PRIVACY POLICY

Mindful Evolution GmbH

Effective date: 6 September 2026

Registered address: Turnerstrasse 18, 4058 Basel, Switzerland

Website: https://www.mind-ful-evolution.com

Contact: [email protected]

 

Privacy at a glance. We use personal data only for clearly stated business and service purposes, apply data minimisation, do not sell personal data, and do not use automated systems to make decisions about clients.

1. Who We Are and Scope

Mindful Evolution GmbH ("Mindful Evolution", "we", "us" or "our") is the controller responsible for the personal data described in this Privacy Policy. This Policy applies when you use our website, book or purchase services, participate in sessions, workshops or programmes, subscribe to communications, or otherwise interact with us.

We provide personal-development, psychoeducational and holistic wellbeing services. Our services do not constitute medical diagnosis, psychotherapy or medical treatment and are not a substitute for care from a qualified healthcare professional.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). The EU General Data Protection Regulation (GDPR) applies where its territorial requirements are met, including where we offer relevant services to individuals located in the European Union or European Economic Area.

2. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identity and contact data, such as your name, email address, telephone number, postal address and communication preferences.
  • Booking and service data, such as the selected service, appointment date and time, duration, language preference, attendance, cancellations and rescheduling history.
  • Account data, where an account is available, such as login identifiers and account preferences. We do not have access to your password in readable form.
  • Communication data, including emails, enquiries, feedback and correspondence with us.
  • Transaction data, such as the service purchased, amount, currency, payment status, invoice information and limited payment metadata. Full card details are processed by the relevant payment provider and are not stored by us.
  • Marketing data, such as newsletter subscription status, campaign interactions and consent records.
  • Website and technical data, such as IP address, device and browser type, pages visited, date and time of access, referral source, cookie identifiers and analytics events.
  • Content and media you choose to provide, such as testimonials, photographs or videos, where applicable and subject to the appropriate permission.

Calendly is used for appointment scheduling. Our Calendly booking form is intended to collect ordinary scheduling and contact information only. We do not ask clients to submit diagnoses, detailed medical records or other health information through Calendly.

3. Information Shared Directly During or After a Session

A client may separately and voluntarily tell us about allergies, contraindications, pregnancy, injuries, discomfort, stress, sleep or other wellbeing matters that are relevant to the safe and appropriate delivery of a chosen service. Such information may qualify as sensitive personal data under Swiss law and as special-category health data where the GDPR applies.

We request only information that is reasonably relevant to safety or service adaptation. Where the GDPR applies and we rely on consent to process health-related information, we will request explicit consent. You may withhold or withdraw consent, although we may be unable to provide or adapt a service safely if essential safety information is unavailable. We do not use this information for medical diagnosis, insurance decisions, employment decisions or unrelated marketing.

4. How We Collect Personal Data

We collect personal data:

  • directly from you through our website, forms, bookings, purchases, emails, calls, messages and in-person or online interactions;
  • automatically when you use our website, through necessary cookies and, where enabled and permitted, analytics technologies; and
  • from service providers you use to interact with us, such as Calendly, Kajabi, Google/Gmail and Stripe, where necessary to complete the requested interaction.

5. Purposes and Legal Bases

We process personal data for the following purposes and, where the GDPR applies, on the following legal bases:

Purpose

GDPR legal basis, where applicable

Responding to enquiries; arranging, administering and delivering bookings, purchases, sessions, workshops and programmes

Steps requested before entering a contract and performance of a contract

Client communication, customer service, service administration and reasonable follow-up

Contract and legitimate interests in operating and improving our services

Payment, invoicing, accounting, fraud prevention and compliance

Contract, legal obligation and legitimate interests

Website security, troubleshooting and essential functionality

Legitimate interests in secure and reliable operations

Optional analytics and non-essential cookies

Consent where required

Newsletters and promotional communications

Consent, or legitimate interests where permitted by law; you may opt out at any time

Testimonials, identifiable photographs or promotional recordings

Consent or a separate written agreement, as appropriate

Health-related information voluntarily shared outside Calendly for safe service adaptation

Explicit consent where the GDPR applies and consent is the relied-upon condition

Establishing, exercising or defending legal claims

Legitimate interests and applicable legal provisions

6. Service Providers and Data Recipients

We use trusted service providers to operate our business. They receive only the data reasonably necessary for their function and process it under their applicable contractual and legal obligations. Depending on the service you use, recipients may include:

  • Kajabi: website hosting, forms, digital content, customer accounts and communications.
  • Calendly: appointment scheduling, confirmations, cancellations and rescheduling.
  • Google, including Gmail: email, communication, document and business administration services.
  • OpenAI, including ChatGPT: limited AI-assisted administrative support as described in Section 7.
  • Stripe and other displayed payment providers: payment processing, transaction security, refunds and payment administration.
  • Google Analytics or other analytics providers, if enabled: consent-based website measurement and performance analysis.
  • Professional advisers and public authorities: legal, accounting, insurance, regulatory or law-enforcement purposes where necessary or required.

We do not sell or rent personal data and do not disclose it to third-party advertisers or data brokers for their own independent marketing.

7. Use of AI-Assisted Tools

We may use AI-assisted tools, including OpenAI's ChatGPT, for limited administrative purposes such as locating booking information in connected services, organising routine correspondence, translating text and preparing draft communications. When we initiate such a task, limited information may be transferred from connected services such as Google/Gmail or Calendly to the AI service provider. Information incidentally contained in a relevant communication may also be processed.

We apply data-minimisation measures and seek to avoid providing detailed medical information, diagnoses or full client records to AI tools. AI tools are not used to diagnose clients, determine eligibility for services, make decisions producing legal or similarly significant effects, or replace our professional judgement. Drafts and outputs are reviewed by a person before use.

8. International Data Transfers

Some providers and their subprocessors may process personal data in Switzerland, the EEA, the United Kingdom, the United States or other countries. A destination country may not provide the same statutory level of data protection as Switzerland or the EEA.

Where required, transfers are supported by an adequacy decision, an applicable recognised data-protection framework, standard contractual clauses adapted as necessary for Swiss law, or another lawful safeguard. Information about a provider's locations and safeguards is available in that provider's privacy notice or data-processing terms.

9. Cookies and Analytics

Our website may use cookies and similar technologies. Necessary cookies support security and essential website functions. Optional analytics or marketing technologies are activated only in accordance with applicable consent requirements. Where a cookie banner is provided, you can accept, reject or adjust non-essential cookies. You can also control cookies through your browser, although blocking necessary cookies may affect website functionality.

10. Marketing Communications

We send newsletters or promotional communications only where we have an appropriate legal basis. You may unsubscribe at any time by using the unsubscribe link or contacting [email protected]. Withdrawal does not affect the lawfulness of earlier processing. We may keep a minimal suppression record to ensure that your opt-out is respected. Service-related messages concerning an existing booking or purchase are not marketing.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the stated purpose, taking account of contractual, safety, accounting, tax, limitation-period and legal requirements. Retention may include:

  • booking, service and correspondence records for the period needed to administer the relationship and handle reasonable follow-up or claims;
  • accounting, invoice and transaction records for the period required by Swiss law, generally ten years;
  • marketing subscription data until consent is withdrawn or the subscription otherwise ends, with a minimal suppression record retained as necessary;
  • consent and release records for as long as the related content is used and thereafter as needed to document permission; and
  • AI-assisted working conversations only for as long as required for the administrative task, subject to provider settings and applicable retention rules.

When data is no longer required, we delete, anonymise or securely archive it, unless continued retention is legally permitted or required.

12. Security and Confidentiality

We use reasonable technical and organisational measures appropriate to the nature and risk of the data, including access controls, password protection, encrypted transmission where supported, provider security controls, software updates, restricted access and data minimisation. No system is completely secure, and we cannot guarantee absolute security.

13. Your Rights

Depending on the applicable law and circumstances, you may have the right to:

  • request information about and access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive eligible data in a portable format;
  • withdraw consent at any time for future processing; and
  • lodge a complaint with a competent data-protection authority.

To exercise a right, email [email protected]. We may request reasonable information to verify your identity. Rights may be subject to legal conditions, exceptions and retention obligations. In Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC). If the GDPR applies, you may also complain to the competent supervisory authority in the EU or EEA country concerned.

14. Children

Our services and website are intended for adults aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so that we can take appropriate action.

15. External Links and Third-Party Services

Our website or communications may link to external websites and services. Their processing is governed by their own privacy notices when they act independently. We encourage you to review those notices. We are not responsible for the content or privacy practices of external websites that we do not control.

16. Changes to This Policy

We may update this Privacy Policy when our services, providers, practices or legal obligations change. The current version will be published on our website with a revised effective date. Where a change is material and appropriate, we may also notify affected individuals by email or another suitable method.

17. Contact

For privacy questions or requests, contact:

Mindful Evolution GmbH
Turnerstrasse 18
4058 Basel
Switzerland
Email: [email protected]
Website: https://www.mind-ful-evolution.com

 

Relevant provider notices