Purifythbio
  • Home
  • Spine Care
  • Exercises
  • Contact

Legal · EU / UN privacy framing

Privacy Policy

This extended policy describes how we collect, store, share, and erase personal data when you read spine wellness guidance, download educational goods, or correspond with our Berlin desk. It mirrors the granularity regulators expect from accountable controllers.

GDPR German TMG / TTDSG context Version

Controller snapshot

Purifythbio editorial and billing desk · Badstraße 57-58, 13357 Berlin · service@purifythbio.world · +49 30 4614050.

Navigate

  • Controller identity
  • Material scope
  • Data categories
  • Sources
  • Purposes and legal bases
  • Consent records
  • Processors and transfers
  • Retention
  • Security
  • Profiling
  • Your rights
  • Supervisory authorities
  • Minors
  • B2B relationships
  • Policy evolution
  • Contact & requests

Plain-language boundary

We publish general spine wellness education. Personal health coaching emails never substitute for regulated diagnosis. If you need a clinical record, contact a licensed practitioner directly.

1

Controller identity and representative functions

The controller within the meaning of Articles 4(7) and 24 GDPR is the service operator using the brand Purifythbio at the address stated in the hero card. Where we process employee or contractor data, separate notices govern HR folders and are available internally.

2

Material and territorial scope

This statement covers visitors to https://purifythbio.world, purchasers of digital publications, participants in remote guidance sessions, newsletter subscribers, and individuals who email us from any country. If you merely load a cached copy delivered through a CDN, the sections on technical logs still apply.

3

Categories of personal data

  • Identity data: name elements, professional title (if volunteered), preferred salutation.
  • Contact data: postal work address, phone, email, timezone descriptors.
  • Financial data: IBAN fragments, payment confirmations, VAT identifiers on invoices.
  • Interaction data: support transcripts, coaching notes prepared collaboratively, workshop evaluations.
  • Technical data: IP address, user agent, language header, referrer URL, timestamp.
  • Preference data: cookie banner flags, accessibility accommodation lists, communication channel preferences.
  • Special categories: we do not aim to collect health data, yet free-text fields might reference symptoms. We instruct staff to minimise such notes and delete incidental medical detail unless a statutory exception applies.
4

Sources of data

Most records originate directly from you. We may receive transactional references from payment processors, fraud-screening services, or accountants reconciling ledgers. If you participate in joint webinars hosted with universities, the partner may relay registration details under documented instructions.

5

Processing purposes and legal bases

  • Website delivery (Art. 6(1)(b) / (f)): TLS termination, denial-of-service mitigation, abuse ticketing.
  • Contract performance (Art. 6(1)(b)): issuing invoices, transferring download links, scheduling guidance.
  • Compliance (Art. 6(1)(c)): tax archives, sanction screening where mandated, responding to court orders.
  • Legitimate interests (Art. 6(1)(f)): internal analytics on article performance when no consent is required, cybersecurity threat hunting balanced via DPIA notes.
  • Consent (Art. 6(1)(a)): non-essential cookies, certain marketing journeys, optional case studies quoting readers.
6

Consent management and withdrawal

Granular consent for cookies can be adjusted through the banner controls on each page. Marketing consents carry their own audit log showing timestamp, language version, and proof of double opt-in when required. Withdrawal mirrors the ease of giving consent; you may email us to propagate a withdrawal across systems within reasonable technician availability.

7

Processors, recipients, and third-country transfers

Typical processor categories include EU-based hosting, transactional email relay, accounting SaaS, and optional analytics suites activated only after consent. Where a vendor stores data in the United States or other third countries, we execute Standard Contractual Clauses plus transfer impact assessments. Copies of redacted SCC references are available upon request.

8

Retention schedule

  • Marketing consents: three years of inactivity.
  • Contact form archives: twenty-four months after last substantive exchange unless litigation holds apply.
  • Accounting records: up to ten years per German HGB / AO requirements.
  • Security logs: ninety days rolling unless an incident extends forensic preservation.
  • Newsletter unsubscribes: minimal suppression hashes indefinitely to honour opt-out.
9

Security measures

We implement TLS 1.2+, segregated admin accounts, encrypted devices for remote staff, quarterly access reviews, and vendor questionnaires. Incident response runbooks include notification timelines aligned with Articles 33–34 GDPR. No control eliminates all risk; please use unique passwords when creating optional accounts.

10

Automated decision-making and profiling

We do not perform automated decisions with legal effect. Lightweight segmentation for editorial surveys may cluster readers by geography or content tags, yet humans retain final discretion on outreach lists.

11

Data subject rights

You may request access, rectification, erasure, restriction, portability, and objection by emailing service@purifythbio.world with subject “DSR” plus a description of the right invoked. We verify identities proportionally. Responses normally ship within one month; complex cases may extend by two further months with explanation.

12

Supervisory authority contacts

Without prejudice to other remedies, you may lodge a complaint with the Berlin Commissioner for Data Protection and Freedom of Information (https://www.datenschutz-berlin.de) or your habitual residence authority under Article 77 GDPR.

13

Children

Offers target adults capable of forming valid consent. If guardians discover submissions from minors, notify us for prompt assessment and deletion where appropriate.

14

Business-to-business relationships

When you represent an organisation, we process your professional contact details under Article 6(1)(f) for negotiating contracts and maintaining supplier due diligence dossiers separate from consumer-facing archives.

15

Policy evolution and archives

Material updates receive a change log excerpt at the bottom of this page via the dynamic date stamp. Prior versions are stored offline for regulatory inquiries. Continued use after notification constitutes awareness unless fresh consent is legally required.

16

Contact points for privacy queries

Email remains the preferred channel for structured requests. Postal inquiries should reference “Privacy” on the envelope. If we designate a data protection officer in the future, this section will list direct coordinates.

Related instruments

Cookie mechanics · Cookie Policy. Contractual expectations · Terms of Use.

Company registry excerpt

Further legal disclosures appear in the Impressum consistent with German publishing law.

Purifythbio

Spine wellness guidance for curious adults. Content is informational and reviewed for cautious language.

Explore

  • Spine Care
  • Exercises
  • Contact

Policies

  • Privacy Policy
  • Cookie Policy
  • Terms of Use
  • Refund Policy
  • Impressum

Reach us

  • Badstraße 57-58, 13357 Berlin
  • +49 30 4614050
  • service@purifythbio.world
© Purifythbio · https://purifythbio.world

Cookies and similar data

We use essential cookies to run this site. Optional analytics or marketing cookies load only if you allow them. Read the Cookie Policy for details.

Strictly necessary

Required for security, form tokens, and preference storage.

Analytics / Marketing

Helps us understand readership patterns or support promotional experiments.

Privacy Policy