Skip to main content
Legal

Privacy Policy

CrossFit Zeeburg processes personal data to answer your questions, arrange memberships and classes, and keep our service safe. Below we explain in plain language what we do, why, and what your rights are.

Last updated: 13 August 2026

  1. Which data we process and where it comes from.
  2. For which purpose and on which legal basis we do so.
  3. Who processes data on our behalf and which tools we use.
  4. How long we keep data and how we protect it.
  5. Which rights you have and how to exercise them.

Controller and contact

CrossFit Zeeburg, Cruquiusweg 96F, 1019 AJ Amsterdam, the Netherlands, Chamber of Commerce 65754964, is the controller. For privacy questions email info@crossfitzeeburg.com or call +31 6 21623912.

What this policy covers

This policy covers our website, the contact, trial class and starter forms, memberships and class planning, group classes and personal training, and the related communication and administration.

For the arrangements on memberships, payment and cancellation, see our terms and conditions.

Which data we process

  • Contact details: name, email address, phone number, preferred language and the content of your message.
  • Membership and service data: chosen product, bookings, attendance, payment status and communication about your membership.
  • Marketing and communication preferences, including any consent for WhatsApp.
  • Origin data per request: route/page, form or offer used, date and time, UTM parameters, landing page, referrer host, an fbclid if present in the link, and a randomly generated first-party anonymous session id.
  • Your choice in the cookie and localStorage settings.
  • Necessary technical security and error data, to detect abuse and failures.

Our own first-party registration layer does not store IP addresses or device fingerprints. We do not process payment card details through website forms; those go through SportBit's payment provider.

Please do not enter medical or other special category data in free-text fields on the website. If such information is needed for safe coaching, discuss it directly with your coach. We then process it in a limited way and only on an applicable GDPR basis.

Purposes and legal bases

  • Handling your request and preparing and performing an agreement: necessary for the (preparation of the) contract.
  • Administration and tax obligations: legal obligation.
  • Security, fraud prevention, improving our services and limited first-party origin attribution: legitimate interest. We limit the data to what is necessary and you can object.
  • Marketing communication, WhatsApp where we ask for it separately, Google Analytics 4 and Meta Pixel: consent, which you can withdraw at any time.

The mandatory checkbox confirming you have read this privacy policy is an information duty, not consent as a legal basis. Processing that is necessary for your request or agreement is based on the contract itself.

Where the data comes from

  • Directly from you: forms, email, phone, WhatsApp or conversations in the box.
  • Automatically through the website: the technical and origin data described above.
  • Where relevant through SportBit and connected systems: membership, booking and payment status.

Recipients and processors

We only share data with parties that help us deliver the service:

  • Supabase: technical database and registration layer.
  • Lovable and the underlying hosting infrastructure: delivery of the website.
  • Activepieces: workflow automation between our systems.
  • Swipe One: CRM and commercial follow-up.
  • SportBit and its connected payment provider: memberships, bookings and payments.
  • Wbiztool, WhatsApp and Meta: only for WhatsApp communication for which the proper consent or legal basis exists.
  • Google Analytics 4 (Measurement ID G-GT1DH1J0TF): only after your consent for statistics.
  • Meta Pixel (315018395766359): only after your consent for marketing.
  • Necessary email, administration, accounting and professional service providers, as a category.

Processors may only use data on our instructions and under appropriate agreements. For their own processing, external platforms may act as independent controllers; their own terms and privacy statements apply to that.

We do not sell or rent your data.

Cookies and localStorage

  • Necessary: your consent choice is stored under the name 'cfz.consent', for a maximum of 365 days.
  • Necessary/legitimate interest: a random first-party anonymous session id and limited first- and last-touch attribution. We do not use fingerprinting.
  • Statistics: Google Analytics 4, only after opt-in.
  • Marketing: Meta Pixel, only after opt-in.

You can change or withdraw your choice at any time through in the footer. Withdrawal works for the future: processing that already took place is not undone by it.

Transfers outside the EEA

Some of our suppliers may process data outside the European Economic Area, for example for support or hosting. This only happens on the basis of an applicable adequacy decision, EU standard contractual clauses and/or other appropriate GDPR safeguards.

We do not claim that all data is stored exclusively within the EU. Would you like to know which safeguards apply to a specific supplier? Just ask us.

How long we keep data

We apply the following retention policy, with periodic clean-up:

  • Contact, lead and form data: in principle a maximum of 24 months after the last relevant contact, unless deleted earlier or unless an agreement is formed.
  • Contract, membership and service data: as long as needed for performance and after that in principle a maximum of 2 years, except data needed longer for claims or legal obligations.
  • Tax and financial administration: 7 years, insofar as legally required.
  • Marketing data: until you withdraw your consent, and at most 24 months without relevant activity.
  • First-party event data: a maximum of 395 days.
  • Integration logs: a maximum of 90 days.
  • Automation and outbox history: a maximum of 180 days.
  • Consent choice: a maximum of 365 days.
  • Backups: on a limited rotation, after which they are overwritten.

Exceptions apply in case of a legal retention obligation, a dispute or an investigation into fraud or abuse. These periods are our retention policy; we do not claim fully automated deletion that cannot be demonstrated technically.

Security

We limit the data we record, restrict access to those who need it, use encrypted connections, validate forms server-side, apply anti-spam measures and keep no keys or secrets in the browser or in log files.

No measure offers absolute certainty. Do you see or suspect a security issue? Let us know and we will pick it up.

Your rights

  • Access to the data we hold about you.
  • Correction of inaccurate data.
  • Erasure of data we no longer need.
  • Restriction of processing.
  • Portability of data you provided yourself.
  • Objection to processing based on legitimate interest.
  • Withdrawal of consent, at any time.

Send your request to info@crossfitzeeburg.com. We respond within one month in principle. Sometimes we ask for a proportionate check of your identity, so we do not disclose data to the wrong person.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority. Of course we would like to hear from you first.

Automated decision-making

CrossFit Zeeburg does not take decisions with legal or similarly significant effects based solely on automated processing. Our systems support people; a coach or staff member decides.

Minors

For people under 16 we only process personal data with the consent of a parent or legal representative, where the law requires it. Do you think we process a child's data without that consent? Email us and we will delete it.

Changes and contact

We may update this privacy policy when our services, tools or the applicable rules change. The date of the last change is shown at the top. Questions or remarks? Email info@crossfitzeeburg.com.