Last updated: August 14, 2026
København Yoga Studio is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of all individuals who interact with our services. This page outlines how we fulfill our obligations under GDPR.
For the purposes of GDPR, the data controller is:
København Yoga Studio
Vesterbrogade 142
1620 København V
Denmark
Email: [email protected]
We collect and process the following categories of personal data:
We process your personal data under the following lawful bases:
You have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You can request that we correct any inaccurate or incomplete personal data we hold about you.
In certain circumstances, you have the right to request deletion of your personal data, including when:
You can request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of your GDPR rights, please contact us at [email protected] with:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months, in which case we will inform you of the extension and the reasons for delay.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Our retention periods are:
When we engage third-party processors to handle personal data on our behalf, we ensure:
We primarily process data within the European Economic Area (EEA). Any transfers outside the EEA are protected by appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement. In Denmark, the supervisory authority is:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Website: datatilsynet.dk
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated to you through our website or by email where appropriate.
For any questions about GDPR compliance or to exercise your rights, contact us at:
Email: [email protected]
Address: Vesterbrogade 142, 1620 København V, Denmark