Privacy Policy

Your message has been sent & I will get back to you ASAP!

Last updated: 28.08.2026

1. Who we are

This Privacy Policy explains how themindfriend OÜ ("we", "us", "our") collects, uses, and protects your personal data when you visit themindfriend.net, purchase or use our courses and group coaching programs, subscribe to our emails, or contact us. We are the data controller of your personal data.

Company Name: themindfriend OÜ
Legal Form: Limited Company
Registered Address: Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
Business Registration Number: 16595490
VAT ID: EE102584987
Email: hello@themindfriend.net
Website: themindfriend.net
Responsible Person: Charlotte Grimmel

For any privacy question or to exercise your rights, email hello@themindfriend.net. We process personal data under the EU General Data Protection Regulation (GDPR) and Estonian law.

2. The personal data we collect

Depending on how you interact with us, we may collect: identity and contact data (name, email, billing details, country); transaction data (purchases, order and payment details — we never store your full card details); account and participation data (login and profile information, and your contributions in our course and community spaces); communications (messages, support requests, feedback); marketing data (subscription status and email engagement); and usage and technical data (such as IP address, device and browser type) collected through necessary cookies and server logs (see Section 5).

We collect this directly from you, automatically through cookies, and from our providers (for example, order confirmations from our checkout).

Sensitive information. Coaching may lead you to share personal information about your wellbeing. Please share only what you're comfortable with. Where you provide health or other sensitive ("special category") information, we process it solely to support you in the program, on the basis of your explicit consent, which you can withdraw at any time.

3. Why we use your data, and our legal basis
Purpose Legal basis (GDPR)
Deliver the Programs you buy, give access, and provide support Performance of a contract (Art. 6(1)(b))
Process payments and prevent fraud Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Keep accounting and tax records Legal obligation (Art. 6(1)(c))
Send marketing emails and newsletters Your consent (Art. 6(1)(a)), or legitimate interest in contacting existing customers about similar offerings, where permitted
Secure and improve our website and services Legitimate interests (Art. 6(1)(f))
Handle sensitive information you share in coaching Your explicit consent (Art. 9(2)(a))

Providing the data needed to deliver a Program is necessary to enter into the contract; without it we cannot provide the service. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out. Every marketing email includes an unsubscribe link, and you can opt out at any time.

4. Who we share your data with

We share personal data only with providers ("processors") who help us run our business, each bound by an agreement to protect it and use it solely on our instructions. Our current providers include ThriveCart (checkout and payment processing, via its connected payment processors), Stan Store (storefront and checkout), Circle (community and course hosting), and Flodesk (email marketing).

More generally, we may share data with these categories of recipient: payment processors; checkout and e-commerce platforms; course-hosting and community platforms; email and communication providers; website hosting providers; our professional advisers; and public authorities where legally required. We do not sell your personal data.

5. Cookies

Our website uses only strictly necessary cookies — those required for the site, checkout, and any logged-in areas (such as our course and community platform) to work. These are set automatically and, under EU rules, do not require your consent. We do not currently use analytics, advertising, or other non-essential cookies. If we introduce them in future, we will ask for your consent through a cookie banner before setting them and update this policy accordingly. You can also control cookies through your browser settings.

6. International data transfers

Several of our providers (including those named above) are based in the United States, so your data may be transferred outside the European Economic Area. Where this happens, we rely on an appropriate safeguard under the GDPR — the provider's certification under the EU–US Data Privacy Framework where it holds one, or the European Commission's Standard Contractual Clauses. Email us for details on a specific transfer.

7. How long we keep your data

We keep accounting and transaction records for 7 years (as required by Estonian law); account, program, and community data for the duration of your relationship with us plus a reasonable period afterwards; and marketing data until you unsubscribe. We then delete or anonymise it.

8. Your rights

Under the GDPR, you have the right to access your data; request rectification, erasure, or restriction; object to processing based on legitimate interests and to direct marketing at any time; receive your data in a portable format (data portability); and withdraw consent where processing relies on it. We do not make decisions with legal or similarly significant effects about you by solely automated means.

To exercise any right, email hello@themindfriend.net. We respond within one month and may need to verify your identity first.

9. Complaints

If you believe we have mishandled your data, please contact us first. You may also complain to the Estonian supervisory authority, Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), www.aki.ee, or to your local data protection authority if you are in another EU/EEA country.

10. Changes

We may update this policy from time to time. The current version is always on our website, with the "Last updated" date shown above.