Privacy as professional responsibility

Personal Data Protection

Personal information can hold ordinary details or intimate truths. It should be collected carefully, used for clear reasons and kept only while a legitimate purpose remains.

This notice explains how the Andrew Barnes website and connected enquiries, consultations, mentoring, retreats, events, practitioner education, purchases and communications handle personal information.

A professional boundary

Privacy belongs inside the standard of care.

You should be able to understand what information is held, why it is needed, who may see it and how to ask for change.

Data protection is wider than confidentiality. It begins before information is collected and continues through access, accuracy, sharing, security, retention and deletion.

Nothing in this notice turns participation in intimate work into permission for unrelated marketing, publicity or casual circulation of personal information.

Protection principles

Restraint before reach.

These principles express the standard across the website and Andrew’s connected services. Applicable privacy law may create additional or more specific duties.

01

A clear purpose comes first

Personal information should be collected for a stated reason and not quietly reused for an unrelated purpose.

02

Only what is reasonably needed

The amount and sensitivity of information requested should be proportionate to the service, event or legal obligation involved.

03

Sensitive information receives greater care

Health, sexuality, accessibility and other intimate information require a specific reason, restricted access and an appropriate lawful condition.

04

Marketing remains a separate choice

Registering, buying, enquiring or attending does not create blanket permission for promotional email or unrelated marketing.

05

Access follows responsibility

Information should be available only to people and service providers who need it for an authorised purpose.

06

Accuracy and accountability continue

Records should be kept accurate, protected, reviewed and removed or anonymised when there is no longer a valid reason to retain them.

Information and purpose

What may be involved, and why.

The information used depends on what you choose to do. Open each area for the intended purpose and the boundary around it.

01Contact and identity detailsThis may include your name, email address, phone number, country, preferred language and the details you place in an enquiry.

These details are used to respond, communicate about a requested service and keep the practical relationship connected to the correct person.

You should not provide another person’s information unless you are authorised to do so and they understand how it will be used.

02Bookings, events and practitioner educationRegistration may involve event choices, attendance records, accommodation, dietary needs, language support and other practical arrangements.

Information may be used to assess whether the stated format can responsibly meet your needs, administer the booking, communicate changes and support the event or training.

Where a regional organiser is responsible for delivery, only the information reasonably needed for that event should be available to that organiser and authorised team members.

03Health, accessibility and intimate informationSome services may invite information about health, disability, trauma history, relationships, sexuality, boundaries or support needs.

This information can be legally sensitive. It should be requested only when there is a clear purpose, accompanied by an appropriate explanation and protected with more restricted access.

You are not asked to disclose intimate detail merely to prove commitment. If information is essential to suitability or safety, that requirement should be explained before you decide whether to provide it.

04Consultations, mentoring and correspondenceMessages, appointment details, notes and information you choose to discuss may be held as part of an ongoing professional relationship.

The purpose is to provide and administer the work, maintain appropriate continuity, respond to requests and keep proportionate records where professional, contractual or legal responsibilities require them.

Professional confidentiality and data protection overlap, but they are not identical. Any legal limits to confidentiality should be explained rather than hidden behind an absolute promise.

05Purchases and payment recordsOrders may involve billing details, transaction records, products, currency, delivery information and tax or accounting data.

Secure checkout and payment providers process payment information under their own security and legal responsibilities. Full payment-card details should not be stored in the ordinary Andrew Barnes website record.

Transaction and invoice records may need to be retained for accounting, tax, fraud prevention, disputes or other legal obligations.

06Email and marketing choicesService messages and promotional messages serve different purposes and should not be treated as the same permission.

Necessary booking, order, appointment and safety communications may be sent as part of providing what you requested. Promotional messages require a valid legal basis and a clear way to unsubscribe.

Unsubscribing from marketing does not prevent essential communications about an active booking, order or professional service.

07Website, device and cookie informationTechnical records may include IP address, browser and device data, timestamps, referring pages, security events and cookie choices.

This information may be used to deliver the website, preserve preferences, maintain security, diagnose faults and understand use in a proportionate way.

The English .org launch uses essential cookies and session tokens for security, carts, bookings, logins and return flows where those features are enabled. A language-preference cookie may be stored for up to 12 months. Advertising and profiling cookies are not used at launch; non-essential analytics will only be introduced with an appropriate consent choice where required.

08Images, recordings, feedback and concernsPhotographs, video, audio, testimonials, survey responses and reports of concerns can carry personal and sometimes highly sensitive information.

Promotional use of an identifiable person’s image, recording or words requires a separate, informed choice. Declining publicity should not affect access to an otherwise available service.

Complaints, grievances, safeguarding information and related evidence are handled for the relevant process, with access limited as far as fairness, safety and law allow.

Lawful use

Personal data needs a valid reason.

A convenient reason is not automatically a lawful one. The basis must fit the real purpose and, when information is highly sensitive, any additional legal condition must also be met.

  • To take steps you request before a booking, purchase or professional agreement, and to perform that agreement
  • To meet accounting, tax, consumer, safety, record-keeping and other legal obligations
  • For carefully assessed legitimate interests, where those interests are not overridden by your rights and reasonable expectations
  • With consent where a genuine, specific and withdrawable choice is the appropriate basis, including optional marketing and publicity
  • With explicit consent or another applicable legal condition before processing special-category or comparably sensitive information
  • To protect vital interests in a genuine emergency, or to establish, exercise or defend legal claims where the law permits

Recipients and transfers

Who may receive information.

Access should follow a defined role. A service provider or organiser should receive only what is needed for the purpose they are authorised to perform.

Recipient categories

  1. 01

    Andrew and authorised team members who need the information for the requested work

  2. 02

    A named regional organiser and authorised event team where they are responsible for the relevant retreat, event or training

  3. 03

    Technology providers for website hosting, Wix content and commerce services, secure checkout, email, communications, security, support and consent management

  4. 04

    Payment, accounting, tax, delivery and professional service providers where their role requires the information

  5. 05

    Insurers, legal or safeguarding advisers, mediators and other independent professionals when their involvement is necessary and lawful

  6. 06

    Courts, regulators, police, emergency services or public authorities where disclosure is legally required or necessary to protect rights or safety

Core service providers

Named services, defined roles.

The following providers support the live website and connected services. They may use their own vetted subprocessors and international infrastructure under their published privacy, security and data-transfer terms.

01

Wix.com Ltd. (Wix)

Bookings, store orders, member accounts, pricing plans, forms and the private practitioner-directory records.

02

Stripe

Payment processing through the approved Stripe account connected to Wix, including transaction and fraud-prevention information required for payment.

03

Proton AG (Proton Mail)

Business email, booking and service communications, replies and privacy requests.

04

Vercel Inc. (Vercel)

Hosting and delivery of the replacement website, secure server requests, technical logs and security monitoring.

Exact retention schedule

Keep what is justified. Protect what remains.

These are the normal maximum periods. Information is removed sooner when the purpose ends and no legal or documented professional reason requires it.

01

Enquiries and unused interest forms

General enquiries and interest forms that do not lead to a booking, service or practitioner listing are normally kept for 24 months after the last meaningful contact, then deleted or anonymised.

02

Events, retreats and training

Practical booking and attendance records are normally kept for 24 months after the activity ends. Sensitive health, accessibility and intimate intake information is reviewed sooner and normally deleted within 12 months after the activity ends.

03

Consultations and mentoring

Appointment correspondence and proportionate working notes are reviewed annually and normally deleted three years after the last session, unless longer retention is needed for a dispute, safeguarding concern or legal duty.

04

Payments, invoices and tax records

Order, invoice, booking-payment and transaction records are retained for seven years after the end of the relevant tax period where UAE tax law applies.

05

Practitioner directory records

Public profiles are removed when a listing ends. Private account, agreement, billing, approval and audit records are retained for seven years after the account closes. Unsuccessful applications and unused interest forms are kept for 24 months.

06

Marketing and consent

Active marketing details are kept until consent is withdrawn or after 24 months without engagement, whichever comes first. A minimal suppression record may remain so an unsubscribe request is honoured.

07

Security logs and cookie choices

Routine security and application logs are normally kept for 90 days. Records connected to a suspected incident may be retained for up to 24 months. Cookie and language choices may remain for up to 12 months.

08

Complaints and documented holds

Complaint and grievance files are normally kept for seven years after closure. Relevant information may be retained longer only while a legal claim, regulatory duty, safeguarding need or other documented hold remains, then reviewed for deletion.

Your rights and choices

Control should remain practical.

Rights differ slightly by jurisdiction and legal basis. The following rights commonly apply under the GDPR and other modern privacy laws.

01Be informed and ask for accessYou may ask what personal information is held about you, how it is used, where it came from and who receives it.

Where the law applies, you may request a copy together with the information needed to understand the processing.

Identity may need to be verified before information is released, so that one person’s privacy is not compromised while responding to another person’s request.

02Correct incomplete or inaccurate informationYou may ask for personal information that is wrong or incomplete to be corrected without undue delay.

Please explain what should be corrected and, where helpful, provide information that allows the record to be verified.

A disagreement about a professional opinion or complaint outcome is not always the same as an inaccurate personal-data record, but your statement may still need to be preserved with the record.

03Request erasure or restrictionYou may ask for information to be deleted or its use restricted where the relevant legal conditions are met.

Erasure is not absolute. Some information may need to remain for legal obligations, freedom of expression, public-interest responsibilities or the establishment, exercise or defence of legal claims.

Where immediate deletion is disputed or not possible, restriction may be an appropriate interim response.

04Object and withdraw consentYou may object to certain processing and withdraw consent at any time where consent is the basis being relied upon.

Withdrawal does not make earlier lawful use invalid, but it should stop future consent-based use unless another lawful basis genuinely applies.

You may object to direct marketing at any time. Every promotional email should provide a practical unsubscribe method.

05Request portability where it appliesFor certain automated processing based on consent or contract, you may request information you provided in a structured, commonly used format.

Where technically feasible and legally applicable, you may ask for that information to be transmitted to another controller.

Portability does not require disclosure of information that would adversely affect another person’s rights.

06Seek human review and complainYou may ask about significant decisions made solely by automated means and seek human involvement where the law provides that right.

This website does not use solely automated decisions that produce legal or similarly significant effects about you.

You may also complain to the data-protection authority that is competent for your location or the relevant controller without first giving Andrew an opportunity to resolve the matter.

Who is responsible

A clear point of responsibility.

Andrew Barnes is responsible for deciding how and why personal information covered by this notice is handled, unless a booking, purchase or collection point clearly names another organiser or provider as separately responsible.

Some retreats, events and training are delivered with a regional organiser. When that organiser independently or jointly decides how information is used, their role and contact details are identified at the relevant form, booking page or communication.

The website uses carefully selected providers for hosting, Wix services, secure checkout and payments, email, communications, security and support where each service is needed. Each provider receives only the information required for its role and handles it under its own legal and security responsibilities.

Requests and complaints

You do not need legal language to ask.

To ask about personal information, request access, correct a record, withdraw consent, object or request deletion, email energy@andrewbarnes.org or use the website contact page. A response may require reasonable identity verification.

The wider framework

Privacy sits beside ethics, not outside it.