PRIVACY POLICY

Last updated: 14 August 2026

This Privacy Policy explains how Yogisart (“Yogisart”, “we”, “us”, or “our”) collects, uses, stores and protects personal data when you visit our website, communicate with us, purchase our products or services, join our programs, subscribe to our communications, or otherwise interact with us online.

We respect your privacy and are committed to protecting your personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and applicable national data protection legislation.

Please read this Privacy Policy carefully.


1. WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA?

The data controller responsible for your personal data is:

Yogisart
Email: yogisartlondon@gmail.com
Telephone: +359 879 051 581

If Yogisart is operated by a specific individual or legal entity rather than “Yogisart” as a trading name, the full legal name and registered details should be inserted above.

For privacy-related questions or to exercise your data protection rights, please contact us using the email address above.

Data Protection Officer: [Not applicable / insert details if one has been formally appointed]


2. WHAT IS PERSONAL DATA?

Personal data is any information that relates to an identified or identifiable individual.

Depending on how you interact with us, this may include your name, email address, telephone number, billing information, information you provide when contacting us, information relating to your participation in our programs or services, and technical information about how you use our website.

We only collect personal data that is reasonably necessary for the purposes described in this Privacy Policy.


3. WHAT PERSONAL DATA DO WE COLLECT?

Depending on your interaction with us, we may collect the following categories of personal data:

Information you provide directly to us

This may include:

  • Full name

  • Email address

  • Telephone number

  • Billing and payment information

  • Address, where required for invoicing or legal purposes

  • Information submitted through contact forms

  • Information provided when booking a consultation or service

  • Information provided when purchasing a product, program, course, workshop, retreat or other service

  • Information provided when communicating with us by email, messaging platforms or other communication channels

  • Information you voluntarily provide in connection with coaching, mentoring, workshops, programs or other services

Information collected automatically

When you visit our website, certain technical information may be collected automatically, depending on the technologies and services used on the website. This may include:

  • IP address

  • Browser type and version

  • Device type

  • Operating system

  • Approximate location

  • Pages visited

  • Time spent on pages

  • Referring website

  • Website interactions and usage information

  • Cookie and similar technology information

This information may be collected through cookies, analytics services and similar technologies.

Information relating to purchases and services

If you purchase or participate in one of our products or services, we may process information necessary to:

  • process and confirm your purchase;

  • provide the service or program;

  • communicate with you about the service;

  • manage bookings and appointments;

  • provide customer support;

  • issue invoices and comply with accounting and tax obligations; and

  • maintain appropriate business records.


4. HOW DO WE USE YOUR PERSONAL DATA?

We may use your personal data for the following purposes:

To respond to your enquiries

If you contact us through our website, email or another communication channel, we may use the information you provide to respond to your enquiry and communicate with you.

To provide products and services

We process personal data when necessary to provide products, coaching, mentoring, courses, programs, workshops, retreats and other services you have purchased or requested.

To process payments

We may share the information necessary to process a payment with the relevant payment service provider.

We do not generally have access to or store your complete payment card details when payment is processed through a third-party payment provider.

To manage bookings and appointments

Where applicable, we may use third-party booking or scheduling services to arrange consultations, coaching sessions, workshops or other appointments.

To communicate with you

We may use your contact information to send you service-related communications, including confirmations, reminders, updates and information relating to a product or service you have purchased.

Where we send marketing communications, we will do so in accordance with applicable law and, where required, based on your consent.

To send newsletters and marketing communications

If you have expressly subscribed to our newsletter, mailing list or other marketing communications, we may use your email address to send you information about:

  • our programs and services;

  • workshops and events;

  • new products;

  • offers;

  • educational content;

  • newsletters; and

  • other information that may be relevant to your interests.

You may unsubscribe from marketing communications at any time by clicking the unsubscribe link included in our emails or by contacting us.

Marketing consent is separate from your acceptance of this Privacy Policy. A general privacy-policy checkbox does not itself constitute marketing consent.

To improve our website and services

We may use aggregated or analytical information to understand how visitors use our website and to improve its functionality, content, products and services.

To protect our business

We may process information where necessary to:

  • prevent fraud or misuse;

  • protect the security of our website and systems;

  • enforce our terms and policies;

  • establish, exercise or defend legal claims; and

  • comply with legal or regulatory obligations.


5. LEGAL BASES FOR PROCESSING

Under the GDPR, we process personal data only where there is an appropriate legal basis.

Depending on the circumstances, our legal bases may include:

Performance of a contract

Where processing is necessary to provide a product or service you have purchased or requested.

Legal obligation

Where processing is necessary for us to comply with legal obligations, such as accounting, taxation or other regulatory requirements.

Consent

Where you have freely and specifically given your consent, for example for certain marketing communications or non-essential cookies.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Consent must be freely given, informed, specific and unambiguous and must be capable of being withdrawn.

Legitimate interests

Where processing is necessary for our legitimate business interests, provided that those interests do not override your fundamental rights and freedoms.

Examples may include maintaining website security, preventing fraud, managing our business and improving our services.


6. COACHING, MENTORING AND OTHER INFORMATION YOU VOLUNTARILY PROVIDE

Our services may involve you voluntarily sharing personal information about your experiences, circumstances, relationships, emotions, goals, beliefs or other aspects of your life.

You are not required to disclose information that you do not wish to share.

Please do not provide us with sensitive personal information unless it is genuinely necessary for the service and you are comfortable doing so.

Where information falls within a special category of personal data under applicable data protection law, we will only process it where an appropriate additional legal condition applies.


7. WHO MAY RECEIVE YOUR PERSONAL DATA?

We may share personal data with trusted third-party service providers where necessary to operate our business and provide our services.

Depending on the services we use, these may include providers of:

  • website hosting;

  • website maintenance and technical support;

  • email and newsletter services;

  • payment processing;

  • booking and scheduling;

  • video conferencing;

  • online course and membership platforms;

  • cloud storage;

  • accounting and invoicing;

  • customer relationship management;

  • analytics;

  • advertising and marketing technology;

  • IT and cybersecurity services; and

  • professional or legal services.

These providers may process personal data on our behalf and will only be permitted to process it in accordance with applicable law and our instructions where they act as processors.

Important: The actual names of the providers you use should be added to this section or to a separate “Third-Party Services” section. For example, if you use Google Analytics, Mailchimp/ConvertKit, Stripe, PayPal, Zoom, Kajabi, Wix, Squarespace, WordPress, Calendly, Meta Pixel, Telegram or WhatsApp, the final policy should reflect the services actually used.


8. INTERNATIONAL DATA TRANSFERS

Some of our service providers may be located outside the European Economic Area (EEA), including in countries such as the United States.

Where personal data is transferred outside the EEA, we will ensure that the transfer is made in accordance with applicable data protection law and using an appropriate legal mechanism, such as an adequacy decision, Standard Contractual Clauses or another legally recognised safeguard where required.

The original Yogisart policy states that personal data is not transferred outside Bulgaria. This statement should not be retained unless it is still factually correct for every provider you use.


9. COOKIES AND ANALYTICS

Our website may use cookies and similar technologies.

Cookies are small files stored on your device that may be used to enable website functionality, remember preferences, understand website usage and, where applicable, support analytics or marketing.

Our website may use analytics services such as Google Analytics.

Where required by law, we will request your consent before placing or accessing non-essential cookies.

You should be able to accept or reject non-essential cookies through our cookie consent mechanism. Rejecting non-essential cookies should not prevent you from using the essential functionality of the website.

Where cookies process personal data, they may also fall within the scope of applicable data protection legislation. The use of non-essential cookies generally requires valid consent, and consent should be obtained through a clear affirmative action.

For more information, please see our Cookie Policy.


10. THIRD-PARTY WEBSITES AND SOCIAL MEDIA

Our website may contain links to third-party websites, platforms or social media services.

Examples may include Instagram, Facebook, YouTube, LinkedIn, payment providers, booking platforms and other external services.

If you follow a link to a third-party website, that website will have its own privacy policy and terms. We are not responsible for the privacy practices, content or security of third-party websites.

We encourage you to review the privacy policies of any third-party services you use.


11. HOW LONG DO WE KEEP YOUR PERSONAL DATA?

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

The appropriate retention period depends on the type of information and the reason for processing it.

For example:

  • Contact enquiries may be retained for as long as reasonably necessary to respond to and manage the enquiry.

  • Customer and transaction information may be retained for the period required by applicable accounting, tax and legal requirements.

  • Marketing information may be retained until you withdraw your consent or unsubscribe, subject to any information we are legally required to retain.

  • Coaching or program-related information may be retained for as long as necessary to provide the service and manage our contractual, legal or legitimate business interests.

Where appropriate, we may delete, anonymise or securely dispose of information once it is no longer required.

The previous Yogisart policy stated that website enquiry history was retained for one year. If you still want to use a fixed one-year period, it can be specified here.


12. HOW DO WE PROTECT YOUR DATA?

We take reasonable technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include appropriate access controls, password protection, secure systems, restricted access and the use of reputable third-party service providers.

However, no method of transmission or electronic storage can be guaranteed to be completely secure.

If a personal data breach occurs that requires notification under applicable law, we will take the appropriate steps required by law.


13. YOUR DATA PROTECTION RIGHTS

Depending on the circumstances and applicable law, you may have the following rights:

Right of access

You may request confirmation as to whether we process your personal data and request a copy of the information we hold about you.

Right to rectification

You may ask us to correct inaccurate or incomplete personal data.

Right to erasure

You may ask us to delete your personal data where there is no lawful reason for us to continue processing it.

Right to restriction

You may ask us to restrict the processing of your personal data in certain circumstances.

Right to object

You may object to certain processing based on legitimate interests and, in particular, object to direct marketing.

Right to data portability

Where the relevant legal conditions apply, you may request that personal data you have provided to us be supplied in a structured, commonly used and machine-readable format or transferred to another controller.

Right to withdraw consent

Where we process your data based on consent, you may withdraw that consent at any time.

Rights relating to automated decision-making

Where applicable, you may have rights relating to automated decision-making or profiling.

The GDPR recognises rights including access, rectification, erasure, restriction, objection and portability.


14. HOW TO EXERCISE YOUR RIGHTS

To exercise any of your rights, please contact us at:

Email: yogisartlondon@gmail.com

Please clearly state your request and provide sufficient information for us to verify your identity where reasonably necessary.

We generally respond to valid requests within one month. This period may be extended by up to a further two months where permitted by law due to the complexity or number of requests.

Requests are generally free of charge, although applicable law permits us in certain circumstances to charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive.


15. YOUR RIGHT TO COMPLAIN

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the relevant data protection supervisory authority.

If you are located in Spain, the relevant supervisory authority is:

Agencia Española de Protección de Datos (AEPD)
Website: https://www.aepd.es/

If the relevant controller is established in Bulgaria or the processing falls under the jurisdiction of the Bulgarian supervisory authority, you may also contact:

Commission for Personal Data Protection (CPDP / КЗЛД)

You may also have the right to complain to the supervisory authority in the EU/EEA country where you live, work or believe an infringement has occurred.


16. CHILDREN’S PRIVACY

Our website and services are intended for adults.

We do not knowingly collect personal data from children where doing so would be prohibited by applicable law.

If you believe that a child has provided us with personal data without appropriate consent, please contact us so that we can take appropriate steps.


17. DATA YOU PROVIDE THROUGH COMMUNICATION PLATFORMS

If you communicate with us through third-party platforms such as WhatsApp, Telegram, Instagram, Facebook Messenger, Zoom or other services, your use of those platforms is also governed by the privacy policies and terms of those providers.

We recommend reviewing the privacy policies of those services before using them to communicate with us.


18. BUSINESS TRANSFERS

If Yogisart is involved in a merger, acquisition, restructuring, sale of assets or other business transaction, personal data may be transferred as part of that transaction where legally permitted and where appropriate safeguards are in place.


19. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes to our business, services, technology or legal requirements.

When we make changes, we will update the “Last updated” date at the top of this policy.

We encourage you to review this page periodically to remain informed about how we protect your personal data.


20. CONTACT US

If you have any questions about this Privacy Policy or how we process your personal data, please contact:

Yogisart
Email: yogisartlondon@gmail.com
Telephone: +359 879 051 581


Last updated: 14 August 2026