Privacy Policy
Last updated: 15 September 2026
Your privacy matters to us. This Privacy Policy explains what personal data we collect, for what purposes, on what legal basis, and what your rights are. We process data in accordance with the General Data Protection Regulation (GDPR) and the Croatian Act implementing the GDPR (NN 42/2018).
1. Who is the controller
The controller of your personal data is:
Anahata House of Soul, Jelena Krajina „ANAHATA, obrt za edukaciju u prakticiranju joge, vl. Jelena Krajina” Address: Krležina ulica 37, 52100 Pula, Croatia Email: anahatahouseofsoul@gmail.com
For any question about data protection, write to the address above.
2. What data we collect
a) Data you give us:
- An enquiry or booking through the web form: name, email address, phone number, the practice you selected, your answers to the form’s questions (for example format and time of day, number of people, experience with yoga, company name), and the content of your message.
- Newsletter subscription: email address.
- Instagram and automated messages (for example when you comment a keyword and receive a direct message): your Instagram username or ID, name, email address if you provide one, and your answers and choices within the conversation.
- Arranging and attending a class: the data needed to arrange a time and, if you choose to share them, health notes relevant to guiding your practice safely (for example injuries or pregnancy). We process such data only with your explicit consent and only for your safety.
b) Data collected automatically:
- Basic technical data required to deliver the site (IP address, browser type), processed by our provider for security and abuse prevention.
- Aggregate, anonymous traffic statistics. We do not use cookies for analytics or advertising (see section 10).
3. Purposes and legal bases
- Answering enquiries and arranging sessions: steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR).
- Sending the newsletter (tips, recipes, announcements): your consent (Art. 6(1)(a)). You may withdraw consent at any time.
- Providing services, bookings and payment: performance of a contract (Art. 6(1)(b)) and compliance with legal accounting obligations (Art. 6(1)(c)).
- Health notes for safely guiding practice: your explicit consent (Art. 9(2)(a)).
- Protecting the web form against automated abuse: our legitimate interest in preventing spam and misuse (Art. 6(1)(f)).
4. Recipients and processors
To provide these services we use trusted third parties who process data on our behalf and on our instructions:
- Cloudflare, Inc.: hosting and delivery of the website, abuse protection, and anonymous traffic statistics.
- Brevo (Sendinblue SAS, France): delivery of messages sent through the web form, and newsletter sending.
- Meta Platforms (Instagram): communication and messaging via Instagram.
- ManyChat, Inc.: automation of Instagram messages and storage of contacts collected through those conversations.
- Google (Gmail): receiving email correspondence.
We do not sell your data to third parties and do not use it for purposes not described in this Policy. Form content is not stored on the website; the message is forwarded by email and removed from the delivery service according to that provider’s retention rules.
5. Transfers outside the EEA
Brevo processes data within the European Union. Cloudflare, Meta and ManyChat may process data outside the European Economic Area, typically in the United States. Where they do, the transfer relies on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and/or participation in the EU–US Data Privacy Framework.
6. How long we keep data
- Newsletter: until you unsubscribe or withdraw consent.
- Enquiries and contact: for as long as needed to reply and, where relevant, to begin working together.
- Data relating to paid services: in line with tax and accounting rules (generally up to 11 years).
Once the purpose ends, we delete or anonymise the data.
7. Your rights
At any time you have the right to:
- access your data,
- rectify inaccurate data,
- erasure (the “right to be forgotten”),
- restriction of processing,
- object to processing,
- data portability,
- withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
Send requests to anahatahouseofsoul@gmail.com. We respond without undue delay and within the period the GDPR prescribes.
Unsubscribing from the newsletter: use the “Unsubscribe” link at the foot of every newsletter, or email us.
8. Right to lodge a complaint
If you believe we are processing your data unlawfully, you may lodge a complaint with the supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia, azop.hr.
9. Data security
We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, alteration or misuse. The site is served only over an encrypted connection (HTTPS), and the forms are protected against automated abuse.
10. Cookies
This website sets no cookies. We use no cookie-based analytics and no advertising or cross-site tracking cookies. The traffic statistics we use are aggregate and anonymous and cannot identify an individual visitor. That is why there is no cookie notice on this site: there is nothing to consent to.
The form’s bot protection (Cloudflare Turnstile) sets no advertising cookies and does not track you across sites.
11. Children
The services and the newsletter are intended for adults. We do not knowingly collect data from children under 16 without the consent of a parent or guardian.
12. Changes to this Policy
We may update this Policy from time to time. The current version is always published on this page, with the date it was last changed.