Privacy Policy

Zen BODY Flow website is owned by Jessica Moritz, which is a data controller of your personal data.

We have adopted this Privacy Policy, which determines how we are processing the information collected by Zen BODY Flow, which also provides the reasons why we must collect certain personal data about you. Therefore, you must read this Privacy Policy before using Zen BODY Flow website.

We take care of your personal data and undertake to guarantee its confidentiality and security.

Personal information we collect:

When you visit the Zen BODY Flow, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the installed cookies on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site. We refer to this automatically-collected information as “Device Information.” Moreover, we might collect the personal data you provide to us (including but not limited to Name, Surname, Address, payment information, etc.) during registration to be able to fulfill the agreement.

Why do we process your data?

Our top priority is customer data security, and, as such, we may process only minimal user data, only as much as it is absolutely necessary to maintain the website. Information collected automatically is used only to identify potential cases of abuse and establish statistical information regarding website usage. This statistical information is not otherwise aggregated in such a way that it would identify any particular user of the system.

You can visit the website without telling us who you are or revealing any information, by which someone could identify you as a specific, identifiable individual. If, however, you wish to use some of the website’s features, or you wish to receive our newsletter or provide other details by filling a form, you may provide personal data to us, such as your email, first name, last name, city of residence, organization, telephone number. You can choose not to provide us with your personal data, but then you may not be able to take advantage of some of the website’s features. For example, you won’t be able to receive our Newsletter or contact us directly from the website. Users who are uncertain about what information is mandatory are welcome to contact us via hi@zenbodyflow.com.

Your rights:

If you are a European resident, you have the following rights related to your personal data:

  • The right to be informed.

  • The right of access.

  • The right to rectification.

  • The right to erasure.

  • The right to restrict processing.

  • The right to data portability.

  • The right to object.

  • Rights in relation to automated decision-making and profiling.

If you would like to exercise this right, please contact us through the contact information below.

Additionally, if you are a European resident, we note that we are processing your information in order to fulfill contracts we might have with you (for example, if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information might be transferred outside of Europe, including Canada and the United States.

Links to other websites:

Our website may contain links to other websites that are not owned or controlled by us. Please be aware that we are not responsible for such other websites or third parties' privacy practices. We encourage you to be aware when you leave our website and read the privacy statements of each website that may collect personal information.

Information security:

We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. We keep reasonable administrative, technical, and physical safeguards to protect against unauthorized access, use, modification, and personal data disclosure in its control and custody. However, no data transmission over the Internet or wireless network can be guaranteed.

Legal disclosure:

We will disclose any information we collect, use or receive if required or permitted by law, such as to comply with a subpoena or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

Data Collection:
We collect personal data only when necessary, e.g.:

  • Contact Forms: Name, email for inquiries.

  • Analytics: IP addresses, browser data via tools like Google Analytics (if used).

  • Embedded Content: YouTube videos or third-party services (e.g., Zoom for future calls) may collect data per their privacy policies.

  • Cookies: Used for functionality, analytics, or marketing (see Cookies section in Terms).

Purpose and Legal Basis:

  • Contact forms: To respond to inquiries (Art. 6(1)(b) GDPR, contract fulfillment).

  • Analytics: To improve the website (Art. 6(1)(f) GDPR, legitimate interest).

  • Cookies: Based on consent (Art. 6(1)(a) GDPR) via our cookie banner.

  • Embedded content: Based on consent or legitimate interest, depending on the service.

Third Parties:
We use third-party services that may process data, including:

Embedded YouTube Videos
Our website includes embedded videos from YouTube. When you view or interact with these videos, data such as your IP address and usage information may be transmitted to Google/YouTube. YouTube may use cookies and other tracking technologies. For more information, please see the YouTube privacy policy: https://policies.google.com/privacy

Payment Processing

Digistore24: We use Digistore24 GmbH (based in Germany) as our platform for selling digital products, processing payments, and managing affiliate relationships. Digistore24 acts as a data processor on our behalf under a data processing agreement that ensures compliance with data protection laws.

When you make a purchase through our website, the following personal information may be shared with Digistore24 to facilitate the transaction, fulfill your order, provide customer support, and handle any refunds or disputes:

  • Your name and contact details (e.g., email address, phone number, and billing address).

  • Payment information (e.g., credit card details, bank account information, or other payment method data—note that we do not store full payment details ourselves).

  • Purchase details (e.g., product ordered, transaction history, date of purchase, and purchase amount).

  • Device and technical information (e.g., IP address, browser type, operating system, and referring URLs) for security and fraud prevention.

Digistore24 handles this information securely and in line with their own privacy practices. For more details on how Digistore24 processes and protects your data, please review their Privacy Policy at https://www.digistore24.com/page/privacy (for non-EEA users) or https://www.digistore24.com/en/page/privacy (for EEA users).

By completing a purchase on zenbodyflow.com, you consent to this sharing of your data with Digistore24. If you do not agree, please do not proceed with the purchase.

Legal Basis for Processing (GDPR): As we are based in Germany, the GDPR applies to our processing activities. The sharing of your data with Digistore24 is necessary for the performance of the contract with you (Article 6(1)(b) GDPR), such as processing your payment and delivering the product. In some cases, it may also be based on our legitimate interests (Article 6(1)(f) GDPR), such as fraud prevention and improving our services, provided these do not override your rights and freedoms.

International Data Transfers: Digistore24 is based in the EEA (Germany), but they may transfer data to third parties outside the EEA, such as to the United States for certain services (e.g., analytics or marketing partners). These transfers are protected by appropriate safeguards, including EU Standard Contractual Clauses (SCCs) or participation in the EU-US Data Privacy Framework (DPF), to ensure an adequate level of data protection. We only transfer data where necessary and in compliance with GDPR Chapter V.

Data Retention: Digistore24 retains your data only as long as necessary for the purposes outlined (e.g., transaction processing, legal obligations like tax records, or dispute resolution). Typically, this is up to 10 years for financial records under German law, but personal data is deleted or anonymized sooner if no longer needed. We require Digistore24 to adhere to these retention limits in our agreement.

Your Rights: You have rights regarding your personal data under applicable laws. Under the GDPR (for EEA users, including Germany):

  • Right of access: Request details of the data we or Digistore24 hold about you.

  • Right to rectification: Correct inaccurate data.

  • Right to erasure ('right to be forgotten'): Request deletion where there is no compelling reason for retention.

  • Right to restriction of processing: Limit how data is used in certain cases.

  • Right to data portability: Receive your data in a structured format.

  • Right to object: Oppose processing based on legitimate interests, including for direct marketing.

  • Right to withdraw consent: Where processing relies on consent.

To exercise these rights, contact us at info(at)zenbodyflow.com or Digistore24 directly at helpdesk@digistore24.com. We will respond within one month (extendable if complex). If unsatisfied, you can complain to your local data protection authority (in Germany, the relevant Landesdatenschutzbehörde or the Federal Commissioner for Data Protection and Freedom of Information).

For users in the United States (especially California under the CCPA/CPRA, if applicable): You may have additional rights, such as the right to know what data is collected/shared/sold, right to delete, right to correct, right to opt-out of sales or sharing for targeted advertising, and right to non-discrimination. Digistore24 provides opt-out options via their "Do Not Sell or Share My Personal Information" page. Contact us or Digistore24 for requests; we verify identity before responding. Note: We do not "sell" data in the traditional sense, but some sharing (e.g., with affiliates) may qualify under CCPA.

If you have questions about your data or wish to exercise your rights, contact us at info(at)zenbodyflow.com. We do not use automated decision-making that significantly affects you.

Newsletter Subscription via Acumbamail

If you subscribe to our newsletter, your email address and any other information provided will be transmitted to and stored by our newsletter service provider, Acumbamail.
We use Acumbamail exclusively for sending newsletters and managing subscriptions. Your data will be processed solely for the purpose of sending you relevant email updates and will not be shared with third parties.
For more information on how your data is handled by Acumbamail, please refer to their privacy policy: https://acumbamail.com/privacy-policy/

Unsubscribe Instructions: If you receive marketing communications (e.g., newsletters) from us, you can unsubscribe at any time by clicking the “Unsubscribe” link at the bottom of any email or by contacting us at info(at)zenbodyflow.com. You may also manage your preferences through your account on our website, if applicable. We will process your unsubscribe request promptly in compliance with GDPR and German data protection laws.

Contact Form

When you use the contact form on our website, we collect personal data such as

  • Name

    Collected via contact form

    Used to respond to your inquiry

  • Email address

    Collected via contact form

    Used for follow-up communication

  • Message content

    Collected via contact form

    Used to address your inquiry

This data is used solely for the purpose of responding to your inquiry and for any necessary follow-up communication.
Your information is stored securely and is not shared with third parties, except as required by law.
As our website is hosted by Hostinger, technical processing and storage of your submitted data may occur on Hostinger’s servers. For more information about Hostinger’s data handling, please refer to their privacy policy: https://www.hostinger.com/privacy-policy

Cookiebot

We use Cookiebot to manage cookie consent on our website. Cookiebot collects information such as your IP address and consent status to ensure compliance with data protection regulations. Data may be shared with third parties, including Cookiebot (Usercentrics). For more details, please refer to the Cookiebot privacy policy: https://www.cookiebot.com/en/privacy-policy/

Data Storage:
Data is stored only as long as necessary for the purpose (e.g., until inquiries are resolved). Analytics data is anonymized where possible and deleted after [e.g., 14 months, specify if using Google Analytics].

Data Subject Rights:
Under GDPR, you have the right to:

  • Access, rectify, or delete your data (Art. 15–17 GDPR).

  • Restrict or object to processing (Art. 18, 21 GDPR).

  • Data portability (Art. 20 GDPR).
    Contact us at hi@zenbodyflow.com to exercise these rights. You may also lodge a complaint with a supervisory authority (in Germany: [Your State’s Data Protection Authority, e.g., Landesbeauftragter für Datenschutz NRW]).

Data Security:
We implement technical and organizational measures (e.g., SSL encryption) to protect your data. However, no online transmission is 100% secure.

Cookies:
We use required and optional cookies. Required cookies ensure functionality and do not need consent. Optional cookies (e.g., analytics, marketing) require your consent via our cookie banner. Third-party cookies may apply for embedded content (e.g., YouTube). Manage preferences in the cookie banner.

Data Transfer to Third Countries:
Data may be transferred to third countries (e.g., USA) via third-party services, subject to GDPR-compliant safeguards (e.g., Standard Contractual Clauses).

Updates:
This policy may be updated. The latest version is available at https://zenbodyflow.com/data-privacy.

Contact information:

If you would like to contact us to understand more about this Policy or wish to contact us concerning any matter relating to individual rights and your Personal Information, you may send an email to info(at)zenbodyflow.com.

Last Update October 30th, 2025