1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified.
2. Controller
The controller for data processing on this website is:
Anoza Labs, Inhaber: Kai Anacker
Reginastraße 1
34119 Kassel
Deutschland
Email: support@tavonto.com
Contact form: Go to contact form
2a. Data protection officer
No separate data protection officer is currently appointed. Please address data protection enquiries to the controller named above.
3. Data collection on this website
Which data is collected?
We collect the following personal data:
- Email address (for account creation and communication)
- Name (first and last name)
- Contact, appointment and video call data for public initial consultations
- Postcode and the location data derived from it
- Sport, experience level and training goals (athletes)
- Profession, specialist areas and hourly rate (professionals)
- Location and booking administration data (location accounts)
- Chat messages between athletes and professionals
- Health data (special category under Art. 9 GDPR), only with your explicit consent. Within a care relationship: weekly check-ins (load, hours of sleep, pain, mood, free-text note), feedback from the professional on them, analysis and measurement values (title, notes, unit, date measured), focus areas, milestones, recommendations from the professional and uploaded documents (file name, file type, content). Outside a care relationship: the health values you document yourself in your record
- Subscription and entitlement status (e.g. Pro features per role)
- Payment and billing information (processed by Stripe)
- Tax-relevant details, insofar as legally required
- IP address and user agent on registration and consent events
Which of these details are published for professionals is set out in section 3a.
How do we collect your data?
Some of your data is collected because you provide it to us. This may be, for example, data that you enter when registering or in your profile.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or the time of the page view).
What do we use your data for?
- Providing and operating the platform
- Handling public online initial consultations including email verification and video appointment
- Matching between athletes and sports professionals (the operator is a software platform provider, not a contracting party to the coaching service)
- Communication via the chat function
- History, feedback and documentation of a care relationship using the health data recorded there (with explicit consent per care relationship). Your own record with self-documented health values (with separate consent). Access by your entire active care team to your record (only with separate team-transparency consent)
- Handling appointment payments and monthly subscriptions
- Enabling and administering role-based Pro features
- Improving our services
3a. Publication of professional profiles
This section describes the publication of the profiles of professionals and of teams of professionals. It states which details we publish, who can retrieve them, whether search engines can index them, and what we base the publication on. We do not publish athlete profiles.
Which details are published
From a professional profile we release exactly the following details:
- the internal identifier of the profile
- first and last name
- professional title
- the sports and activities offered
- the languages offered
- hourly rate and price of the first session
- the region
- the postcode and the coordinates derived from it (latitude and longitude); they are used to calculate distance
- the self-written profile text
- the usual appointment duration
- whether online appointments, on-site appointments or both are offered
- whether any appointment slots exist at all
- whether a verification badge has been granted
- whether a paid platform subscription exists and until when
- whether payment via the platform is currently possible
The following are not published, in particular: email address, telephone number, postal address, date of birth, bank details, the information from payment onboarding, tax-relevant details, messages, appointments including athlete names, and all contents of ongoing care relationships.
Additionally on the public booking page
If a professional creates a public booking link, a separate page is created for it. It is accessible without a login and additionally shows:
- the display name of the professional or the team
- the self-written introductory text of the link
- the free appointment slots of the coming days
- the packages offered, with name, description, price, number of sessions, duration and sports
The page title and the short description of that page contain the name of the professional or the team.
Who can retrieve this information
The search results require a login, and since 6 August 2026 the technical interface behind it also serves profile data only to signed-in accounts. Anyone who registers can retrieve the information listed above for all professionals — we do not vet who creates an account. The information is therefore visible to an indeterminate group of registered people.
The only page reachable without any login is the public booking page; that is its purpose.
Indexing by search engines
The logged-in areas of the platform — including the result list — and the programming interfaces are excluded from search engine crawling in the robots.txt file.
The public booking page is not excluded. It is not listed in our sitemap, but search engines can crawl it and include it in their results as soon as the link is shared publicly or linked from another site. Search engine operators and the indeterminate public of the internet are therefore categories of recipients within the meaning of Art. 13(1)(e) GDPR.
For as long as the platform has not been released publicly, indexing is switched off for the entire domain: the robots.txt file prohibits it completely, and every response additionally carries the header "noindex, nofollow".
Legal basis
- Display to logged-in athletes — Art. 6(1)(b) GDPR: A professional account is created in order to be found and contacted on the platform. Displaying the profile in the search is therefore part of the subject matter of the usage contract.
- Public booking page and possible indexing by search engines — Art. 6(1)(f) GDPR: This reach goes beyond what the user agreement strictly requires. We base it on legitimate interests, which we name individually below.
The legitimate interests are, individually:
- the ability to make one’s own offering visible outside the platform: a professional should be able to share their booking link without requiring interested people to create an account.
- enabling professionals to pass their own booking link to interested parties without forcing those parties to register.
- making the offer comprehensible before an enquiry: profession, sports, languages, price and distance should be visible without having to ask, so that enquiries do not come to nothing.
Professionals may object to the publication at any time under Art. 21(1) GDPR. We then remove the profile from the search and deactivate any existing public booking link. There is currently no button for this; an informal message to support@tavonto.com is sufficient.
Visibility and payability are separate
A profile appears in the search without any payment onboarding with the payment service provider Stripe having taken place. Without that onboarding a professional is findable and can accept free first sessions; they cannot accept payments via the platform. The result card states this.
This also means that in such a case no identity check by Stripe takes place. Whether the details in a profile are accurate has not been verified before an enquiry, unless a verification badge has been granted.
4. Legal bases for processing
Your data is processed on the following legal bases:
- Art. 6(1)(a) GDPR (consent): where you have consented to the processing
- Art. 9(2)(a) GDPR (explicit consent): for health data, in three consents that are given and withdrawn separately. Per care relationship for the health data recorded there (check-ins, feedback from the professional, analysis and measurement values, focus areas, milestones, recommendations, documents). For the health values you document yourself in your record. For access by your entire active care team to your record. Withdrawal applies for the future; the lawfulness of processing up to that point is not affected.
- Art. 6(1)(b) GDPR (performance of a contract): for the performance of our service contract
- Art. 6(1)(c) GDPR (legal obligation): for compliance with statutory retention, record-keeping and possible reporting obligations
- Art. 6(1)(f) GDPR (legitimate interests): for the secure and stable operation of the platform (technical error logs, abuse and fraud prevention, rate limiting) and for the publication of professional profiles beyond logged-in use. We name the interest pursued in each case where the processing is described — for the publication in section 3a, for the error logs in section 5.
5. Recipients and third-party providers
Categories of recipients at a glance
Personal data reach the following categories of recipients:
- Processors: providers that process exclusively for us and on our instructions. They are listed individually below.
- Stripe as an independent controller: payment processing, Connect onboarding and the identity check carried out as part of it.
- Other users of the platform as recipients: the professional responsible and the co-professionals, observers and temporary stand-ins they bring into the team of a care relationship see the data required for that care relationship; locations see the data of the respective booking. Health data of a care relationship is seen only by the professional and their team, and only with your explicit consent. Beyond the individual care relationship they see your record only with your team-transparency consent. Locations never see health data.
- Organisations: clubs, studios and federations as independent controllers. The scope is set out below.
- Search engine operators and the indeterminate public of the internet: for the published details from professional profiles (section 3a).
- Authorities and public bodies: only where there is a legal obligation or where transfer is necessary to establish, exercise or defend legal claims.
Processors in detail
We work with the following third-party providers, which may have access to your data:
Supabase (database)
EUWe use Supabase to store your data. Supabase is a service of Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992.
We have concluded a data processing agreement (DPA) with Supabase. For any transfers to third countries, the EU Standard Contractual Clauses (SCCs, Implementing Decision (EU) 2021/914) are used and a Transfer Impact Assessment (TIA) is documented.
Vercel (hosting and delivery)
EUWe use Vercel as our hosting and infrastructure provider to deliver this website. The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. In doing so, technically necessary connection data (in particular IP address, user agent, timestamp and the URL requested) is processed in order to enable the secure and stable operation of the platform.
A data processing agreement (DPA) is in place with Vercel. For any third-country transfers to the USA we use appropriate safeguards under Art. 44 et seq. GDPR (in particular SCCs; additionally a valid Data Privacy Framework, provided that the respective recipient is certified).
Vercel Speed Insights (Web Vitals)
EUIf you have enabled analytics cookies in your cookie settings, we collect anonymized Web Vitals metrics (e.g. Largest Contentful Paint, First Input Delay) via Vercel Speed Insights for performance optimization. No cookies are set; technical connection data (IP address, user agent, requested route) is processed. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you may withdraw at any time via the cookie settings.
Stripe (payments)
EU + USAPayments and subscriptions are processed via Stripe (one-off payments for appointments as well as monthly Pro subscriptions). Stripe is a service of Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Stripe processes payment data directly as an independent controller.
Professionals and locations who wish to accept payments via the platform additionally go through Stripe Connect onboarding. Stripe collects the details required for this — including name, address, date of birth, bank details and the documents for the identity check — directly on its own pages and as an independent controller. We transmit the email address and an internal identifier for this purpose. In return we receive only the processing status: whether the details have been submitted, whether payments and payouts are enabled, and which details Stripe is still missing. We do not see identity documents or bank details.
For transfers to the USA we rely on appropriate safeguards under Art. 44 et seq. GDPR (in particular SCCs; additionally on a valid Data Privacy Framework, provided that the respective Stripe recipient is certified under it). The assessment of the third-country transfer is documented as part of our TIAs.
Daily.co (video calls)
EU + USAFor video calls we use Daily.co, a service of Daily.co Inc., 465 California St., Suite 1010, San Francisco, CA 94104, USA.
We conclude a data processing agreement with Daily.co. For data transfers to third countries, SCCs are used and supplementary technical and organisational measures are implemented.
Accessibility note: with live video calls, automatic captions may be available to differing extents depending on the browser, operating system and end device. As a text-based alternative, the integrated chat is available to accompany the appointment.
Resend (transactional emails)
EUFor transactional emails such as appointment confirmations, verification links and follow-up messages we use Resend, a service of Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
We conclude a data processing agreement with Resend. For any third-country transfers we use appropriate safeguards under Art. 44 et seq. GDPR, in particular SCC and, where applicable, further supplementary measures.
Sentry (error analysis)
EUWe use Sentry for technical error analysis and stability monitoring. The provider is Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. In doing so, technical error and performance data may be processed insofar as this is necessary for the secure operation of our services.
The Session Replay function is activated only after analytics consent has been given. Without consent, no session recording takes place.
For technical error logs we use Sentry on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in order to ensure the stability and security of the platform. Only data necessary for that purpose is processed; unnecessary default PII transmission is disabled in our configuration.
We have concluded a data processing agreement (DPA) with Sentry. For any transfers to third countries we use appropriate safeguards under Art. 44 et seq. GDPR, in particular EU Standard Contractual Clauses (SCCs).
OpenStreetMap (geocoding)
EUTo convert your postcode into coordinates (for the distance calculation) we use the Nominatim API of OpenStreetMap. In doing so we transmit the postcode you entered and the country parameter. The request is made via our server; your client IP is not transmitted directly to Nominatim in the process.
OpenStreetMap Foundation privacy policy (opens in a new tab)
The public and search engines
The published details from professional profiles are retrievable without a login, and the public booking page can be indexed by search engines. Which details this concerns, what we base the publication on, and how it can be objected to is set out in section 3a.
Organisations (clubs, studios, federations)
If you belong to an organisation as a member, its administration learns your name and email address, and whether and by which trainer you are being supported under the organisation's licence. All trainers of that organisation can also see the member list — not only the one supporting you. The organisation is an independent controller for this, not our processor.
The legal basis is the consent you give by joining (Art. 6(1)(a) GDPR). You can withdraw it at any time by leaving under „Clubs“ in your account. Without joining, the organisation does not learn your name — it only sees anonymous totals.
What the organisation explicitly does NOT see: the contents of your care relationship, your record, health and measurement values, check-ins, recommendations and messages. Those stay with you and your care team.
Authorities / public bodies
Personal data is transferred to authorities only insofar as there is a legal obligation to do so or the transfer is necessary to establish, exercise or defend legal claims.
This may include, in particular, retention, record-keeping or reporting obligations under tax and commercial law (e.g. statutory platform-related reporting obligations), insofar as these apply in the individual case.
Where providers supply a VAT identification number, we verify it against the European Commission’s VAT Information Exchange System (VIES/MIAS). We transmit the number supplied and receive only whether it is valid. The basis is section 18(2) of the German Platform Tax Transparency Act (PStTG), which obliges us to carry out this check.
Safeguards for third-country transfers
Insofar as we transfer data to countries outside the EU/EEA, this takes place only where the requirements of Art. 44 et seq. GDPR are met. For this purpose we use in particular:
- EU Standard Contractual Clauses (SCCs)
- supplementary technical and organisational measures
- Transfer Impact Assessments (TIAs)
- where applicable, a valid Data Privacy Framework (DPF)
6. Retention period
Your data is stored for as long as your account is active or for as long as it is necessary for the provision of our services.
- Account data: until the account is deleted
- Chat messages: 365 days after they are sent, then deleted automatically — regardless of whether the account remains
- Payment data: 10 years (statutory retention obligation)
- Subscription and invoice data: for the duration of the subscription and thereafter in accordance with statutory retention obligations
- Tax and record-keeping data: in accordance with statutory retention and documentation obligations
- Audit logs: 10 years (statutory retention obligation for financial transactions)
- Public initial consultations without a platform account: only for as long as is necessary for handling the appointment, abuse prevention and evidentiary purposes; cases that do not convert are retained for a shorter period
Health data from care relationships and your record: tied to your consent and your account. After a withdrawal the data stays stored but is hidden from the professional and everyone else involved in the care relationship; if you consent again, it becomes visible again. Your own entries stay visible to you and can be deleted individually; only documents uploaded by the professional are hidden from you. You delete this data completely at any time by deleting your account.
7. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): you can request information about the data stored about you.
- Right to rectification (Art. 16 GDPR): you can request the rectification of inaccurate data.
- Right to erasure (Art. 17 GDPR): you can request the erasure of your data, provided that no statutory retention obligations preclude this.
- Restriction (Art. 18 GDPR): you can request the restriction of processing.
- Notification obligation (Art. 19 GDPR): where legally required, we inform recipients about the rectification, erasure or restriction of your data.
- Data portability (Art. 20 GDPR): you can receive your data in a commonly used format.
- Right to object (Art. 21 GDPR): you can object to the processing of your data.
- Withdrawal of consent: you can withdraw consent you have given at any time.
To exercise your rights, please contact us by email at support@tavonto.com.
8. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about our processing of personal data. Which supervisory authority is responsible for you depends on your place of residence.
You can find a list of the data protection supervisory authorities and their contact details at: www.bfdi.bund.de (opens in a new tab)
9. Cookies
Our website uses cookies. These are small text files that are stored on your end device.
Necessary cookies
We use technically necessary cookies for authentication and session management. These cookies are required for the operation of the website and cannot be deactivated.
- Supabase Auth cookies: for login and session management
Optional analytics and marketing cookies
We set analytics and marketing cookies only after your explicit consent. You can change your selection at any time via the “Cookie settings” link.
- Analytics: Sentry Browser Monitoring and Session Replay (only after consent)
- Marketing: currently no active marketing tracking services; if activated in future, only with consent
In order to be able to demonstrate your consent, we store the time of the decision as well as technical metadata (including IP address and user agent).
10. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can tell that a connection is encrypted by the browser's address bar changing from "http://" to "https://" and by the padlock symbol in your browser bar.
11. Validity and amendment of this privacy policy
This privacy policy is currently valid and is dated September 2026.
As our website develops further, or as a result of changed statutory or regulatory requirements, it may become necessary to amend this privacy policy.