available at blackroll.com/de/shop) or any of our other websites. Furthermore, it does not apply to third-party websites operated by other providers that are linked to from the app, in particular the online stores of distributors of BLACKROLL products. Therefore, please also review the privacy notices on those sites as needed. In addition, we may provide you with further privacy notices in other situations involving contact or data processing, which you should also review as necessary.
1. Scope of Data Protection, Categories of Data, and Sources
The subject matter of data protection is personal data. Personal data refers to any information relating to an identified or identifiable natural person. Your personal data therefore includes all data that allows you to be identified, such as your name, address, phone number, or email address.
We regularly process the following categories of data about you:
- Master data, in particular last name, first name, and gender.
- Contact information, specifically mailing address, phone number, and email address.
- Interest data, specifically data you provide to us as part of our contractual user relationship, e.g., regarding sports, pain points, etc.
- Usage data, specifically the pages/screens of our app that you visit, access times, and your IP address.
- Training data, specifically information regarding the type, date/time, and duration of the exercises you perform in the app.
Within the scope of our contractual relationship, you must provide the personal data necessary to fulfill the contractual obligations under the Terms of Use and to comply with legal obligations. We will inform you in an appropriate manner (e.g., by marking required fields in forms) as to which specific data this entails in your case.
Your personal data is provided by you, specifically from the information you provide and from your use of the app.
2. Purposes of Processing and Legal Bases
We process your data only for specific purposes and to the extent permitted by applicable law. We will process your data for the following purposes and based on the following legal grounds:
- Consent: We will process certain data only on the basis of your prior voluntary consent. You have the right to withdraw your consent at any time with future effect (see also Section 15).
- Performance of a contract or implementation of pre-contractual measures: In particular, to carry out and manage our contractual relationship with you based on the Terms of Use.
- Compliance with a legal obligation: In addition, we process your personal data to comply with legal obligations, such as commercial and tax-related retention requirements.
- Protection of legitimate interests: We will process certain data to protect our legitimate interests, e.g., to provide and operate this app.
For information on how you can object to such processing and under what conditions we must cease or restrict our processing, please see Section 15.
Please note that this is not a complete or exhaustive list of possible legal bases, but merely examples intended to make the legal bases under data protection law more transparent. For more detailed information on the legal bases for the individual data processing activities in our app, please refer to the explanations in the following sections.
Since we are headquartered in Switzerland and operate our app from there, the collection, processing, and use of your personal data generally take place in Switzerland, unless otherwise specified in this Privacy Policy. Specifically , we collect, process, and use your personal data in the contexts described in the following sections.
3. Downloading the app
When you download our app, the necessary information is transmitted to the respective app store. This includes, in particular, your username, email address, the time of the download, and your device’s unique identifier. However, we have no control over this data collection, as it is carried out by the respective app store operator. Furthermore, we do not store this data.
In this context, please also refer to the respective privacy policies of the app store operators:
- for the iOS App Store: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, available at www.apple.com/de/privacy/privacy-policy/, and
- for the Google Play Store: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, available at policies.google.com/privacy?hl=de.
4. Usage Data
You can generally visit our app without providing any personal information. However, when you visit our app, the following information regarding your access and usage may be stored:
- IP address of the requesting device,
- screens/videos viewed,
- the HTTP response code (if applicable),
- the previous screen or the linked screen(s)/page(s) you accessed (referrer/destination URL),
- date, time, duration, and time zone of the server request or interaction (e.g., first/last time the app was opened/closed, last login, screens/videos viewed, starting/ending a workout, clicking a call-to-action button),
- browser type and version,
- operating system used by the requesting device,
- uninstallations/updates of the app,
- Your device model, unique identifier of the device used (IMEI – International Equipment Identity), device name, and the ID assigned to the device.
We process this usage data based on our legitimate interests in providing the app, ensuring its technical operation, logging the consent you have provided, and maintaining the security of our IT systems. In doing so, we pursue the interest of enabling and permanently maintaining the use of our app and its technical functionality. This data is processed automatically when you access our app. Without providing this data, you cannot use our app. We do not use this data for the purpose of drawing conclusions about your identity.
You cannot object to the processing of your usage data, as this data is absolutely necessary for the smooth operation of the app. It is not possible to use the app without the processing of this data.
5. Cookie-like technologies
We use cookie-like technologies to optimize the app’s design. Among other things, this enables us to provide certain features, simplify navigation, and ensure a high level of user-friendliness.
Cookie-like technologies are based on identifiers that allow our web server to recognize your device, for example, to determine whether your device has previously communicated with us. As such, they serve the purpose of enabling the use of our app, making it more convenient for you, and optimizing our service offerings. For detailed information on the type, function, purposes, and any third-party providers used in connection with the use of cookie-like technologies, please refer to the provisions below. The legal basis for the use of cookie-like technologies is your consent, which you provide to us when you open the app for the first time.
You can revoke your consent at any time by preventing the storage of cookie-like technologies through the appropriate app settings. To do so, go to the “Settings > Privacy” menu and disable the “Allow cookie-like technologies and usage analytics” feature.
5. Newsletter
We use the so-called double opt-in procedure to send the newsletter; that is, we will only send you a newsletter via email once you have expressly confirmed that you would like us to activate the newsletter service. We will then send you a confirmation email and ask you to confirm that you wish to receive our newsletter by clicking on a link contained in that email. By completing this separate double opt-in process, you have given your consent to receive the newsletter.
If you subscribe to the newsletter through your user account, we may waive the requirement for a second double opt-in, as your email address has already been verified via a confirmation link during the user account activation process. In this case, a simple opt-in (by checking a box) in your user account is sufficient.
We send newsletters as defined in this Section 8 only after you have subscribed, i.e., based on your consent. If the newsletter’s content is specifically described during the subscription process, that description determines the scope of your consent. Otherwise, our newsletters contain information about our products, offers, promotions, events, and our company.
If you no longer wish to receive newsletters from us, you may withdraw your consent at any time. A written notice (e.g., email, letter) sent to the contact information listed in Section 16 or to [email protected] is sufficient for this purpose. Of course, you will also find an unsubscribe link in every newsletter.
Newsletters are sent via MailChimp, a newsletter distribution platform provided by the U.S. company Rocket Science Group LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. Data processing is carried out on our behalf based on a Data Processing Agreement that we have entered into with MailChimp. In this agreement, MailChimp commits to protecting our users’ data, processing it only on our behalf, and, in particular, not disclosing it to third parties.
The email addresses of our newsletter subscribers, as well as their other data described in this notice, are stored on MailChimp’s servers in the United States. MailChimp uses this information to send and analyze the newsletters on our behalf. Furthermore, according to MailChimp’s own information, it may use this data to optimize or improve its own services—for example, to technically optimize the delivery and presentation of newsletters or for business purposes, such as determining which countries the recipients are from. However, MailChimp does not use our newsletter recipients’ data to contact them directly or to disclose it to third parties.
We trust in MailChimp’s reliability, IT security, and data security. MailChimp is certified under the EU-U.S. Privacy Shield and is therefore committed to complying with EU data protection regulations (see www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG).
You can view MailChimp’s privacy policy here: mailchimp.com/legal/privacy/. MailChimp also uses the analytics tool Google Analytics and may integrate it into the newsletters. Information about Google Analytics can be found in the relevant section of our website’s general privacy policy: www.blackroll.com/de/datenschutzerklaerung.
Please note that after the newsletter is sent, we analyze your user behavior in relation to our newsletter. For this analysis, the emails we send contain so-called web beacons—also known as tracking or tracking pixels—as well as specially encoded links. Web beacons are single-pixel image files that link to our website and, together with the encoded links, enable us to analyze your user behavior regarding our newsletter (so-called open or click tracking). This is done by collecting technical information—such as details about your browser, your system, your IP address, and the time the email was opened or the link was clicked—via web beacons and encoded links, which are assigned to your email address and linked to a unique ID.
So-called “open tracking” via web beacons is not possible if you have disabled the display of images by default in your email program. In this case, however, the newsletter will not be displayed in its entirety, and you may not be able to use all of its features. If you manually enable the display of images, the tracking described above will take place. You can prevent so-called “click tracking” only by refraining from clicking on links in the respective email.
6. Device Permissions / Push Notifications
The app supports the display of notifications (so-called push notifications) on your device’s home screen as well as within the app (so-called in-app messages) using the Firebase Cloud Messaging feature of the Google Firebase service (see section 7 above). Therefore, the app may prompt you to grant the corresponding device permission. Granting this permission is voluntary. However, if you wish to receive push notifications, granting this permission is required, as you will otherwise be unable to use this feature. We need this permission to provide you with the desired services in accordance with our Terms of Use.
To send you push notifications or in-app messages, we use Google Firebase technology (see Section 7 of this Privacy Policy for details). Your device is assigned a pseudonymized push reference, which also provides information about when and for how long a specific push notification or in-app message was read. This serves as the destination for push notifications and in-app messages and is used by us to display push notifications and in-app messages on your device.
Even if push notifications or in-app messages contain third-party content from distributors of BLACKROLL products, your personal data will not be transmitted to these distributors.
This permission remains active until you disable it on your device. Push notifications can be disabled and re-enabled at any time. On a device running the Android operating system, this can be done, for example, via “System Settings > Apps > BLACKROLL App > Permissions”; on a device running the iOS operating system, via “System Settings > BLACKROLL App > Notifications.”
7. Security
We implement technical and organizational security measures to protect your personal data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our data processing and security measures are updated in line with the current state of the art.
In particular, the personal data you transmit as part of your user account is securely transmitted to us via encryption. This applies to both the registration process and the login process.
We use the Transport Layer Security (TLS) encryption protocol, more widely known by its predecessor name, Secure Sockets Layer (SSL).
Please note, however, that we cannot guarantee complete data security, particularly when communicating via the contact form or email. Therefore, especially when sending confidential information, we recommend using a secure method of transmission, such as regular mail.
Our employees are bound by confidentiality regarding personal data.
8. Contact for Questions Regarding Data Protection
If you have questions regarding data protection or wish to exercise your rights as a data subject, you can contact us as follows:
BLACKROLL AG
Hauptstraße 17
CH-8598 Bottighofen
Switzerland
Fax: +49 (0)7141 309 8853-9
Email: [email protected]
9. Changes
From time to time, it may be necessary to update the content of this Privacy Policy. We therefore reserve the right to change it at any time. We recommend that you review the most current version of this Privacy Policy whenever you visit our app again. We will also publish the updated version of the Privacy Policy here.
As of: October 2022