Privacy Policy

Last updated: 9 September 2026
Explorează

This Policy explains how DAVID ELIOT S.R.L. processes personal data through the davideliot.me website, its forms and services, newsletter, courses, and the Elemente app. The Policy is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian legislation.

1. Data Controller

The data controller is DAVID ELIOT S.R.L., with registered office in Maramureș County, Baia Mare municipality, Str. Victoriei nr. 11, ap. 26, registered with the Trade Registry Office under no. J2024038670006, EUID ROONRC.J2024038670006, CUI 50841050.

For questions and to exercise your rights regarding personal data, you can contact us at hello@davideliot.me.

2. Who and What This Applies To

This Policy applies to website visitors, people who submit forms, subscribe to the newsletter, request information, make a booking, purchase or use services or courses, and users of the Elemente app. It also applies to another person's data provided for a relational analysis, within the limits described below.

3. Our Principles

We process data lawfully, fairly, and transparently, for determined purposes, using only the information necessary. We limit the retention period, access, and disclosure, apply reasonable security measures, and do not sell personal data. We do not use data for behavioral advertising and do not track users across services belonging to different companies.

4. Data We May Process

Identification and contact data: first name, last name, email, phone, address, and billing information, when necessary.

Order and contract data: the service chosen, price, currency, payment status, invoices, bookings, correspondence, and the history of the contractual relationship.

Astrological data: date, time, and place of birth, the locality relevant to the solar return, the type of analysis, and any questions or context provided voluntarily.

Data for relational services: date of birth and initials regarding the other person, provided by the client. We do not request that person's contact details.

Yoga and safe-participation data: physical limitations, contraindications, or other health information communicated only when necessary to adapt the practice.

Course and account data: login credentials, progress, access history, answers, materials sent, and interactions with the course platform.

Communication data: messages from forms, emails, requests, feedback, and communication preferences.

Newsletter and CRM data: name, email address, language, lists and tags, subscription source and date, proof of consent, confirmation status, communications sent, and unsubscribe history, managed through FluentCRM.

Email data: recipient, subject, date, delivery status, and, if logging is enabled in FluentSMTP, metadata or content of messages temporarily recorded in WordPress.

Booking data: the service booked, date, time, time zone, booking status, and information necessary to manage the reservation through Fluent Booking Pro.

Technical and security data: IP address, device and browser type, operating system, timestamps, pages visited, login attempts, suspicious activity, technical identifiers, security logs, and cookies, according to your settings.

App data: permissions granted, app version, device type, diagnostic data and, depending on the features used, the location required to calculate local sunrise, date of birth for biorhythms, and configured preferences.

Limited payment data: transaction identifier, status, amount, and limited information made available by the payment processor. We do not directly store the full card number or security code.

5. Sources of Data

We collect data directly from you, from your forms and actions, from payment processors and distribution platforms regarding the status of a transaction, from the website's and app's technical systems, and, for a relational analysis, from the client requesting the service.

6. Purposes and Legal Bases

When we rely on legitimate interest, we assess the necessity of the processing and its impact on the individual's rights. You may request information about this assessment and object to the processing, under the conditions set out in the GDPR.

7. Sensitive Data and Health Information

We do not request medical data through the general contact form. For a yoga session or a practice requiring adaptation, we may request strictly the information relevant to safety. This data is processed based on explicit consent, separate from acceptance of the Terms.

You may refuse or withdraw consent; however, if the information is necessary for the safe conduct of a practice, we may be unable to provide or adapt the service. We do not perform diagnoses and do not create medical records.

Please do not submit information regarding health, sexual life, religious or philosophical beliefs, or other special categories of data that are not necessary for the requested service through free-text fields. If such information is incidentally provided to us, we will limit its use to what is strictly necessary and delete it without undue delay, unless there is a valid legal basis under Article 6 GDPR and an applicable condition under Article 9(2) GDPR.

8. Data of the Other Person in a Relational Analysis

For synastry and composite charts, the client may provide the date, time, and place of birth of another person. The source of this data is the client. We request the use of initials only and do not request that person's address, email, or phone number.

The client must have a legitimate basis for the disclosure and must provide that person with a link to this Policy before submitting the data. We process the data only to carry out the requested analysis, based on the performance of the contract with the client and the legitimate interest in providing the service under conditions of minimization and confidentiality. The data subject may contact us directly to exercise their rights.

When the data is not obtained directly from the data subject, we provide the information required by Article 14 GDPR, within the time frame and manner it prescribes, except where one of the legal exemptions demonstrably applies. The client may be asked to forward the information notice made available by DAVID ELIOT S.R.L. to the data subject.

9. The Elemente App

The app may use the device's location to determine position and local sunrise, date of birth to calculate biorhythms, and preferences for displaying cycles and practices. In the configuration considered as of the date of this Policy, the main calculations are performed locally on the device, and the exact location and date of birth are not transmitted to DAVID ELIOT S.R.L. and are not used for advertising or tracking.

Location permission can be denied or withdrawn from device settings. In that case, the app may prompt manual selection of a locality, or certain features may become unavailable. Data kept only on the device can be deleted from the app's settings or by uninstalling it.

If a future version introduces an account, cloud sync, personalized notifications, usage analytics, or crash reporting that collects data, the Policy and App Store information will be updated before the feature is activated. The app will request permissions only for the features that require them.

10. Application Providers Used and Recipients

Access to data is limited to the people and providers who need it for the purposes described. The website uses WordPress and the following technical components:

    • Fluent Forms Pro — for contact and service forms, collecting the information necessary for orders, and initiating payments via Stripe;
    • FluentCRM — for local management, within the WordPress infrastructure, of contacts, subscriber lists, consents, unsubscribes, and newsletters;
    • FluentSMTP — for sending emails generated by the site and, if logging is enabled, for temporarily storing information about messages and their status in WordPress;
    • Fluent Community Pro — for managing courses, student accounts, access to materials, and progress;
    • Fluent Booking Pro — for scheduling and managing sessions;
    • ACF Pro and Elementor — for organizing, managing, and displaying the site's content and fields;
    • MalCare — for site protection, malicious access filtering, security scanning, vulnerability detection, and, when necessary, site cleanup or restoration.

These components operate primarily within the WordPress infrastructure. Data may become accessible to their providers only if external features, telemetry, or third-party integrations are enabled, or if we request technical assistance requiring access to the site.

Depending on the service used, data may be disclosed to the following recipients:

    • the WordPress hosting and maintenance provider, for the site's storage, operation, backup, and security;
    • Stripe Payments Europe, Limited and its affiliated entities, for processing payments initiated via Fluent Forms Pro, Fluent Community Pro, and Fluent Booking Pro, transaction authentication, and fraud prevention;
    • Amazon Web Services EMEA SARL and Amazon Simple Email Service, for sending operational emails, confirmations, notifications, and newsletters;
    • MalCare and its technical provider, for firewall protection, suspicious activity monitoring, and security scanning, including off-server scanning of WordPress files and tables to the extent necessary for the service;
    • Apple Distribution International Limited, Apple Inc., and App Store operators, for app distribution, payments, subscriptions, reporting, and platform services;
    • video conferencing or calendar providers used for sessions, as communicated at the time of booking;
    • technical providers for security, backup, optimization, and support, to the extent they may have incidental access to data;
    • the accountant, legal consultants, and other professionals bound by confidentiality obligations;
    • public authorities, courts, or other entities, when disclosure is required by law or necessary to defend a right.

Data entered into Fluent Forms Pro, FluentCRM, Fluent Community Pro, and Fluent Booking Pro is stored in the WordPress database or in the infrastructure associated with the site, according to the configuration applied by DAVID ELIOT S.R.L.

Telegram may be used for administrative alerts. Notifications are limited to minimal operational information and do not include date or place of birth, health information, free-text message content, documents, or payment data. The full content of forms is not transmitted via Telegram.

We do not sell or rent personal data and do not disclose it to third parties for their own advertising purposes.

11. Transfers Outside the European Economic Area

The use of certain international providers, including Amazon Web Services, Stripe, Apple, MalCare, and Telegram, may involve accessing or processing data outside the European Economic Area. When such a transfer occurs, it is based on a mechanism recognized by the GDPR, such as an adequacy decision, the EU-U.S. Data Privacy Framework for certified recipients, Standard Contractual Clauses approved by the European Commission, additional technical and organizational measures, or another applicable legal safeguard.

You may request further information about the mechanism used for a specific provider at hello@davideliot.me.

12. Retention Period

Upon expiry of the applicable retention periods, data is deleted, anonymized, or archived with restricted access, as appropriate. A dispute, audit, or legal obligation may justify retention until final resolution.

13. Cookies and Similar Technologies

Strictly necessary cookies may be used without consent when indispensable to the requested functionality. Analytics, marketing, personalization, or non-essential third-party content cookies are activated only after the user's choice, through the consent mechanism.

Refusing non-essential cookies must be just as easy as accepting them. Users may change their choices at any time. The specific list of cookies, providers, purposes, and durations is available in the Cookie Policy and in the preferences panel.

Videos, maps, reCAPTCHA, analytics tools, or other third-party elements that place non-essential cookies will not be loaded before consent, except where another clear legal basis exists and the user is informed.

14. Newsletter and Commercial Communications

The newsletter is sent only after consent is expressed and subscription is confirmed via the double opt-in mechanism. Consent may be withdrawn at any time through the unsubscribe link in each message or by email to hello@davideliot.me. Withdrawal does not affect the lawfulness of prior processing.

Messages strictly necessary for contract performance, account security, service changes, or resolving a request are not commercial communications and may be sent on the basis of the contract, a legal obligation, or legitimate interest.

15. Data Subject Rights

Under the GDPR, you may request:

    • access to your data and a copy of it;
    • rectification of inaccurate data or completion of it;
    • erasure of data, when there is no longer a basis for retention;
    • restriction of processing;
    • portability of data you provided, when processing is based on consent or contract and carried out by automated means;
    • objection to processing based on legitimate interest;
    • withdrawal of consent at any time;
    • not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you;
    • to lodge a complaint with a supervisory authority.

To exercise your rights, write to hello@davideliot.me. We may request additional information strictly necessary to verify your identity. We respond without undue delay and, generally, within one month at most. This period may be extended by a further two months for complex or numerous requests, in which case you will be informed within the first month.

These rights are not absolute. For example, certain data cannot be deleted as long as there is a legal obligation to retain it or it is necessary for the establishment, exercise, or defense of a legal claim.

16. Automated Decisions and Profiling

We do not use data for decisions based solely on automated processing that produce legal effects or significantly affect the individual. The automatic calculations and displays in Elemente are informational in nature and do not make decisions on behalf of the user.

17. Children's Data

The website, contractual services, and newsletter are not directly intended for persons under 16 without the involvement of a legal guardian. We do not knowingly collect children's data for marketing purposes. If we learn that such data has been provided without an appropriate basis, we will delete it.

A minor's participation in yoga, courses, or other activities requires the consent of their legal guardian and compliance with the specific conditions communicated before enrollment.

The 16-year threshold applies only to situations where an information society service is offered directly to a child and the data processing is based on consent, under Article 8 GDPR. This threshold is distinct from the age of 18 regarding full legal capacity and the ability to enter into contracts. Persons under 18 may purchase or use paid services only through their legal guardian or with their consent, as provided by law.

18. Data Security

We apply technical and organizational measures proportionate to the risk, including access control, appropriate passwords and authentication, encrypted connections, updates, backups, limiting the data included in notifications, and incident response procedures. No method of transmission or storage can guarantee absolute security.

In the event of a security breach, we assess the risk and notify the supervisory authority and affected individuals when required by the GDPR.

19. Complaints

We encourage you to contact us first at hello@davideliot.me to try to resolve your request. You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), Bd. G-ral Gheorghe Magheru nr. 28-30, sector 1, Bucharest, 010336, Romania, email anspdcp@dataprotection.ro, website dataprotection.ro, or with the competent authority in the country where you live or work.

20. Changes to This Policy

We may update this Policy to reflect legislative, technical, or processing-activity changes. The date of the last update is displayed at the top. For significant changes we will use appropriate notice, and if a new purpose requires consent, it will be requested before processing begins.

21. Contact

DAVID ELIOT S.R.L.

Registered office: Maramureș County, Baia Mare municipality, Str. Victoriei nr. 11, ap. 26

CUI: 50841050 | Trade Registry No.: J2024038670006

Privacy email: hello@davideliot.me