PRIVACY POLICY
Privacy Policy
This Privacy Policy explains what personal data Letting Go Zen Studio processes, why and on what legal basis, who we share it with, how long we keep it, and the rights you have under UK GDPR and the EU GDPR.
Effective date: 14 August 2026
1. Data Controller and Contact
The controller of your personal data is Letting Go Zen Studio (a sole trader, Joanna Witkowska), 42 Leslie Road, Aberdeen AB24 4EF, Scotland, United Kingdom.
- For anything relating to your personal data, contact: lettinggozenstudio@gmail.com
- Given the size and nature of the business we are not required to appoint a Data Protection Officer. All enquiries are handled directly by the controller.
- We respond to requests about your UK GDPR and GDPR rights within one month of receiving them.
2. What We Collect and Where It Comes From
We only collect data you give us yourself, in one of three places on this website. Here is exactly what we store in each case.
- Booking consent form — your full name, email address, phone number, typed signature, the service you chose, seven consent confirmations, your site language, the date and time you signed, and — as evidence that consent was given — your IP address and browser identifier (user agent).
- Contact form — your name, email address, optionally your phone number and subject, your message, and your site language.
- Shop or cart purchase — your email address, the name and type of the product, the amount and currency, the Stripe payment reference, a record of the terms you accepted and when, and for shipped products your name and delivery address.
- Booking an appointment — your name, email address and answer to the consent question are entered directly into the Cal.com widget. That data goes to Cal.com rather than into our database; we see it on the booking confirmation.
- Technical data — our hosting provider (Vercel) records standard server logs, including IP address and browser type, to keep the site secure and working.
We do not run a newsletter, buy mailing lists, or collect data from any source other than those above. We do not carry out profiling or automated decision-making that produces legal effects.
3. Health Data (Special Category Data)
The booking consent form asks you to confirm that the health information you have given is truthful, and during a session itself you may share information about your health and wellbeing. This is special category data under Article 9 of the UK GDPR and GDPR. We process it only on the basis of your explicit consent (Article 9(2)(a)), which you may withdraw at any time, and — so far as necessary to establish, exercise or defend legal claims — on the basis of Article 9(2)(f). Please do not enter health information into the contact form or the signature field; share it directly during your session instead.
4. Purposes and Legal Bases
Each purpose has its own legal basis. They are set out explicitly below.
- Delivering the service or purchase you asked for (booking a session, sending a PDF, shipping a product) — necessary for the performance of a contract, Article 6(1)(b).
- Keeping the signed consent form together with your IP address and browser identifier — our legitimate interest in being able to demonstrate that consent was given and in establishing or defending legal claims, Article 6(1)(f).
- Processing health information — your explicit consent, Article 9(2)(a).
- Replying to a message sent through the contact form — our legitimate interest in handling your enquiry, Article 6(1)(f).
- Keeping sales and tax records — a legal obligation to which we are subject, Article 6(1)(c), read with HMRC record-keeping requirements.
- Keeping the site secure and preventing abuse (server logs, spam protection on forms) — our legitimate interest, Article 6(1)(f).
5. How Long We Keep It
We do not keep data indefinitely. Each type of record has a defined period, after which it is deleted.
- Booking consent forms (name, contact details, signature, IP address) — 6 years from the date of the session, reflecting the limitation period for claims, after which the record is deleted.
- Contact form messages — 12 months from our reply, unless the exchange becomes a booking or an order.
- Shop and cart orders (including delivery addresses) — 6 years from the end of the tax year in which the sale took place, in line with HMRC requirements for financial records.
- Technical email delivery records (the send queue and provider events) — 90 days, for troubleshooting only.
- Payment incident records flagged for manual review — 12 months after the issue is resolved. These contain no personal data, only a payment reference.
- Download links for purchased PDFs — these expire automatically 30 days after purchase.
- Server logs held by our hosting provider — in line with Vercel's standard retention, approximately 30 days.
Stripe also retains payment data and Cal.com retains booking data, each under its own retention policy and legal obligations. You may ask us to delete your data sooner at any time, and we will do so unless a legal obligation prevents it (for example tax records).
6. Who We Share It With
We do not sell your data and we do not share it for marketing. We use the providers listed below, each of which processes data only on our documented instructions under a data processing agreement.
- Supabase, Inc. — database and file storage. This is where consent forms, contact messages and orders are stored.
- Stripe Payments Europe, Ltd. and Stripe, Inc. — payment processing for shop and cart purchases.
- Cal.com, Inc. — the booking calendar and the session payment taken inside the booking widget.
- Resend, Inc. — sending automated email: download links, order confirmations and notifications to the controller.
- Vercel, Inc. — website hosting and server logs.
- Sanity AS (Norway) — content management system. It holds website content only (service descriptions, prices) and no customer data.
- Google Ireland Limited — the business mailbox that receives order notifications and customer correspondence.
We may also disclose data to an accountant or legal adviser so far as necessary for accounts and legal claims, and to public authorities where the law requires it.
7. Transfers Outside the UK and EEA
Several of the providers listed above (Supabase, Stripe, Cal.com, Resend and Vercel) are based in the United States, which means your data may be processed outside the United Kingdom and the European Economic Area. Any such transfer is made under the safeguards required by Article 46 of the UK GDPR and GDPR: the UK International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses together with the UK Addendum, and for providers that participate in the Data Privacy Framework also under the adequacy decision and its UK Extension. We will provide a copy of the safeguards in place on request to the address in section 1.
8. Payments and Card Details
We never see or store your card number. The payment fields are presented directly by Stripe (in the shop and cart) or by Cal.com together with Stripe (when booking a session), and your card details go straight to the payment provider. Our database records only the transaction reference, the amount, the currency and the buyer's email address — the information we need to fulfil the order and account for the sale.
9. Security
We apply technical and organisational measures appropriate to the risk of the data we hold.
- All traffic to the site runs over an encrypted HTTPS connection.
- Tables holding personal data are protected by Row Level Security and are not publicly readable or reachable from the browser — only the server can read them, using a service key.
- PDF files are held in a private storage bucket, and every download link is signed and expires after 30 days.
- Payments are only ever acted on after a cryptographically signed notification from Stripe, so an order cannot be forged.
- Access to the admin panel, the database and the payment account is protected by individual accounts with identity-provider sign-in.
10. Your Rights
You have the following rights over your personal data, and you can exercise any of them free of charge by writing to lettinggozenstudio@gmail.com.
- The right to access your data and receive a copy of it.
- The right to have inaccurate or incomplete data corrected.
- The right to erasure where the data is no longer needed for the purpose it was collected for.
- The right to restrict processing, and the right to object to processing based on legitimate interests.
- The right to portability for data processed under a contract or on the basis of consent.
- The right to withdraw consent at any time, without affecting the lawfulness of processing carried out before it was withdrawn.
To verify who is making the request we may ask you to confirm details you gave when booking or ordering. We do not charge a fee unless a request is manifestly unfounded or excessive.
11. Complaints to a Supervisory Authority
If you believe we are handling your data unlawfully, please contact us first and we will try to put it right. You also have the right to complain to a supervisory authority. In the United Kingdom this is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. If you live in Poland or another EEA country you may also complain to the authority for your place of residence — in Poland this is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
12. Cookies
This website uses only cookies that are strictly necessary for it to work — remembering your chosen language (NEXT_LOCALE). It is written only when you deliberately switch language and kept for 180 days; ordinary browsing does not create it, because the /pl and /en addresses already carry the language themselves. We do not use analytics or marketing cookies and we do not analyse visitor traffic, which is why the site shows no cookie consent banner. When you pay or book, our providers (Stripe and Cal.com) may set their own cookies that are necessary to complete the transaction securely and to prevent fraud. You can change cookie settings in your browser.
13. Changes to This Policy
We update this policy when the way the site works changes, or when the list of providers we share data with changes. The current version is always available at this address, and its effective date is shown at the top of the page. Where a change materially affects people we are in contact with, we will also tell them by email.