Privacy Policy

Last updated: 25 June 2025

This Privacy Policy explains how Jana Marie Hoffmann ("I", "me", "my"), a sole trader registered in Sweden under VAT number SE 19820514470501, collects and uses personal information when you visit janamariehoffmann.com, purchase coaching services, attend events, download resources, interact on social media, or engage with my business (the "Services"). It also details your rights under the EU GDPR, Swedish Data Protection Act, and e‑privacy rules.

1. Who is responsible for your data?

RoleDetails
Data ControllerJana Marie Hoffmann, sole proprietor (enskild firma)
Postal addressc/o J. M. Hoffmann, address on file, Stockholm, Sweden
Contact for privacy mattersUse the secure form at janamariehoffmann.com/contact – mark your message “Privacy.”
Data-Protection OfficerNot required; responsibility sits with Jana Marie Hoffmann.
Supervisory authorityIntegritetsskyddsmyndigheten (IMY) – Box 8114, 104 20 Stockholm – Tel +46 8 657 61 00 – imy.se

2. Quick summary

  • I collect only what’s necessary to provide coaching, run the Site, market my Services, and comply with legal obligations.
  • I never sell personal information.
  • Main legal bases: contract, legitimate interest, consent. Special‑category data is processed only with explicit consent.
  • International transfers rely on Standard Contractual Clauses or the EU–US Data Privacy Framework.
  • You can exercise your GDPR rights anytime via the contact form; I respond within 30 days.

3. What data I collect

CategoryExamplesSource
Identity & contactName, postal address, email, phone (optional)You
Billing & paymentsInvoices, Stripe/PayPal tokensYou / provider
Coaching session notesChallenges, goals, wellbeing observationsYou during sessions
Marketing & commsNewsletter preferences, surveys, testimonialsYou
Support & check-insWhatsApp Business messages, community chat postsYou via WhatsApp
Technical & usageIP, browser, device, pages visited, cookie IDsYour device
Social mediaProfile name, messages, comments, likesYou / platform
Children’s data
The Services target adults (18+). Parents may share their children’s information only for coaching purposes with parental consent. No data is collected directly from minors.

4. Legal bases, purposes & retention

PurposeDataLegal basisRetention
Deliver coaching & membershipsIdentity, contact, billing, session notesContract Art 6(1)(b)10 years after last session
Billing, accounting, taxInvoices, recordsLegal obligation Art 6(1)(c)10 years
Scheduling sessionsContact detailsLegitimate interest Art 6(1)(f)3 years
Marketing emailsEmail, preferencesConsent Art 6(1)(a)Until unsubscribe
TestimonialsName, text, photo (optional)Consent Art 6(1)(a)Until withdrawn
Analytics & cookiesTechnical & usageConsent Art 6(1)(a)Up to 2 years
Security & fraud preventionLogs, access dataLegitimate interest Art 6(1)(f)3 years
Special-category dataHealth & wellbeing notesExplicit consent Art 9(2)(a)10 years or on request

5. Who I share data with (processors &trusted third parties)

All suppliers sign GDPR‑compliant Data‑Processing Agreements (Art 28).

PurposeProviderLocationTransfer safeguard
Website hosting & CMSSquarespace Inc.USASCCs + EU–US DPF
SchedulingSquarespace Scheduling (Acuity)USASCCs + DPF
PaymentsStripe; PayPalEEA / USASCCs + DPF
Video conferencingZoom; Google MeetUSASCCs + DPF
Email & file storageGoogle WorkspaceUSASCCs + DPF
Messaging & communityWhatsApp BusinessUSASCCs + DPF
Analytics & adsGoogle Analytics 4; Google Ads; Meta Pixel; LinkedIn Insights; Pinterest Tag; YouTubeUSASCCs + DPF
Forms & quizzesTypeform (EU); Jotform (USA)EU / USASCCs
AI draftingOpenAI Ireland; OpenAI LLCEU / USASCCs
Membership areasSquarespace Member AreasUSASCCs + DPF
Bookkeeping & invoicingFortnox ABSwedenEEA (no transfer)

6. International transfers outside the EEA

Data in non-adequate countries (mainly USA) is protected by:

  • Standard Contractual Clauses (2021/914)
  • EU–US Data Privacy Framework certification
  • Encryption in transit & at rest

Request SCCs anytime via contact form.

7. Cookies & tracking technologies

Essential cookies are always on; analytics & marketing cookies set only after consent via the banner. You can change preferences in the footer.

  • Strictly necessary – session & security cookies;
  • Analytics – GA4 first-party (after opt-in);
  • Marketing – Meta, LinkedIn, Pinterest, Google Ads, YouTube (after opt-in).

8. How long I keep your data

Data setRetention
Coaching files & notes10 years post-service or sooner on request
Financial records10 years (per Bokföringslagen)
Newsletter listUntil unsubscribe or bounce
Form queries12 months after last correspondence
TestimonialsUntil consent withdrawn
Security logs3 years

9. How I protect your data (security)

  • Squarespace SSL/TLS encryption
  • Strong passwords & MFA on admin accounts
  • Data at rest encrypted by providers
  • Regular updates & monitoring
  • Access restricted to Jana Marie Hoffmann

10. Your rights under GDPR

  1. Access – request your data
  2. Rectification – correct inaccuracies
  3. Erasure – delete your data
  4. Restriction – limit processing
  5. Portability – receive data in machine-readable form
  6. Object – object to processing
  7. Withdraw consent – at any time
  8. Complain – to IMY or local authority

Exercise rights via the contact form; response within 30 days.

11. Third-party links

The Site may link to external sites; I’m not responsible for their privacy practices—please review their policies.

12. Changes to this Privacy Policy

I review this annually or when processing changes. Significant updates will be announced on the Site or by email.

Last full rewrite: 25 June 2025