← Back to the site

Privacy Policy

Last updated: September 2, 2026

In short: this site does not collect personal data automatically. It has no forms, no analytics and no advertising trackers. Data only exists once you write to us or book a place.

1. Who processes your data

The data controller is Amrita essence LLC, the organiser of The Wisdom of Sedona retreat (“we”, “the Organiser”).

NameAmrita essence LLC, a Florida limited liability company
Registered address6356 SW 32nd Street, Miami, FL 33155, USA
Emailamritaessence@gmail.com
Telegram@Amritapower

2. What data we receive

2.1. When you simply read the site

There is not a single form on this site, and we use no visitor counters or advertising pixels. Two things still happen automatically:

WhatWhich dataWho receives itWhy
Hosting IP address, browser type, time of request, page requested Netlify, Inc. (USA) Serving the pages, protection against attacks, technical logs
Fonts IP address Google LLC (USA) Loading the Montserrat and Prata typefaces

Please note: the fonts are loaded from Google's servers, so opening the page makes your IP address known to Google. We intend to move the fonts onto our own server and remove that transfer.

2.2. When you book a place

To arrange your participation we need:

  • your first and last name;
  • your email address and phone number;
  • information material to your safety on the programme: contraindications, allergies, injuries, pregnancy, medication you take (see § 6);
  • an emergency contact;
  • your accommodation and dietary preferences.

We do not receive or store card details. Payment is taken by Stripe, Inc. on Stripe's own checkout page, not on this site. Stripe acts as its own controller in respect of payment credentials, under Stripe's Privacy Policy. From Stripe we receive the fact of payment, the amount, the contact details you enter at checkout, and the card's brand and last four digits.

2.3. When you write to us

Conversations on Telegram or Instagram are stored on those platforms' servers under their own rules. We do not control those services and we recommend reading their policies.

3. Legal bases for processing

PurposeLegal basis (GDPR)
Performing the agreement to take part in the retreatArt. 6(1)(b) — performance of a contract
Participant safety, accounting for contraindicationsArt. 6(1)(b) and Art. 9(2)(a) — explicit consent to the processing of health data
Accounting and tax recordsArt. 6(1)(c) — legal obligation
Running the site, protection against abuseArt. 6(1)(f) — legitimate interest
News about future retreatsArt. 6(1)(a) — consent, withdrawable at any time

Health data is a special category. We ask for it only to the extent needed for your safety on the programme, process it on the basis of your explicit consent, and do not pass it to third parties except in the case of emergency medical care.

4. Who we share data with

We do not sell or rent personal data. It may be shared only with the following categories of recipient:

  • Payment providers — to take payment, once payment is enabled;
  • Our hosting provider (Netlify, Inc.) — hosting this site;
  • Accommodation and transfer partners — the venue and the transport company receive a list of names for check-in and travel;
  • Public authorities — where the law requires it.

5. Transfers outside the EEA

The Organiser is established in the United States, the retreat takes place there, and our hosting and payment services are located there too. This means data is transferred to a country outside the European Economic Area. Transfers are made on the basis of the European Commission's standard contractual clauses and, for bookings, on the basis of Art. 49(1)(b) GDPR (the transfer is necessary to perform a contract concluded in your interest).

6. How long we keep data

CategoryRetention period
Health data and contraindicationsDeleted within 30 days of the end of the retreat
Participants' contact details3 years after the retreat, then deleted
Payment recordsThe period set by tax law [TO CONFIRM: usually 5–7 years]
Mailing-list subscriptionUntil consent is withdrawn
Web server logsPer Netlify's rules, normally up to 30 days

7. Your rights

If the GDPR applies to you (you are in the EEA, the United Kingdom or Switzerland), you have the right to:

  • access your data and receive a copy of it;
  • have inaccurate data corrected;
  • request erasure (the “right to be forgotten”);
  • restrict processing;
  • receive your data in a machine-readable format and transfer it to another controller;
  • object to processing based on legitimate interest;
  • withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal;
  • lodge a complaint with the data protection authority in your country.

If you are a California resident, the CCPA/CPRA give you the right to know which categories of data have been collected about you, to request their deletion and correction, and not to be discriminated against for exercising those rights. We do not sell personal data and do not share it for cross-context behavioural advertising within the meaning of the CCPA.

To exercise any of these rights, write to amritaessence@gmail.com. We will respond within 30 days.

8. Security

The site runs over HTTPS with a Let's Encrypt certificate. Only the organiser has access to participant lists. Health data is stored separately from everything else and deleted immediately after the retreat.

No method of transmitting data over the internet is completely secure, so we cannot guarantee absolute protection.

9. Children

The retreat is intended for adults. We do not knowingly collect data about anyone under 18.

10. Cookies

This site uses no cookies for analytics or advertising. Details are in the Cookie Policy.

11. Changes to this policy

We may update this policy. The date of the last change is shown at the top of the page. If the changes are significant, we will tell participants by email.

12. Contact

Questions about personal data: amritaessence@gmail.com or Telegram @Amritapower.

See also: Terms of Participation · Cookie Policy