Privacy Policy
Responsible Body:
One Step Ahead UG (haftungsbeschränkt)
Schlangenstr. 13
33607 Bielefeld
Deutschland
Email: support@thenn-os.de
Management: Marcel Klemme
1. Data Protection at a Glance
General Information
The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator (service provider within the meaning of DDG). You can find their contact details in the section "Information about the responsible body".
How do we collect your data?
Your data is collected in part by you providing it to us. This may be data that you enter in a registration form or provide when booking a training session.
Other data is collected automatically or with your consent when you visit the website through our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website (e.g., IP addresses in logs). Other data may be used to analyze your user behavior (inactivity, churn) to improve the service. We do not sell your data to third parties.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future.
2. Hosting and Content Delivery Networks (CDN)
External Hosting
This website is hosted by external service providers (hosters). The personal data collected on this website is stored on the hosters' servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated through a website.
Hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR).
We use the following hosters:
- Application Server: Strato AG, Germany
- Database & Cache: Ubicloud (auf Hetzner), Server location: 🇩🇪 Germany
- Email & Domain: ALL-INKL.COM - Neue Medien Münnich, Germany
Data Processing Agreement
We have concluded data processing agreements (DPA) with the above-mentioned providers. These are contracts required by data protection law that ensure they process the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
3. General Information and Mandatory Disclosures
Data Security
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser's address bar changes from http:// to https:// and by the lock icon in your browser bar.
Additionally, we employ modern security measures such as Argon2 hashing for passwords, HttpOnly cookies for sessions, and Role-Based Access Control (RBAC) to protect your data from unauthorized access.
Retention Period & Backups
Unless a more specific retention period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate deletion request or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data.
Backup Retention Policy:
After termination of the contract with your tennis school, your personal data will be deleted from the active system following a grace period of 30 days for a final data export and within a further 14 days.
Note: If immediate deletion ("Hard Delete") is requested, the data is removed from the live system immediately. Due to technical backups for disaster recovery (Ubicloud/Hetzner Germany), encrypted fragments may remain in backup copies for up to 90 days until they are automatically overwritten. Records subject to statutory retention (e.g. invoices) remain for the statutory period.
Right to Object (Art. 21 GDPR)
Important Notice:
IF THE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.Delete Account
The "Delete Account" function in your profile under Settings → Privacy allows you to request the deletion of your data. Your account will first be suspended for 14 days. During this grace period, you can revoke the deletion at any time. After the period expires, all personal data will be permanently and irrevocably deleted from our active system.
4. Data Collection on This Website
Cookies & local storage
Our websites use so-called "cookies" and the local browser storage (LocalStorage).
We use technically necessary cookies/storage entries:
- Access token (in memory): Used to authenticate you after login. Held solely in the browser's memory (XSS protection) and not stored persistently.
- HttpOnly Cookies: Used for the secure renewal of your session (Refresh Token).
- Persistent Login ("Stay logged in"): Stores your login status permanently at your request (until logout).
- thennos_analytics_consent (localStorage): Stores your consent to usage analysis on the landing page (opt-in).
- thennos_lp_session (sessionStorage): Pseudonymized session ID for landing-page analytics. Automatically deleted when the tab is closed.
Legal basis: The storage of information on your device (cookies/storage) is based on § 25(2)(2) TDDDG (Telecommunications Digital Services Data Protection Act), as this is technically mandatory for the operation of the site or was expressly requested by you (login checkbox).
AI-Powered Features (AI Act Transparency)
We use Artificial Intelligence (AI) to create personalized training plans.
- Transparency: The creation of training plans is automated through algorithms.
- Data processing: Your profile data is used for generation. Sharing for AI training purposes does not take place.
5. Product Analytics by THENN·OS
Type and Purpose of Processing
THENN·OS processes certain usage data to technically and functionally improve the platform, to measure app adoption, and to quickly see the relevant context for support requests. Controller for this product analytics is One Step Ahead UG (haftungsbeschränkt), not your tennis academy. The following data is collected:
- Usage duration and session: when and how long you actively use the app (active, idle, total), pseudonymous session ID
- Access mode: whether you access the app via browser or as an installed app from the home screen (PWA)
- Usage events: coarse events (e.g. page view, booking created), frustration signals (rage clicks, dead clicks), activation steps and technical metadata — no content data, no training content, no payment details
Controllership & Separation from Your Tennis Academy
This product analytics is carried out for One Step Ahead UG's own purposes. Your tennis academy receives no access to this data — neither as personalized analysis nor as individual records. We do not use the data to assess your playing strength, to evaluate training content, or to provide your tennis academy with personalized usage profiles of individuals. This separation is contractually established in § 13 of the Data Processing Agreement with your tennis academy.
Recipients & Visibility
The analytics are visible exclusively to authorized platform administrators of One Step Ahead UG (currently: Marcel Klemme as Managing Director). There is no transfer to third parties — no advertising networks, no data brokers, no external analytics service providers. All data remains on our servers in Germany (Ubicloud/Hetzner).
Legal Basis & Retention Period
Legal basis is Art. 6(1)(f) GDPR (legitimate interest in product improvement, activation measurement and PWA adoption analysis), supplemented for support diagnostics by Art. 6(1)(b) GDPR (contract performance of the service component). The legitimate interest assessment (LIA) is documented internally and can be reviewed on request. We retain this data for a maximum of 90 days and delete it automatically thereafter.
Right to Object (Opt-Out)
You can object to this processing at any time (Art. 21 GDPR) — either by email to support@thenn-os.de or via the "Product analytics" toggle in your Profile settings → Privacy. Upon opt-out, existing data is not deleted but anonymized within 24 hours (your user ID is removed). Aggregated statistics thus remain valid, while re-identification is excluded.
5a. Landing-Page-Analytics & A/B-Tests
Type and Purpose of Processing
On our public landing page, we collect pseudonymized usage data with your consent in order to optimize usability and conversion. This is an in-house analytics system — we do not use Google Analytics, Facebook Pixel or any other third-party tracking tools.
- Page views and scroll depth (in 25% steps)
- Visibility of individual page sections (section tracking)
- Clicks on call-to-action buttons (CTA tracking)
- Verweildauer auf der Seite and in einzelnen Abschnitten
- Visit origin (referrer, UTM parameters)
- Gerätetyp (Desktop/Mobil/Tablet) and gekürzter Browser-String
A/B tests
To optimize the landing page, we run A/B tests in which different versions of the page are shown. Assignment to a variant happens automatically based on a random session ID. The assignment is stored in your browser session storage (sessionStorage) and deleted when the tab is closed.
No persistent identifiers
All identifiers (visitor ID, session ID, A/B test assignment) are stored exclusively in your browser's sessionStorage. They are automatically deleted when the tab is closed. No cross-session tracking takes place.
Legal basis & consent
Collection only takes place after your explicit consent (opt-in) pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. The technically necessary session management (sessionStorage) is permitted without consent under § 25(2) no. 2 TDDDG. You can withdraw your consent at any time.
IP anonymization & retention period
IP addresses are anonymized immediately upon collection (last IPv4 octet or last 5 IPv6 groups zeroed out). Landing-page events are automatically deleted after 24 months. There is no transfer to third parties — all data remains on our own servers in Germany.
5. Internal Communication (Messages)
Type and Purpose of Processing
The platform offers an internal messaging function through which coaches, managers, and players within an organization can communicate. The following data is processed:
- Sender and recipient of the message
- Subject and content of the message
- Time of sending and reading
Legal Basis
Processing is based on Art. 6(1)(b) GDPR (contract performance) to enable communication between coaches and players within the context of training operations.
Access by the Operator
The platform operator is entitled to inspect message content and, if necessary, delete it in the event of justified suspicion of violations of the terms of use or reports of illegal content.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and protecting users from illegal content).
Retention Period
Messages are stored as long as your user account exists. When your account is deleted, all messages you have sent are also automatically deleted (Art. 17 GDPR).
6. Special Categories of Personal Data (Art. 9 GDPR)
Type and Purpose of Processing
In the course of using our platform, you may voluntarily provide information about your health condition (e.g., injuries, allergies, physical limitations).
Processing is carried out exclusively for the following purposes:
- Individual adaptation of training plans to avoid overexertion
- Consideration of health limitations in competition planning
- Emergency management (e.g., allergies for first responders)
Legal Basis
Processing is based on your explicit consent pursuant to Art. 9(2)(a) GDPR. The information is voluntary. Non-provision has no effect on your membership or the general usability of the platform.
Circle of Recipients
Your health data is accessible exclusively to the coaching staff responsible for you and the academy management. No transfer to third parties takes place.
Retention Period and Revocation
We store the data until you revoke your consent or leave the academy. You can revoke your consent at any time in your profile settings. After revocation, the corresponding data will be deleted immediately.
7. Season Surveys
Type and Purpose of Processing
Through public survey links, tennis schools and sports organizations can collect training preferences from their members. The following data is collected:
- Name and email address (for identification and verification)
- Phone number (optional, for follow-up questions)
- Training preferences (preferred days, times, group size, etc.)
- Answers to individual questions from the respective organization
Legal Basis
Processing is based on your explicit consent pursuant to Art. 6(1)(a) GDPR, which you give by submitting the survey form.
Recipients of Data
The respective organization (tennis school/sports club) that created the survey is responsible for data processing. The organization receives access to your responses for training planning.
THENN·OS — platform of One Step Ahead UG (haftungsbeschränkt), HRB 46189, Schlangenstraße 13, 33607 Bielefeld, Germany acts as a data processor pursuant to Art. 28 GDPR and provides the technical infrastructure.
Retention Period
Your survey responses are stored for the duration of the training planning, usually until the end of the respective season. You can revoke your consent at any time by email to the respective organization. After revocation, your data will be deleted immediately.
Double Opt-In
To verify your email address, we will send you a confirmation link. Only after clicking this link will your preferences be saved and transmitted to the organization.
8. Additional Features & Third Parties
Web Push Notifications
The legal basis is your explicit consent (Art. 6(1)(a) GDPR), which you give by activating notifications. Delivery is handled technically via the push service of your browser or device manufacturer (e.g. Google FCM, Apple, Mozilla). In doing so, an anonymous device endpoint is transmitted to this service; for Google and Apple this may involve a transfer to the USA, safeguarded by the Standard Contractual Clauses (Art. 46 GDPR) or the EU-US Data Privacy Framework. The contents of the notifications are generated on our server.
Google Fonts (Local)
We have stored fonts locally on our own server. No connection to Google servers takes place.
Email Sending via All-Inkl
For sending transactional emails, we use the SMTP servers of our hoster All-Inkl in Germany. Before dispatch, the email passes through our own automation infrastructure (self-hosted n8n, server location Germany).
Payment Processing (Stripe)
For payment processing, we use the service Stripe (Stripe Payments Europe Ltd., Dublin, Ireland). When you make a payment, the required payment data is transmitted directly to Stripe. THENN·OS does not store complete credit card data.
Processed data: Payment amount, payment status, invoice ID, timestamp. Credit card data is exclusively processed by Stripe (PCI-DSS certified).
Recipient: Stripe Payments Europe Ltd., Dublin, Ireland (EU — adequate level of protection). For Stripe Inc. (USA), Standard Contractual Clauses (SCC) apply.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for payment processing; Art. 6(1)(c) GDPR (legal obligation) for tax-related retention.
Retention period: Invoice data is retained for 10 years due to tax retention obligations (German Commercial Code § 257). After expiration, it is automatically anonymized.
Live Chat (internal notification)
Our platform offers a voluntary live chat for support inquiries. Your message and optional contact details remain in THENN·OS. Telegram receives only a generic notification that a new support message arrived and that the platform operator must reply in THENN·OS. Message content, names, contact details, page URLs, and session data are never sent to Telegram.
Processed data: The support chat processes message content, optional name, current page URL, and session ID inside THENN·OS. Telegram receives only the generic new-message notification.
Recipient: The Telegram Bot API (Telegram FZ-LLC, Dubai, UAE) is used only for the generic notification. There is no adequacy decision of the EU Commission for the UAE.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing efficient customer support). The use of the chat is at your own initiative.
Retention period: Chat sessions are archived in THENN·OS after 30 days of inactivity and deleted no later than 90 days after the last activity. THENN·OS sends Telegram only the generic notification and no message content, replies, or contact details.
Technical error diagnosis and incident alerting
We process incident data to detect, group and resolve technical errors in the backend and frontend and to alert platform operations quickly. This processing is not used to monitor the performance or behavior of users or coaches.
Processed data: Only for signed-in users, the verified user and organization assignment from the authentication context (user ID, organization ID, role and, where applicable, impersonation status), plus technical metadata such as incident reference/fingerprint, status/code, cleaned path, build, user agent, language, time zone, access mode, viewport and timing data. With a real client error, up to 20 technical breadcrumbs buffered briefly in the browser (up to 5 minutes) may also be sent: coarse page area, generic click/UI action type, and API family, method, outcome/status and duration. No input values, form data, request/response contents, URL parameters or fragments, names, messages or headers are captured. The server validates and reduces these breadcrumbs again before storing them in the incident record. Error message, error name, stack and component-stack data are server-side redacted before storage. Browser reports without verified authentication are not stored as incidents.
Recipients and access: Incident entries in the platform-wide error center are accessible only to the authorized PlatformAdmin role; tennis schools, organization managers, coaches and players have no access. For important incidents – backend errors from HTTP 500, blocked pages, and permanently failed app loads – Telegram (Telegram FZ-LLC, UAE; no DPA, servers worldwide without an EU adequacy decision) may receive a minimized alert containing only the incident reference, environment, cleaned path, status/code, build and a technical deep link. Message, stack, user/organization assignment and user agent are never sent to Telegram; unauthenticated browser reports are not stored.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security, error analysis and rapid remediation); Art. 6(1)(b) GDPR additionally applies to the technical service component. No consent or re-consent is required for this processing.
Retention period: Incident entries in the activity feed are deleted after 12 months by the automatic retention job. External Telegram storage is outside this deletion routine and cannot be controlled technically; therefore, only the listed minimized alert data is transmitted there.
AI assistant (support chatbot)
Our platform offers an optional AI-powered support chatbot that automatically answers common questions about using the platform. Usage is voluntary — you can switch to human support at any time.
Data processed: message content, first name (if logged in), current page URL, user role, session ID (pseudonymous). No passwords, payment data or sensitive personal data are transmitted to the AI provider.
Service provider: AI processing is performed via the OpenAI API (OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland — the contracting party for EU customers; technical processing may be carried out by OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA). Using the OpenAI API automatically applies the OpenAI Data Processing Addendum (DPA) as the data processing agreement under Art. 28 GDPR. OpenAI is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses (Art. 46 GDPR) apply. Per the OpenAI Data Usage Policy, OpenAI does not use chat content submitted via the API to train its models and deletes it from abuse-monitoring logs within 30 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing efficient customer support available around the clock). Use is at your own initiative.
EU AI Act (Art. 50): The chatbot is labeled as an AI system. It is classified as a minimal-risk system (assistance chatbot) and is subject to the transparency obligation under EU Regulation 2024/1689.
Retention period: Chat histories are stored server-side in the database and automatically deleted after 12 months. No data is permanently stored at the AI provider.
Usage statistics (Plausible Analytics)
To improve our offering, we use Plausible Analytics, a cookieless, data-minimizing usage measurement that we operate ourselves on our server in Germany (analytics.thenn-os.de). No cookies are set, no cross-device profiles are created, and no data is transferred to third parties or third countries. IP addresses are only used briefly to generate an anonymous, daily-rotating count value and are not stored.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in statistical usage measurement). Since no information is stored on or read from your device, no consent under § 25 TDDDG is required.
10. Your Rights
Right to Complain to the Supervisory Authority (Art. 77 GDPR)
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged infringement.
Competent Supervisory Authority:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Website: www.ldi.nrw.de
Right to Data Portability (Art. 20 GDPR)
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format (JSON). You can find this function in your Settings → Privacy → Data Export.
11. AI-Assisted Software Maintenance (Anthropic Claude)
For rapid bug fixing, further development and technical quality assurance, we use the AI service Anthropic Claude (Anthropic PBC, USA). We have designed this access to protect your privacy as much as possible:
- Only pseudonymized data: Your real name, email address, phone number, postal address and date of birth are NEVER sent to Anthropic. Claude only receives stable, organization-scoped pseudo-IDs (e.g. <em>User_a1b4</em>) and generalized data (e.g. birth year only).
- Server-side enforcement: Pseudonymization happens in a middleware before every API response. The AI service cannot bypass it.
- Read-only access: Claude cannot modify or delete data. Every single access is audit-logged (90-day retention).
- US transfer safeguarded: Anthropic is certified under the EU-US Data Privacy Framework. Additionally, standard contractual clauses (SCC) are in place.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in software quality and operational security). The balancing test is documented and can be reviewed on request. You have the right to object to this processing at any time under Art. 21 GDPR.
Last updated: August 2026