◀︎ back

Coachistant — Privacy policy

Preamble

This privacy policy explains which kinds of personal data (hereinafter "data") we process, for which purposes and to what extent. It applies to all processing of personal data we carry out, both in providing our services and in particular on our websites, in mobile applications and within external online presences such as our social media profiles (together the "online offering").

Terms used are not gender-specific.

Last updated: 10 September 2026

 

Contents

Controller

KRANNICH
Owner: Dr.-Ing. Dennis Krannich

Amselbusch 10
29640 Insel
Germany

Phone: +49 5193 966-4729

E-mail: ed.hcinnarksinned

VAT ID pursuant to § 27 German VAT Act: DE208892357

Overview of processing

The following overview summarises the kinds of data processed, the purposes of processing and the data subjects concerned.

Kinds of data processed

Categories of data subjects

Purposes of processing

Legal bases

Legal bases under the GDPR: Below is an overview of the GDPR legal bases on which we process personal data. Please note that in addition to the GDPR, national data protection rules in your or our country of residence may apply. Where more specific legal bases apply in individual cases, we state them in this policy.

National data protection rules in Germany: In addition to the GDPR, the German Federal Data Protection Act (BDSG) applies, in particular regarding the right of access, the right to erasure, the right to object, the processing of special categories of data, processing for other purposes and transfer, and automated decision-making. State data protection laws may also apply.

Security measures

We take appropriate technical and organisational measures in accordance with the law, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, input, transfer, availability and separation. We also have procedures in place to ensure the exercise of data subject rights, the deletion of data and responses to data breaches. We take data protection into account when developing and selecting hardware, software and procedures, in line with the principles of privacy by design and by default.

TLS/SSL encryption (https): We use TLS/SSL encryption to protect data transmitted through our online offering. Encrypted connections are recognisable by the prefix https:// in the browser's address bar.

Transfer of personal data

In the course of processing, personal data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include, for example, service providers entrusted with IT tasks. We comply with legal requirements and conclude the necessary contracts or agreements with the recipients to protect your data.

International data transfers

We process data in Germany. Where data is processed in a third country (outside the European Union or the European Economic Area), this happens only in accordance with the legal requirements of Art. 44 et seq. GDPR, i.e. on the basis of an adequacy decision, standard contractual clauses or your explicit consent.

Storage and deletion

We delete personal data we process in accordance with the law as soon as the underlying consent is withdrawn or no other legal basis for processing applies, unless retention is required for legal reasons. Data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise or defend legal claims, is restricted from further processing and deleted once the retention period has expired. Log data of the web host is deleted after 30 days at the latest.

Rights of data subjects

As a data subject you have various rights under the GDPR, in particular Art. 15 to 21 GDPR:

The Coachistant app

In short: The app collects no personal data and sends nothing to us or to third parties. There is no user account, no server, no analytics and no advertising.

Local storage: Teams, player names, shirt numbers, matches, goals, substitutions, cards and playing times you enter are stored on your iPhone only. They leave the device only through actions you take yourself, such as sharing a match report image via the iOS share sheet, or through an iCloud backup of your device, which is subject to Apple's privacy policy.

Apple Watch: When you send a match or a timer to Apple Watch, the data travels directly between your iPhone and your watch via the WatchConnectivity system interface. No server is involved.

HealthKit / workout session: During a match or interval timer the watch app starts a workout session (HKWorkoutSession, activity type soccer) solely to keep the match clock running while your wrist is down. The app reads no health data and writes nothing to Health beyond the session itself. You grant this permission on first launch on the watch and can revoke it at any time in the Health settings. Which workout data watchOS stores in Health during a session depends on your settings and Apple's privacy policy.

Deletion: All data of the app is removed when you delete the app from your device.

Provision of the online offering and web hosting

We process users' data in order to provide our online services. For this purpose we process the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or device.

Collection of access data and log files: Access to our online offering is logged in server log files. Log files may include the address and name of the pages and files accessed, date and time of access, data volume transferred, notification of successful access, browser type and version, the user's operating system, referrer URL and, as a rule, IP addresses and the requesting provider. Log files are used for security purposes (e.g. to prevent overload or abuse) and to ensure the stability of the servers. Log data is deleted after 30 days at the latest, unless it must be retained for evidence in connection with a specific incident.

Changes and updates

We ask you to check this privacy policy regularly. We update it whenever changes in our data processing make this necessary. We will inform you if changes require your cooperation (e.g. consent) or other individual notification.

Where we provide addresses and contact details of companies and organisations in this policy, please note that these may change over time; please verify them before making contact.

Definitions

This section provides an overview of terms used in this policy. Where terms are defined by law, their legal definitions apply; the explanations below serve primarily for understanding.

Based on the German policy generated with Datenschutz-Generator.de by Dr. Thomas Schwenke. The German version is authoritative.