A clear purpose comes first
Personal information should be collected for a stated reason and not quietly reused for an unrelated purpose.
Privacy as professional responsibility
Personal information can hold ordinary details or intimate truths. It should be collected carefully, used for clear reasons and kept only while a legitimate purpose remains.
This notice explains how the Andrew Barnes website and connected enquiries, consultations, mentoring, retreats, events, practitioner education, purchases and communications handle personal information.
A professional boundary
You should be able to understand what information is held, why it is needed, who may see it and how to ask for change.
Data protection is wider than confidentiality. It begins before information is collected and continues through access, accuracy, sharing, security, retention and deletion.
Nothing in this notice turns participation in intimate work into permission for unrelated marketing, publicity or casual circulation of personal information.
Protection principles
These principles express the standard across the website and Andrew’s connected services. Applicable privacy law may create additional or more specific duties.
Personal information should be collected for a stated reason and not quietly reused for an unrelated purpose.
The amount and sensitivity of information requested should be proportionate to the service, event or legal obligation involved.
Health, sexuality, accessibility and other intimate information require a specific reason, restricted access and an appropriate lawful condition.
Registering, buying, enquiring or attending does not create blanket permission for promotional email or unrelated marketing.
Information should be available only to people and service providers who need it for an authorised purpose.
Records should be kept accurate, protected, reviewed and removed or anonymised when there is no longer a valid reason to retain them.
Information and purpose
The information used depends on what you choose to do. Open each area for the intended purpose and the boundary around it.
These details are used to respond, communicate about a requested service and keep the practical relationship connected to the correct person.
You should not provide another person’s information unless you are authorised to do so and they understand how it will be used.
Information may be used to assess whether the stated format can responsibly meet your needs, administer the booking, communicate changes and support the event or training.
Where a regional organiser is responsible for delivery, only the information reasonably needed for that event should be available to that organiser and authorised team members.
This information can be legally sensitive. It should be requested only when there is a clear purpose, accompanied by an appropriate explanation and protected with more restricted access.
You are not asked to disclose intimate detail merely to prove commitment. If information is essential to suitability or safety, that requirement should be explained before you decide whether to provide it.
The purpose is to provide and administer the work, maintain appropriate continuity, respond to requests and keep proportionate records where professional, contractual or legal responsibilities require them.
Professional confidentiality and data protection overlap, but they are not identical. Any legal limits to confidentiality should be explained rather than hidden behind an absolute promise.
Secure checkout and payment providers process payment information under their own security and legal responsibilities. Full payment-card details should not be stored in the ordinary Andrew Barnes website record.
Transaction and invoice records may need to be retained for accounting, tax, fraud prevention, disputes or other legal obligations.
Necessary booking, order, appointment and safety communications may be sent as part of providing what you requested. Promotional messages require a valid legal basis and a clear way to unsubscribe.
Unsubscribing from marketing does not prevent essential communications about an active booking, order or professional service.
This information may be used to deliver the website, preserve preferences, maintain security, diagnose faults and understand use in a proportionate way.
The English .org launch uses essential cookies and session tokens for security, carts, bookings, logins and return flows where those features are enabled. A language-preference cookie may be stored for up to 12 months. Advertising and profiling cookies are not used at launch; non-essential analytics will only be introduced with an appropriate consent choice where required.
Promotional use of an identifiable person’s image, recording or words requires a separate, informed choice. Declining publicity should not affect access to an otherwise available service.
Complaints, grievances, safeguarding information and related evidence are handled for the relevant process, with access limited as far as fairness, safety and law allow.
Recipients and transfers
Access should follow a defined role. A service provider or organiser should receive only what is needed for the purpose they are authorised to perform.
Andrew and authorised team members who need the information for the requested work
A named regional organiser and authorised event team where they are responsible for the relevant retreat, event or training
Technology providers for website hosting, Wix content and commerce services, secure checkout, email, communications, security, support and consent management
Payment, accounting, tax, delivery and professional service providers where their role requires the information
Insurers, legal or safeguarding advisers, mediators and other independent professionals when their involvement is necessary and lawful
Courts, regulators, police, emergency services or public authorities where disclosure is legally required or necessary to protect rights or safety
Core service providers
The following providers support the live website and connected services. They may use their own vetted subprocessors and international infrastructure under their published privacy, security and data-transfer terms.
Bookings, store orders, member accounts, pricing plans, forms and the private practitioner-directory records.
Payment processing through the approved Stripe account connected to Wix, including transaction and fraud-prevention information required for payment.
Business email, booking and service communications, replies and privacy requests.
Hosting and delivery of the replacement website, secure server requests, technical logs and security monitoring.
Exact retention schedule
These are the normal maximum periods. Information is removed sooner when the purpose ends and no legal or documented professional reason requires it.
General enquiries and interest forms that do not lead to a booking, service or practitioner listing are normally kept for 24 months after the last meaningful contact, then deleted or anonymised.
Practical booking and attendance records are normally kept for 24 months after the activity ends. Sensitive health, accessibility and intimate intake information is reviewed sooner and normally deleted within 12 months after the activity ends.
Appointment correspondence and proportionate working notes are reviewed annually and normally deleted three years after the last session, unless longer retention is needed for a dispute, safeguarding concern or legal duty.
Order, invoice, booking-payment and transaction records are retained for seven years after the end of the relevant tax period where UAE tax law applies.
Public profiles are removed when a listing ends. Private account, agreement, billing, approval and audit records are retained for seven years after the account closes. Unsuccessful applications and unused interest forms are kept for 24 months.
Active marketing details are kept until consent is withdrawn or after 24 months without engagement, whichever comes first. A minimal suppression record may remain so an unsubscribe request is honoured.
Routine security and application logs are normally kept for 90 days. Records connected to a suspected incident may be retained for up to 24 months. Cookie and language choices may remain for up to 12 months.
Complaint and grievance files are normally kept for seven years after closure. Relevant information may be retained longer only while a legal claim, regulatory duty, safeguarding need or other documented hold remains, then reviewed for deletion.
Your rights and choices
Rights differ slightly by jurisdiction and legal basis. The following rights commonly apply under the GDPR and other modern privacy laws.
Where the law applies, you may request a copy together with the information needed to understand the processing.
Identity may need to be verified before information is released, so that one person’s privacy is not compromised while responding to another person’s request.
Please explain what should be corrected and, where helpful, provide information that allows the record to be verified.
A disagreement about a professional opinion or complaint outcome is not always the same as an inaccurate personal-data record, but your statement may still need to be preserved with the record.
Erasure is not absolute. Some information may need to remain for legal obligations, freedom of expression, public-interest responsibilities or the establishment, exercise or defence of legal claims.
Where immediate deletion is disputed or not possible, restriction may be an appropriate interim response.
Withdrawal does not make earlier lawful use invalid, but it should stop future consent-based use unless another lawful basis genuinely applies.
You may object to direct marketing at any time. Every promotional email should provide a practical unsubscribe method.
Where technically feasible and legally applicable, you may ask for that information to be transmitted to another controller.
Portability does not require disclosure of information that would adversely affect another person’s rights.
This website does not use solely automated decisions that produce legal or similarly significant effects about you.
You may also complain to the data-protection authority that is competent for your location or the relevant controller without first giving Andrew an opportunity to resolve the matter.
Who is responsible
Andrew Barnes is responsible for deciding how and why personal information covered by this notice is handled, unless a booking, purchase or collection point clearly names another organiser or provider as separately responsible.
Some retreats, events and training are delivered with a regional organiser. When that organiser independently or jointly decides how information is used, their role and contact details are identified at the relevant form, booking page or communication.
The website uses carefully selected providers for hosting, Wix services, secure checkout and payments, email, communications, security and support where each service is needed. Each provider receives only the information required for its role and handles it under its own legal and security responsibilities.
Requests and complaints
To ask about personal information, request access, correct a record, withdraw consent, object or request deletion, email energy@andrewbarnes.org or use the website contact page. A response may require reasonable identity verification.
You may also contact the privacy or data-protection authority competent for your location or the relevant controller. You do not have to contact Andrew first before approaching an authority.
European Commission: Your Data RightsEuropean Data Protection AuthoritiesUAE Data Protection LawsThe wider framework