Data protection

1. Responsible body

The entity responsible for processing your personal data is:


Iron Alps AGSchoretshuebstrasse 249015 St. GallenSchweizE-Mail: info@iron-alps.ch

The responsible body within the meaning of data protection law is the management of Iron Alps AG.


2. Legal basis

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP).


3. Personal data collected

We process the following personal data in particular:

Mandatory information

  • Full name
  • Wohnadresse
  • Email Address
  • birth date
  • Gender
  • Image and video recordings of people as part of the video surveillance of our premises


Optional information

  • Telephone number
  • Emergency contact (name and phone number)


As a general rule, we do not process any particularly sensitive personal data as defined by the GDPR. If individual details collected during training sessions could allow inferences to be drawn about a participant's physical condition, this data is processed solely for the purpose of ensuring the safe conduct of the training and without any medical assessment. Should a medical assessment or any other processing of particularly sensitive personal data become necessary in the future, we will obtain the consent of the data subject and comply with all other related obligations.


4. Purpose of data processing

Personal data is processed for the following purposes:

  • Management of memberships and customer relationships
  • Handling of course bookings, check-ins and training offers
  • Communication related to training operations
  • Invoicing and accounting
  • Emergency contact during training
  • Internal administrative and organizational purposes
  • Internal evaluations and operational analyses
  • Ensuring the safety of employees and customers, as well as protecting the premises from burglaries and unauthorized use.
  • Marketing (via email, SMS, WhatsApp and similar channels)


Use for marketing purposes only occurs within the scope of ongoing business operations and without disclosure to third parties.


5. Video surveillance

We operate video surveillance in our premises and in the outdoor area.

Video surveillance serves exclusively the following purposes:

  • Protection of people, customers
  • Protection of property and infrastructure
  • Prevention and investigation of theft, property damage or other security-related incidents

The data will not be used to monitor the performance or behavior of customers or employees.


Video surveillance is limited to security-relevant areas. Areas requiring special protection (e.g., changing rooms, showers, or restrooms) are not monitored by video surveillance.


Access to the video recordings is restricted to authorized members of management or expressly appointed individuals. Disclosure to third parties only occurs when necessary, particularly to law enforcement agencies.


Video recordings are generally deleted after a maximum of 72 hours, unless security-related incidents occur. Recordings required for evidentiary purposes are retained until the conclusion of the respective proceedings.


The video-monitored areas are marked by clearly visible signs.


Video surveillance is carried out based on our overriding legitimate interest in the safety of persons and property in accordance with the GDPR and while maintaining proportionality.


6. Systems and service providers used

We use the following systems to collect and manage personal data:

  • Wodify (App and Website) – © Wodify Technologies, LLC Use as member management, booking and administration software
  • Stripe payment processing via the payment platform integrated into Wodify
  • Microsoft 365 (e.g., SharePoint, Outlook): Internal processing, management, and archiving of exported personal data


The aforementioned providers process personal data on behalf of Iron Alps AG and exclusively in accordance with our instructions. We reserve the right to export personal data from Wodify and reuse it for internal business purposes.


7. Data transfer abroad

The use of Wodify, Stripe and Microsoft may result in the transfer of personal data abroad, particularly to the USA.


Insofar as personal data is transferred to countries without an adequate level of data protection (in particular the USA), we ensure the protection of the data through suitable guarantees, in particular by concluding standard contractual clauses pursuant to Art. 16 GDPR and supplementary technical and organizational measures.


8. Disclosure of personal data

Personal data will not be sold or passed on to uninvolved third parties.


Data will only be shared with:

  • to commissioned service providers within the scope of service provision
  • to the extent necessary for the operation
  • or due to legal obligations


9. Storage duration

Personal data is stored only as long as necessary for the respective purposes or as required by law. The following retention periods apply in particular:

  • Master data of members and customers (name, address, email, date of birth, gender): duration of membership and for up to 24 months after the end of the contract.
  • Course bookings, check-ins and participation history: 12 months after the respective event
  • Communication data related to training operations: 24 months
  • Optional contact details (e.g., telephone number): Duration of membership and for up to 6 months after the end of the contract.
  • Emergency contacts: Only during active membership; deletion no later than 30 days after contract end.
  • Invoices, payment and accounting documents: 10 years in accordance with statutory retention requirements (Swiss Code of Obligations and Commercial Accounting Ordinance)
  • Video recordings: Generally a maximum of 72 hours; in security-related incidents, until the incident is clarified or proceedings are concluded.


After the respective retention periods have expired, personal data will be deleted or anonymized. Data that must be retained due to legal obligations will be blocked, and access will be restricted to the necessary minimum.



9. Data security

We take appropriate technical and organizational measures to protect personal data from unauthorized access, loss or misuse.


10. Rights of data subjects

Under the GDPR, data subjects have the following rights:

  • Information about the personal data we process
  • Correction of inaccurate or incomplete personal data
  • Deletion of personal data, provided there are no legal retention obligations.
  • Disclosure or transmission of personal data in a commonly used electronic format
  • Objection to data processing, insofar as legally provided for



Inquiries should be directed to the contact address mentioned above.


11. Changes

We reserve the right to amend this privacy policy at any time. The current, published version always applies.