Sadha Yoga

EN DE

Privacy Policy

This is a courtesy translation. The legally binding version is the German one: Datenschutzerklärung.

Last updated: August 2026

Overview

This policy explains what personal data is processed when you visit this website, for what purpose, and what rights you have. It applies to all pages under sadhayoga.org.

In short: this website sets no cookies for analytics or advertising, embeds no tracking services and builds no user profiles. Data is only processed when you use the contact form, book a course or write to us.

Controller

Marc Euler / SadhaYoga
Luthmerstraße 53
65934 Frankfurt am Main
Germany

Email: welcome@sadhayoga.org
Phone: +49 176 5609 6617
Imprint: imprint.html

A data protection officer is not legally required and has not been appointed. For any question about data protection, please write to the address above.

Legal bases

Depending on the context, processing is based on one of the following provisions of the General Data Protection Regulation:

German national provisions under the Federal Data Protection Act (BDSG) apply in addition.

Hosting and access data

This website is hosted by Cloudflare. Cloudflare delivers the site through a global server network and also handles the encryption of the connection and protection against denial-of-service attacks.

When you open the site, Cloudflare processes technically necessary access data. This includes your IP address, the date and time of access, the page requested, the previously visited page, the volume of data transferred, and details about your browser and operating system. Without this data the site could not be delivered to you.

The legal basis is our legitimate interest in a stable website protected against attack (Art. 6(1)(f) GDPR). We do not evaluate this data ourselves and do not combine it with other sources.

Provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA
Privacy policy: cloudflare.com/privacypolicy
Processing agreement: A data processing agreement under Art. 28 GDPR is in place.
Basis for transfers: Data Privacy Framework, supplemented by standard contractual clauses.

Cookies and fonts

This website sets no cookies for analytics, advertising or tracking. No cookie banner is required, because no storage operations requiring consent take place.

For security purposes Cloudflare may set a technically necessary cookie in order to identify repeated automated requests. This cookie serves only to fend off attacks and holds no information usable for advertising.

The typefaces used on this site are served locally from our own server. There is no connection to external font providers, in particular not to Google Fonts. Your IP address is therefore not transmitted to any third party for this purpose.

Contact form and email

You can send us a message through the contact form. The details you enter are processed: first name, last name, email address and the content of your message. We use these details solely to answer your enquiry.

The technical transmission is handled by the service provider Formspree. Your entries are received there and forwarded to our mailbox by email. Formspree also stores submissions in its own system for a limited period so that messages are not lost if delivery fails.

The legal basis is your consent, given by ticking the box before sending (Art. 6(1)(a) GDPR), and, for enquiries about courses, the initiation of a contract (Art. 6(1)(b) GDPR). You may withdraw your consent at any time without formality; the lawfulness of processing carried out up to that point remains unaffected.

Provider: Formspree, Inc., USA
Privacy policy: formspree.io/legal/privacy-policy
Basis for transfers: Standard contractual clauses of the European Commission.

If you write to us directly by email instead, your message is processed in our mailbox at Proton. Proton is a Swiss provider; following an adequacy decision of the European Commission, Switzerland is regarded as offering an adequate level of data protection, so no additional safeguards are required.

Provider: Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland
Privacy policy: proton.me/legal/privacy

Bookings and payment

When you book a course, you are directed to a page operated by our payment provider Stripe. Your payment details are entered there and nowhere else.

Stripe processes the details required for the transaction, in particular name, email address, billing address, card or bank details and the amount. We neither receive nor store complete card or account details at any point. What is passed on to us is your name, your email address, the course booked and confirmation that payment was successful.

The legal basis is the performance of the booking contract (Art. 6(1)(b) GDPR). Payment records are additionally retained where we are required to do so under commercial and tax law (Art. 6(1)(c) GDPR).

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, for European customers; parent company Stripe, Inc., USA
Privacy policy: stripe.com/privacy
Basis for transfers: Data Privacy Framework, supplemented by standard contractual clauses.

Participant data

To run the courses we process your name, your contact details and the course booked.

If, before a session, you tell us of your own accord about health restrictions, injuries or a pregnancy, this constitutes health data within the meaning of Art. 9 GDPR. We process such information solely in order to show you safe alternatives to individual postures, relying on your explicit consent (Art. 9(2)(a) GDPR). You are under no obligation to provide it, and we do not pass it on to third parties. On request we delete it once the course has ended.

Transfers to the USA

Some of the services used are based, or keep servers, in the United States. For transfers there we rely on the Data Privacy Framework, which the European Commission recognised as an adequate legal framework by decision of 10 July 2023. In addition, standard contractual clauses are in place with these providers and would continue to apply should anything about the Data Privacy Framework change.

Despite these safeguards it cannot be entirely ruled out that US authorities may access data on the basis of laws applicable there. A list of certified companies is available at dataprivacyframework.gov.

Retention periods

Your rights

In relation to your personal data you have the following rights:

An informal message to welcome@sadhayoga.org is enough for any of these.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany. You may equally approach the authority for your place of residence or work.

Changes

We update this policy whenever the processing on this website changes, for instance because a new service is added. The version published here, bearing the date given above, is the one that applies.

Back to the home page