Effective date: 16 August 2026
This policy explains what personal data Soulful Solutions collects, why, what we do with it, and what you can require of us. It is written to be read, not to be survived.
Soulful Solutions S.A.C.S., RUC 20615502422, Mza. S Lote 6 Int. 101, Asoc. Pro. Parque Industrial El Asesor, Ate District, Lima Province, Lima Department, Peru, is the data controller.
Questions, requests, or complaints: jordy@soulfulsolutions.co.
We are established in Peru and comply with Peruvian data protection law (Ley N° 29733 and its regulations). Because we offer services to people in the European Union, we also comply with the EU General Data Protection Regulation (GDPR) in respect of those visitors and customers, and the rights described below are granted to everyone regardless of where they live.
When you subscribe to a free resource — such as our newsletter, a mini-course, a quiz, or a downloadable guide — we collect your first name and email address, and, where the resource is a quiz, your answers and the result. We use this to deliver what you asked for and to send related emails about our work. Legal basis: consent, which you give by submitting the form and can withdraw at any time.
When you buy something we collect your name, email address, billing address and country, purchase history, and the payment confirmation returned by our payment provider. We use this to deliver what you bought, provide support, and meet our tax and accounting obligations. Legal basis: performance of a contract, and legal obligation for the accounting records.
We never see or store your full card number. Card details are entered directly with our payment provider, which is PCI-DSS compliant. We receive only a confirmation, the last four digits, and the card type.
When you book a retreat or private retreat we additionally collect, through an intake form and your clarity call, information about your health, dietary requirements, emergency contact, and travel details. Health and dietary information is special-category data. We collect it only to keep you safe and to adapt the programme, we ask for it only when you have chosen to proceed with a booking, and we process it on the basis of your explicit consent. We do not use it for marketing, ever. It is shared only with the facilitators and venue staff who need it for your safety, and it is deleted 12 months after the retreat ends unless you ask us to keep it for a future booking.
When you take a one-to-one session we may keep brief session notes to give you continuity between sessions. These are private, are never shared, and you may ask to see or delete them at any time.
When you attend a retreat or in-person event we may take photographs or film, which we sometimes use to describe our work publicly. We ask for your consent first, on the basis of that consent alone, and you can decline or withdraw it at any time without it affecting your participation. Ceremonial and other sensitive parts of the programme are not recorded.
When you visit the website we collect standard technical data — IP address, browser and device type, pages viewed, referring page — through our website platform and, if you consent, analytics cookies. Legal basis: legitimate interest in operating and improving the site, and consent for non-essential cookies.
Essential cookies keep the site working — your session, your cart, your cookie choice. These run without consent because the site cannot function without them.
Non-essential cookies (analytics, and any embedded media that sets them) run only if you accept them. You can change your mind at any time by clearing cookies for this site and choosing again. Declining costs you nothing: every part of the site works either way.
We share personal data only with service providers who need it to run the business, and only for that purpose. Each is bound by contract to protect it:
| Who | What for |
|---|---|
| Simplero | Website, email, course delivery, customer records |
| Our payment providers | Processing payments and refunds |
| Retreat venue and co-facilitators | Accommodation, dietary and safety needs — retreat bookings only |
| Accounting and tax advisers | Statutory record-keeping |
We do not sell your personal data. We do not rent it, trade it, or share it with advertisers.
We may disclose data if legally required to do so, or to establish or defend a legal claim.
Our suppliers may store data outside your country, including in the United States and the European Union. Where data of EU residents is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard. You may request details of the safeguard applying to a specific transfer.
| Data | Retained for |
|---|---|
| Newsletter and free-resource subscribers | Until you unsubscribe, then deleted within 30 days |
| Customer and purchase records | 10 years, as required for tax and accounting |
| Course access and progress | As long as your access lasts, plus 12 months |
| Retreat health and dietary intake | 12 months after the retreat, unless you ask otherwise |
| Session notes | 24 months after your last session, or until you ask us to delete them |
| Website technical logs | Up to 14 months |
You may at any time:
Write to jordy@soulfulsolutions.co. We will respond within 30 days. We do not charge for this, and we will never make you justify the request.
If you believe we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: INDECOPI / Autoridad Nacional de Protección de Datos Personales in Peru, or the data protection authority of your country of residence if you are in the EU.
Our services are for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
We protect your data with encrypted connections (HTTPS across the whole site), access controls limiting who can see customer records, and reputable suppliers who maintain their own security standards. No system is perfectly secure, but if a breach ever affects your rights we will notify you and the relevant authority without undue delay, as the law requires.
If we change this policy we will update the date at the top. For any change that materially affects your rights, we will email everyone on our list rather than quietly editing the page.