Privacy Policy
Last updated: 15 July 2026
My Inner Center ("we", "us", "our") is a service that creates personalized guided meditation and inner-child sessions from the information you share with us. This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Spanish data protection law.
Please read it carefully. Some of the information you may share with us (for example, answers about your emotional wellbeing) is sensitive, and we treat it with particular care as described below.
1. Who is responsible for your data
The data controller is:
Inner Spark Center S.L.
Carrer de Floridablanca 68, Coworking Local 9F, 08015 Barcelona, España
VAT: ESB12345678
Email: [email protected]
For any question about this policy or your personal data, or to exercise your rights, write to us at [email protected].
2. What we collect and why
We only collect information we need to answer you, create your session, deliver it, and run the website. The sections below group what we collect by situation.
When you browse the website
We collect standard technical and usage data: your IP address, browser and device type, pages viewed, and how you arrived at the site (including referral source and, where present, advertising click identifiers). We use Google Analytics 4 for aggregate audience statistics, and we record basic attribution information (such as the campaign or link that brought you to us) so we understand which content works. This is described further in the Cookies section below.
When you subscribe to the newsletter
We collect your email address so we can send you the updates and content you asked for. You can unsubscribe at any time using the link in every email.
When you request or purchase a session
To prepare a personalized session we collect the answers you give in our session forms. Depending on the session this can include your first name, the name or pronoun you would like to be addressed by, your email address, your phone number (if you provide one), your age range, your country, your preferred language, your voice, speed and background-music preferences, and your free-text answers to the session questions.
Those free-text answers are the heart of the service, and they often describe your feelings, personal history, difficulties, beliefs and goals. Some of this is sensitive information about your mental and emotional wellbeing. We treat it as a special category of data (see section 3).
When you pay
Payments are processed by Stripe. We do not see or store your full card number. Stripe handles the card data and shares with us only what we need to confirm the purchase (such as your name, email, and the fact that payment succeeded). Stripe acts as an independent controller for the payment data it processes; see Stripe's own privacy policy for details.
Data we generate about you
To deliver the service we also create some information ourselves: a short internal summary of your situation (generated by an AI model to help us prepare and personalize your session), the audio files of your session, a timeline of our interactions with you (forms submitted, sessions generated and delivered, messages exchanged), and, where relevant, an internal safety flag. The safety flag exists so that answers suggesting distress or risk of harm are reviewed by a person before anything is sent automatically. It is used only to protect you and to handle your request responsibly.
3. Sensitive ("special category") data
Some of the answers you give us concern your mental and emotional health. Under Article 9 GDPR this is a special category of personal data that receives extra protection.
We process it only on the basis of your explicit consent, which we ask for in the session form before you submit your answers. You are never required to share more than you want to. You can withdraw this consent at any time by contacting us, and we will stop using that data and delete it on request (see sections 6 and 7).
We do not use this data to make any automated decision that produces legal or similarly significant effects about you. A person is always involved in reviewing and approving your session before it is delivered.
4. Legal bases
Under the GDPR we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): to create and deliver the session you requested and to provide customer support.
- Explicit consent (Article 9(2)(a)): to process the sensitive wellbeing information in your answers, and (Article 6(1)(a)) to send you the newsletter and to use non-essential analytics and attribution cookies.
- Legitimate interests (Article 6(1)(f)): to keep the website secure, prevent abuse, understand aggregate usage, and improve our service, balanced against your rights.
- Legal obligation (Article 6(1)(c)): to keep records we are legally required to keep, for example for tax and accounting.
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Who we share it with
We do not sell your personal data. We share it only with service providers ("processors") that help us run the service, and only to the extent each needs to do its job. Each is bound by a data processing agreement. Our main providers are:
- Supabase — database and file storage for your answers, session documents and audio, hosted in the European Union.
- OpenAI — generates some drafted text fields through its API. Data sent through the API is not used to train its models.
- Brevo (Sendinblue) — sending session delivery emails, reminders and the newsletter.
- Stripe — payment processing.
- Google Analytics (Google Ireland/LLC) — website audience statistics.
- Cloudflare — hosting and delivery of the public website.
- Vercel — hosting of the application that produces and serves your session.
We may also disclose data if required by law, to establish or defend legal claims, or to protect the safety of a person.
6. International transfers
Some of these providers are based outside the European Economic Area, mainly in the United States. When your data is transferred outside the EEA, we rely on appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU-US Data Privacy Framework. You can ask us for more detail about the safeguards in place.
7. How long we keep it
We keep your personal data only as long as needed for the purposes above:
- Session answers, generated sessions and interaction history: for as long as you remain a client and up to 36 months after your last activity with us, so we can provide follow-up and support, then deleted or anonymized.
- Newsletter subscription: until you unsubscribe or ask us to remove you.
- Payment and invoicing records: for six years, as required by the Spanish Commercial Code (Código de Comercio, Article 30).
- Website analytics: for 14 months, the maximum retention period offered by Google Analytics 4.
When data is no longer needed, we delete it or irreversibly anonymize it.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability, receiving your data in a structured, machine-readable format;
- withdraw consent at any time, including consent to process your sensitive answers or to receive the newsletter.
To exercise any of these, email [email protected]. We will respond within one month. We may need to verify your identity first to protect your data.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or the supervisory authority in your country of residence.
9. Children
The service is intended for adults. Some sessions may be requested for or by younger people, and our forms ask for an age range so that requests involving a minor receive appropriate human review. If you are under 18, please only use the service with the involvement of a parent or guardian. If you believe a minor has given us personal data without appropriate consent, contact us and we will delete it.
10. Cookies and analytics
We use a small number of cookies and similar technologies:
- Essential storage that makes the site and forms work.
- Analytics (Google Analytics 4) to understand aggregate usage.
- Attribution storage that remembers how you arrived at the site (for example the referring link or campaign, and advertising click identifiers such as Google or Facebook click IDs) so we can measure which content brings people to us.
Non-essential cookies (analytics and attribution) are only used after you give consent through our cookie banner, and you can change or withdraw that choice at any time.
11. How we protect your data
We use reputable providers, restrict access to your data to the people who need it, protect our systems with authentication, and keep credentials out of our public code. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your information.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date at the top and, where appropriate, notify you.
13. Contact
For any privacy question or request, contact us at [email protected].