easybook.studio

Privacy for class participants

What easybook.studio does with your data, and which parts are your studio's to answer for.

Last updated: 21 August 2026

Two organisations, two roles

When you book a class, two different organisations handle your data, and which one does what matters.

Your studio decides what happens with your bookings, your attendance and your purchases. Under the GDPR it is the controller for those, and its own privacy policy covers them. easybook.studio only carries out the studio's instructions there, as its processor under Art. 28 GDPR.

easybook.studio is the controller for one part: the account itself — the login you created and the technical records that keep it working and secure. That part is what this notice is about.

So: questions about your bookings go to your studio. Questions about your account and this notice come to us.

Who is responsible

easybook.studio, Christoph Morosoli, c/o embrace yoga, Felsenkellerstr. 1b, 07745 Jena, Germany. Email: [email protected].

We are not required to appoint a data protection officer. Write to the address above with any data protection question.

What we hold as controller

  • Your account: first and last name, email address, and the language you use the software in.
  • Your password, stored only as a cryptographic hash. We cannot read it.
  • Sign-in tokens that keep you signed in between visits.
  • Technical records from our servers: your IP address, the time, what was called, and error details — used to keep the service up and to stop abuse such as automated login attempts.

Everything else — your bookings, your attendance, your credits, your purchases — we hold for your studio, on its instructions, not on our own account.

Why, and on what legal basis

  • To give you an account and let you sign in and book — Art. 6(1)(b) GDPR, performance of this agreement with you.
  • To keep the service secure and working — rate limiting, blocking abuse, investigating faults — Art. 6(1)(f) GDPR, our legitimate interest in a service that is not abused and does not fall over.
  • To meet legal obligations where they apply to us — Art. 6(1)(c) GDPR.

We do not profile you, we make no automated decisions about you, and we do not use your data for advertising. The software sets only the cookies and local storage it technically needs to sign you in.

Who else sees it

We use service providers who process data on our instructions:

  • Supabase — database hosting, EU servers
  • Cloudflare and Google Cloud — hosting and delivery, EU servers
  • Amazon Web Services (SES) and Resend — sending email
  • Stripe and PayPal — payments, where your studio has connected them; they act for your studio when you pay
  • Whereby — video rooms, if your studio runs online classes

Where a provider processes data outside the EU, we rely on the EU Standard Contractual Clauses. We do not sell your data, and we do not pass it to anyone else except where the law requires it.

How long we keep it

We keep your account data for as long as your account exists. Once it is deleted, we remove or anonymise it within 90 days, unless the law requires us to keep something longer.

Technical and security records are kept only as long as we need them to investigate faults and abuse, and then deleted.

Your rights

You can ask us for a copy of your data (Art. 15), to correct it (Art. 16), to delete it (Art. 17), to restrict what we do with it (Art. 18), to hand it over in a portable format (Art. 20), and you can object to processing we base on legitimate interests (Art. 21). Where you gave consent, you can withdraw it at any time, which does not affect what we did before.

Write to [email protected]. If your request is about your bookings rather than your account, we will pass it to your studio, who decides on it.

You can also complain to a supervisory authority. Ours is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit, and you may instead go to the authority where you live or work.