Privacy Policy
This policy reflects only the services actually used on psysoulogy.com; services not in use are deliberately omitted. Where data subjects in the EU/EEA or the United Kingdom are concerned, the EU General Data Protection Regulation (GDPR) applies by virtue of the marketplace principle.
1. Controller
PSYSOULOGY LLC, 1242 SW Pine Island Road, Ste 42-348, Cape Coral, FL 33991, United States. Represented by: Kristina Peters. E-mail: evolve@psysoulogy.com · Phone: +1 727 205 2731
2. Overview of processing
Categories of data: master data (e.g. names); contact data (e.g. e-mail address, postal address); contract data (e.g. booked coaching services, time-account balance); content data (e.g. form entries, content of coaching communication); usage data (e.g. pages accessed, access times); meta/communication data (e.g. device information, IP addresses).
Categories of data subjects: customers; prospects; coaching participants; users; communication partners.
Purposes: provision of coaching services and customer care; provision of the online offering; appointment booking; handling enquiries and communication; security measures; office and organisational procedures.
Special categories of personal data (Art. 9 GDPR) are not collected. The offerings serve personal development and lie outside statutorily defined healthcare.
3. Legal bases (GDPR)
Consent (Art. 6(1)(a) GDPR); performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR). National data-protection rules at the user’s place of residence remain unaffected.
4. Security measures
We take appropriate technical and organisational measures to ensure a level of protection commensurate with the risk. Transmission is encrypted (SSL/TLS, recognisable by the https:// prefix).
5. International transfers
Origin hosting takes place in Switzerland, for which an EU adequacy decision exists (Art. 45 GDPR), so that no third-country transfer in the narrower sense occurs. Where individual services process data outside the EU (in particular CleanTalk, TidyCal and the communication medium chosen by the customer), this is based on EU Standard Contractual Clauses or Art. 49 GDPR. Details are provided with the respective services.
6. Erasure of data
Data are erased once they are no longer required for their purposes and no statutory retention obligations apply (under commercial and tax law generally 6 or 10 years). Server log files are erased or anonymised after a maximum of 30 days.
7. Hosting and infrastructure
To provide the website we use hosting, infrastructure and maintenance services. We process in particular access data / server log files (pages accessed, date/time, data volume, browser type/version, operating system, referrer URL, IP address) for security and stability purposes. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- SwissNetWorX (hosting/server, Switzerland): J. Kuder, Bodenmattstrasse 23, CH-4153 Reinach BL. Server location Switzerland (adequacy decision).
- Cloudflare (proxy/CDN/security): Cloudflare, Inc. (USA) may be placed upstream to deliver, secure and accelerate the website. IP address and technical connection data are processed and may be handled on servers outside the EU, on the basis of EU Standard Contractual Clauses. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
Caching (W3 Total Cache): page and browser caching is performed locally on the origin server; no external content delivery network is active, so no transfer to third parties or third countries occurs through caching.
8. Fonts and page builder (local)
The website is built with Elementor. The fonts used (including Montserrat) are self-hosted from the origin server; Google Fonts is disabled. No connection to Google or other third-party font servers is established, and no related third-country transfer occurs.
9. Cookies and consent management
We use cookies in accordance with Sec. 25 TDDDG and the ePrivacy rules. For cookies/services that are not strictly necessary we obtain prior consent; strictly necessary functions may be provided without consent. Consent may be withdrawn at any time.
- Complianz (consent management): stores the user’s consent decision (server-side and/or in a cookie) as proof. Legal basis: legal obligation (Art. 6(1)(c) GDPR) or legitimate interests (Art. 6(1)(f) GDPR).
- CleanTalk (spam protection): sets strictly necessary functional cookies (incl. ct_*, apbct_*) to detect automated input (see section 12).
10. Appointment booking (TidyCal)
For booking (initial) calls and appointments we use TidyCal, which is linked from our pages. When you open and use the booking calendar, we process in particular your name, e-mail address, requested time and any further information you provide. Processing may take place on servers in the USA, on the basis of EU Standard Contractual Clauses or Art. 49 GDPR. Legal bases: performance of a contract / pre-contractual steps (Art. 6(1)(b) GDPR); legitimate interests in efficient scheduling (Art. 6(1)(f) GDPR).
11. Delivery of coaching (time account, communication medium)
To deliver the booked coaching we process the required master, contact and contract data as well as the content of the communication during the engagement. The time account (prepaid minutes) is kept pseudonymised, encrypted and locally; it does not contain information enabling conclusions about your person and is not disclosed to third parties for this purpose. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Coaching sessions take place by default via Zoom (Zoom Communications, Inc., USA); connection, audio and, where applicable, video data are processed. Processing in the USA is based on EU Standard Contractual Clauses. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
At the customer’s express request and on the customer’s own responsibility, a medium other than Zoom may be used (telephone, Signal, Telegram, Threema). The choice of medium and the associated transfer of data to the respective provider are made by the customer on their own responsibility; in this respect the respective provider is the controller within the meaning of the GDPR. WhatsApp and Facebook Messenger are excluded by the provider. Legal basis for use of the chosen medium: consent or performance of a contract (Art. 6(1)(a)/(b) GDPR).
12. Spam protection (CleanTalk)
To prevent spam in forms we use CleanTalk. Input data (incl. IP address, where applicable name/e-mail, content, time) are transmitted to CleanTalk servers (USA) for spam checking and briefly retained there. Legal basis: legitimate interests in the security and spam-freeness of the offering (Art. 6(1)(f) GDPR); third-country transfer based on EU Standard Contractual Clauses.
13. Newsletter (handled on a separate site)
This website does not operate its own newsletter sign-up and does not process newsletter data. Where a newsletter is referenced, the link leads to a separate website operated for that purpose; the data protection information of that website applies to any sign-up made there.
14. Contacting us
If you contact us (e.g. by e-mail or contact form) we process the information provided to handle your request. Legal bases: performance of a contract / pre-contractual steps (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
15. Rights of data subjects
Subject to the statutory requirements, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and a right to object (Art. 21) to processing based on Art. 6(1)(e) or (f) GDPR and to direct marketing. You may withdraw consent given at any time with effect for the future.
Right to lodge a complaint: you have the right to lodge a complaint with a data-protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
16. Amendments to this Privacy Policy
We update this Privacy Policy as changes to our processing require. Please review its content regularly.
