PRIVACY POLICY
Last Updated: August 2026
This Privacy Policy explains how Dorota Kubala, operating under Wild Blossom Consultancy & Retreats Ltd (Company Reg No: 10491582) and Women Without Limits Academy Ltd (Company Reg No: 17397445) ("we", "us", or "our"), collects, uses, stores, and protects your personal data when you visit our website, enroll in our academy, book a coaching or consultancy session, or register for our retreats.
We are committed to respecting your privacy and protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Details
For the purpouses of applicable data protection legislation, the Data Controller is:
-
Business Entities: Wild Blossom Consultancy & Retreats Ltd & Women Without Limits Academy Ltd
-
Registered Office Address: 126 Suez Road, Cambridge, CB1 3QD, United Kingdom
-
Lead Practitioner / Representative: Dorota Kubala
-
Contact Email: [Insert Contact Email Address]
2. Information We Collect About You
We may collect, use, store, and transfer different kinds of personal data depending on how you interact with us:
-
Identity Data: Name, date of birth, gender.
-
Contact Data: Email address, telephone number, billing address, residential address.
-
Financial Data: Payment details, bank account info, card details (processed securely via encrypted third-party payment gateways like Stripe or PayPal).
-
Transaction Data: Details about payments to and from you, and details of coaching packages, academy courses, or retreats you have purchased.
-
Technical Data: IP address, browser type, time zone setting, location data, and access metrics collected via website cookies.
-
Profile & Marketing Data: Your preferences in receiving irregular updates, event announcements, and tribe communications.
-
Special Category / Sensitive Data (Retreats & Coaching): Emergency contact details, medical history, dietary requirements, or mobility considerations provided strictly for retreat safety and health considerations.
3. How We Collect Your Personal Data
We collect data from and about you through:
-
Direct Interactions: When you fill out contact/opt-in forms, apply for coaching, enroll in the academy, book a retreat, or correspond with us by email.
-
Automated Technologies: As you interact with our website, technical data regarding your equipment and browsing patterns may be automatically collected via cookies.
-
Third Parties: Payment service providers, scheduling platforms (e.g., Acuity, Calendly), or analytics providers.
4. How We Use Your Personal Data & Lawful Basis
We will only use your personal data when the law allows us to. The primary lawful bases we rely on include:
-
Performance of a Contract: Delivering coaching services, managing academy course access, executing retreat logistics, processing transactions, and providing customer support.
-
Consent: Sending you occasional, irregular email updates, wisdom, and news about upcoming retreats ("Join Our Tribe"). You can withdraw your consent at any time via the unsubscribe link in emails.
-
Legitimate Interests: Improving our programs, website functionality, client service, and maintaining legal/financial records.
-
Legal Obligation: Maintaining accounting, tax, and corporate compliance records under UK law.
-
Vital Interests: Sharing relevant medical or dietary information with emergency services or retreat hosts in the event of an urgent physical or health emergency.
5. Third-Party Sharing
We do not sell, rent, or trade your personal data. We share data only with trusted service providers essential for operating our business, including:
-
Payment gateways (e.g., Stripe, PayPal).
-
Email delivery platforms and CRM tools.
-
Online learning & academy hosting environments.
-
Retreat venue hosts, caterers, or travel partners (strictly limited to logistical or dietary/health requirements).
-
Professional advisors (accountants, insurers, legal counsel).
6. International Data Transfers
Some of our third-party service providers (such as cloud hosting, scheduling software, or email systems) may be located outside the UK or European Economic Area (EEA). Whenever we transfer your data internationally, we ensure a similar degree of protection is afforded by utilizing UK GDPR-approved standard contractual clauses or equivalent legal safeguards.
7. Data Retention
We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements:
-
Financial & Transactional Data: Kept for 6–7 years following transaction completion in accordance with UK tax laws.
-
Coaching & Client Records: Retained for up to 6–7 years following session completion for legal and insurance record-keeping.
-
Marketing / Tribe Email Lists: Retained until you unsubscribe or request data erasure.
8. Your Legal Rights
Under UK GDPR, you have the following rights regarding your personal data:
-
Right of Access: Request a copy of the personal data we hold about you.
-
Right to Rectification: Request correction of inaccurate or incomplete data.
-
Right to Erasure: Request deletion of your personal data where there is no legal requirement for us to keep it.
-
Right to Restrict or Object: Object to or restrict processing based on legitimate interests or direct marketing.
-
Right to Withdraw Consent: Opt out of email newsletters at any time.
To exercise any of these rights, please contact us at [Insert Contact Email Address].
9. Right to Lodge a Complaint
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns directly before you approach the ICO