Privacy.
Information on the processing of personal data pursuant to the GDPR.
Responsible Body
Responsible for data processing on this website is:
Christian Kock
Lübeck Athletics / Trave CrossFit
Posener Str. 7, 23554 Lübeck
Email: info@trave-crossfit.de
The responsible body decides on the purposes and means of processing personal data (e.g. names, contact details).
Your Rights
You have the right at any time to obtain information about your stored personal data, its origin and recipients, and the purpose of processing (Art. 15 GDPR), as well as the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20), and the right to object to processing (Art. 21). You may withdraw consent you have given at any time with effect for the future; the lawfulness of the processing carried out up to the withdrawal remains unaffected. An informal notice to the address stated above is sufficient for all matters.
Right to Lodge a Complaint with the Supervisory Authority
In the event of breaches of data protection law, you have the right to lodge a complaint with the competent supervisory authority. The competent authority is the Independent State Centre for Data Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel (datenschutzzentrum.de).
Hosting and Server Log Files
This website is hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). When the pages are accessed, your browser transmits technically necessary information that the server processes in order to deliver them: browser type and version, operating system used, referrer URL, time of the request, the page accessed, and the IP address. Successful page requests are not logged permanently; only failed requests are stored, for the purpose of attack prevention — see the following section. The legal basis is our legitimate interest in error-free and secure operation (Art. 6 (1) (f) GDPR). A data processing agreement is in place with Hetzner. The servers are located in Germany.
Server Logs for Attack Prevention
To protect against attacks — such as large-scale password guessing or the automated search for security vulnerabilities — our server logs failed requests: IP address, time, requested address, browser identifier, and error code. These logs are deleted automatically after 7 days.
They are analysed by the open-source security software CrowdSec. IP addresses that trigger an attack pattern are blocked temporarily and transmitted to CrowdSec SAS (20 rue Maurice Arnoux, 92120 Montrouge, France), which uses them to operate a community blocklist of known attackers. Only addresses that have triggered an attack detection rule are transmitted — never the addresses of ordinary visitors. CrowdSec is based in the EU; no transfer to a third country takes place. More information: crowdsec.net/privacy-policy. The legal basis is our legitimate interest in defending against attacks on our website (Art. 6 (1) (f) GDPR, Recital 49).
Contact and Trial Session Form
When you send us an inquiry via the contact form or the trial session form, we process the data you provide in order to handle your request. For the contact form, this is your name, email address, optionally your phone number, the subject, and your message; for the trial session form, your name, email address, and the desired date. The legal basis is Art. 6 (1) (b) GDPR (performance of pre-contractual measures) and our legitimate interest in responding to your inquiry (Art. 6 (1) (f) GDPR).
To send these form messages, we use the service Resend (operated by Plus Five Five, Inc., USA). Processing takes place on servers within the EU (Ireland region). As Resend is a US company, a transfer of data to, or access from, the USA cannot be ruled out; for this, Resend is certified under the EU-US Data Privacy Framework (adequacy decision of the EU Commission). A data processing agreement is in place with Resend, which additionally includes the EU Standard Contractual Clauses as a further safeguard. Your inquiry remains in our mailbox until it has been handled and no statutory retention periods stand in the way; it is then deleted. No disclosure to further third parties takes place.
Analytics with Umami
For the statistical analysis of website usage, we use Umami. Umami runs on our own server (umami.trave-crossfit.de); no data is passed on to third parties. The measurement takes place without cookies and without storing information on your device. No data that would allow the identification of individual persons is collected; IP addresses are not stored in plain text. The legal basis is our legitimate interest in a data-minimizing analysis of website usage (Art. 6 (1) (f) GDPR). Since no access to your device takes place, no consent is required for this (Section 25 (1) TDDDG does not apply).
External Links and Booking
Our website links to the external booking system Resawod (box.resawod.com), to our external shop (travecrossfit.athlete-solutions.de), to our profiles on Instagram and Facebook, to Google Maps (directions and our business profile), and to a WhatsApp direct-contact link (wa.me); in addition, there are individual links to partner and press pages. This content is embedded as links, not as plugins or embedded widgets. Only when you click on such a link do you leave our website; from that point on, the privacy policy of the respective provider applies. We have no influence over their data processing.
Cookies and Local Storage
This website does not set any consent-requiring cookies and does not embed any consent-requiring services. A cookie banner is therefore not required.
When you switch the language (German/English), your browser stores this choice locally on your device (local storage) so that the site shows you the chosen language on your next visit. Only the chosen language and whether the one-time language notice has been dismissed are stored — no personal data; nothing is transmitted to us or third parties. As this storage merely implements a setting you have explicitly made, it is technically necessary and requires no consent (Section 25 (2) no. 2 TDDDG).
Last Updated
August 2026.