PRIVACY POLICY
Effective Date: 09 September 2025
1. Data Controller
Sandra Halbe
25, rue d’Auvers, 77123 Noisy-sur-Ecole, France
Email: info@sandrahalbe.com
Processing follows the GDPR and applicable French data protection law.
2. Scope
This policy applies when you:
-
visit this website
-
purchase products or services
-
book sessions
-
access programs, communities or memberships
-
download free resources
-
subscribe to newsletters
-
communicate via email or Messenger
-
use social media pages
-
play videos, audio or podcasts
3. Categories of Personal Data
We process:
-
Identification: name, email, postal address, phone
-
Contract & billing: invoices, payments, transaction IDs
-
Technical: IP address, browser, operating system, device
-
Usage: page views, clicks, session duration
-
Communication: emails, messages, bookings
-
Community & program: profiles, access logs, participation
4. How Data Is Collected
Data is collected via:
-
forms and checkout
-
ThriveCart orders
-
Calendly bookings
-
Wildmail subscriptions
-
Communi participation
-
cookies and analytics
-
server log files
You provide most data. Technical data is collected automatically.
5. Purposes and Legal Bases (Art. 6 GDPR)
| Purpose | Legal Basis |
|---|---|
| Contract fulfilment (delivery, access, support) | Art. 6(1)(b) |
| Accounting and tax duties | Art. 6(1)(c) |
| Email and newsletters | Art. 6(1)(a) / (b) |
| Website security and logs | Art. 6(1)(f) |
| Analytics and statistics | Art. 6(1)(a) |
| Community management | Art. 6(1)(b) |
| Free resources | Art. 6(1)(a) or (f) |
6. Mandatory vs Optional Data
Mandatory: name, email, billing data, payment data.
Optional: newsletter, Messenger, community content.
Without mandatory data, services cannot be delivered.
7. Storage and Retention
| Data | Retention |
|---|---|
| Invoices | 10 years |
| Contracts | 6 years |
| Newsletter | until unsubscribe |
| Community data | until deletion |
| Analytics | 26 months |
| Server logs | a few weeks |
| Cookies | by consent settings |
Legal duties may extend retention.
8. Processors and Third Parties
Checkout & Payments
ThriveCart – orders, access, invoice data (Art. 6(1)(b),(c))
Stripe, PayPal, Klarna – payments (Art. 6(1)(b))
Email & Newsletter
Wildmail (powered by ActiveCampaign) – newsletters, automation
Data: name, email, interaction data. Legal basis: consent and contract.
Booking
Calendly – scheduling (Art. 6(1)(b),(f))
Community & Courses
Communi App – hosting communities and courses (Art. 6(1)(b))
Website & Consent
WordPress + Divi
Borlabs Cookie – consent management (Art. 6(1)(c)/(f))
Analytics
Google Analytics (IP anonymised) – consent via banner
Media & Streaming
YouTube, Vimeo, SoundCloud – embedded media (consent)
Podcast
Spotify – podcast hosting and players
Data: IP address, usage, device data.
Consent arises through usage/interaction. Spotify is an independent controller.
Cloud Storage
Google Drive
Social Media
Instagram, Facebook, TikTok, YouTube
Each platform processes data under its own policy.
9. Website Hosting
Hosted by:
ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68, 02742 Friedersdorf, Germany
Purpose: hosting, security, backups.
Data: IP address, access logs, browser and device data.
Legal basis: Art. 6(1)(f).
10. International Transfers
Some providers operate outside the EU/EEA.
Transfers rely on EU adequacy decisions or Standard Contractual Clauses.
11. Cookies
Borlabs Cookie manages consent.
You can accept, reject or change settings at any time.
The banner and Cookie Policy show details and lifetimes.
12. Server Log Files
Recorded: IP (anonymised), pages, referrer, timestamps, data volume.
Purpose: security and stability.
Legal basis: Art. 6(1)(f).
13. Security
SSL/TLS encryption protects transmissions.
14. Free Resources & Newsletter
Free content may require email registration.
Double opt-in is used.
Unsubscribe any time via link in each email.
15. Your Rights (GDPR)
You may:
-
access data
-
correct data
-
delete data
-
restrict processing
-
withdraw consent
-
object (incl. direct marketing)
-
request portability
-
lodge a complaint
Requests are handled within 30 days.
Contact: info@sandrahalbe.com
16. Automated Decisions
No profiling or automated decision-making under Art. 22 GDPR.
17. Supervisory Authority
CNIL – Commission Nationale de l’Informatique et des Libertés
https://www.cnil.fr
18. Updates
We update this policy when law or technology changes.
Older versions are archived.
19. Contact
Sandra Halbe
info@sandrahalbe.com