Last updated: July 2026
This Privacy Policy explains how Damien Soitout Holdings (Cyprus), trading as Retraite Eveil ("we", "us"), processes personal data when you use the Retraite Eveil community platform at app.retraite-eveil.com (the "Community") and the Retraite Eveil mobile application (the "App").
This policy covers the Community and App only. Retreat booking, payment, health questionnaires, and shop account data on retraite-eveil.com are described in our separate Website Privacy Policy. Both policies should be read together where you use both services.
1. Data controller
- Controller: Damien Soitout Holdings
- Brand: Retraite Eveil
- Address: P.O. Box 21472, 1599 Nicosia, Cyprus
- Email: [email protected]
- Community URL: https://app.retraite-eveil.com
2. Scope
This policy applies when you:
- Log in to or browse the Community on the web;
- Use the Retraite Eveil mobile App;
- Receive Community-related email or push notifications;
- Post content, send messages, join spaces, or upload files within the Community.
It does not govern third-party websites linked from member posts. It does not cover health questionnaire data collected on retraite-eveil.com (see the Website Privacy Policy).
3. How you get an account
Community accounts are created when:
- Our retreat shop confirms you are eligible (paid ticket, completed questionnaire, approved ticket) and provisions access via our integration; or
- A Retraite Eveil administrator invites you manually.
From the shop we typically receive your email address, display name, and information needed to assign you to the correct spaces (for example retreat type and language). We do not import your health questionnaire answers into the Community.
You set your Community password separately (for example via "Forgot password" on first login).
4. Data we collect
4.1 Account and profile
- Email address, username, display name;
- Profile photo, banner, biography, and other fields you choose to add;
- Language preference, timezone, notification settings;
- Password (stored hashed); login timestamps.
4.2 Community activity
- Posts, comments, likes, and reactions;
- Direct messages and conversation metadata (via community messaging where enabled);
- Files and images you upload (photos, documents, attachments);
- Space memberships and participation history;
- Moderation records if your content is reported or removed.
4.3 Technical and usage data
- IP address, browser or App user-agent, device type;
- Session cookies and similar identifiers needed for login and security;
- Push notification tokens (FCM) when you enable notifications on the App;
- Error and performance logs on our servers.
4.4 Communications
- Emails sent by the platform (password reset, notifications, digests if enabled);
- Support correspondence if you contact us about the Community.
5. Purposes and legal bases (GDPR)
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide Community and App access | Account, profile, spaces | Art. 6(1)(b) contract / pre-contract steps |
| Operate posts, messages, and files | User-generated content | Art. 6(1)(b) contract |
| Security, abuse prevention, moderation | Logs, IP, reports | Art. 6(1)(f) legitimate interests |
| Push notifications (optional) | Device token | Art. 6(1)(a) consent (device prompt) |
| Legal compliance | Relevant records | Art. 6(1)(c) legal obligation |
6. Community content and visibility
Content you post in a space is visible to other members of that space and to authorised administrators. Direct messages are visible to participants and administrators where required for moderation or legal compliance. The Community is not indexed as a public social network, but you should assume other members can see what you share within your spaces.
Do not post special-category data (for example detailed health records) unless you accept the risk of other members viewing it. We do not require you to publish health information in the Community.
7. Cookies and similar technologies
We use essential cookies for authentication, session management, and security. Optional analytics or consent tools may be configured through the Community cookie consent notice where enabled. You can control non-essential cookies through that notice or your browser settings.
The mobile App may store tokens locally for login persistence and notifications according to your device settings.
8. Push notifications
If you install the Retraite Eveil App and allow notifications, we process a Firebase Cloud Messaging token to deliver alerts (for example new messages). You can disable notifications at any time in your device settings. Without a token, push delivery is not possible but you can still use the Community in a browser.
9. Retention
- Active accounts — data retained while your account exists and you use the Community;
- Deleted accounts — profile and content removed or anonymised within a reasonable period, subject to backups and legal holds;
- Logs — server and security logs for a limited operational period;
- Legal export packages — temporary files created when you use "Export your data" (see section 11).
If your retreat ticket is refunded or cancelled, we may deactivate Community access and retain minimal records needed for audit and dispute resolution.
10. Processors and international transfers
We use service providers including:
- FastComet — web hosting and database;
- Amazon Web Services (S3) and CloudFront — media and file storage/delivery;
- Cloudflare — DNS, CDN, and security;
- Google Firebase — push notification delivery to the App;
- Email delivery provider — transactional email.
Some providers may process data outside the European Economic Area. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
We do not sell your personal data.
11. Your rights
Under GDPR you may have the right to access, rectify, erase, restrict, object, and port your data, and to withdraw consent where processing is consent-based.
Export your data: Where enabled, you can request a data export package from your account settings in the Community. This may include profile data, posts, comments, and related files.
Deletion: Contact us at [email protected] to request Community account deletion. Shop account deletion on retraite-eveil.com is separate — request both if you want all services removed.
We respond within one month unless complexity requires an extension permitted by law.
12. Security
Measures include HTTPS encryption, hashed passwords, access controls for administrators, and private object storage for uploaded media. No online service is completely secure — please use a strong unique password and report suspected breaches promptly.
13. Children
The Community is for adults aged 18 and over only. We do not knowingly collect data from minors. Contact us if you believe a minor has access.
14. Changes
We may update this policy. The "Last updated" date will change and, where appropriate, we will notify you on login or by email. Continued use after updates constitutes acceptance unless mandatory law requires explicit consent.
15. Complaints
Contact us first at [email protected]. You may lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus: dataprotection.gov.cy, or your local supervisory authority if you live in the EU/EEA.
