Privacy Policy
Do for Life · Website, bookings and events · Last updated: 01 October 2026 · Deutsch: Datenschutzbestimmungen auf Deutsch
This Privacy Policy applies to do-for.life, booking.do-for.life and the courses, weekend formats, Heidelberg retreats, live online offers and related communications provided through them. It describes the processing currently planned and used. Paid on-demand products and package travel are not currently part of this offering.
1. Controller
Pranado gGmbH
Zeppelinstr. 189
69121 Heidelberg
Germany
Represented by Dr. Björn Pospiech
Email: bjoern@do-for.life
General privacy contact: info@pranado.org
2. Principles and legal bases
We process personal data only where necessary to provide our website, communicate with you, take steps before entering into and perform contracts, deliver our programmes safely, or where you have given consent.
- Art. 6(1)(b) GDPR for pre-contractual steps and performance of contracts.
- Art. 6(1)(c) GDPR where legal obligations require processing or retention.
- Art. 6(1)(f) GDPR for legitimate interests, in particular secure and efficient operation of our systems, prevention of misuse and evidence of lawful processes.
- Art. 6(1)(a) GDPR for voluntary consent, in particular newsletters and photo/media permissions.
- Art. 9(2)(a) GDPR where you explicitly consent to the processing of health data.
3. Website, hosting, server logs and cookies
When you access our website, technically necessary connection and log data are processed, in particular IP address, time, requested URL, browser/device information and, where applicable, referrer. This is used to deliver the website, maintain stability, diagnose errors and protect security (Art. 6(1)(f) GDPR).
We currently do not use our own marketing or reach tracking. Technically necessary cookies or comparable storage/access may be used where strictly necessary to provide a digital service explicitly requested by you. Non-essential cookies or external content that accesses your device requires prior consent under section 25 TDDDG.
External content |
4. Contact and appointment booking
If you contact us by email, telephone, contact form or another communication channel we offer, we process the information you provide in order to respond and, where relevant, take pre-contractual steps (Art. 6(1)(b) GDPR; for general enquiries, Art. 6(1)(f) GDPR may also apply).
5. Bookings through pretix
We use pretix Hosted by pretix GmbH for bookings of paid and, where applicable, free events. Our booking system is available at booking.do-for.life and may also be embedded into our website as a widget.
Depending on the offer, we process in particular:
- contact details of the purchaser and/or participant (e.g. name, email, telephone number, address),
- booking, product, price, payment and invoice data,
- event-specific information such as experience, organisational preferences or support needs,
- where food is provided: relevant allergies or dietary requirements that you choose to provide,
- for suitable programmes: voluntarily provided health and safety information,
- for Solidarity Tickets: the information necessary to assess the requested price category.
The legal basis for general booking data is Art. 6(1)(b) GDPR. pretix Hosted processes data for us as a processor. According to pretix’s current documentation, Hosted data is processed exclusively within the European Union and stored in data centres in Germany.
6. Health and safety information, including breathwork
Some of our programmes include physical practice, martial arts, movement, meditation and breathwork. We do not routinely collect health data. Additional health-related questions are shown only where relevant to the safety of a specific programme.
For more intensive breathwork, we provide safety information and programme-specific contraindications. You may voluntarily tell us if a listed situation applies to you, if you are unsure, or if we should adapt individual practices. You do not need to provide a detailed medical history.
If you provide health data, we use it only to support safe delivery of the booked programme and, where needed, adapt individual practices. The legal basis is your explicit consent under Art. 9(2)(a) GDPR together with Art. 6(1)(a) GDPR. You may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal.
No blanket transfer of risk |
7. Food, allergies and support needs
Where food is included, we may ask about relevant allergies, intolerances or dietary requirements. These details are used only to plan and provide food safely. Health-related information is processed on the basis of your explicit consent. Other organisational preferences are processed for performance of the contract (Art. 6(1)(b) GDPR).
8. Payments and invoices
Depending on the offer and chosen payment method, payments may be processed through Mollie, SEPA direct debit through our banking process, or bank transfer. When Mollie is used, the payment, transaction and technical data required for the selected payment method are processed. Mollie acts as an independent controller to the extent that it determines the purposes and means of its payment processing.
For SEPA direct debit, we process in particular the account holder, IBAN, mandate data and payment status where required for collection. For bank transfers, we receive the account and transaction information necessary to allocate the payment.
Invoices and other accounting records are retained in accordance with legal requirements. Under current German law, accounting vouchers are generally retained for eight years; other records may be subject to different statutory periods.
9. CRM and event organisation with monday.com
We transfer data required for customer and event organisation from pretix to our monday.com CRM. This may include contact details, booked programmes, booking status and selected organisational information. Event-specific and sensitive information is kept technically separate and deleted when the purpose ends.
Our monday.com account uses the EU data region. monday.com notes that, depending on plan and subprocessors, individual processing operations may still take place outside the EEA. Where required, the applicable safeguards for international transfers are used.
10. Signal groups and event communication
For longer or more intensive programmes, we may use Signal for organisational communication, short-notice updates and group exchange. Signal messages and calls are end-to-end encrypted. According to Signal, the service itself cannot access the content of those communications.
If you join a Signal group, other group members can see your Signal profile. Whether your telephone number is visible to others depends, among other things, on your Signal privacy settings and whether another person already has your number stored. Signal also allows usernames to reduce exposure of your telephone number.
The group is used for event communication. You decide whether to remain in any continuing group after the programme ends. We ensure that essential contractual information is also reasonably accessible through an alternative communication channel.
11. Newsletter
If you voluntarily subscribe to the Do for Life newsletter, we use your email address to send information about Do for Life, new dates, courses, retreats, free content and similar offers. Subscription is voluntary and is not required to make a booking.
We use a double opt-in process. After subscribing, you receive a confirmation message; newsletter delivery is activated only after confirmation. In monday.com we store, in particular, the newsletter status, source of subscription and the time of subscription, confirmation and, where applicable, unsubscribe, to the extent necessary to manage and demonstrate consent.
The legal basis for newsletter delivery is your consent (Art. 6(1)(a) GDPR; electronic marketing is also subject to section 7 UWG). You may withdraw consent at any time via the unsubscribe link or by contacting us. After withdrawal, we no longer use your address for newsletters. Minimal proof data may remain restricted where required to demonstrate compliance or defend legal claims.
Newsletters are sent using the email infrastructure selected by Pranado for this purpose. Where an external email delivery or hosting provider is used, it receives only the data necessary for delivery and is integrated in accordance with applicable data-protection requirements.
12. Photos and recordings
Sessions are not routinely recorded. Identifiable photos or videos that go beyond a purely internal or private memory are created or published only on an appropriate legal basis, in particular separate voluntary consent. Refusing photo or publication consent has no disadvantage for participation.
13. Live online programmes
For live online courses or webinars, the platform used may process your name/display name, email address, connection data and any chat, audio or video content you choose to share. The platform is identified for the relevant offer. Recording takes place only if announced in advance and supported by an appropriate legal basis; by default, we do not record sessions.
14. Retention and deletion
We retain personal data only for as long as required for the relevant purpose or where legal obligations require longer retention.
- Health, safety, allergy and comparable event-specific information: generally deleted promptly after the relevant programme; as an organisational target, no later than four weeks afterwards unless a specific reason requires longer retention.
- Signal groups: there is no requirement to remain permanently; content stored on participants’ devices is not fully under our deletion control.
- Contact enquiries: after the communication has concluded and a reasonable follow-up period has passed, unless contractual or evidential requirements require retention.
- Booking and contract data: according to contract administration and applicable evidential/limitation periods.
- Invoices and accounting vouchers: according to statutory retention periods, currently generally eight years for accounting vouchers.
- Newsletter data: until withdrawal; afterwards only minimal proof where legally required.
15. Recipients and international transfers
Data is shared only with recipients that need it for the purposes described above. These may include pretix as processor for the booking system, monday.com for CRM and organisation, payment providers such as Mollie, our bank/payment service providers, hosting and email providers and – where you use them – Signal or the platform identified for a live online programme.
Where a service involves processing outside the EU/EEA, transfers take place only where the requirements of Arts. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.
16. Requirement to provide data
For a booking, we require the information necessary to perform the contract, handle billing and organise the programme safely. Without this information, we may not be able to complete a booking. Voluntary information – in particular newsletter, photo and non-required health information – is not a condition of entering into the contract.
17. Your rights
Subject to the statutory requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection to processing based on Art. 6(1)(e) or (f) GDPR. You may withdraw consent at any time with effect for the future.
You also have the right to lodge a complaint with a data-protection supervisory authority. The supervisory authority generally responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI Baden-Württemberg).
18. Security and updates
We use appropriate technical and organisational measures to protect personal data and restrict access to people who require it for their work. We update this Privacy Policy when our programmes, systems or the legal framework change.
Other Pranado programmes |