Privacy Policy
Last updated: 3 September 2026
Data controller
Júlia Gabrielle Cristina Gomes de Abreu, tax number 303268522, Rua de Nossa Senhora de Lourdes 7, 2495-422 Fátima, Portugal. Contact for data protection matters: info@soulifyoga.com.
We have not appointed a data protection officer, as none of the situations requiring one apply. Requests are handled directly by the business owner.
What data we process
Purchase: email, your name when you give it, country, plan bought, amount, payment session identifier and the last four digits of the card that Stripe returns to us. We never receive the full card number or the security code.
Invoicing: name, address and tax number when you provide them for the invoice.
Customer support: the content of the messages you send us and the email address you write from.
Lesson access: the signed proof stored in your browser. We do not record which lessons you watched or when.
Browsing: IP address, device type, browser and pages visited, in the hosting provider's technical logs.
Why we use the data and on what basis
To deliver access to the course and perform the purchase contract. Basis: performance of a contract.
To issue an invoice and meet tax and record keeping obligations. Basis: legal obligation.
To answer customer support and handle refunds. Basis: performance of a contract.
To prevent payment fraud and misuse of access. Basis: legitimate interest.
To measure site audience, if and when we turn that on. Basis: your consent, given in the cookie notice and withdrawable at any time.
What we do not do
We do not sell, rent or pass your data to third parties for commercial purposes.
We do not send marketing email without your consent. The emails you get are the purchase and access ones.
We do not profile you to set prices or to target advertising.
Who processes data on our behalf
Stripe Payments Europe, Ltd. (Ireland): payment processing and fraud prevention. Stripe is also a controller for its own processing, under its own policy.
Vercel Inc. (United States): site hosting and running the functions that validate access.
Resend (United States): sending the access and purchase confirmation email.
These providers only process data to provide the service to us and are bound by a data processing agreement.
Transfers outside the European Union
Vercel and Resend are based in the United States. Transfers rely on the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, on the EU-US Data Privacy Framework.
The site's fonts are served from this domain. Normal browsing makes no requests to third party servers, so your IP address does not leave here before consent exists.
How long we keep data
Invoicing and purchase data: ten years, as tax law requires.
Support messages: two years after the last contact.
Technical browsing logs: up to twelve months.
Access proof in your browser: one year, renewed when you come back. You can delete it in your browser settings.
Your rights
You may request access to your data, correction, erasure, restriction of processing, portability, and object to processing based on legitimate interest. You may also withdraw consent for audience measurement, without affecting what was done before.
Write to info@soulifyoga.com. We reply within one month. We only ask for what is needed to confirm you are the data subject.
If you believe your data is not handled properly you may complain to the Portuguese data protection authority CNPD at www.cnpd.pt, or to the authority in your country of residence.
Security
The site is served over HTTPS only. Payment details are entered directly on a Stripe page and never pass through our servers.
The access proof is cryptographically signed and cannot be altered without invalidating the signature.
If a data breach poses a risk to your rights we notify the authority within 72 hours and notify you directly where the risk is high.
Minors
The course is for people aged 18 and over and we do not knowingly collect data from minors. If you know a minor has given us data, write to info@soulifyoga.com and we will delete it.
Automated decisions
We do not make automated decisions with legal effects about you. Stripe may apply automatic anti fraud rules when authorising a payment; if a payment is declined that way, write to us and we will handle it manually.
Changes to this policy
If we change this policy we update the date at the top. Material changes are emailed to people who have already bought.