Privacy Policy

  1. General Information
  2. Controller
  3. Data Protection Responsible Person
  4. Hosting
  5. Access Data (Server Log Files)
  6. Cookies and Consent Management
  7. WooCommerce
  8. Geolocation and Currency Display (MaxMind / Aelia Currency Switcher)
  9. Newsletter and Marketing Communications
  10. Contact and Customer Support
  11. Customer Account, RiverCalm Journey Platform and Automated Email Sequences
  12. Appointment Booking (Amelia)
  13. Video Conferencing (Zoom)
  14. Embedded Video Content (Vimeo)
  15. Online Purchases, Payment Processing and Tax Compliance
  16. Gift Cards
  17. Age Self-Declaration
  18. Social Media
  19. Cross-Border Data Transfers
  20. Use and Disclosure of Data
  21. Encryption (SSL/TLS)
  22. Retention Period
  23. Your Data Protection Rights
  24. Validity and Amendments to this Privacy Policy

1. General Information

1.1. In this Privacy Policy, you will find detailed information about what happens to your personal data when you visit our website https://rivercalm.life. All data that enables personal identification is considered personal data. When processing your data, we strictly adhere to legal requirements, in particular the General Data Protection Regulation (“GDPR”). It is very important to us that your visit to our website is completely secure.


2. Controller

2.1. Responsibility for the collection and processing of personal data on this website lies with:

  • Name: Santiago Celorio Galan
  • Professional Designation (Berufsbezeichnung): RiverCalm
  • Represented by: Santiago Celorio Galan, Sole Proprietor
  • Street, House Number, Postal Code, City: Gormannstraße 14, 10119 Berlin
  • Country: Germany
  • Email: info@rivercalm.life
  • Tel.: +49 17670618010
  • Website: https://rivercalm.life

3. Data Protection Responsible Person

3.1. As a sole proprietor, there is no external Data Protection Officer appointed for this website. Data protection responsibilities are handled internally by the controller:

  • First Name, Last Name: Santiago Celorio Galan
  • Street, House Number, Postal Code, City: Gormannstraße 14, 10119 Berlin
  • Country: Germany
  • Email: info@rivercalm.life
  • Tel.: +49 17670618010

3.2. If you have any questions or suggestions regarding data protection, you can contact the data protection responsible person at any time using the details above.


4. Hosting

4.1. This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. When you visit our website, Hostinger processes certain personal data on our behalf as a data processor, including IP addresses and server log data, solely for the purpose of providing and maintaining the hosting infrastructure. For further information, please refer to Hostinger’s privacy policy at https://www.hostinger.com/privacy-policy.

4.2. The RiverCalm Journey platform (https://journey.rivercalm.life) is also hosted by Hostinger International Ltd. under the same terms. When customers access their purchased content on this platform, Hostinger processes technical data including IP addresses and server log data as a data processor on our behalf. We have entered into a data processing agreement with Hostinger in accordance with Art. 28 GDPR covering both this website and the RiverCalm Journey platform.


5. Access Data (Server Log Files)

5.1. When you visit our website, we automatically collect access data transmitted by your browser and store it in so-called server log files. These include:

  • Browser type and version of your device
  • Operating system used by your device
  • Referrer URL (source/referral from which you arrived at our website)
  • Hostname of the accessing device
  • Date and time of the server request
  • The IP address currently used by your device (where applicable, in anonymised form)

5.2. As a rule, it is neither possible nor our intention to assign this data to a specific person. The processing of this data is carried out in accordance with Art. 6(1)(f) GDPR to protect our legitimate interest in improving the stability and functionality of our website.

5.3. We do not use any traffic analytics or web analytics tools (such as Google Analytics) on our website. The server log data described above is used solely for technical security and stability purposes and is not used to analyse or profile visitor behaviour.


6. Cookies and Consent Management

6.1. We use so-called cookies to make visiting our website more attractive and to enable the use of certain functions. These are small text files stored on your device. Cookies are not capable of executing programs or transferring viruses to your computer system.

6.2. Cookie consent on this website is managed through the Complianz plugin. When you first visit our website, a cookie consent banner will be displayed allowing you to accept or decline non-essential cookies. Only strictly necessary cookies will be set without your prior consent. Your cookie preferences are stored and can be changed at any time by revisiting the cookie settings on our website. Complianz is provided by Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands. We have entered into a data processing agreement with Complianz in accordance with Art. 28 GDPR. For further information, please refer to Complianz’s privacy policy at https://complianz.io/privacy-statement/ and their Data Processing Agreement at https://complianz.io/data-processing-agreement/.

6.3. Necessary cookies required for electronic communication or the provision of requested functions are stored in accordance with Art. 6(1)(f) GDPR. Our legitimate interest in storing them serves the technically flawless and optimised provision of our services. All non-essential cookies are only set following your explicit consent in accordance with Art. 6(1)(a) GDPR and the German Telecommunications Digital Services Data Protection Act (TDDDG).

6.4. We primarily use so-called “session cookies”, which are automatically deleted after your visit ends. We also use cookies that remain stored on your device until you delete them yourself, allowing us to recognise your browser on your next visit.

6.5. You can configure your browser to notify you when cookies are about to be set. You may then decide whether to allow cookies on a case-by-case basis, for certain situations, or to reject them entirely. Please note that the functionality of this website may be limited if you disable cookies.


7. WooCommerce

7.1. Our online shop is operated via WooCommerce, a plugin for WordPress provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110-4929, USA. WooCommerce processes order and customer data on our behalf for the purpose of operating the shop, managing orders, and providing purchase confirmations.

7.2. We have entered into a Data Processing Agreement with Automattic for WooCommerce in accordance with Art. 28 GDPR. Data transfers to Automattic in connection with WooCommerce are carried out on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission. For further information, please refer to Automattic’s privacy policy at https://automattic.com/privacy/ and their Data Processing Agreement at https://wordpress.com/support/data-processing-agreements/.


8. Geolocation and Currency Display (MaxMind / Aelia Currency Switcher)

8.1. To determine which of our three fixed currency price lists (EUR, USD, or GBP) to display to a visitor, our website uses IP-based geolocation via MaxMind’s GeoIP2 web service, provided by MaxMind, Inc., 51 Pleasant Street, Suite 1020, Malden, MA 02148, USA, together with the Aelia Currency Switcher plugin for WooCommerce.

8.2. This is a live lookup: each time it is performed, your IP address is transmitted to MaxMind’s servers in the United States, which return an estimated country location used solely to select the appropriate currency for display.

8.3. This processing is used exclusively for the purpose described above and is not combined with any other data we hold about you, nor used for advertising or profiling. If you manually select a different currency, Aelia may store that preference in a cookie in your browser; see Section 6 for further information on cookies used on this site.

8.4. We rely on MaxMind’s GeoLite2/GeoIP2 End User License Agreement and Data Processing Addendum for this processing. MaxMind, Inc. is an active participant in the EU-U.S. Data Privacy Framework (DPF); data transfers to MaxMind are carried out on the basis of the DPF adequacy decision, supplemented by Standard Contractual Clauses (SCCs) as a subsidiary safeguard. For further information, please refer to MaxMind’s privacy policy at https://www.maxmind.com/en/privacy-policy.

8.5. The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in presenting accurate, currency-appropriate pricing to visitors).


9. Newsletter and Marketing Communications

9.1. We operate two types of email communications:

  • Transactional emails — sent automatically to all customers as part of the service, including order confirmations with invoice PDF attachment, course access notifications, course completion congratulations, and content update notifications. These are delivered via SMTP2Go and do not require separate consent as they form part of the contracted service.
  • Marketing newsletter — sent only to visitors and customers who voluntarily register via the newsletter sign-up form on our website. The newsletter includes tips, new course announcements, promotional offers, and general RiverCalm communications, and is delivered via Sendfox.

9.2. The newsletter sign-up form on our website is built and displayed using Noptin, a self-hosted newsletter plugin for WordPress. Noptin runs on our own WordPress installation (hosted by Hostinger, see Section 4) and does not transmit your registration data to any third-party server operated by the plugin developer merely by displaying or submitting the form.

9.3. Newsletter subscriptions are confirmed via a double opt-in process. After registering via the newsletter form, you will receive a confirmation email containing a verification link. Your subscription is only activated once you click this link, confirming your consent in accordance with Art. 7 GDPR. This process ensures that subscriptions are genuine and provides clear proof of consent.

9.4. To subscribe to the marketing newsletter, providing and verifying your email address is required. No additional data is collected, or only on a voluntary basis.

9.5. Our marketing newsletter is sent via Sendfox, a service provided by Sumo Group Inc. (d.b.a. SendFox), 1305 E. 6th St #3, Austin, TX 78702, USA. Sendfox processes your email address and any other data you provide on our behalf for the purpose of delivering the newsletter. We rely on Sendfox’s Data Processing Agreement, available at https://sendfox.com/dpa, and their privacy policy at https://sendfox.com/privacy. As Sendfox is based in the United States, data transfers are carried out on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission.

9.6. Transactional emails are delivered via SMTP2Go, an email delivery service provided by Sand Dune Mail Ltd, 96-106 Manchester Street, Christchurch 8011, New Zealand. SMTP2Go processes your email address and message content solely to deliver transactional emails on our behalf. New Zealand benefits from an adequacy decision of the European Commission, meaning data transfers to SMTP2Go can take place without additional safeguards. For further information, please refer to SMTP2Go’s privacy policy at https://www.smtp2go.com/privacy/.

9.7. Transactional emails are processed on the basis of Art. 6(1)(b) GDPR (performance of a contract). Marketing newsletter communications are processed on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR.

9.8. You may withdraw your consent to the marketing newsletter at any time by sending an informal email to info@rivercalm.life or by using the unsubscribe link contained in every newsletter. Withdrawal of consent does not affect the sending of transactional emails, which form part of the contracted service for as long as your account remains active.

9.9. Upon unsubscribing from the marketing newsletter, the data stored solely for that purpose will be deleted. Data stored elsewhere for other purposes, such as order records, will remain stored in accordance with the applicable retention periods outlined in this Privacy Policy.

9.10. If you would like your personal data or your entire account permanently erased, or if you do not wish to receive any emails from us whatsoever — including transactional emails, which will require closing your account and forfeiting further access to purchased content — please contact us at info@rivercalm.life.


10. Contact and Customer Support

10.1. When you contact us, including by email, the data transmitted — including your contact details — will be stored in order to process your enquiry and for any follow-up questions. This data will not be passed on to third parties without your express consent.

10.2. The processing of your personal data is based solely on your consent given in accordance with Art. 6(1)(a) GDPR. You have the right to withdraw this consent at any time and without giving reasons. An informal email to info@rivercalm.life is sufficient. The lawfulness of data processing carried out prior to withdrawal is not affected.

10.3. The transmitted data will be stored until you request deletion, withdraw your consent to storage, or the necessity for data storage no longer exists. Statutory retention periods remain unaffected.

10.4. Customer support enquiries submitted to info@rivercalm.life are handled under the same terms as general contact data outlined in this section. The provider will endeavour to respond to all support enquiries within 3 business days. Support correspondence is retained for the duration of the customer relationship and deleted thereafter unless a longer retention period is required by law or is necessary for the establishment, exercise, or defence of legal claims.


11. Customer Account, RiverCalm Journey Platform and Automated Email Sequences

11.1. Creating a customer account on our website requires your consent to the storage of your master data (name, address, email address) and usage data (username, password). This data is stored to allow you to access your account, manage purchases, and access your purchased digital products and online courses.

11.2. Upon purchase, the customer will also receive access to the RiverCalm Journey platform (https://journey.rivercalm.life), a Moodle-based learning environment hosted by Hostinger International Ltd. The following personal data is processed in connection with the use of this platform:

  • Name and email address used during registration
  • Login and access data
  • Course progress and completion data
  • Download activity in connection with purchased e-books

11.3. Course activity data — including course progress and completion status — is used to trigger automated transactional email sequences via SMTP2Go. These sequences form part of the contracted service and include the following communications:

  • Course access confirmation — sent upon successful purchase and platform access being granted
  • Course completion congratulations — sent automatically upon completion of a course, and may include a one-time reward discount applicable to future RiverCalm courses. The redemption and validity status of reward discount codes issued in this way are tracked within WooCommerce solely to verify redemption and prevent misuse. Customers are informed of this at the time of purchase
  • Content update notifications — sent when purchased course content is updated or revised

11.4. These automated emails are processed on the basis of Art. 6(1)(b) GDPR (performance of a contract) as they form an integral part of the service the customer has purchased. They are distinct from the optional marketing newsletter described in Section 9 and will continue to be sent regardless of whether the customer has subscribed to the marketing newsletter.

11.5. This data is processed exclusively for the purpose of providing access to purchased content and ensuring the continuity and functionality of the platform. In accordance with the lifetime license granted under the provider’s Terms and Conditions, access to purchased content — and the account and course data necessary to provide it — is retained for as long as the purchased product continues to be offered by RiverCalm and RiverCalm continues to operate, rather than for a fixed period. Where a product or the RiverCalm Journey platform is discontinued, data will be retained for the notice period described in the Terms and Conditions and reviewed for deletion thereafter unless retention is required for legal or contractual purposes.

11.6. In the event that a customer’s account is terminated due to a breach of the Terms and Conditions (for example, account sharing), the customer’s personal data will be retained for a legally reasonable period following termination for the purpose of establishing, exercising, or defending legal claims. This data will not be used for any other purpose and will be deleted once the retention period has expired.

11.7. The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent).


12. Appointment Booking (Amelia)

12.1. Coaching sessions are booked through Amelia, a booking plugin operated on our own WordPress installation and hosted by Hostinger International Ltd. (see Section 4). When you book, reschedule, or cancel a session, the following data is processed: your name, email address, appointment date and time, and any details you choose to provide in the booking form.

12.2. Appointment data is used to manage your bookings, to display your upcoming and past sessions in the “Sessions” tab of your account on our website, and to send you appointment-related communications (such as confirmations, reminders, and, where applicable, cancellation or no-show notices) in accordance with our Terms and Conditions.

12.3. As Amelia operates on our own server, no booking data is transmitted to any third-party server operated by the plugin developer merely by using the booking system. Amelia does, however, integrate with Zoom via Zoom’s API to automatically generate a unique meeting link for each booked session; see clause 12.5 and Section 13 for further information.

12.4. The legal basis for processing appointment data is Art. 6(1)(b) GDPR (performance of a contract).

12.5. As part of the Amelia-Zoom integration described in clause 12.3, your name and email address are transmitted to Zoom via its API at the time a session is booked, in order to generate the meeting link for that session — not only at the time you join the call. See Section 13 for further information on Zoom’s processing of this data.

12.6. In the limited circumstances described in our Terms and Conditions (clause 5.6) — where there is a reasonable, documented suspicion of repeated or abusive reliance on the illness/emergency exception to the cancellation policy — we may ask a customer to provide proof of illness or emergency (such as a doctor’s note). This constitutes special category health data under Art. 9 GDPR. Any such proof is provided voluntarily, is requested and handled only in a manner separately and explicitly agreed with the customer beforehand, is used solely to resolve the specific matter, is not stored for longer than necessary to do so, and is deleted once the matter is resolved. The legal basis for this processing is your explicit consent (Art. 9(2)(a) GDPR), given at the time such proof is requested and provided.


13. Video Conferencing (Zoom)

13.1. Coaching sessions are conducted via Zoom, a video conferencing service provided by Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.

13.2. Sessions are conducted using Zoom’s end-to-end encryption functionality. In accordance with our Terms and Conditions, sessions are never recorded, by either the provider or the customer, under any circumstances.

13.3. To participate in a session, Zoom processes data including your name, email address, IP address, device and connection information, and the audio and video data transmitted during the call. As described in clause 12.5, your name and email address are also transmitted to Zoom via its API at the time a session is booked, in order to generate the meeting link. This data is processed by Zoom in accordance with its own privacy policy, available at https://zoom.us/privacy.

13.4. We rely on Zoom’s Data Processing Addendum, incorporated into Zoom’s Terms of Service, for this processing in accordance with Art. 28 GDPR. Zoom Communications, Inc. is based in the United States and is a certified participant in the EU-U.S. Data Privacy Framework (DPF). Data transfers to Zoom are carried out on the basis of the DPF adequacy decision, supplemented by Standard Contractual Clauses (SCCs) as a subsidiary safeguard.

13.5. The legal basis for processing data in connection with Zoom sessions is Art. 6(1)(b) GDPR (performance of a contract).


14. Embedded Video Content (Vimeo)

14.1. Our website and the RiverCalm Journey platform embed video content hosted on Vimeo, a service provided by Vimeo LLC, 330 West 34th Street, 10th Floor, New York, NY 10001, USA.

14.2. Video trailers are embedded on the public rivercalm.life website and are visible to all visitors. Full course videos are embedded exclusively within the RiverCalm Journey platform and are only accessible to logged-in customers with an active purchase.

14.3. All Vimeo videos are embedded using Vimeo’s privacy-enhanced mode, which prevents Vimeo from setting tracking cookies or collecting data about visitors who do not interact with the video. However, when a video is played, Vimeo may process technical data including your IP address, browser type, device information, and viewing activity. This data is processed by Vimeo in accordance with their own privacy policy.

14.4. Vimeo LLC is based in the United States. Data transfers to Vimeo are carried out on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission. For further information, please refer to Vimeo’s privacy policy at https://vimeo.com/privacy and Vimeo’s cookie policy at https://vimeo.com/cookie_policy.

14.5. The legal basis for processing data in connection with embedded Vimeo content is Art. 6(1)(f) GDPR (legitimate interest in providing video content as part of our services) for logged-in course customers, and Art. 6(1)(a) GDPR (consent via the Complianz cookie banner) for public trailer content on rivercalm.life.


15. Online Purchases, Payment Processing and Tax Compliance

15.1. When you make a purchase, we collect and process the following data:

  • Name and billing address
  • Email address
  • Country of residence
  • Payment information (processed by third-party payment providers)
  • Order details and purchase history

15.2. The customer’s country of residence is collected at checkout for the purpose of monitoring cross-border sales in accordance with applicable tax regulations. This data is processed on the basis of Art. 6(1)(c) GDPR (legal obligation).

15.3. Upon successful purchase, an invoice is automatically generated and sent to the customer as a PDF attachment to the order confirmation email. By completing a purchase the customer agrees to receive their invoice in this format. Invoice data — including name, billing address, email address, order details, and applicable tax information — is retained for a period of 10 years in accordance with §147 AO (German Fiscal Code) and applicable commercial law retention obligations.

15.4. Stripe — Payment processing is handled through Stripe, through which the following payment methods are available: credit/debit card, Google Pay, and Apple Pay. Stripe is provided by Stripe Technology Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. We have entered into a data processing agreement with Stripe in accordance with Art. 28 GDPR. Stripe processes your payment data under its own data processing terms. For further information, please refer to Stripe’s privacy policy at https://stripe.com/en-de/privacy and their Data Processing Agreement at https://stripe.com/en-de/legal/dpa.

15.5. The legal basis for processing purchase and payment data is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligation) for invoice and tax retention purposes.


16. Gift Cards

16.1. When a customer purchases a gift card, we collect and process the purchaser’s own account and order data (see Section 15) together with the following additional data provided at checkout: the intended recipient’s email address, and any personal message the purchaser chooses to include for the recipient.

16.2. This data — including the recipient’s email address and the personal message — is stored on our own WordPress installation, hosted by Hostinger International Ltd. (see Section 4), and the recipient’s email address and message are also transmitted via SMTP2Go (see Section 9) solely for the purpose of delivering the gift card to the recipient.

16.3. By purchasing a gift card, the customer confirms they are entitled to share the recipient’s email address with us for this purpose, and agrees that the personal message provided will be disclosed to the recipient as part of gift card delivery, as described in our Terms and Conditions.

16.4. The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract) in relation to the purchaser, and Art. 6(1)(f) GDPR (legitimate interest in delivering a gift purchased on their behalf) in relation to the recipient.

16.5. Gift card recipient and message data is retained together with the associated order record; see Section 22 (Retention Period) for the applicable retention periods.


17. Age Self-Declaration

17.1. RiverCalm’s products are intended for adults aged 18 and over, and coaching sessions may only be booked by individuals who have reached the age of majority under the laws of their country of residence. By completing a purchase and accepting the Terms and Conditions, the customer confirms that they meet the applicable age requirement. This self-declaration is recorded as part of the order data and retained for the same period as other purchase records in accordance with Section 15.3 of this Privacy Policy.

17.2. The legal basis for processing this confirmation is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in ensuring contractual compliance).


18. Social Media

18.1. Our website contains links to the following social media platforms:

  • Instagram — operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland
  • Facebook — operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland
  • YouTube — operated by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
  • TikTok — operated by TikTok Technology Ltd., 10 Earlsfort Terrace, Dublin 2, Ireland (European entity)

18.2. These links are implemented as simple hyperlinks. No social media plugins or tracking pixels are embedded on our website, meaning no data is transferred to these platforms merely by visiting our website. Data is only transferred when you actively click one of the links and visit the respective platform.

18.3. Upon clicking a social media link, you will leave the rivercalm.life website and be directed to the respective platform, which operates under its own terms of service and privacy policy. We have no control over the data collected by these platforms once you visit them. We recommend reviewing the privacy policy of each platform before interacting with it:

18.4. TikTok — additional notice: TikTok is operated by ByteDance Ltd., a company with headquarters in China. When you visit TikTok by clicking our link, your data may be transferred to and processed on servers located outside the European Economic Area, including potentially in the United States and China. The level of data protection in these countries may differ from EU standards. TikTok states that it relies on Standard Contractual Clauses (SCCs) for data transfers from the EEA, however EU data protection authorities have raised concerns regarding TikTok’s data practices. By clicking the TikTok link you do so at your own discretion and we encourage you to review TikTok’s privacy policy carefully.

18.5. The legal basis for providing social media links is Art. 6(1)(f) GDPR (legitimate interest in maintaining a public presence and communicating with our community).


19. Cross-Border Data Transfers

19.1. Some of the service providers used by RiverCalm are based outside the European Economic Area (EEA). Where personal data is transferred to third countries, we ensure that appropriate safeguards are in place in accordance with Chapter V GDPR. The following third-country transfers apply:

  • Automattic Inc. (WooCommerce) — United States. Transfers carried out on the basis of Standard Contractual Clauses (SCCs). Further information: https://automattic.com/privacy/ and https://wordpress.com/support/data-processing-agreements/
  • Zoom Communications, Inc. (video conferencing for coaching sessions, see Section 13) — United States. Transfers carried out on the basis of the EU-U.S. Data Privacy Framework (DPF), supplemented by Standard Contractual Clauses (SCCs). Further information: https://zoom.us/privacy
  • MaxMind, Inc. (live IP geolocation lookup used for currency display, see Section 8) — United States. Transfers carried out on the basis of the EU-U.S. Data Privacy Framework (DPF), supplemented by Standard Contractual Clauses (SCCs). Further information: https://www.maxmind.com/en/privacy-policy
  • Vimeo LLC — United States. Transfers carried out on the basis of Standard Contractual Clauses (SCCs). Further information: https://vimeo.com/privacy
  • Sendfox (Sumo Group Inc.) — United States. Transfers carried out on the basis of Standard Contractual Clauses (SCCs). Further information: https://sendfox.com/privacy and https://sendfox.com/dpa
  • Meta Platforms (Instagram and Facebook) — United States. Transfers carried out on the basis of Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Further information: https://www.facebook.com/privacy/policy/
  • Google LLC (YouTube) — United States. Transfers carried out on the basis of Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Further information: https://policies.google.com/privacy
  • TikTok / ByteDance — United States and potentially China. Transfers carried out on the basis of Standard Contractual Clauses (SCCs), however the adequacy of data protection for transfers to China cannot be fully guaranteed. Further information: https://www.tiktok.com/legal/page/eea/privacy-policy/en

19.2. SMTP2Go (Sand Dune Mail Ltd) is based in New Zealand, a country recognised by the European Commission as providing an adequate level of data protection. Data transfers to SMTP2Go may therefore take place without additional safeguards.

19.3. Amelia (appointment booking, see Section 12) operates entirely on our own WordPress installation. No third-country transfer takes place in connection with the use of this plugin, aside from the Zoom API integration described in clause 12.5 and Section 13.

19.4. All other service providers used by RiverCalm — including Hostinger, Stripe, and Complianz — are based within the European Economic Area and no third-country transfer applies.


20. Use and Disclosure of Data

20.1. We assure you that personal data you provide to us — such as your name, address, or email address — will not be sold or otherwise commercially exploited. Your data is processed exclusively for correspondence with you and to fulfil the purpose for which you provided it. Payment data is forwarded to the commissioned payment service provider for payment processing purposes only.

20.2. Data automatically collected during your visit to our website is used exclusively for the purposes stated above. Your data will generally not be passed on to third parties unless there is a legal obligation to do so, you have given your express consent, or disclosure is necessary for the establishment, exercise, or defence of legal claims — for example in the event of a breach of the Terms and Conditions, including copyright infringement or unauthorised account sharing. In such cases, data may be shared with legal advisors or competent authorities on the basis of Art. 6(1)(f) GDPR (legitimate interest) or Art. 6(1)(c) GDPR (legal obligation).


21. Encryption (SSL/TLS)

21.1. Our website uses SSL/TLS encryption to ensure the security and protection of confidential content during transmission — in particular for orders or enquiries you send to us as the website operator. An encrypted connection is indicated by “https://” in your browser’s address bar and the padlock symbol.

21.2. Activating SSL/TLS encryption means that data you send to us cannot be read by unauthorised third parties.


22. Retention Period

22.1. Your personal data transmitted to us via our website is stored only for as long as necessary to achieve the respective purpose of data processing. Specific retention periods applicable to different categories of data are as follows:

  • Invoice and tax data: retained for 10 years in accordance with §147 AO (German Fiscal Code)
  • Course access and account data: retained for as long as the purchased product remains available and RiverCalm continues to operate (lifetime license, as described in the Terms and Conditions); reviewed for deletion following a discontinuation notice period, unless retention is required for legal purposes
  • Appointment and session booking data (Amelia): retained for the duration of the customer’s account and for three (3) years thereafter for the establishment, exercise, or defence of legal claims, then deleted unless a longer legal retention period applies. As coaching sessions are never recorded (see Section 13.2), no session audio or video data is retained by RiverCalm following a call
  • Proof of illness or emergency (special category health data, see Section 12.6): retained only for as long as necessary to resolve the specific dispute for which it was requested, and deleted immediately afterward
  • Gift card recipient and message data (see Section 16): retained together with the associated order record, in line with the retention period for order and invoice data described above
  • Contact and correspondence data: retained until the purpose of the correspondence has been fulfilled and no further retention obligation applies
  • Marketing newsletter data: retained until the customer unsubscribes or withdraws consent
  • Transactional email data: retained for the duration of the customer relationship and deleted thereafter unless required for legal purposes
  • Support correspondence: retained for the duration of the customer relationship and deleted thereafter unless required for legal purposes

23. Your Data Protection Rights

23.1. Right of Withdrawal (Art. 7(3) GDPR) — Where data processing is based on your consent, you have the right to withdraw that consent at any time with future effect. The lawfulness of processing carried out prior to withdrawal remains unaffected.

23.2. Right of Access (Art. 15 GDPR) — You have the right to request confirmation of whether we process your personal data, and if so, to receive information about it, including the purposes of processing, categories of data, recipients, planned retention periods, and the existence of rights to rectification, erasure, restriction, and objection.

23.3. Right to Rectification (Art. 16 GDPR) — You may request the correction of inaccurate personal data and/or the completion of incomplete data at any time.

23.4. Right to Erasure (Art. 17 GDPR) — You may request the deletion of your personal data where, for example, the data is no longer necessary for its original purpose, you have withdrawn your consent, the processing was unlawful, or a legal obligation requires deletion. This right may be restricted where processing is necessary to comply with a legal obligation, for public interest tasks, or for the establishment, exercise, or defence of legal claims. To request full erasure of your data or account, or to stop receiving any emails from us whatsoever, see Section 9.10 and contact info@rivercalm.life.

23.5. Right to Restriction of Processing (Art. 18 GDPR) — You may request that the processing of your data be restricted, for example if you contest the accuracy of the data, the processing is unlawful, or you need the data for legal claims despite us no longer requiring it.

23.6. Right to Notification (Art. 19 GDPR) — If you exercise your right to rectification, erasure, or restriction, we are obliged to inform all recipients to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort.

23.7. Protection Against Automated Decision-Making / Profiling (Art. 22 GDPR) — You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly significantly affects you, unless the decision is necessary for a contract, permitted by law, or based on your explicit consent.

23.8. Right to Data Portability (Art. 20 GDPR) — Where processing is based on consent or a contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

23.9. Right to Object (Art. 21 GDPR) — Where we process your personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. In the case of direct marketing, you may object at any time without restriction.

23.10. Right to Lodge a Complaint (Art. 77 GDPR) — In the event of violations of the GDPR, you have the right to lodge a complaint with a competent supervisory authority. Since this website is operated from Berlin, Germany, the responsible supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstr. 219, 10969 Berlin
Tel.: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de


24. Validity and Amendments to this Privacy Policy

24.1. This Privacy Policy comes into effect on 3 September 2026. We reserve the right to amend it as necessary and in compliance with applicable data protection laws — for example, to meet new legal requirements or to reflect changes to our website or services. The version of the Privacy Policy available on our website at the time of your visit is binding.

24.2. In the event of changes, we will publish the updated version on this page to keep you fully informed about what personal data we collect, how we process it, and under what conditions we may share it. Customers who have purchased products will be notified of material changes via the transactional email system.

24.3. This Privacy Policy should be read alongside the RiverCalm Terms and Conditions, available at https://rivercalm.life/terms-conditions.