Privacy Policy

Last updated: 24.08.2026

Your privacy matters to me. This page explains what information I collect when you visit this site or work with me, why I collect it, and what rights you have over it.

‍ ‍

WHO IS RESPONSIBLE FOR YOUR DATA

‍The person responsible (the "controller" under the General Data Protection Regulation) is:

‍Lena Maria Janßen
Rhythms of Wellbeing
Schlegelstr. 10
10115 Berlin, Germany

‍Email: hello@rhythmsofwellbeing.co

I am a sole practitioner and am not legally required to appoint a Data Protection Officer. You can reach me directly at the address above with any question about your data.

‍ ‍

WHAT DATA I COLLECT, WHY, AND ON WHAT LEGAL BASIS

When you visit the website

My website is hosted on Squarespace. When you open a page, your browser automatically transmits certain technical information to the hosting servers — your IP address, browser type and version, operating system, the page you came from, and the date and time of your visit. This is standard for any website and is necessary to deliver the site to you securely and reliably.

‍Legal basis: Article 6(1)(f) GDPR — my legitimate interest in operating a functional, secure website.

‍ ‍

Cookies and website analytics

My site uses cookies. Some are strictly necessary for the site to work (for example, remembering your cookie preferences or keeping a form session alive). Others are used by Squarespace's built-in analytics to help me understand how many people visit, which pages they read, and roughly where they come from. I do not use Google Analytics, Meta Pixel, or any other third-party tracking or advertising tools.

When you first visit, a cookie banner lets you accept or decline non-essential cookies. Analytics cookies are only set if you consent. You can change or withdraw your choice at any time through the banner settings.

Legal basis: Article 6(1)(a) GDPR (your consent) for analytics and other non-essential cookies, in conjunction with § 25(1) TDDDG. Article 6(1)(f) GDPR for strictly necessary cookies.

‍ ‍

When you use the contact form

If you write to me through the contact form, I receive the information you enter — typically your name, your email address, and your message. I use this solely to respond to you and, if relevant, to discuss whether working together might be a good fit.

Legal basis: Article 6(1)(b) GDPR where your message relates to a possible coaching relationship, and Article 6(1)(f) GDPR for general inquiries.

‍ ‍

When you book a call or a session

Bookings are handled through Acuity Scheduling. When you book, Acuity collects your name, email address, time zone, appointment details, and any information you choose to enter in the booking fields. I ask that you keep booking notes brief and general — anything sensitive is better shared inside our session.

Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps taken at your request before entering into one.

‍ ‍

When you pay for a session

Payments are processed through Acuity Scheduling using Stripe as the payment provider. Your card details are entered directly into Stripe's systems and are never visible or accessible to me. I receive only the transaction record: amount, date, name, and payment status.

Legal basis: Article 6(1)(b) GDPR for processing your payment, and Article 6(1)(c) GDPR for the retention of accounting records required under German commercial and tax law (§ 147 AO, § 257 HGB).

‍ ‍

Health-related information shared during coaching

Coaching with me often involves discussing things like your cycle, energy, sleep, stress, eating patterns, or how you feel in your body. Under Article 9 GDPR, this counts as a special category of personal data and is given extra protection.

I keep session notes as a file stored locally on my own password-protected, encrypted computer. These notes are not stored in Acuity, not kept in a cloud service, and are not shared with anyone.

Legal basis: Article 9(2)(a) GDPR — your explicit consent, which I ask for separately before we begin working together. You can withdraw this consent at any time, and I will delete your notes on request.

‍

Video sessions

Sessions take place via Google Meet. Google processes connection data (such as IP address and technical session information) in order to establish the call.

Sessions are recorded only when you ask for a recording. If you request one, the recording is saved and shared with you through Google Drive via a private link. I delete my own copy from Google Drive within 30 days unless you ask me to keep it available longer. If a recording contains health-related information, the same Article 9 protections apply.

Legal basis: Article 6(1)(b) GDPR for holding the session; Article 6(1)(a) and Article 9(2)(a) GDPR for making and storing a recording.

‍ ‍ ‍

WHO ELSE PROCESSES YOUR DATA

I work with a small number of service providers, each bound by a data processing agreement:

Squarespace — website hosting and built-in analytics. Provided to EU customers by Squarespace Ireland Limited, with data processing also occurring in the United States.

Acuity Scheduling — appointment booking and payment initiation. A Squarespace company, with data processing occurring in the United States.

Stripe — payment processing. Provided to EU customers by Stripe Payments Europe Limited, with data processing also occurring in the United States.

Google — video sessions (Google Meet) and delivery of requested recordings (Google Drive). Provided to EEA users by Google Ireland Limited, with data processing also occurring in the United States.

I do not sell your data, and I do not share it with anyone for advertising purposes.

‍ ‍

TRANSFERS OUTSIDE THE EUROPEAN UNION

Some of the providers listed above process data in the United States. These transfers are safeguarded under Articles 44–49 GDPR through the EU-U.S. Data Privacy Framework, where the provider is certified, and through Standard Contractual Clauses adopted by the European Commission.

You should be aware that data protection standards in the United States differ from those in the EU, and that US authorities may in some circumstances be able to access data held there. If you would prefer not to use a particular tool, please let me know and we can look at an alternative.

‍ ‍

HOW LONG I KEEP YOUR DATA

Contact form inquiries that do not lead to working together: deleted after 6 months.

Booking data in Acuity: deleted when our working relationship ends.

Session notes: kept for the duration of our work together and for 3 years afterward, then deleted. This period allows me to pick up where we left off if you return.

Session recordings: my copy is deleted from Google Drive within 30 days of sharing, unless you ask otherwise.

Payment and accounting records: retained for 10 years, as required by German tax law (§ 147 AO). I cannot delete these earlier, even on request.

Where data is held on the basis of your consent, I delete it as soon as you withdraw that consent, unless a legal retention obligation applies.

‍ ‍

YOUR RIGHTS

Under the GDPR, you have the right to:

Access (Article 15) — ask what data I hold about you and receive a copy.

Rectification (Article 16) — have inaccurate or incomplete data corrected.

Erasure (Article 17) — ask me to delete your data, subject to any legal retention obligations.

Restriction (Article 18) — ask me to limit how your data is used while a question about it is resolved.

Data portability (Article 20) — receive your data in a structured, machine-readable format, or have it transferred to another provider.

Objection (Article 21) — object to processing based on legitimate interest, including on grounds relating to your particular situation.

Withdrawal of consent (Article 7(3)) — withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise any of these, simply write to hello@rhythmsofwellbeing.co. I will respond within one month.

‍ ‍

YOUR RIGHT TO COMPLAIN

If you believe I have handled your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for me is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
Germany

‍You may also complain to the supervisory authority in the EU country where you live or work.

‍ ‍

SECURITY‍ ‍

My website uses SSL/TLS encryption, which you can recognise by the https:// in the address bar. Files stored on my computer are protected by full-disk encryption and a strong password, and my accounts with the providers listed above are secured with two-factor authentication where available.

‍ ‍

CHANGES TO THIS POLICY

If I change the tools I use or the way I work, I will update this page and revise the date at the top. Please check back occasionally.

‍ ‍

CONTACT‍ ‍

Questions about your data, requests to see or delete it, or anything else on this page: hello@rhythmsofwellbeing.co