How your information is handled.
Draft · pending counsel reviewThis notice explains, in plain words, what Eleusis does with your information under the EU General Data Protection Regulation. It is written to be honest; where a fact is not yet settled it is marked, and it will be finalised before it governs a real guest.
Who holds your information
The controller is [Eleusis operating entity, legal name and address, Saint Vincent and the Grenadines]. Because guests include people in the EU and EEA, an EU representative is required and will be appointed before any real guest: [name and address, GDPR Art. 27, appointment pending]. You can reach us about your data at [privacy contact address].
What we collect, and why
- Health information you share for your care (your medical review, clearances, the session record). This is special-category data. We process it to provide the retreat and to keep you safe. The exact legal basis for each purpose is being set with our data-protection counsel: [GDPR Art. 6 basis and Art. 9(2) condition per purpose, counsel to confirm; essential care will not rest on a consent you could be asked to refuse].
- Logistics: your room, travel, dietary needs, and the days of the retreat, to arrange your stay.
- Messages you send the team, kept on your record. They are private to you and the team; no other guest can read them.
- Optional product analytics, only if you say yes, and never on your own device without that yes. It records which screen was reached, not who you are or what you wrote. In this version, analytics does not run on your screens at all.
Who else sees it
Your information is held on infrastructure we operate (hosting and database) and, if you consent, an analytics tool, all acting only on our instructions under written agreements. The current list of these processors is: [hosting provider and region; analytics provider, EU-hosted; and any others, GDPR Art. 28 + subprocessor list]. Your data is stored in [region]; any transfer outside the EEA is protected by [the transfer mechanism, GDPR Chapter V].
How long we keep it
We keep your information only as long as your care and our legal duties require, then delete or anonymise it, on the schedule at [retention schedule]. Some safety information may be kept longer where the law requires.
Your rights
You can ask us at any time to: see your information, correct it, delete it, restrict or object to its use, or receive a copy to take elsewhere (GDPR Art. 15 to 21). You can withdraw a consent you gave, at any time, without affecting what came before. To make a request, contact [request channel]; we verify it is really you, and answer within [one month]. You may also complain to your data-protection authority.
The honest part
This app is offered only after your intake and medical review are complete. It holds no more than it needs, it defaults to empty, and the medicine itself is always the physician's, never the software's. Where this notice still shows a bracket, that decision has not been finalised, and the app is not yet running with any real guest's data.
Back to the door