Hollÿ's Pilates

Denmark · owned by Independent (Denmark) · hollyspilates.dk · 3 vendors

Hollÿ's Pilates is Odense's first and original pilates studio, founded in 2018 and located at Kongensgade 31A, 5000 Odense, Denmark. The studio offers classical mat pilates, reformer pilates, and apparatus classes on equipment such as the Wunda Chair, Spine Corrector, and Tower, delivered by highly qualified instructors in small groups. It operates on the principles of the classical pilates tradition, emphasising quality, personal development, and professional guidance.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 3

3 direct vendors, 72 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Hollÿ's Pilates exhibits medium migration readiness, leaning towards the lower end due to significant vendor lock-in. The company's core operations are heavily reliant on SaaS platforms (Squarespace for website/e-commerce, YOGO for booking/CRM). While these are modern cloud-based solutions, migrating away from them would involve substantial effort and cost due to proprietary data formats, APIs, and business logic, leading to high vendor lock-in. The number of critical vendors (at least 4 based on the tech stack, despite the "Total Vendors: 0" data point) is relatively small, meaning each vendor represents a significant dependency and potential migration hurdle. Regulatory compliance with GDPR is a known factor, but data residency requirements are not specified, which could introduce complexities during a migration if strict requirements emerge. The absence of financial stability data also makes it difficult to assess the company's capacity to fund a significant migration effort. The current setup is not cloud-native in a way that facilitates easy re-platforming or containerization, further reducing readiness for a flexible migration.

Compliance

5 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

GDPR is universally applicable to Hollÿ's Pilates as a Danish (EU) company processing personal data of EU residents. The company has taken visible steps toward compliance — publishing a GDPR clause in its terms and conditions, referencing EU-based data storage via YOGO, and stating a 5-year data retention policy. However, several gaps elevate risk to Medium: (1) No standalone, comprehensive privacy policy page was found — the GDPR notice is embedded in the general T&Cs rather than a dedicated, layered privacy notice as required by GDPR Articles 13/14; (2) Consent for photography/video is bundled into booking acceptance rather than being freely given and separately obtained, which may not meet GDPR Article 7 standards; (3) MailChimp is a US-based processor — no mention of Standard Contractual Clauses (SCCs) or adequacy decisions for this transfer; (4) No Data Processing Agreements (DPAs) are publicly referenced for third-party processors (Squarespace, MailChimp); (5) No Data Protection Officer (DPO) is mentioned, though one is not mandatory for companies of this size unless processing is large-scale or involves special categories; (6) No cookie consent banner or cookie policy was detected on the website. Enforcement by Datatilsynet (the Danish DPA) is active, and fines for SMEs, while typically lower than for large enterprises, are a real risk. The Danish DPA has issued guidance specifically targeting small businesses.

Evidence: https://www.hollyspilates.dk/priser-og-vilkaar, https://www.hollyspilates.dk, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Danish Marketing Practices Act — Assessment Required

The Danish Marketing Practices Act (Consolidated Act No. 426 of 3 May 2017, as amended) governs commercial communications, consumer protection, and direct marketing in Denmark. Hollÿ's Pilates engages in direct email marketing via MailChimp and social media marketing (Instagram, Facebook). The Act implements the EU's Unfair Commercial Practices Directive and contains specific rules on unsolicited electronic communications (implementing the ePrivacy Directive). Risk is Medium because: (1) the company automatically enrolls new customers in its MailChimp newsletter ('Alle nye kunder modtager vores nyhedsbrev via MailChimp'), which may not comply with opt-in consent requirements for direct marketing under Section 10 of the Act and the ePrivacy Directive; (2) the photography/video consent mechanism (bundled into booking acceptance) may not meet the standard for freely given, specific consent for marketing use of images. Enforcement by the Danish Consumer Ombudsman (Forbrugerombudsmanden) is active.

Evidence: https://www.hollyspilates.dk/priser-og-vilkaar, https://www.hollyspilates.dk

ISO 27001 (source) — Assessment Required

ISO 27001 is a voluntary international standard for information security management. It is not legally mandated for fitness studios in Denmark. However, it represents best practice for any organization processing personal data, and GDPR implicitly encourages appropriate technical and organizational security measures (Article 32). For a small pilates studio of this size and complexity, ISO 27001 certification would be disproportionate and is not expected by regulators or customers. Risk is Low because non-certification carries no legal penalty and is standard for micro/small businesses in this sector. The primary information security obligation for this company flows from GDPR Article 32.

Evidence: https://www.hollyspilates.dk/priser-og-vilkaar, https://www.hollyspilates.dk

Financials

Three-year financials

Financial Resilience Score: 5/10

Hollÿ's Pilates is a small, single-location boutique Pilates studio in Odense, Denmark, founded in 2018 under CVR 39233738. The business operates on a recurring-revenue model through monthly memberships and prepaid class passes, which provides predictable cash flow. Its differentiated positioning as 'Odense's first and original Pilates studio' with emphasis on classical training and high instructor qualification (partnerships with Den Danske Pilates Skole and Emotion School of Classical Pilates) supports premium pricing. The studio also benefits from multiple revenue streams including group classes, private training, intro packages, retail, and gift cards. However, the company faces significant resilience risks typical of micro-businesses. It has key-person dependency tied to the founder, single-location concentration with no geographic diversification, a fixed cost base (central Odense rent and reformer equipment leases), and likely a thin absolute equity buffer. Competitive intensity in the Danish Pilates/Reformer market has increased since 2022 with new chain entrants potentially pressuring pricing and retention. Without access to filed financial figures, external verification of resilience is limited, warranting a mid-range resilience score.

Key strengths: Recurring revenue from monthly memberships and prepaid class passes, Differentiated premium positioning as Odense's first Pilates studio, Multiple revenue streams (group classes, 1:1 training, retail, gift cards), Capital-light single-location operating model, Post-COVID tailwind in Reformer Pilates demand, Strong instructor qualification through educational partnerships

Risk factors: Key-person dependency on founder/lead instructor, Single-location geographic concentration in Odense, Increasing competitive intensity from new chain entrants since 2022, Fixed cost base (rent and reformer equipment leases) sensitive to churn, Small scale with likely thin equity buffer, No publicly disclosed financials limiting external verification

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report