Effective Date: July 1, 2025 · Last updated: July 1, 2025
Summary: We collect only what we need, we don’t sell your data, and you control how your information is used.
HĒDO (“HĒDO”, “we”, “our”, “us”) operates transformational travel and personal development services. For the purposes of the EU/UK GDPR, we act as the data controller when we decide why and how personal data is processed.
This Policy covers our website and digital platforms, profiling protocols, retreats, events, and related communications. It applies to visitors, members, applicants, and partners using our services.
We process personal data under GDPR legal bases: consent, contract, legitimate interests, and legal obligation.
We use essential cookies to operate the site and optional analytics cookies to improve it. You can manage preferences at any time via our Cookie Settings control or your browser settings.
We do not sell or rent your personal data. We may share limited data with:
If personal data is transferred outside the EEA/UK/Switzerland, we use appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and additional measures where necessary.
We keep personal data only as long as needed for the purposes above:
Depending on your location, you may have the following rights (subject to legal limits):
To exercise rights, email privacy@hedo.world. We aim to reply within 30 days.
We use technical and organizational measures (encryption in transit, access controls, backups, monitoring) to protect personal data. No method is perfectly secure; we continuously improve our safeguards.
Our services are intended for adults (18+). We do not knowingly collect data from children. If you believe a minor has provided data, contact us for deletion.
We do not use automated decision-making that produces legal or similarly significant effects without human involvement.
We may update this Policy from time to time. Material changes will be announced on this page and, where appropriate, by email.