Privacy Policy
This privacy policy for The Hot Room SRL describes how and why we might collect, store, use, and/or share your information when you use our services.
Last updated:
Introduction#
This privacy policy for The Hot Room SRL ("THR", "Company", "we", "us", or "our") describes how and why we might collect, store, use, and/or share (“Process”) your information when you use our services (the “Services” and/or our “Site”), such as when you:
- Visit our website at https://thr.ro, or any website of ours that links to this privacy policy;
- Access and utilize any features or services of our platform and/or our Services;
- Engage with us in other related ways, including any sales, marketing, or events.
This Privacy Policy is part of and should be read in conjunction with our Terms of Service. By using our Services, you agree to the Terms and this Privacy Policy.
Summary of Key Points#
This summary provides key points from our privacy policy.
- What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with THR and the Services, the choices you make, and the features or Services you use.
- Do we process any sensitive personal information? Yes, with your explicit consent, we may collect limited sensitive health information to ensure your safety while using our services.
- Do we receive any information from third parties? We do not receive any information from third parties (other than what you provide to us, such as through social login).
- How do we process your information? We process your information to provide, improve, and administer our Services and Site, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.
- In what situations and with which types of parties do we share personal information? We may share information in specific situations and with specific categories of third parties.
- What are your rights? Depending on where you are located geographically, the applicable privacy law may grant you certain rights regarding your personal information.
- How do you exercise your rights? The easiest way to exercise your rights is by contacting us using our contact form. We will consider and act upon any request in accordance with applicable data protection laws.
What information do we collect?#
In short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, participate in activities on the Services, or otherwise contact us. This also includes information you provide to use specific features of our Services.
Personal Information Provided by You
The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the features or services you use. The personal information we collect may include the following:
- Contact and Account Data: Such as your name, email address, phone number, and username. We may also collect emergency contact information for safety purposes.
- Purchase History: Information related to your purchases of memberships, class packs, or other services.
- Any other personal information you choose to provide: For example, responses you give when contacting support or feedback you provide in surveys.
- Sensitive information: For the health and safety of our clients, we may collect sensitive health-related information, such as pre-existing medical conditions, injuries, or pregnancy status, which you provide to us directly (for example, on a waiver or intake form). This information is used solely to ensure your well-being and safety while participating in our classes and is not used to build profiles or for any other purpose. We process this information only with your explicit consent, but we may require some of it to safely provide you with our services.
- Social Media Login Data: When you register with us, we may provide you with the option to connect your existing social media accounts to your THR account in order to access certain features of our Services. If you choose to connect your social media accounts, we will collect the information described in the section “How do we handle your social logins?” below (such as certain profile information from your social media account).
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In short: Some information – such as your Internet Protocol (IP) address and/or browser and device characteristics – is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes. This data is processed based on our legitimate interest (Art. 6(1)(f) GDPR) in ensuring the security, availability, and performance of our Services.
Like many businesses, we also collect information through cookies and similar technologies. (See “Do we use cookies and other tracking technologies?” below for more details.)
The information we collect automatically includes:
- Log and Usage Data: Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services, which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type and settings, and information about your activity in the Services (such as the date/time stamps of your usage, pages and files viewed, searches you conduct, and other actions you take, for example which features you use and for how long), as well as device event information (such as system activity, error reports (sometimes called “crash dumps”), and hardware settings).
- Device Data: We collect device data such as information about your computer, phone, tablet, or other devices you use to access the Services. Depending on the device used, this device data may include information like your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.
- Location Data: We collect location data such as information about your device’s location, which can be either precise or imprecise. How much location information we collect depends on the type of device and its settings. For example, we may use GPS and other technologies to collect geolocation data (which can give us your precise location) based on your IP address or mobile device’s GPS. You can opt out of allowing us to collect this information at any time either by refusing access (when your device requests your permission) or by disabling the Location setting on your device. However, note that if you choose to opt out, you may not be able to use certain aspects of the Services.
How do we process your information?#
In short: We process your information to provide, improve, and administer our Services, communicate with you, ensure security and fraud prevention, and comply with law. We may also process your information for other purposes with your consent.
We only process your information when we have a valid legal reason to do so. We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To facilitate account creation and authentication, and otherwise manage user accounts. We may process your information so that you can create and log in to your account, as well as to keep your account in working order.
- To deliver and facilitate the delivery of services to the user. We may process your information to provide you with the requested Services.
- To respond to user inquiries and offer support to users. We may process your information to respond to your inquiries, assist with issues you might be experiencing, and resolve any problems you report with the requested service.
- To send administrative information to you. We may process your information to send you details and updates about our products and Services, changes to our terms, conditions, and policies, and other similar information.
- To enable user-to-user communications. If you choose to use a feature of our Services that allows communication with another user, we may process your information to facilitate user-to-user communications with your consent.
- To request feedback. We may process your information when necessary to request feedback and to contact you about your experience with our Services.
- To send you marketing and promotional communications. We may process the personal information you send to us for marketing purposes, if this is in accordance with your marketing preferences. For example, with your consent (or as otherwise permitted by applicable law), we may use your email address to send you newsletters, new product updates, and special offers. You can opt out of our marketing emails at any time (see “What are your privacy rights?” below).
- To deliver targeted advertising to you. We may process your information to develop and display personalized content and advertising tailored to your interests and location, and to measure its effectiveness.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To identify usage trends. We may process information about how you use our Services to better understand usage patterns and user behavior, so we can improve our Services and make them more efficient and user-friendly.
- To determine the effectiveness of our marketing and promotional campaigns. We may process your information to better understand how to provide marketing and promotional campaigns that are most relevant to our users’ interests and to measure whether our campaigns are successful.
- To save or protect an individual’s vital interest. In extreme cases, we may process your information when necessary to save or protect someone’s life or vital interests, such as to prevent harm.
Do we collect payment information?#
In short: We do not collect or store your payment information. All payments are securely processed by our third-party partner, Viva Pay.
When you make a purchase through our Services, we do not directly collect or store your payment card details. Instead, all payment transactions are handled by our trusted payment processor, Viva Pay, which collects your payment data directly through their secure payment platform. Viva Pay is responsible for processing your payments and storing your payment information in accordance with its own privacy policy. We do not have access to or control over your full payment information (such as credit card numbers), and we rely on Viva Pay to maintain the security and compliance of all payment data.
What legal bases do we rely on?#
In short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) under applicable law to do so.
If you are located in the European Economic Area (EEA) or United Kingdom (UK), this section applies to you. The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. These legal bases include:
- Consent (Art. 6(1)(a) GDPR): We will ask for your consent to process certain optional personal information. You have the right to withdraw your consent at any time.
- Performance of a Contract (Art. 6(1)(b) GDPR): We process your information to carry out our obligations or take steps linked to a contract with you.
- Legitimate Interests (Art. 6(1)(f) GDPR): We may process your information to pursue our legitimate interests in operating and improving our Services.
- Legal Obligations (Art. 6(1)(c) GDPR): We may need to process your information to comply with applicable laws, regulations, and legal processes.
- Vital Interests (Art. 6(1)(d) GDPR): In extraordinary circumstances, we may process personal information to protect vital interests.
If you are located in Canada, this section applies to you. We will only process your personal information with your consent where required by Canadian law. In some cases, we may be legally permitted to process your information without your consent.
When and with whom do we share your personal information?#
In short: We may share information in specific situations and with the following categories of third parties.
We may need to share your personal data in the following situations:
- Vendors, Consultants, and Other Third-Party Service Providers: We may share your data with third-party vendors who perform services for us.
- Business Transfers: We may share or transfer your information in connection with any merger, sale of company assets, financing, or acquisition.
- Affiliates: We may share your information with our affiliates.
- Other Users: When you share personal information in public areas of the Services, it may be viewed by all users.
Do we use cookies and other tracking technologies?#
In short: Yes, we may use cookies and similar tracking technologies to collect and store your information.
We use cookies and similar tracking technologies to access or store information. You can control cookies through your browser settings.
How do we handle your social logins?#
In short: If you choose to connect a social media account with our Services, we will have access to certain information from that account.
Our Services offer you the ability to register or log in using your third-party social media account details. If you choose to do so, we will receive certain profile information about you from your social media provider. We use this information only for the purposes described in this policy.
Is your information transferred internationally?#
In short: Yes, we may transfer, store, and process your information in countries other than your own.
Our servers are located in the European Union. If you are accessing our Services from outside the EU, your information may be transferred to, stored, and processed by us in our facilities and by third parties with whom we may share your personal information, in the EU, the United States, and other countries.
If you are a resident in the European Economic Area (EEA) or United Kingdom (UK), these countries may not have data protection laws as comprehensive as those in your country. However, we have taken measures to protect your personal information, including implementing the European Commission’s Standard Contractual Clauses for transfers of personal data.
How long do we keep your information?#
In short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless otherwise required by law.
We will only keep your personal information for as long as you have an active account with us. When your account is terminated, we will either delete or anonymize your personal information.
Do we collect information from minors?#
In short: We do not knowingly collect data from or market to children under 18 years of age without parental consent.
By using the Services, you represent that you are at least 18 years old. If you are under 18, you must obtain your parent's or legal guardian's written consent to use the Services, and this consent must be provided in person at one of our locations. If we learn that we have collected personal information from a user under 18 without the required consent, we will take steps to delete such information.
What are your privacy rights?#
In short: In some regions (like the EEA, UK, and Canada), you have rights that allow you greater access to and control over your personal information.
Depending on your location, you may have the following rights:
- Right of Access: Request access to the personal information we hold about you.
- Right of Rectification: Request correction of inaccurate personal information.
- Right to Erasure: Request deletion of your personal information.
- Right to Restrict Processing: Request that we restrict the processing of your personal information.
- Right to Data Portability: Obtain your personal information in a machine-readable format.
- Right to Object: Object to the processing of your personal information.
If you are in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your local data protection supervisory authority.
Controls for do-not-track features#
Most web browsers include a Do-Not-Track (“DNT”) feature. We do not currently respond to DNT browser signals.
Do California residents have specific rights?#
In short: Yes, if you are a resident of California, you are granted specific rights regarding access to your personal information under the CCPA.
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request that we delete any personal information about you that we have collected.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information. THR does not sell your personal information.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your privacy rights.
Do we make updates to this policy?#
In short: Yes, we will update this policy as necessary to stay compliant with relevant laws.
We may update this privacy policy from time to time. The updated version will be indicated by an updated “Last updated” date.
How can you contact us about this policy?#
If you have questions or comments about this policy, we strongly recommend you use our contact form, however, you may contact us by post:
Postal Mail:
The Hot Room SRL
Bucharest, District 1,
31 General Gheorghe Magheru Boulevard, floor 5, office 2
Romania
How can you review, update, or delete your data?#
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please use our contact form.