Privacy Policy
We take the protection of your personal data seriously and treat it confidentially in accordance with the General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the Spanish data protection act (Ley Orgánica 3/2018, LOPDGDD). The controller is established in Spain; the supervisory authority is the Spanish Data Protection Agency (AEPD).
1. Controller
Ursula Pichler
AddressAvenida Litoral de Agache 38
38591 La Puente
Tenerife, España
Phone Email2. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and to withdraw consent given (Art. 7(3) GDPR). An informal message to the contact details above is sufficient.
3. Right to lodge a complaint
The competent supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You may also contact the authority of your place of residence.
4. Hosting and transfer to a third country (USA)
This website is operated with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (an EU-based processor; data processing agreement under Art. 28 GDPR). Server location: a data centre in Ashburn, Virginia, USA → processing in a third country. The transfer is safeguarded by EU Standard Contractual Clauses (Art. 46 GDPR) and technical measures (TLS). The USA does not offer a fully equivalent level of data protection; access by US authorities cannot be entirely ruled out. Legal basis: Art. 6(1)(f) in conjunction with Art. 46(2)(c) GDPR.
5. Server log files
On each access the following are automatically collected: shortened IP address, date/time, requested resource, HTTP status, data volume, referrer, browser/operating system. Purpose: technical provision and security (Art. 6(1)(f) GDPR). Deleted after 14 days at the latest.
6. SSL/TLS encryption
The website uses SSL/TLS encryption throughout ("https://").
7. Contact form
When you contact us we process your name, email, treatment interest (optional) and your message in order to handle your enquiry (Art. 6(1)(b) or (f) GDPR). A honeypot field and rate limiting are used for spam protection. Enquiries are forwarded by email and stored in our internal inbox; they are automatically deleted after 6 months at the latest, unless an ongoing enquiry requires longer storage. You can request deletion at any time.
8. Fonts (self-hosted)
Fonts are served locally from our server. There is no connection to Google Fonts; your IP is not transmitted to third parties for this purpose.
9. Cookies
This website sets no cookies for analytics or marketing and integrates no tracking services. The members' area uses a single technically necessary session cookie to keep you logged in.
10. Instagram widget (SnapWidget)
The Instagram feed on the home page is embedded via SnapWidget (SnapWidget Inc., USA). When this section of the page loads, your IP address and browser information may be transmitted to SnapWidget's servers and, depending on whether you are logged in to Instagram, to Meta Platforms Ireland Ltd. We have no influence over this processing. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in presenting social content). You can prevent transmission by using a browser extension that blocks third-party embeds. For further details see SnapWidget's privacy policy and Instagram's privacy policy.
11. Members' area (login, profile, favourites, comments)
If you register for the members' area we process: your name and email address (stored encrypted, AES-256-GCM; the email is additionally stored as a one-way hash used solely for login), and your password (stored only as a bcrypt hash, never in plain text). Optionally, if you provide them: a display name, a short bio and a profile picture. While using the area we also store your membership level, login timestamps, your session, the recipes and meditations you mark as favourites, the lists you create, any comments you post on meditations, and your personal meditation practice log (date and duration of your sessions plus an optional self-chosen mood afterwards; visible only to you). Your comments, display name and profile picture are visible to other logged-in members. Profile pictures and all member media are accessible to authenticated members only. Legal basis: performance of the membership (Art. 6(1)(b) GDPR). Storage: until you delete your account. You can delete your account at any time under Settings; this irrevocably removes all of the above data (right to erasure, Art. 17 GDPR). Via "Settings → My data" you can also export your data yourself at any time as a machine-readable file (data portability, Art. 20 GDPR).
12. Newsletter ("Join our community")
If you sign up for our newsletter we process your email address (stored encrypted, AES-256-GCM, plus a one-way hash) together with the date and language of your sign-up and, once given, the date of your confirmation. We use the double opt-in procedure: after signing up you receive an email with a confirmation link, and only after you click it is your address added to the list. The sign-up and confirmation records serve as evidence of your consent (Art. 7(1) GDPR). Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time with effect for the future — every email contains a link through which you can unsubscribe and have your data deleted completely. A newsletter sign-up on its own does not grant access to the members' area; it can be upgraded to a full membership account at your own request at any time (see section 11). Your address is stored until you unsubscribe or delete your data.
13. Status
As of August 2026. We update this policy as needed.