Privacy Policy for hannoeigenbrod.com
Effective Date: April 8, 2025
1. Introduction
Welcome to hannoeigenbrod.com (the "Website"), dedicated to meditation resources and information. This Privacy Policy explains how Hanno Eigenbrod ("I", "me", "my") collects, uses, shares, and protects the personal data of visitors ("you") to this Website.
As I am based in France, I am committed to complying with the General Data Protection Regulation (GDPR) and other relevant data protection laws. Protecting your privacy is important to me.
For the purposes of the GDPR, Hanno Eigenbrod is the Data Controller for the personal data processed through this Website.
2. What Personal Data Do We Collect?
I may collect the following types of personal data:
- Information You Provide Directly:
- Contact Information: Name, email address when you subscribe to a newsletter, fill out a contact form, register for a course/event (if applicable), or otherwise communicate with me.
- Communication Content: Any information you include in your messages or feedback.
- Payment Information: If you purchase services or courses, payment details may be collected by my third-party payment processors (e.g., Stripe, PayPal). I typically do not store full credit card details myself.
- Information Collected Automatically:
- Usage Data: Information about how you interact with the Website, such as your IP address, browser type, operating system, device information, pages visited, time spent on pages, referring URLs, and dates/times of access.
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies (see Section 9 for more details).
- Sensitive Personal Data: This Website focuses on meditation. While the topic relates to well-being, I do not intentionally collect sensitive personal data (like specific health conditions) unless you explicitly provide it with clear consent for a specific purpose (e.g., tailoring a specific program if offered and if consent is obtained). Please avoid sharing sensitive data unless specifically requested and consented to.
3. How Do We Collect Your Personal Data?
I collect personal data:
- Directly from you: When you fill out forms, subscribe, contact me, or make purchases.
- Automatically: As you navigate the Website, through server logs, analytics tools (like Google Analytics, Matomo, or similar), and cookies.
4. Legal Basis for Processing Your Personal Data (GDPR)
I process your personal data based on the following legal grounds under GDPR:
- Consent (Article 6(1)(a) GDPR): When you have given clear consent for me to process your personal data for a specific purpose, such as subscribing to a newsletter or consenting to non-essential cookies. You can withdraw your consent at any time.
- Contractual Necessity (Article 6(1)(b) GDPR): When processing is necessary for the performance of a contract with you (e.g., providing a paid course you registered for) or to take steps at your request before entering into a contract (e.g., responding to your inquiry about services).
- Legal Obligation (Article 6(1)(c) GDPR): When processing is necessary for me to comply with the law (e.g., retaining financial records for tax purposes).
- Legitimate Interests (Article 6(1)(f) GDPR): When processing is necessary for my legitimate interests, provided these interests are not overridden by your fundamental rights and freedoms.
This includes:
- Operating, maintaining, and improving the Website.
- Understanding how visitors use the Website (using anonymized or aggregated analytics).
- Ensuring the security of the Website.
- Responding to your communications initiated via contact forms (arguably also contractual necessity depending on context).
5. How Do We Use Your Personal Data?
I use your personal data for the following purposes:
- To provide, operate, and maintain the Website.
- To respond to your inquiries, comments, or questions.
- To send you newsletters, updates, or promotional materials, if you have consented to receive them.
- To process transactions and deliver services or courses you have requested (if applicable).
- To improve the Website, content, and user experience (e.g., through analytics).
- To monitor and ensure the security and integrity of the Website.
- To comply with legal obligations.
6. How Do We Share Your Personal Data?
I do not sell your personal data. I may share your personal data with third parties only in the following circumstances:
- Service Providers: With trusted third-party vendors who perform services on my behalf, such as website hosting, email delivery (e.g., Mailchimp, Sendinblue), payment processing (e.g., Stripe, PayPal), analytics providers (e.g., Google Analytics), and IT support. These providers are contractually obligated to protect your data and use it only for the purposes for which it was disclosed.
- Legal Requirements: If required to do so by law, regulation, court order, or other governmental authority.
- Protection of Rights: To protect my rights, property, or safety, or the rights, property, or safety of others.
- Business Transfers: In connection with, or during negotiations of, any merger, sale of assets, financing, or acquisition of all or a portion of my activities by another company, provided that users are notified.
7. Data Retention
I will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Contact form data: Retained until your query is resolved and for a reasonable period thereafter for record-keeping.
- Newsletter subscription data: Retained until you unsubscribe.
- Analytics data: Typically retained in an aggregated or anonymized form for a specific period (e.g., as determined by the analytics provider's settings, like 26 months).
- Transaction data: Retained for the period required by financial and tax laws (often several years).
When retention is no longer necessary, your data will be securely deleted or anonymized.
8. Data Security
I implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures may include SSL/TLS encryption for data transmission, access controls, and secure hosting environments. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure.
9. International Data Transfers
Your personal data may be processed by service providers located outside the European Economic Area (EEA). If I transfer your personal data outside the EEA, I will ensure appropriate safeguards are in place to protect your data, such as:
- Transferring data to countries deemed to have adequate data protection laws by the European Commission.
- Using Standard Contractual Clauses (SCCs) approved by the European Commission.
- Relying on Binding Corporate Rules (BCRs) for intra-group transfers (if applicable).
- Ensuring the provider adheres to other approved mechanisms under GDPR.
10. Cookies and Tracking Technologies
This Website uses cookies and similar technologies (like web beacons or pixels) to enhance user experience, analyze site traffic, and ensure proper functioning.
- What are Cookies? Small text files stored on your device when you visit a website.
- Types of Cookies Used:
- Strictly Necessary Cookies: Essential for the Website to function (e.g., session management, security). These do not require consent.
- Performance/Analytics Cookies: Help me understand how visitors interact with the Website by collecting information anonymously (e.g., Google Analytics).
- Functionality Cookies: Allow the Website to remember choices you make (e.g., language preferences).
- Targeting/Marketing Cookies: Used to deliver relevant content or ads (Note: Specify if you use these; many meditation sites may not).
- Your Consent: For cookies that are not strictly necessary, I will ask for your consent via a cookie banner or management tool when you first visit the Website. You can manage your cookie preferences and withdraw consent at any time through the tool or your browser settings.
- More Information: For detailed information on the specific cookies used, their purpose, and duration, please refer to my [Link to your Cookie Policy - Recommended to create a separate, detailed Cookie Policy] or [Include detailed list here if not creating separate policy].
11. Your Rights Under GDPR
As a resident of the EU/EEA, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data I hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You can request the deletion of your personal data under certain conditions (e.g., if it's no longer necessary for the purpose collected, or you withdraw consent).
- Right to Restriction of Processing: You can request that I limit the processing of your data under certain circumstances.
- Right to Data Portability: You can request to receive your data in a structured, commonly used, machine-readable format and have the right to transmit that data to another controller.
- Right to Object: You can object to the processing of your data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: If processing is based on consent, you can withdraw your consent at any time (this does not affect the lawfulness of processing before withdrawal).
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. In France, the supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL) - https://www.cnil.fr/.
To exercise any of these rights, please contact me using the details provided in Section 14. I may need to verify your identity before processing your request.
12. Children's Privacy
This Website is not intended for individuals under the age of 16 (or a potentially lower age if specified by French law requiring parental consent). I do not knowingly collect personal data from children under this age. If I become aware that I have inadvertently collected such data, I will take steps to delete it promptly.
13. Changes to This Privacy Policy
I may update this Privacy Policy from time to time to reflect changes in my practices or for legal or regulatory reasons. Any changes will be posted on this page with an updated effective date. For significant changes, I may provide a more prominent notice (e.g., on the Website homepage or via email if you are subscribed). I encourage you to review this policy periodically.
14. Contact Information
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact me:
contact@hannoeigenbrod.com
hannoeigenbrod.com