Privacy Policy
Last updated: July 2026
This Privacy Policy explains how Damien Soitout Holdings (Cyprus), trading as Retraite Eveil ("we", "us"), processes personal data when you use retraite-eveil.com (the "Website"), create a customer account, book a retreat, contact us, or interact with related services.
This policy covers the Website and retreat booking platform only. Our invitation-only community app at app.retraite-eveil.com has its own Privacy Policy governing activity inside that platform. Below we explain what data we share to provision your access and where to look for app-specific rules.
Table of contents
- Data controller
- Scope
- Data we collect
- Purposes and legal bases
- Health questionnaire data
- Community app provisioning
- Retention periods
- Sharing and processors
- International transfers
- Security
- Your rights
- Account deletion and data export
- Cookies and analytics
- Children
- Changes to this policy
- Complaints to a supervisory authority
- Contact
1. Data controller
The data controller for processing described in this policy is Damien Soitout Holdings, a company located in Cyprus, trading as Retraite Eveil.
Damien Soitout Holdings
Trading as: Retraite Eveil
P.O. Box 21472
1599 Nicosia
Cyprus
Email: [email protected]
Phone: +33 6 14 37 57 01
Website: https://retraite-eveil.com
Retreat operations: Amsterdam area, Netherlands
For privacy enquiries, data-subject requests, or questions about this policy, email [email protected].
2. Scope
This policy applies to:
- Browsing and searching the Website;
- Creating and using a customer account;
- Retreat registration, checkout, and payment;
- Health questionnaires and ticket administration;
- Refund requests and customer support;
- Contact forms and email correspondence;
- Affiliate referral tracking on the Website;
- Integration Partner applications, public Partner profiles, Partner-service bookings, disputes, and Partner payouts;
- Automated provisioning of community app access for eligible guests.
It does not replace the privacy policy of the community app itself, which covers posts, messages, profile content, push notifications, and other activity on app.retraite-eveil.com.
3. Data we collect
3.1 Account and profile
- Name, email address, phone number;
- Password (stored hashed);
- Preferred language/locale;
- Invoice or billing address where provided.
3.2 Booking and orders
- Buyer and guest names and email addresses (one unique email per ticket);
- Retreat date, ticket type, add-ons, and order totals;
- Payment method, payment status, PayPal transaction references, bank-transfer references;
- Order history, ticket status, PDF ticket metadata.
3.3 Health questionnaire
- Medical history, medications, mental-health disclosures, contraindications, and safety-related answers you submit;
- Administrative review notes and approval/rejection status.
3.4 Communications
- Messages sent via contact forms or email;
- Transactional emails we send (confirmations, questionnaire invites, ticket approvals, refund updates, community access instructions).
3.5 Technical and usage data
- IP address, browser type, device information;
- Session and authentication cookies;
- Analytics and marketing identifiers where you have consented (see Cookies);
- Cloudflare Turnstile verification tokens on protected forms;
- Affiliate referral cookie when you arrive via a partner link.
3.6 Refunds
- Refund reasons, selected tickets, amounts, admin decisions, payout references, and uploaded proof documents where applicable.
3.7 Integration Partners
- Partner application data (name, email, bio, expertise, website, motivation, services of interest);
- Public profile content (photo, bio, languages spoken, links) when approved;
- Partner-service listings (titles, descriptions, prices) and approval status;
- Booking, completion, dispute, and payout records linking Partners and Clients;
- Audit logs of Partner dashboard actions.
4. Purposes and legal bases (GDPR)
We process personal data only where we have a lawful basis under the General Data Protection Regulation (GDPR).
| Purpose | Typical data | Legal basis |
|---|---|---|
| Retreat registration and contract performance | Account, order, guest, payment data | Art. 6(1)(b), contract |
| Health screening and participant safety | Questionnaire answers | Art. 6(1)(b) contract; Art. 9(2)(a) explicit consent for special-category health data |
| Ticket PDFs, venue communications, attendee hub | Guest contact, ticket status | Art. 6(1)(b), contract |
| Community app access provisioning | Guest email, name, retreat/locale mapping | Art. 6(1)(b), contract (included benefit) |
| Customer support and contact requests | Name, email, message content | Art. 6(1)(b) or Art. 6(1)(f) legitimate interest |
| Refund administration | Order, ticket, payout data | Art. 6(1)(b) and Art. 6(1)(c) legal obligation |
| Accounting, tax, and audit records | Order and invoice data | Art. 6(1)(c), legal obligation |
| Fraud prevention and site security | IP, session, Turnstile data | Art. 6(1)(f), legitimate interest |
| Affiliate commission tracking | Referral cookie, order attribution | Art. 6(1)(f), legitimate interest |
| Integration Partner programme | Application, profile, booking, payout, dispute data | Art. 6(1)(b) contract with Partner; Art. 6(1)(b)/(f) for Client bookings and Platform safety |
| Website analytics and conversion measurement | Analytics cookies, usage events | Art. 6(1)(a), consent (via cookie banner) |
| Legal claims and dispute defence | Relevant account and order records | Art. 6(1)(f), legitimate interest |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Providing booking and questionnaire data is contractually necessary to register and attend a retreat. Without it, we cannot assess safety, issue tickets, or deliver the service.
5. Health questionnaire data
Health questionnaires contain special-category data under GDPR Article 9. We collect this data only to assess whether a guest can safely participate, to plan facilitator support, and to meet our duty of care.
- Access is restricted to authorised Retraite Eveil staff and facilitators who need it for safety review;
- Questionnaire data is stored securely and is not used for marketing;
- We retain questionnaire records for 3 years from submission unless a longer period is required by law or an active dispute (see Retention);
- After a second safety rejection, related ticket data may be retained in anonymised or aggregated form for safety auditing.
6. Community app provisioning
Eligible guests (paid order, completed questionnaire, approved ticket) receive access to our community app at app.retraite-eveil.com. To enable this benefit we:
- Create or locate a community account using the guest email address and display name from the ticket;
- Assign membership to retreat-alumni and language-based groups matching your booking;
- Send you an email with first-login instructions (password recovery flow).
We do not set your community password from the shop. Login credentials for the community app are separate from your Website account.
Once provisioned, further processing inside the app (posts, direct messages, media uploads, push tokens) is governed by the community app's Privacy Policy. We encourage you to read it when you first sign in.
7. Retention periods
We keep data only as long as necessary for the purposes above:
- Account profile, until you delete your account, plus short technical backup cycles;
- Orders and invoices, typically 7–10 years for accounting and tax compliance;
- Health questionnaires - 3 years from submission (configurable operational standard);
- Refund records and payout proofs, for the duration of the transaction and applicable legal limitation periods;
- Partner application and profile data, for the life of the Partner relationship plus applicable limitation periods after rejection, suspension, or ban;
- Partner booking and dispute records, aligned with order/accounting retention;
- Contact form messages, as long as needed to resolve the enquiry, then archived or deleted;
- Analytics data, according to Google Analytics and Meta retention settings while consent is active;
- Anonymised transaction records, after account deletion, where law requires continued retention without personal identification.
8. Sharing and processors
We share data with trusted service providers who process it on our instructions and under appropriate safeguards:
- PayPal, payment processing;
- Hosting provider (FastComet) - Website and database hosting;
- Amazon Web Services (S3) and CloudFront, encrypted storage for private documents (ticket PDFs, refund proofs, backups) and media assets;
- Cloudflare - CDN, security, and Turnstile bot protection;
- Email delivery provider, transactional email;
- Google Analytics - Website usage statistics (with consent);
- Meta (Facebook) Pixel, conversion measurement (with consent);
- Community platform, limited guest profile data to provision app access as described above;
- Integration Partners, Client contact details necessary to deliver a booked Partner service (Partners must use this data only for that purpose);
- Accounting and professional advisers, where required for compliance;
- Public authorities, when legally obliged to disclose information.
We do not sell your personal data. We do not share health questionnaire content with other guests or the public.
9. International transfers
Some processors are located outside the European Economic Area (for example the United States). Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms approved under GDPR.
10. Security
We implement organisational and technical measures including:
- HTTPS encryption (TLS/SSL) across the Website;
- Hashed password storage;
- Role-based access to admin and questionnaire data;
- Private object storage for sensitive documents (tickets, refund proofs);
- Bot protection on authentication and contact forms.
No online system is completely secure. Please use a strong unique password and notify us promptly if you suspect unauthorised access.
11. Your rights
Under GDPR you have the right to:
- Access your personal data;
- Rectify inaccurate data (you can update much of your profile in your account);
- Erase data in certain circumstances;
- Restrict processing in certain circumstances;
- Data portability for data you provided, where technically feasible;
- Object to processing based on legitimate interests, including direct marketing;
- Withdraw consent where processing is consent-based (for example analytics cookies).
To exercise these rights, email [email protected]. We respond within one month unless complexity requires an extension permitted by law.
12. Account deletion and data export
From your account profile you may:
- Download a JSON export of personal data we hold about you (orders, tickets, messages, questionnaire answers including height, weight, and BMI, partner profile data if you are a partner, and affiliate account data if you are an affiliate);
- Delete your account through the guided deletion flow.
Account deletion removes your login access and identifiable profile. We retain anonymised transaction records where accounting, tax, or audit law requires. Community app accounts created for retreat access are managed separately; contact us if you also want community access removed.
13. Cookies and analytics
13.1 Essential cookies
We use strictly necessary cookies for session management, authentication, checkout, affiliate attribution, and security. These do not require consent.
13.2 Analytics and marketing cookies
With your consent (via our cookie banner), we load:
- Google Analytics (measurement ID configured in our production environment), aggregated traffic and conversion statistics;
- Meta Pixel, conversion tracking for advertising effectiveness.
Analytics scripts are deferred until you accept the cookie notice. You may refuse analytics cookies and still use the Website. You can also clear or block cookies in your browser settings.
13.3 Managing cookies
Browser help pages explain how to delete or block cookies. Useful starting points: Firefox, Chrome, Safari, and Microsoft Edge support documentation.
14. Children
Our services are for adults aged 18 and over only. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us and we will delete it.
When a medical clearance consult is required, we share relevant questionnaire answers and case messages with the assigned Medical Partner under our Medical Partner Terms and this Privacy Policy. Medical Partners must not use that data to recruit you for competing psychedelic programmes.
15. Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or service changes. The "Last updated" date at the top will change accordingly. Material changes may be communicated by email or a Website notice where appropriate.
16. Complaints to a supervisory authority
If you believe we process your data unlawfully, you may lodge a complaint with your local data-protection authority. As Damien Soitout Holdings is established in Cyprus, the lead supervisory authority is the Commissioner for Personal Data Protection (dataprotection.gov.cy). You may also complain to the authority in your EU country of residence.
17. Contact
Questions about this Privacy Policy or your personal data:
Damien Soitout Holdings (trading as Retraite Eveil) - Privacy
P.O. Box 21472
1599 Nicosia
Cyprus
Email: [email protected]
Phone: +33 6 14 37 57 01