Privacy Policy

Effective Date: November 17, 2025

Last Updated: November 20, 2025


1. Data Controller

The data controller responsible for your personal information is:

Ecoaching.site

Independent Professional

Address: Europe

Email: contact@ecoaching.site

We value your privacy and are committed to protecting your personal information in accordance with the General Data Protection Regulation (GDPR) and European data protection laws. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how we protect it, and your rights regarding your data.

2. Scope

This Privacy Policy applies to all personal information collected through:

  • Our website: ecoaching.site
  • Contact forms and inquiry submissions
  • Email communications
  • Coaching session bookings and applications
  • Any other interactions with our coaching and mentoring services

3. Information We Collect

3.1 Information You Provide Directly

We collect information that you voluntarily submit to us, including:

  • Contact Information: Name, email address, phone number (if provided)
  • Inquiry Details: Messages, questions, or requests submitted through contact forms
  • Application Information: Information provided when applying for coaching services
  • Communication Records: Correspondence via email or other channels

3.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • Technical Data: IP address, browser type and version, device information, operating system
  • Usage Data: Pages visited, time spent on pages, access times and dates, referring websites
  • Cookies: Essential cookies for security and functionality (see Section 7)

4. How We Use Your Information

We use your personal information for the following purposes:

4.1 To Provide Our Services

  • Respond to your inquiries and messages
  • Process coaching session applications and bookings
  • Deliver coaching and mentoring services
  • Communicate with you about your sessions and services
  • Send appointment reminders and scheduling updates

4.2 To Improve Our Services

  • Analyze website usage and performance
  • Understand client needs and preferences
  • Improve our coaching programs and materials
  • Ensure website security and prevent fraud

4.3 For Business Operations

  • Maintain business records and fulfill legal obligations
  • Comply with European and EU legal requirements
  • Enforce our Terms and Conditions

4.4 For Marketing (With Your Consent)

  • Send newsletters or promotional content (only if you explicitly opt-in)
  • Inform you about new services or programs

5. Legal Basis for Processing (GDPR Article 6)

Under GDPR, we process your personal data based on the following legal grounds:

  • Consent (Article 6(1)(a)): When you submit information through our forms, subscribe to communications, or explicitly agree to processing
  • Contract Performance (Article 6(1)(b)): To provide coaching services you requested or contracted for
  • Legitimate Interests (Article 6(1)(f)): To respond to inquiries, improve our services, ensure website security, and operate our business efficiently
  • Legal Obligation (Article 6(1)(c)): To comply with European tax, accounting, and other legal requirements

Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

6. How We Share Your Information

6.1 We Do NOT Sell Your Data

We will never sell, rent, or trade your personal information to third parties for marketing purposes.

6.2 Service Providers (Data Processors)

We may share limited information with trusted third-party service providers who assist us in operating our business. These processors act on our behalf and under our instructions:

  • Web and Email Hosting Provider: Namecheap - Hosts our website and manages email communications on secure servers located within the EU/EEA where possible. View their privacy policy: https://www.namecheap.com/legal/general/privacy-policy/

All service providers are bound by data processing agreements (DPA) that ensure GDPR compliance. They are contractually obligated to:

  • Process data only on our documented instructions
  • Implement appropriate security measures
  • Maintain confidentiality
  • Assist us in responding to data subject requests
  • Delete or return data upon termination of services

6.3 Legal Requirements and Public Authorities

We may disclose your information when required by European or EU law, court order, or lawful request from public authorities, including to:

  • Comply with legal processes and obligations
  • Respond to requests from European authorities (e.g., tax authorities, CNPD)
  • Enforce our Terms and Conditions
  • Protect our rights, property, or safety, or that of others
  • Prevent fraud or illegal activities

6.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the acquiring entity. We will ensure that the same level of data protection is maintained and will notify you of any such transfer.

7. Cookies and Tracking Technologies

7.1 What Cookies We Use

In accordance with the ePrivacy Directive and GDPR, this website uses minimal cookies:

  • Strictly Necessary Cookies: Essential for website functionality, security, and navigation. These do not require consent under GDPR.
  • Functional Cookies: Remember your preferences (e.g., language settings). These require consent.

7.2 What We Don't Use

We do NOT use:

  • Advertising or marketing cookies
  • Third-party tracking cookies
  • Retargeting or remarketing technologies
  • Social media tracking pixels
  • Cross-site tracking technologies

7.3 Managing Cookies

You can control and manage cookies through your browser settings. Please note that disabling essential cookies may affect website functionality. For more information about cookies and how to manage them, visit: https://www.aboutcookies.org

8. Data Retention

We retain your personal information only as long as necessary for the purposes outlined in this policy and as required by European and EU law:

  • Contact Inquiries: Retained for up to 3 years after last contact, unless you request earlier deletion
  • Client Records: Retained for up to 10 years after the end of the business relationship, in compliance with European tax and accounting obligations
  • Marketing Data: Retained until you unsubscribe or request deletion, or after 2 years of inactivity
  • Website Logs: Retained for up to 12 months for security purposes

After the retention period expires, we securely delete or anonymize your data in accordance with GDPR requirements (Article 5(1)(e) - storage limitation principle).

9. Confidentiality of Coaching Sessions

All information shared during coaching and mentoring sessions is kept strictly confidential in accordance with professional coaching ethics and GDPR, except:

  • When disclosure is required by European or EU law
  • When you provide explicit written consent to share specific information
  • In cases of imminent harm to yourself or others (legal obligation)

9.1 Session Notes and Recordings

We do not record coaching sessions or keep detailed session notes.

10. Data Security

In accordance with GDPR Article 32, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption: SSL/TLS encryption (HTTPS) for all data transmission
  • Secure Hosting: Data stored on secure servers with restricted access controls
  • Access Management: Limited access to personal data on a strict need-to-know basis
  • Pseudonymization: Where appropriate, data is pseudonymized to enhance security
  • Regular Security Updates: Systems and software kept up to date with security patches
  • Password Protection: Strong password policies and authentication measures
  • Data Breach Procedures: Established procedures to detect, report, and investigate data breaches

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the European Data Protection Authority (CNPD) within 72 hours, as required by GDPR Article 33.

11. Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

11.1 Right of Access (Article 15)

You have the right to obtain confirmation as to whether or not we process your personal data and, if so, to access that data and receive information about how it is processed.

11.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate or incomplete personal data we hold about you.

11.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

11.4 Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

11.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

11.6 Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

11.7 Right Not to be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you. (Note: We do not engage in automated decision-making.)

11.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

11.9 Right to Lodge a Complaint

You have the right to lodge a complaint with the European Data Protection Authority (CNPD) if you believe we have not handled your personal data appropriately:


Address: Europe

11.10 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: contact@ecoaching.site
Subject Line: "GDPR Rights Request"

We will respond to your request without undue delay and within one month of receipt, as required by GDPR Article 12. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.

To verify your identity when exercising your rights, we may request additional information from you. We will only use this information to verify your identity and will not use it for any other purpose.

12. International Data Transfers

Your personal data is primarily processed and stored within the European Union / European Economic Area (EU/EEA).

12.1 Transfers Within the EU/EEA

As we operate from Europe (an EU member state) and use service providers primarily within the EU/EEA, your data benefits from the full protections of GDPR.

12.2 Transfers Outside the EU/EEA

In the event that we need to transfer your personal data to a country outside the EU/EEA, we will ensure that:

  • The transfer is to a country with an adequacy decision from the European Commission (Article 45 GDPR), OR
  • Appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission (Article 46 GDPR), OR
  • Your explicit consent has been obtained for the specific transfer (Article 49 GDPR)

You have the right to obtain information about the safeguards we have put in place for international transfers by contacting us.

13. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately.

If we become aware that we have collected personal data from a child under 18 without verification of parental consent, we will take steps to delete that information as quickly as possible, in compliance with GDPR Article 8.

14. Third-Party Links

Our website may contain links to third-party websites not operated by us. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

When you leave our website, we recommend you read the privacy policy of every website you visit.

15. Email Marketing and Communications

15.1 Consent and Opt-In

In accordance with the ePrivacy Directive and GDPR, we will only send you marketing emails if you have explicitly opted in to receive them. We use a double opt-in process to ensure clear consent.

15.2 Right to Unsubscribe

You can unsubscribe from marketing emails at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Contacting us at contact@ecoaching.site
  • Updating your preferences in your account (if applicable)

We will process your unsubscribe request promptly and within 48 hours.

15.3 Transactional Emails

Even if you opt out of marketing emails, we may still send you transactional emails related to your coaching services, such as:

  • Appointment confirmations and reminders
  • Responses to your inquiries
  • Important updates about our services
  • Legal or security notifications

These emails are necessary for the performance of our contract with you or to comply with legal obligations.

16. Data Protection by Design and by Default

In accordance with GDPR Article 25, we implement data protection by design and by default:

  • We collect only the minimum personal data necessary for our purposes (data minimization)
  • Privacy settings are set to the most privacy-friendly options by default
  • We implement appropriate technical and organizational measures at the design stage
  • We regularly review and update our data processing practices

17. Data Protection Officer (DPO)

As a small independent professional, we are not required to appoint a Data Protection Officer under GDPR Article 37. However, you can contact us directly with any data protection questions or concerns at contact@ecoaching.site.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify you via email or prominent notice on our website at least 30 days before the changes take effect (if the changes materially affect your rights)
  • For significant changes, we may request your renewed consent

We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are implemented constitutes acceptance of the updated policy, unless the changes require your explicit consent.

19. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, data protection, or wish to exercise your GDPR rights, please contact us:

Data Controller: Ecoaching.site
Email: contact@ecoaching.site
Mail: Europe

We will respond to your inquiry within one month, as required by GDPR Article 12.

20. EU Online Dispute Resolution

In accordance with EU Regulation No 524/2013, consumers have access to the Online Dispute Resolution (ODR) platform for out-of-court resolution of disputes arising from online contracts:

ODR Platform: https://ec.europa.eu/consumers/odr


Acknowledgment: By using our website and services, you acknowledge that you have read, understood, and agree to this Privacy Policy and consent to the processing of your personal data as described herein.

This Privacy Policy complies with the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and European Law No. 58/2019.

Last Updated: November 20, 2025

Scroll to Top