PRIVACY POLICY

Effective Date: October 2, 2025

This Privacy Policy applies to the operations of From Gaia for You (https://www.fromgaiaforyou.com/) (referred to as “the Website,” “we,” “us,” or “our”) and ensures compliance with the General Data Protection Regulation (GDPR) and the e-Privacy Directive.

We are committed to being transparent about how we collect, use, and protect your personal data, and to ensuring that you understand your rights and choices.

1. Who We Are (The Data Controller)

Controller Name:
From Gaia for You – Danilo Bruni
Registered Company Name: From Gaia for you
Address: Calle Rio Guadalmedina 20, PO box 13, 29120, Alhaurin el Grande, Málaga, Spain
Email for Data Inquiries: fromgaiaforyou@gmail.com

EU Representative: Not applicable, as the company is based within the EU/EEA.
Data Protection Officer (DPO): Not required based on the scope of our processing activities.

Please use the email above for all requests related to your personal data or this Policy.

2. The Data We Collect, Purpose, and Legal Basis

We collect only data necessary for our specific, explicit, and legitimate purposes.

PurposeData CollectedLegal BasisRetention PeriodOrder Fulfilment & DeliveryName, billing/shipping address, email, phone, payment details (processed by third party)Contractual Necessity (Art. 6(1)(b))7 years (for accounting and legal obligations)Marketing CommunicationsEmail, name (optional)Consent (Art. 6(1)(a))Until withdrawal of consentWebsite Security & ImprovementIP address, browser, device info, usage dataLegitimate Interest (Art. 6(1)(f))12 months (then aggregated or deleted)Customer Service & ComplaintsContact details, correspondence, order historyContractual Necessity or Legitimate InterestDuration of inquiry + 2 yearsRetreat Bookings & CommunicationsName, contact details, preferences, booking informationContractual Necessity (Art. 6(1)(b))7 years (for service and legal obligations)

Statutory Requirement:
Providing data necessary for order fulfilment (e.g., name, address, payment details) is required to enter into and execute a contract. Without this data, we cannot process your order or booking.

3. Cookies and Tracking Technologies (e-Privacy Directive)

Our website uses cookies and similar technologies to function properly and analyse traffic.

  • Necessary Cookies: Used for essential site functions like remembering your shopping cart. No consent required.

  • Analytics & Marketing Cookies: Used to measure engagement and improve experience. Prior consent is required.

We provide a detailed Cookie Policy linked on our site, explaining each cookie’s purpose, duration, and management options.

4. Recipients of Your Personal Data

We share your data only with trusted partners essential to providing our services:

  1. Payment Processors: Stripe, PayPal (for secure payment handling)

  2. Shipping Providers: DHL, local couriers (for order delivery)

  3. Hosting & IT Providers: Secure EU-based or GDPR-compliant platforms

  4. Analytics & Marketing Providers: Google Analytics, Meta (based on your consent)

All service providers are bound by strict confidentiality and data protection agreements.

5. International Data Transfers

Your data may occasionally be transferred outside the European Economic Area (EEA), for example when using cloud or analytics providers based in the U.S.

Whenever this occurs, we apply the European Commission’s Standard Contractual Clauses (SCCs) and conduct Transfer Risk Assessments (TRA) to ensure your data remains secure and compliant with EU standards.

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

  1. Access – request a copy of your personal data

  2. Rectification – correct inaccurate or incomplete data

  3. Erasure – request deletion in certain circumstances

  4. Restriction – limit how your data is processed

  5. Objection – object to processing based on legitimate interests or direct marketing

  6. Portability – receive data in a structured, machine-readable format

  7. Withdraw Consent – withdraw your consent at any time (for marketing or other consent-based processing)

To exercise your rights, email fromgaiaforyou@gmail.com.

If you believe your rights have been violated, you have the right to lodge a complaint with your national data protection authority.

7. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or significant effects.

8. Updates to This Policy

We regularly review and update this Policy to ensure accuracy and compliance.
Any updates will be posted on this page, with the revised date clearly shown at the top.