Privacy policy
What this website collects, why, how long we keep it and what you can ask us to do with it.
Who the controller is
Crossgym Satu Mare is the trading name of ASOCIAȚIA SPORTIVĂ CROSS GYM SATU-MARE, fiscal registration number 37397059, registered office at Str. Fântânele, CF 14, floor II, Satu Mare, Romania, represented by Mr Vlad Verdeș, President. The gym itself is at Bulevardul Vasile Lucaciu 3, Satu Mare.
For any question about your data, call 0742116610 or write to contact@crossgymsatumare.ro.
What this website collects
The contact form: your name, email address, optionally your phone number, and your message. The form contains one hidden, empty field that spam robots fill in and people never see; whatever lands in it is discarded, never stored. Beyond that we add nothing to what you type.
Your preferences: the language you chose and your cookie choice. These stay in your browser, not on our servers.
We do not use Google Analytics. We use Vercel Web Analytics, which counts visits without cookies and without identifying you: it builds no profile, does not follow you to other sites and sells nothing. We have no tracking pixels, we do not profile you and we make no automated decisions about you.
Legal basis
Messages sent through the form are processed on the basis of your consent (Art. 6(1)(a) GDPR), given by ticking the box next to the button. Without the tick, the form sends nothing.
Strictly necessary cookies rest on the legitimate interest of making the site work (Art. 6(1)(f)). Anything else requires separate consent.
How long we keep things
Messages received through the form are kept for at most 12 months after the last exchange, then deleted. If you become a member, membership data is handled separately, in the gym’s own system.
Your cookie choice is remembered for 12 months, after which we ask again.
Who else sees the data
Messages reach the coaches and whoever is on reception. We do not sell data and we do not share it for marketing.
Our hosting provider processes data technically on our behalf under a processing agreement. If you choose to load the map, Google receives your IP address — which is why the map stays off until you ask for it.
Member accounts
If you have a member account we keep: your name, email address, optionally your phone number, an encrypted form of your password (never the password itself), your memberships and their dates, sessions used, class bookings, and any training results you choose to log.
The legal basis is performance of the contract between you and the gym (Art. 6(1)(b) GDPR) — without this data we cannot track your membership or your bookings. Training results are optional: you log them only if you want to.
What other members see: on a class you have booked, other signed-in members see your name in the attendee list, and under the workout of the day they see the results and comments you post. None of this is visible to visitors who are not signed in.
Signing in uses a strictly necessary session cookie, described in the cookie policy. It contains no password and is not used for tracking.
Technical logs
Like any website, the server records the requests it receives: IP address, time, the page requested and the browser type. These logs exist to run and protect the site — for example to limit repeated sign-in attempts. The basis is the legitimate interest of keeping the service secure (Art. 6(1)(f)).
The counter that limits sign-in attempts briefly remembers the IP address and the email address used, only in the server memory and only for one minute.
Where the data is hosted
The website is hosted by Vercel Inc. and the database by Neon Inc. Both run on servers in Frankfurt, Germany, so the data sits inside the European Union.
Both companies are, however, registered in the United States, and administration or technical support may involve access from outside the European Economic Area. Such transfers take place under the Standard Contractual Clauses approved by the European Commission, set out in the processing agreements signed with each provider.
Your rights
You have the right to ask for access to your data, to have it corrected or erased, to restrict processing, to portability, and to object to processing. You can withdraw consent at any time, as easily as you gave it.
If you have a complaint, you can lodge it with the Romanian data protection authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest.
Security
The site is served over HTTPS, sends security headers (including a content security policy) and loads no scripts from other domains. The form is rate-limited against automated abuse.