Privacy Policy

Last updated: 14 March 2026.

1. Controller

FlowAway
Lena Bludau
Zollhof 7
90443, Nürnberg, Germany
Email: info@flowaway.org
Website: flowaway.org

2. Overview

FlowAway is a digital marketplace connecting users with independent yoga teachers, wellness facilitators, and movement coaches across Europe. This privacy policy explains what personal data we collect, why we collect it, how we process it, and what rights you have.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Bundesdatenschutzgesetz (BDSG).

3. Data We Collect

From Participants (Users who book sessions)

Name and email address – To confirm your booking and communicate with you about your session. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Payment information – Processed by our payment providers Stripe and PayPal. FlowAway does not store your credit card or bank details. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Booking history – To manage your orders and process any refunds. Legal basis: Art. 6(1)(b) GDPR (contract performance).

IP address and browser data – Collected automatically for website functionality and security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

Health information: After booking, Teachers may optionally collect health information (e.g., injuries, pregnancy) via a form. This data is stored on the FlowAway platform and made visible to the Teacher. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 9(2)(a) GDPR (explicit consent of the participant via the form).

From Teachers

Name, email address, and phone number – To manage your account and communicate with you. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Bank or PayPal details – To process payouts. Legal basis: Art. 6(1)(b) GDPR (contract performance).

Tax ID / Steuernummer – For legal and tax compliance. Legal basis: Art. 6(1)(c) GDPR (legal obligation).

Photos, bio, certifications, and social media links – To display your profile on the platform. Legal basis: Art. 6(1)(b) GDPR (contract performance).

4. How We Use Your Data

We use personal data exclusively for:

- Providing and operating the FlowAway marketplace
- Processing bookings and payments
- Communicating with Users and Teachers about their bookings
- Fulfilling legal obligations (e.g., tax, accounting)

We do not sell your data. We do not share personal data with third parties for advertising purposes.

5. Data Sharing

We share personal data only with the following categories of recipients, and only to the extent necessary.

With Teachers

When a User books a session, the Teacher receives the User's name and email address for the purpose of session delivery. Teachers are required to handle this data in compliance with GDPR.

With Payment Processors

Payment information is processed by Stripe, Inc. (USA) and PayPal (Europe) S.à r.l. (Luxembourg). These processors handle payment data under their own privacy policies and Data Processing Agreements.

Stripe: https://stripe.com/privacy
PayPal: https://www.paypal.com/webapps/mpp/ua/privacy-full

With Service Providers (Data Processors)

We use the following service providers to operate the platform. Each processes data on our behalf under a Data Processing Agreement (DPA) or Standard Contractual Clauses (SCCs) where applicable.

Website and hosting: Webflow, Inc. (USA) – website hosting and CMS. webgo GmbH (Germany) – domain and DNS management.

Communication: Google LLC (USA) – email sending via Gmail.

Payments: Stripe, Inc. (USA) – payment processing. PayPal (Europe) S.à r.l. (Luxembourg, EU) – payment processing.

Teacher dashboard: Softr (EU) – teacher-facing admin interface.

For US-based providers, data transfers are protected by Standard Contractual Clauses (SCCs) as per Art. 46(2)(c) GDPR, and/or the EU-US Data Privacy Framework where applicable.

6. Cookies

FlowAway currently uses only technically necessary cookies that are required for the website to function (e.g., session management). These do not require consent under GDPR. We do not currently use analytics, marketing, or tracking cookies. If this changes in the future, we will update this policy and implement a cookie consent mechanism before any such cookies are activated.

7. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy.

Booking and transaction data – 10 years after the calendar year of the transaction, as required by German tax law (§147 AO, §257 HGB).

Teacher data – For the duration of the contractual relationship, plus 10 years for tax and legal obligations.

9. Your Rights

Under the GDPR, you have the following rights:

Right of access (Art. 15) – You can request information about what personal data we process about you.

Right to rectification (Art. 16) – You can request correction of inaccurate data.

Right to erasure (Art. 17) – You can request deletion of your data, unless we are legally required to retain it.

Right to restriction (Art. 18) – You can request that we limit how we process your data in certain circumstances.

Right to data portability (Art. 20) – You can request your data in a structured, machine-readable format.

Right to object (Art. 21) – You can object to processing based on legitimate interest at any time.

Right to withdraw consent (Art. 7(3)) – Where processing is based on consent (e.g., newsletter), you can withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at: info@flowaway.org. We will respond within 30 days.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for FlowAway is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption of data in transit (TLS/SSL), encryption of data at rest by our service providers, access controls limiting who can view personal data, and SPF, DKIM, and DMARC email authentication.

11. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at flowaway.org/privacy-policy.
Today is the day to

..meet your future favorite Yoga teacher