Privacy Policy
Last updated: 8 October 2026
1. Who is responsible for your data?
The controller within the meaning of Article 4 No. 7 GDPR is:
Atlas Cove, Lda. is incorporated and registered in Portugal. We have not appointed a Data Protection Officer (DPO): under Article 37 GDPR a DPO is not mandatory at our current scale of processing, as our core activity does not consist of large-scale processing of special categories of data or large-scale, regular and systematic monitoring. The health-readiness answers we collect when you book a retreat are limited in scope and volume, and do not change that assessment. We keep it under review and will revisit it before the consumer health product launches, which will involve health data at a different scale.
2. Scope of this Privacy Policy
This Privacy Policy applies to the website atlascove.health and its sub-pages (the “Website”), including the retreat booking and payment flow that runs on it. Our retreats are bookable and payable here today. The Atlas Cove mobile and web application is a separate product that is not yet available to the public; a separate Consumer Health Data Privacy Policy and product Terms of Service will apply to it when it launches and will be linked from this page at that time.
3. What personal data we process and why
We process personal data only where we have a clear purpose and a valid legal basis under Article 6 (or, for special categories, Article 9) GDPR. The following sections describe each processing activity individually.
3.1 Server access logs
When you visit our Website, our servers automatically log the following technical data: shortened IP address, date and time of the request, the URL requested, HTTP status, referrer URL, user agent string. We use this data to operate, secure and troubleshoot our infrastructure.
Legal basis: Article 6 (1)(f) GDPR (legitimate interest in a secure, functioning service).
Retention: 30 days. IP addresses are redacted in our application logs by our logger (Pino).
3.2 Marketing-website analytics & advertising (consent-based)
On this marketing Website only, and only after you opt in via our consent banner, we use a small set of analytics and advertising tools to understand how the Website is used and to measure which of our advertisements lead to bookings:
- Google Analytics 4 (Google Ireland Ltd. / Google LLC) — to understand aggregate Website usage and support advertising measurement. Processes usage and device data, pseudonymous identifiers and your IP address.
- Google Ads (Google Ireland Ltd. / Google LLC) — to measure which of our advertisements lead to bookings (conversion measurement) and to support remarketing. This includes enhanced and offline conversions, for which we transmit hashed (irreversibly transformed) identifiers such as your email address or phone number; we do not share these in plain text.
- Meta Pixel and Conversions API (Meta Platforms Ireland Ltd.) — to measure the performance of our advertising on Facebook and Instagram (ad performance and conversion measurement). This likewise uses hashed identifiers (such as email or phone) for conversion matching. If you asked for information through Meta's own lead form on Facebook or Instagram, we report the later steps of your enquiry (call booked, invitation, booking) to Meta with the lead ID Meta gave your form entry and your hashed email and phone number, also without cookie consent: you gave these details to Meta in Meta's own lead form.
- PostHog (PostHog Inc., data hosted in its EU Cloud in Frankfurt) — to see how visitors move through the Website and where an application or booking is left unfinished. See the PostHog paragraph below.
- Google Tag Manager (Google Ireland Ltd. / Google LLC), which we run self-hosted (web and server-side) on our own EU infrastructure, as the container that loads the consented tools above and acts as a final filtering point for sensitive parameters.
Marketing-website only — no health data. These advertising and analytics tools run exclusively on the marketing Website ( atlascove.health). They are never loaded in the Atlas Cove product / application, and no health data and no special-category data (Article 9 GDPR) is ever sent to Google Analytics, Google Ads or Meta. The booking health questionnaire (PAR-Q), the assessment and the preparation page are excluded from all marketing tags; PostHog runs on the application and booking pages too, but it never receives an answer you type and records no clicks on the health questions (see the PostHog paragraph). The application page (/apply) loads the consented tags like any other page; your written answers on it are sent only to our own backend, never to a tag. Your health questionnaire and assessment answers stay on our own backend in France and never reach an analytics or advertising provider.
Legal basis: Article 6 (1)(a) GDPR (your consent) and Article 5 (3) of the ePrivacy Directive 2002/58/EC, as transposed in Portugal by Lei n.º 41/2004 (consent for the storage of and access to information on your device). We operate Google Consent Mode v2, so these tags only fire after consent. You can withdraw consent at any time via Cookie Settings. You can also use the providers' own opt-outs, including Google's Analytics opt-out and the advertising controls in your Google Ad settings and Meta ad preferences.
Transfers: Where personal data is transferred to the United States, we rely on the EU–US Data Privacy Framework (Google LLC and Meta Platforms, Inc. are certified) and Standard Contractual Clauses as a fallback.
Roles of the parties. For Google Analytics 4, Google acts as our processor under a data processing amendment (Article 28 GDPR). For Google Ads conversion data, Google and Atlas Cove act as independent controllers under Google's controller-to-controller data protection terms.
Joint controllership with Meta. For the data collected through the Meta Pixel and transmitted via the Conversions API, Meta Platforms Ireland Ltd. and Atlas Cove act as joint controllers within the meaning of Article 26 GDPR in respect of the collection and transmission of that event data. The essence of our joint arrangement follows Meta's Controller Addendum. Any further processing of that data by Meta for its own purposes takes place under Meta's sole responsibility. You may exercise your data subject rights against either party.
Retention: Google Analytics 4 user- and event-level data is configured for a 14-month retention period; advertising and conversion data is retained by Google and Meta in line with their own published retention policies. The campaign-attribution fields we store with your contact record (see section 3.3) follow the retention periods set out there.
PostHog (website analytics and session recordings). Only after you allow “PostHog Analytics” in our consent banner, we use PostHog to record page views, the steps of the application and booking flow, screen recordings of your visit, and your clicks: which buttons and links you click, where on a page you click and scroll (heatmaps) and clicks that lead nowhere. For a click we store the element and its visible label, never what you typed. The health questions, health notes, dietary needs and the details of a second guest are excluded from click capture entirely, and no click is recorded on the booking confirmation and management pages. In these recordings every form entry and all text on the page are hidden in your browser before anything is sent, so no answer you type, including the health questionnaire on the application and booking pages, ever reaches PostHog. Recordings are switched off completely on the booking confirmation and management pages and on e-mail confirmation and unsubscribe links. Web addresses are cut down to the page itself and its campaign parameters, so tokens, codes and booking numbers in a link are never sent. PostHog does not run at all in our back office, on the assessment, preparation and report pages, or in the Atlas Cove app. When you send an application or pay a booking, the events (for a payment, with the amount paid in euros) are linked to your application or booking number, never to your name or e-mail address.
Legal basis: Article 6 (1)(a) GDPR (your consent) and Article 5 (3) of the ePrivacy Directive 2002/58/EC, as transposed in Portugal by Lei n.º 41/2004. You can withdraw it at any time via Cookie Settings; PostHog then stops immediately.
Processor and transfers: PostHog Inc. acts as our processor under a data processing agreement (Article 28 GDPR). The data is stored in PostHog's EU Cloud (Frankfurt); any access from outside the EU is covered by the Standard Contractual Clauses in that agreement.
Retention: screen recordings 30 days; event data for the retention period of our PostHog plan, and deleted earlier on request.
Advertising audiences (Custom Audiences). To show relevant ads to people who have consented to our marketing, we share a hashed (SHA-256) version of your email address, never in plain text, with Meta Platforms Ireland Ltd. for its Custom Audiences feature. Meta matches the hashed data against its own users to build a target audience for our ads; non-matching data is discarded. We and Meta act as joint controllers for this processing under our joint controller arrangement.
Legal basis: Article 6 (1)(a) GDPR (your consent), which you give by subscribing to our mailing list. You can withdraw at any time by unsubscribing from our e-mails, which automatically removes you from the audience, and you can additionally opt out via your Meta ad settings. We never use health-related data to build or define these audiences.
3.3 Waitlist, newsletter and contact forms
When you fill in one of our forms, we process the data you provide for the specific purpose described on each form:
- Waitlist: first name, last name, e-mail address, city, country, planned stay length. Used to register your interest, keep you informed about programme availability and contact you when a relevant slot opens. You receive a double opt-in confirmation e-mail; we only process your data after you have confirmed.
Legal basis: Article 6 (1)(a) GDPR (your consent).
Retention: Until you withdraw consent or after 24 months of inactivity, whichever is earlier. - Newsletter: e-mail address. Used to send you our newsletter. You receive a double opt-in confirmation e-mail; we only send the newsletter after you have confirmed. Each newsletter contains a one-click unsubscribe link (RFC 8058 compliant).
Legal basis: Article 6 (1)(a) GDPR (your consent).
Retention: Until you unsubscribe. - Contact / inquiry: name, e-mail address, chosen recipient and message content. Used to respond to your enquiry and to follow up where appropriate.
Legal basis: Article 6 (1)(b) GDPR (steps prior to a possible contract) and Article 6 (1)(f) GDPR (legitimate interest in handling enquiries).
Retention: 24 months after last contact, longer if a contractual or legal retention obligation arises. - Application: name, e-mail address, phone number, how you want us to reach you (e-mail or WhatsApp), the cohort you are interested in, and your free-text answer to what motivates you to apply. Used to assess whether a programme is a fit for you and to get back to you. The phone number is required, because the fit call that follows an application is a phone or video conversation and we would otherwise have to write to you to ask for it. It is stored encrypted, and we use it to reach you about your fit call and your stay, and for WhatsApp messages only if you chose WhatsApp. We do not use it for marketing calls or marketing messages. Confirmations and invoices always come by e-mail, whichever channel you choose.
Your free-text answer may touch on your health. It is encrypted in our own database and also stored with your contact record in our CRM (ActiveCampaign), so that the team preparing your fit call can read it. It is never passed to our scheduling tool, our advertising tools or any other third party. Our CRM also receives your name, e-mail address, phone number, your chosen channel and the non-free-text answers.
Legal basis: Article 6 (1)(b) GDPR (steps taken at your request prior to a possible contract). Where your free-text answer contains health data, Article 9 (2)(a) GDPR (your explicit consent, given by choosing to write it).
Retention: 24 months after last contact, longer if a contractual or legal retention obligation arises.
Referral and campaign data. When you submit a form, we also record the marketing source that brought you to the Website: the campaign parameters (UTM) of the link you arrived on, the referring website, and the page you first landed on. This is stored with your contact record. It is first-party data captured as part of your submission, sets no additional cookies, and is not shared with third parties.
Legal basis: Article 6 (1)(f) GDPR (legitimate interest in understanding which channels our contacts come from).
All forms include a hidden honeypot field for bot protection. Submissions identified as automated are discarded without storing personal data.
3.4 Error tracking (Sentry)
We use Sentry (Sentry GmbH, EU hosting at de.sentry.io) to detect and diagnose errors. Sentry receives technical error information, limited request metadata and stack traces. Sensitive request data and any health-related data are scrubbed before transmission via configured PII redaction.
Legal basis: Article 6 (1)(f) GDPR (legitimate interest in operating a stable, secure service).
Retention: 90 days (Sentry default retention).
3.5 Cookie consent management (Klaro, self-hosted)
When you interact with our cookie banner, your decision is stored in a first-party cookie called klaro-consent. This is required to remember your choice and demonstrate compliance.
Legal basis: Article 6 (1)(c) GDPR (legal obligation to evidence consent decisions) and Article 5 (3) of the ePrivacy Directive 2002/58/EC, as transposed in Portugal by Lei n.º 41/2004 (storage strictly necessary to provide the consent service you expressly requested by using the banner).
Retention: 365 days.
3.6 Writing to us on WhatsApp
Our WhatsApp links are plain hyperlinks with rel="noopener noreferrer"; we do not embed any Meta scripts, pixels or widgets on our Website. When you write to us on WhatsApp, the conversation runs through the WhatsApp Business Platform of Meta Platforms Ireland Ltd. and is stored with your contact record in our CRM (ActiveCampaign, see section 4). We use it to answer you and, if you chose WhatsApp as your channel, to send reminders about your application and your stay. Anything you choose to tell us in a chat, including details about your health, is stored there too; please use the health questionnaire for health details instead.
To answer common questions quickly, an automated assistant may reply to you. For that purpose the text of your message and our own reference material (our published FAQ, our retreat dates and our fact register) are sent to Google Ireland Ltd. (Gemini API), which processes them on our instructions. The assistant answers only from that reference material. Messages about health, payments, refunds or complaints, and anything the assistant cannot answer with certainty, are never passed to it: they go straight to a member of our team. You can ask for a person at any time by writing "human".
Legal basis: Article 6 (1)(b) GDPR (steps prior to and performance of a contract). Where you share health details in a chat, Article 9 (2)(a) GDPR (your explicit consent, given by choosing to write them). For the automated assistant, Article 6 (1)(f) GDPR (our legitimate interest in answering enquiries promptly); you can object at any time by writing to hello@atlascove.health.
Retention: 24 months after last contact, longer if a contractual or legal retention obligation arises.
WhatsApp itself is operated by Meta Platforms Ireland Ltd., and that company's privacy policy applies to your use of WhatsApp. WhatsApp is voluntary; you can choose e-mail instead everywhere on our service.
3.7 Booking a fit call
Every application includes a free 20-minute fit call with a member of our team: after you send the application form, you choose a time in our scheduling calendar, and your application is complete once a time is booked. If you book a retreat without applying first, you book the same call after your booking. When you book, we process your name, e-mail address, telephone number, the time slot you choose and your time zone.
The scheduling tool is Calendly (Calendly, LLC, USA), embedded on our Website. Calendly receives exactly those booking details and nothing else. It processes them in the United States as our processor under its data processing addendum; the transfer relies on Calendly’s certification under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. The calendar only loads when you open it.
Two further things happen when you book:
- Google Calendar and Google Meet (Google Ireland Ltd., Dublin) — the appointment is created in our team calendar and you receive the calendar invitation with the video link. Your name, e-mail address and the time slot are therefore visible to Google. This runs under our Google Workspace data processing agreement.
- Call notes: during the call, Google Meet’s note-taking feature (part of our Google Workspace) writes a summary of the conversation. We keep that summary with your application in our CRM (ActiveCampaign), so that the team member who follows up knows what was discussed. It never decides the outcome of your application; a member of our team does.
- Our own backend (OVHcloud, France) reads the booked time from Calendly, marks your application as complete and sends you the confirmation e-mail.
We also record in our CRM (ActiveCampaign) that a call is booked and for when, so we do not chase you about a call you already scheduled, together with the call summary described above.
The free-text answer from your application is never sent to the scheduling tool or to Google. The booking flow only ever receives your name, e-mail address and telephone number.
Legal basis: Article 6 (1)(b) GDPR — you are asking us for a call, so the processing is a step taken at your request prior to a possible contract. For noting the booking status in our CRM we also rely on Article 6 (1)(f) GDPR (legitimate interest in a coherent record of our conversations with you).
Retention: If you send the application form but do not book a call, we keep the unfinished application for 90 days and then delete it. Booking records and call summaries are kept for 24 months after the appointment and the calendar entry is removed with them; if you book a retreat, the summary is kept with your guest record. The booking status stored with your contact record follows the retention period for that record.
Your options: The calendar invitation lets you reschedule or cancel. Cancelling removes the appointment; the fact that a call had been booked remains in our CRM until your contact record is deleted.
3.8 Booking and paying for a retreat
When you book a retreat we process the data you enter in the booking form: your first and last name, e-mail address, telephone number, your billing address, the name of a second guest if you book a shared room, dietary requirements, the name and telephone number of an emergency contact, any special requests, and any discount code you use. You can add a tax number if you want one on your invoice; it is optional and we do not ask for it otherwise. We also record which retreat and room category you booked, the price, and the IP address the booking was sent from (as a safeguard against abuse).
The booking form also asks a short set of health-readiness questions (PAR-Q). Those are health data under Article 9 GDPR and are described in section 7 below. They are never passed to our CRM, our e-mail tool, our analytics or our advertising providers.
Payment is handled by Mollie (see section 4.5). We never see or store your card details. We store the payment reference Mollie returns to us, together with the amount and the payment status, so we can reconcile your booking.
Booking records are stored on our own infrastructure in France. Direct identifiers and free-text fields are encrypted at field level in the database. Your name, e-mail address and the status of your booking (retreat, room, add-ons, payment status, invoice numbers and the status of your preparation) are also recorded in our CRM (ActiveCampaign) so that we can correspond with you about your stay; your answers to the health questions are not included. Receipts, reminders and preparation e-mails are delivered by Postmark (see section 4.2). Invoices are issued by Moloni (see section 4.5), which also reports them to the Portuguese tax authority, as the law requires.
Legal basis: Article 6 (1)(b) GDPR — the processing is necessary to perform the booking contract with you. For the billing address, the tax number and the payment and accounting records we rely on Article 6 (1)(c) GDPR: Portuguese law requires a full invoice for amounts of this size, and a full invoice requires those details. For the health-readiness answers we rely on your explicit consent under Article 9 (2)(a) GDPR, which you give separately in the form.
Retention: Data that forms part of an accounting record — the booking, the amounts and the payment reference — is kept for the statutory Portuguese retention period of ten years. The health-readiness answers, dietary requirements, special requests and emergency contact are deleted within twelve months of the end of your stay, as they serve no purpose after it.
Your options: You can withdraw your consent to the health-readiness answers at any time by writing to us, and we will delete them. Because we need them to run the retreat safely, withdrawing consent before your stay may mean we cannot host you. Withdrawal does not affect the lawfulness of processing before it, and it does not reach the accounting record, which we are required by law to keep.
3.9 Preparing your stay
Before your retreat we send you a personal link to a preparation page. There you tell us your flight and arrival time, food preferences, any allergies and intolerances, your sizes for the items we prepare for you, and an emergency contact. These answers are stored only on our own infrastructure in France. Our CRM only learns whether the page is still open or has been sent, so that we remind you on your chosen channel and stop once you are done.
Legal basis: Article 6 (1)(b) GDPR (performance of the booking contract). Allergies and intolerances are health data; the fields are optional, and for them we rely on Article 9 (2)(a) GDPR (your explicit consent, given by entering them).
Retention: as for the dietary requirements and the emergency contact in section 3.8.
3.10 After your stay, and follow-up messages
On your last day we ask you to fill in a short survey, including a score from 0 to 10 for your stay. We keep your answers with your guest record and note the score in our CRM, so that we reply in the right way. About a month after your stay we invite you to a short re-assessment and send you your progress report; both are health data and follow section 7. If you enjoyed your stay, we may send you a personal Lifetime Member code, a one-time link to pass on to a friend, and a link to leave a review on Google; a review is published by Google under its own terms.
If you applied, held an invitation or booked and did not continue, we write to you a small number of times about it, for example to offer a new time for your fit call or to tell you about future dates. You can object at any time by replying or using the unsubscribe link.
Legal basis: Article 6 (1)(b) GDPR for the survey, re-assessment and report that are part of your stay; Article 6 (1)(f) GDPR (our legitimate interest in looking after our guests and applicants) for the member code, referral link, review request and follow-up messages.
4. Service providers and processors
We work with the following service providers. Where they process personal data on our behalf, they do so under a Data Processing Agreement (DPA) pursuant to Article 28 GDPR.
4.1 Hosting and infrastructure
- OVHcloud (OVH SAS, 2 rue Kellermann, 59100 Roubaix, France) hosts our primary infrastructure including database, application servers and self-hosted tools, in ISO 27001 certified data centres in France. All of it sits inside the EU.
- Our workflow, messaging and monitoring tools run on that same infrastructure, operated by us. They are not third-party services and no external provider receives your data through them.
- Until 24 July 2026 the same infrastructure was hosted by Hetzner Online GmbH (Gunzenhausen, Germany), also inside the EU. Data processed before that date was held there.
4.2 Communication and customer relationship
- Postmark (AC PM LLC, USA, part of the ActiveCampaign group) delivers our transactional e-mails: confirmations, receipts, reminders and preparation e-mails. It receives your name, e-mail address and the content of those e-mails, never answers from our health questionnaire. We do not track whether you open these e-mails or click their links. Transfers to the USA rely on the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.
- ActiveCampaign (ActiveCampaign, LLC, Chicago, USA) is our CRM and marketing-automation platform. It stores contact, lead and engagement data (name, e-mail, phone, chosen channel, tags, lifecycle stage, e-mail open / click metadata, the status of your application or booking), our WhatsApp conversations (section 3.6) and the summaries of fit calls (section 3.7). It does not receive the answers from our health questionnaire or assessments. It does receive free text you write yourself (your application answer, WhatsApp messages) and the summary of a call you had with us. Transfers to the USA rely on ActiveCampaign’s certification under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.
- Google Calendar and Google Meet (Google Ireland Ltd., Dublin) are used only when you book a fit call with us: the appointment is created in our team calendar, you are invited, and the video link is generated. Google therefore receives your name, e-mail address and the time slot, and, through the Meet note-taking feature, the content of the call. See section 3.7.
- Calendly (Calendly, LLC, USA) is our fit-call scheduling tool. It receives your name, e-mail address, telephone number, time zone and the chosen time slot, and does not receive any health data or your application answer. Transfers to the USA rely on Calendly’s certification under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. See section 3.7.
4.3 Operations and observability
- Sentry (Sentry GmbH, EU hosting at
de.sentry.io) for error tracking. Health data scrubbing is configured. - Google (Analytics 4, Ads, Tag Manager) (Google Ireland Ltd., Dublin / Google LLC, USA) — consent-based analytics and advertising on this marketing Website only. Google Tag Manager is run self-hosted on our own EU infrastructure. These tools never run in the product and never receive health data. See section 3.2.
- Meta (Pixel and Conversions API) (Meta Platforms Ireland Ltd.) — consent-based advertising conversion measurement on this marketing Website only; for the pixel/CAPI event data we and Meta act as joint controllers (Article 26 GDPR, see section 3.2). Never runs in the product and never receives health data.
- n8n, ntfy, Keycloak, LiveKit, Ollama / Meditron, Grafana / Prometheus / Loki, and Uptime Kuma are all self-hosted on our own EU infrastructure. They are not third-party processors.
4.4 Analytics in the Atlas Cove app
The Atlas Cove app (app.atlascove.health) does not use PostHog or any other analytics tool. PostHog runs only on this Website, and only after your consent, as described in the PostHog paragraph above.
4.5 Payments
Mollie (Mollie B.V., Amsterdam, Netherlands) is our payment processor for retreat bookings made on this Website. When you pay, you are taken to Mollie’s own secure checkout. Mollie receives your name, e-mail address, the amount and a reference to your booking, and processes the payment details you enter there. Those payment details are never transmitted to or stored by us. Mollie acts as an independent controller for the parts of the payment it is legally required to handle itself. Depending on your device, country and the amount, the methods offered may include credit or debit card, PayPal, iDEAL, Bancontact, EPS, SEPA bank transfer, Pay by Bank, and Apple Pay or Google Pay.
For the balance payment, and for the full payment if you book within 45 days of the start, Mollie also offers Klarna (Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden) where Klarna is available in your country. The deposit is never paid through Klarna.
If you choose Klarna, Klarna is an independent controller of the data you give it, not our processor: the credit agreement is between you and Klarna, and Klarna decides on its own whether to accept the payment, which may involve a credit assessment. To make the option appear at all, we pass Mollie your name, e-mail address, billing address and the amount, and Mollie passes them to Klarna. Klarna processes them under its own privacy notice, which we do not control. If you pay by any other method, no data reaches Klarna.
If you pay with PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg), PayPal is likewise an independent controller: the payment runs inside your PayPal account under its own privacy statement, which we do not control. Mollie passes PayPal the amount and a payment reference; your PayPal login and funding details stay with PayPal. If you pay by any other method, no data reaches PayPal.
Legal basis: Article 6 (1)(b) GDPR (performance of the booking contract) and Article 6 (1)(c) GDPR (statutory accounting and tax obligations in Portugal).
Moloni (Moloni Unipessoal, Lda, Portugal) is our certified invoicing provider. It receives your name, e-mail address, billing address, tax number (if you give one), the amount and the date, issues your invoice and reports it to the Portuguese tax authority. Invoices are kept for ten years, as Portuguese tax law requires.
Legal basis: Article 6 (1)(c) GDPR (statutory invoicing and tax obligations in Portugal).
4.6 Internal tooling
- Google Workspace (Google Ireland Ltd.) for team e-mail, calendar and documents. Customer correspondence passes through this system, and it holds the fit-call appointments and call summaries described in section 3.7. The WhatsApp assistant uses the Gemini API of Google Ireland Ltd. (section 3.6).
- GitHub (GitHub Inc., USA) for source code hosting. No personal data of website visitors is stored in repositories.
5. International data transfers
Most processing takes place inside the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on the following mechanisms under Chapter V GDPR:
| Recipient | Country | Transfer mechanism |
|---|---|---|
| Postmark (transactional e-mails) | USA | EU-US Data Privacy Framework, Standard Contractual Clauses as fallback. No questionnaire or assessment answers. |
| Google Gemini API (only if you write to us on WhatsApp) | Ireland / worldwide | Google’s data processing terms (EU-US Data Privacy Framework, Standard Contractual Clauses). Message text only; messages about health are never passed to it. |
| ActiveCampaign | USA | EU-US Data Privacy Framework certification, Standard Contractual Clauses as fallback. No questionnaire or assessment answers. |
| Meta Platforms Ireland Ltd. (only if you write to us on WhatsApp; through ActiveCampaign, our WhatsApp provider) | Ireland / USA | Your active choice and Meta's Standard Contractual Clauses. |
| Google Workspace | Ireland / USA | Standard Contractual Clauses. |
| Calendly (fit-call scheduling) | USA | EU-US Data Privacy Framework certification, Standard Contractual Clauses as fallback. Name, e-mail address, telephone number, time zone and time slot only. No health data. |
| Google Calendar / Google Meet (only if you book a fit call) | Ireland / USA | Standard Contractual Clauses under our Google Workspace agreement. Name, e-mail address, time slot and the call summary (section 3.7). |
| Google Analytics 4 / Google Ads / Google Tag Manager (only if you consent, marketing Website only) | Ireland / USA | EU–US Data Privacy Framework (Google LLC certified) and Standard Contractual Clauses as fallback. |
| Meta Pixel / Conversions API (only if you consent, marketing Website only) | Ireland / USA | EU–US Data Privacy Framework (Meta Platforms, Inc. certified) and Standard Contractual Clauses as fallback. |
| Meta Custom Audiences (only consented marketing contacts) | Ireland / USA | EU–US Data Privacy Framework (Meta Platforms, Inc. certified) and Standard Contractual Clauses as fallback. Only hashed (SHA-256) e-mail; no health data. |
| GitHub | USA | Standard Contractual Clauses. No personal data of Website visitors is stored. |
You can request a copy of the safeguards in place for any transfer by writing to privacy (at) atlascove (dot) health.
6. Cookies and similar technologies
For details on which cookies and storage technologies we use and how you can control them, please see our separate Cookie Policy.
7. Health data (special categories)
The Website collects health-related data (a special category under Article 9 GDPR) in three places: the retreat booking readiness screen (PAR-Q), the pre-arrival assessment and re-assessment, and the allergies and intolerances on the preparation page (section 3.9). They are processed on the basis of your explicit consent under Article 9 (2)(a) GDPR and kept on our own infrastructure in France. Your answers are not shared with our CRM, e-mail tools, analytics or advertising providers. Full details are set out in our separate Consumer Health Data Privacy Notice. Beyond these touchpoints, the Website does not collect health data. The future Atlas Cove product will process health data more extensively; when it launches, the following principles will apply and will be detailed in its own privacy notice:
- Health data is processed only on the basis of your explicit consent under Article 9 (2)(a) GDPR, captured in a separate, granular consent flow.
- Health data never leaves our own infrastructure in France. It is not shared with our CRM, our e-mail provider, our website analytics or any other third-party tool.
- AI analysis of health data is performed locally on self-hosted models (Ollama / Meditron). No cloud AI provider receives your data.
- You can withdraw consent for health data processing at any time, with the effect that the corresponding data is deleted.
8. Health disclaimer
Editorial content on this Website (including community pages, programme descriptions, blog posts and member stories) is for general information only. It does not constitute medical, diagnostic or therapeutic advice and is not a substitute for consultation with a qualified healthcare professional. We do not offer or provide medical services through this Website. If you are dealing with a health condition or considering changes to your health, please seek individual advice from a qualified professional.
9. Your rights as a data subject
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Article 15) — confirmation whether we process your data and a copy of that data.
- Right to rectification (Article 16) — correction of inaccurate or incomplete data.
- Right to erasure (Article 17) — deletion of your data, subject to lawful retention requirements.
- Right to restriction (Article 18) of processing under specific circumstances.
- Right to data portability (Article 20) for data you provided based on consent or contract.
- Right to object (Article 21) to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent (Article 7 (3)) at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint (Article 77) with a supervisory authority. The competent authority for us is the Comissão Nacional de Proteção de Dados (CNPD) in Lisbon, Portugal.
To exercise any of these rights, please contact us at privacy (at) atlascove (dot) health. We will respond within one month, which may be extended by two further months for complex requests.
10. Security measures
We implement technical and organisational measures (TOMs) under Article 32 GDPR to protect your data, including: TLS encryption in transit (Let's Encrypt managed via Traefik), secure authentication via Keycloak with SSO, role- based access control, server hardening within OVHcloud's ISO 27001 certified data centres in France, structured logging with PII redaction (Pino), error monitoring with health-data scrubbing (Sentry) and regular backup procedures. Direct identifiers and free-text fields in our booking, contact and health-readiness records are additionally encrypted at field level in the database, so that database access alone does not reveal them. The wider field-level encryption scheme for the consumer health product, which will process health data at a different scale, is being built alongside that product.
11. Retention periods
We keep personal data only as long as necessary for the purposes described in this policy or as required by law. The specific retention periods for each processing activity are listed in section 3 above.
12. Automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or significantly affects you in a similar way (Article 22 GDPR).
13. Minors
Our Website and future product are intended for adults only. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us so we can delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when we add or remove tools, when our processing activities change, or when legal requirements change. The latest version is always available at this URL with the update date shown at the top.
15. Contact
For all questions about this Privacy Policy or our data handling, please contact us at privacy (at) atlascove (dot) health. Full operator details are available in the Imprint.