Privacy policy
At aureyoga, we respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and otherwise process personal data when you visit our website www.aureyoga.com (the “Website”), book or attend our yoga classes and workshops, contact us, or otherwise interact with us.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Austrian Data Protection Act (Datenschutzgesetz – DSG) and other applicable data-protection laws.
1. Data Controller
The controller responsible for the processing of your personal data is:
aureyoga
Email: aureyoga18@gmail.com
Website: www.aureyoga.com
If you have any questions about how we process your personal data or wish to exercise your data-protection rights, please contact us at the email address above.
2. Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data.
2.1. Booking and customer information
When you book a yoga class or workshop, we may collect:
-
first and last name;
-
email address;
-
telephone number, where provided;
-
postal or residential address, where required or provided;
-
booking and attendance information;
-
information about the class or workshop booked;
-
cancellation information; and
-
payment and transaction information.
2.2. Communications
When you contact us by email, through our Website or through another communication channel, we may process the information you provide, including your name, contact details and the content of your communication.
2.3. Health-related information
Yoga is a physical activity. You may choose to inform us or our instructors about injuries, physical limitations, pregnancy or other health-related circumstances that may affect your participation.
We ask that you only provide health information that is relevant to your safe participation.
Health information may constitute special category personal data under Article 9 GDPR. Where such information is processed, we will do so only where a lawful basis under applicable data-protection law permits us to do so, including where explicit consent is required.
You are not generally required to disclose medical information to us. However, you are responsible for determining whether participation in yoga is appropriate for you and for informing the instructor of any relevant circumstances that may affect your safety.
2.4. Website and technical information
When you visit our Website, certain technical information may be collected automatically, such as:
-
IP address;
-
browser type and version;
-
device type;
-
operating system;
-
date and time of access;
-
pages visited;
-
referring website;
-
approximate usage and interaction information; and
-
technical information necessary to operate and secure the Website.
The exact information collected depends on the technical configuration of the Website and the services and cookies in use.
3. How We Use Your Personal Data
We may process your personal data for the following purposes:
-
to process and manage class and workshop bookings;
-
to process payments and refunds;
-
to communicate with you about your booking;
-
to notify you about class cancellations, changes or rescheduling;
-
to manage attendance;
-
to respond to questions and enquiries;
-
to provide and improve our services;
-
to operate, maintain and secure our Website;
-
to comply with legal and accounting obligations;
-
to prevent misuse, fraud or security incidents;
-
to send newsletters or promotional communications where you have provided the required consent or where another lawful basis permits us to do so;
-
to manage customer and business administration, including where an address is required for invoicing, accounting or other administrative purposes; and
-
to protect and enforce our legal rights where necessary.
We do not sell your personal data.
4. Legal Bases for Processing
Depending on the circumstances, we process personal data on one or more of the following legal bases under the GDPR:
-
Performance of a contract (Art. 6(1)(b) GDPR): for processing bookings, payments, refunds and related communications.
-
Legal obligations (Art. 6(1)(c) GDPR): where processing is necessary to comply with legal, accounting, tax or other legal obligations.
-
Legitimate interests (Art. 6(1)(f) GDPR): where necessary for the operation, security and administration of our business, provided that our interests do not override your rights and freedoms.
-
Consent (Art. 6(1)(a) GDPR): where we ask for your consent, for example for certain newsletters, marketing activities or non-essential cookies.
-
Explicit consent (Art. 9(2)(a) GDPR): where applicable to the processing of health-related information.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5. Booking and Payment Providers
We may use third-party booking, payment and service providers to process registrations, payments, cancellations and refunds.
These providers may process personal data on our behalf or as independent controllers, depending on the service and their respective legal roles.
Only the information necessary for the relevant transaction or service will be shared.
6. Wix
Our Website is hosted and operated using Wix.com.
Wix may process personal data on our behalf in connection with the operation of our Website and related services. Wix provides tools and infrastructure for website hosting, bookings, payments, analytics and other website functions, depending on the services we use.
Wix may process or store personal data in different locations, including locations outside the European Economic Area. Where personal data is transferred to a country outside the EEA, appropriate safeguards required under applicable data-protection law will apply.
For further information, please refer to Wix’s Privacy Policy and information concerning data processing and GDPR.
7. Third-Party Services
We may use third-party service providers for purposes such as:
-
website hosting;
-
booking and class-management services;
-
payment processing;
-
email and newsletter delivery;
-
website analytics;
-
website security;
-
communication and customer support; and
-
other technical or administrative services.
Where these providers process personal data on our behalf, we take appropriate steps to ensure that the processing is carried out in accordance with applicable data-protection requirements.
Third-party providers may also process data independently under their own privacy policies where they act as separate controllers.
8. Cookies and Similar Technologies
Our Website may use cookies and similar technologies.
Some cookies are technically necessary for the Website to function properly, maintain security or provide services that you have requested.
Other cookies, including certain analytics, marketing or similar technologies, may require your consent before they are used.
Where required, we will ask for your consent through our cookie-consent mechanism. You can change or withdraw your cookie preferences at any time through the available cookie settings.
For more information about the cookies used on our Website, please refer to our cookie settings and the information provided through our cookie-consent mechanism.
9. Newsletter and Marketing Communications
If you subscribe to our newsletter or otherwise provide the required consent to receive marketing communications, we may use your email address to send you information about aureyoga, including classes, workshops, events, offers or other relevant updates.
You can unsubscribe at any time by using the unsubscribe option included in our marketing emails or by contacting us directly.
Where required by law, marketing communications will only be sent on the basis of your consent.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.
The applicable retention period depends on the type of data and the reason for which it was collected.
For example, booking and payment records may need to be retained for longer periods where required by Austrian tax, accounting or other legal obligations.
When personal data is no longer required and there is no legal reason to retain it, we will delete or anonymise it securely.
11. Data Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
However, no method of transmission or electronic storage can be guaranteed to be completely secure.
We regularly review the security measures used by us and our relevant service providers.
12. Your Rights
Under the GDPR, you may have the following rights in relation to your personal data:
-
Right of access – to obtain information about whether and how your personal data is being processed and, in certain circumstances, a copy of that data.
-
Right to rectification – to request correction of inaccurate or incomplete personal data.
-
Right to erasure – to request deletion of your personal data where the legal requirements are met.
-
Right to restriction of processing – to request that processing be restricted in certain circumstances.
-
Right to data portability – to receive certain personal data in a structured, commonly used and machine-readable format.
-
Right to object – to object to certain processing, particularly processing based on legitimate interests or for direct marketing.
-
Right to withdraw consent – where processing is based on consent, you may withdraw your consent at any time.
These rights are subject to the conditions and limitations provided by applicable law.
To exercise your rights, please contact us at:
We may need to verify your identity before processing certain requests.
13. Right to Lodge a Complaint
If you believe that your personal data is being processed unlawfully, you have the right to lodge a complaint with the competent data-protection supervisory authority.
In Austria, the competent authority is:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
Telephone: +43 1 52 152-0
14. Children
Our services are primarily intended for adults.
Where a minor participates with the consent or supervision of a parent or legal guardian, we may process the personal data necessary to organise and administer that participation.
We do not knowingly collect unnecessary personal data from children.
15. Links to Other Websites
Our Website may contain links to third-party websites or services.
We are not responsible for the privacy practices or content of third-party websites. We recommend reviewing the privacy policy of any third-party website you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, the Website, applicable legislation or our data-processing practices.
The updated version will be published on this page and will include the date of the latest update.
17. Contact
If you have questions about this Privacy Policy, your personal data or the way we process your information, please contact:
aureyoga
Email: aureyoga18@gmail.com
Website: www.aureyoga.com
Last updated: 09.09.2026