Hedo-privacy

Privacy Policy

Effective Date: July 1, 2025 · Last updated: July 1, 2025

Summary: We collect only what we need, we don’t sell your data, and you control how your information is used.

1) Who we are (Data Controller)

HĒDO (“HĒDO”, “we”, “our”, “us”) operates transformational travel and personal development services. For the purposes of the EU/UK GDPR, we act as the data controller when we decide why and how personal data is processed.

  • Contact (privacy): privacy@hedo.world
  • General: journey@hedo.world
  • Registered seat/jurisdiction for website: France (Paris courts), unless otherwise stated in a specific contract.

2) Scope

This Policy covers our website and digital platforms, profiling protocols, retreats, events, and related communications. It applies to visitors, members, applicants, and partners using our services.

3) Information we collect

  • Identifiers & Contact: name, email, phone, country, billing details.
  • Profiling Data (optional and voluntary): birth data, questionnaire and audio responses, preferences you share.
  • Transaction Data: purchases, bookings, refunds, payment method tokens (processed by PCI-compliant providers).
  • Technical Data: IP address, device/browser, cookies, analytics, approximate location, interaction logs.
  • Sensitive Data (if you choose to share): wellbeing notes during protocols or retreats. We treat these with heightened confidentiality and process them only with your explicit consent.

4) Why we use your data (Purposes & Legal bases)

We process personal data under GDPR legal bases: consent, contract, legitimate interests, and legal obligation.

  • Deliver services & bookings (contract): create accounts, process payments, run programs, provide support.
  • Personalize experiences (consent / legitimate interests): recommend journeys and content relevant to you.
  • Communications (consent / legitimate interests): service messages, community updates, newsletters (you can opt out anytime).
  • Safety, security & fraud prevention (legitimate interests / legal obligation).
  • Analytics & improvement (legitimate interests): understand usage to improve what we offer.
  • Compliance (legal obligation): tax, accounting, lawful requests.

5) Cookies & similar technologies

We use essential cookies to operate the site and optional analytics cookies to improve it. You can manage preferences at any time via our Cookie Settings control or your browser settings.

Cookie categories

  • Essential — required for security, load balancing, and basic functions.
  • Analytics — aggregated usage statistics (e.g., pages visited, session length).
  • Functional — remember choices (e.g., language, region).
  • Marketing — only if we run campaigns; disabled by default.

6) Sharing & disclosures

We do not sell or rent your personal data. We may share limited data with:

  • Service providers: payments, hosting, email, analytics, booking platforms—bound by confidentiality and data processing agreements.
  • Retreat partners/facilitators: only with your prior consent and only what is necessary for logistics and safety.
  • Authorities or legal requests: where required to comply with law or protect rights and safety.

7) International transfers

If personal data is transferred outside the EEA/UK/Switzerland, we use appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and additional measures where necessary.

8) Retention

We keep personal data only as long as needed for the purposes above:

  • Account & service data: while your account is active and a reasonable period thereafter.
  • Profiling content you submitted: until you delete it or request erasure.
  • Financial records: retained as required by tax and accounting laws.

9) Your rights

Depending on your location, you may have the following rights (subject to legal limits):

  • Access, rectification, erasure (“right to be forgotten”).
  • Restriction or objection to processing.
  • Data portability.
  • Withdraw consent at any time (does not affect prior lawful processing).
  • Lodge a complaint with a supervisory authority (e.g., CNIL in France).

To exercise rights, email privacy@hedo.world. We aim to reply within 30 days.

10) CCPA/CPRA notices (California)

  • We collect the categories listed in section 3 for the purposes in section 4.
  • We do not sell or share personal information as defined by the CPRA.
  • You may request to know, correct, or delete your personal information, and we will not discriminate against you for exercising your rights.
  • Contact: privacy@hedo.world.

11) Security

We use technical and organizational measures (encryption in transit, access controls, backups, monitoring) to protect personal data. No method is perfectly secure; we continuously improve our safeguards.

12) Children

Our services are intended for adults (18+). We do not knowingly collect data from children. If you believe a minor has provided data, contact us for deletion.

13) Automated decisions

We do not use automated decision-making that produces legal or similarly significant effects without human involvement.

14) Changes to this Policy

We may update this Policy from time to time. Material changes will be announced on this page and, where appropriate, by email.