Privacy Policy

Privacy Policy – Mystika School
Mystika School · Legal

Privacy
Policy

Mystika School Limited
Effective Date: June 2026

We respect your privacy. We collect only what we need, we never sell your personal data, and we are transparent about how we use it. This policy explains everything clearly — without legal jargon where it can be avoided.

This Privacy Policy explains how Mystika School Limited (“Mystika School”, “we”, “us”, “our”) collects, uses, discloses, and protects your personal information when you visit mystikaschool.com or purchase our products and programmes.

Data Controller: Mystika School Limited

21st Floor, CMA Building, 64 Connaught Road, Central, Hong Kong

Privacy enquiries: support@mystikaschool.com

By using our website or purchasing our programmes, you agree to the collection and use of information in accordance with this policy.

01

Who We Are

Mystika School is an online mystery school offering spiritual education, initiatory programmes, and transformational practices. We are incorporated in Hong Kong and serve participants globally.

For the purposes of data protection law — including the EU General Data Protection Regulation (GDPR) and the UK GDPR — we act as the data controller for personal data collected through our website and programmes.

02

What Data We Collect

Personal Data You Provide

  • Identity data: name, username
  • Contact data: email address, billing address
  • Financial data: payment details (processed securely via Stripe — we do not store raw card numbers)
  • Account data: login credentials, purchase history, course progress
  • Application data: responses to programme application forms
  • Communications data: enquiries, support messages, feedback

Technical & Usage Data (Collected Automatically)

  • IP address and approximate location
  • Browser type and version, device type
  • Pages visited, time spent, referral source
  • Interaction with emails (opens, clicks)
  • Advertising interaction data (via Meta Pixel, Google Analytics)

Special Category Data

Our application forms may ask about health conditions or personal circumstances relevant to participation in breathwork or somatic practices. This information is collected under your explicit consent and is used solely to assess suitability and ensure your safety. It is not shared with third parties except where required by law.

03

How We Collect Data

  • When you place an order or create an account
  • When you complete a programme application form
  • When you subscribe to our email list
  • When you book a call via Calendly
  • Through cookies, pixels, and tracking technologies (see Section 5)
  • Through advertising platforms (Meta, Google)
  • When you contact us by email or through our website
04

Why We Use Your Data & Our Legal Basis

We only process your data where we have a lawful basis to do so. The table below sets this out clearly:

Purpose Legal Basis
Processing your order and delivering programmes Contract performance
Managing your account and customer support Contract performance
Sending transactional emails (receipts, booking confirmations) Contract performance
Sending marketing emails and newsletters Consent (you can unsubscribe at any time)
Running advertising campaigns (Meta, Google) Consent (via cookie banner)
Website analytics and improvement Legitimate interests
Fraud prevention and security Legitimate interests
Tax, accounting, and legal compliance Legal obligation
Assessing suitability for intensive programmes Explicit consent
05

Cookies & Tracking Technologies

We use cookies and similar technologies on our website. You can manage your cookie preferences via our cookie consent banner when you first visit the site.

Types of Cookies We Use

  • Essential cookies: Required for the website and shop to function. Cannot be disabled.
  • Analytics cookies: Google Analytics — helps us understand how visitors use our site. Only active with your consent.
  • Marketing cookies: Meta Pixel and Google Ads — used for advertising, retargeting, and conversion tracking. Only active with your consent.
  • Functional cookies: Remember your preferences, login state, and cart contents.

Meta (Facebook) Pixel & Conversions API

We use the Meta Pixel and Meta Conversions API (via PixelYourSite Pro) to measure the performance of our advertising and improve ad relevance. This may transmit data including IP address, browser information, purchase events, and page views to Meta Platforms, Inc.

Meta processes this data in accordance with its own Privacy Policy. You can manage your Meta ad preferences at facebook.com/ads/preferences.

Google Analytics & Google Ads

We use Google Analytics to understand website behaviour and improve user experience, and Google Ads for advertising and remarketing. You can opt out via the Google Analytics Opt-out Browser Add-on.

Managing Cookies

You can withdraw your consent for non-essential cookies at any time via our cookie banner or by adjusting your browser settings. Note that disabling certain cookies may affect the functionality of our website.

06

Third-Party Data Processors

We do not sell your personal data. We may share data with the following trusted service providers who process data on our behalf under contractual safeguards:

Provider Purpose Data Shared Privacy Policy
Stripe Payment processing Name, email, payment details, billing address stripe.com/privacy
WooCommerce / WordPress E-commerce platform Order data, account data automattic.com/privacy
Meta Platforms Advertising & analytics IP address, browser data, purchase events facebook.com/privacy
Google Analytics & advertising Usage data, IP address policies.google.com/privacy
Email service provider Email marketing & delivery Name, email address, email engagement data Per provider
Calendly Booking introductory calls Name, email, timezone, booking data calendly.com/privacy
YouTube / Google Video hosting IP address, viewing data (if cookies accepted) policies.google.com/privacy
Website hosting provider Web hosting & infrastructure Server logs, IP addresses Per provider
07

International Data Transfers

As Mystika School operates globally and uses international service providers, your data may be transferred to and processed in countries outside your country of residence, including the United States.

Where transfers occur from the European Economic Area (EEA) or the United Kingdom to countries not deemed adequate by the relevant authority, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms to protect your data.

08

Data Retention

We retain your personal data only for as long as necessary for the purposes it was collected. Our general retention periods are:

  • Customer & order data: 7 years from the date of purchase (required for tax and accounting compliance)
  • Programme participation records: Duration of the programme + 3 years
  • Marketing consent records: Until you unsubscribe, then 3 years for compliance records
  • Application form data (health-related): 12 months from submission, unless enrolment proceeds
  • Website analytics data: 26 months (Google Analytics default)
  • Support communications: 3 years from resolution

When data is no longer required, it is securely deleted or anonymised.

09

Your Rights

Depending on your location, you have the following rights regarding your personal data. We will respond to all requests within 30 days.

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate or incomplete data.

Erasure

Request deletion of your data (“right to be forgotten”), subject to legal retention obligations.

Restriction

Request that we limit processing of your data in certain circumstances.

Portability

Request a machine-readable copy of your data to transfer to another service.

Object

Object to processing based on legitimate interests or for direct marketing purposes.

Withdraw Consent

Withdraw consent at any time where processing is based on consent. This does not affect prior processing.

Automated Decisions

Request human review of any decision made about you solely by automated means.

To exercise any of these rights, email support@mystikaschool.com with your request. We may need to verify your identity before processing the request.

EU & UK Residents

You have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO). In the EU, contact your national Data Protection Authority.

10

Children’s Privacy

Our programmes are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us immediately at support@mystikaschool.com and we will delete it.

11

Sensitive & Special Category Data

Some of our programme application forms ask about health conditions, mental health history, or personal circumstances relevant to participating in breathwork, somatic, or energetic practices. This is for your safety.

This data is classified as special category data under GDPR and equivalent laws. We process it only with your explicit consent, which you can withdraw at any time. It is stored securely, accessed only by relevant programme staff, and is never used for marketing or shared with third parties except where required by law.

12

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect, use, and disclose
  • The right to delete your personal information
  • The right to opt out of the “sale” of personal information
  • The right to non-discrimination for exercising your rights
We Do Not Sell Your Data

Mystika School does not sell personal information to third parties. We share data only with service providers under contractual safeguards for the purposes described in this policy.

To submit a CCPA request, email support@mystikaschool.com with “CCPA Request” in the subject line.

13

Policy Updates

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on our website, with an updated effective date at the top of this page.

We encourage you to review this policy periodically. Continued use of our website or programmes after changes constitutes acceptance of the updated policy.

14

Contact Us & How to Complain

For any questions, requests, or concerns about this Privacy Policy or how we handle your data:

Mystika School Limited

21st Floor, CMA Building, 64 Connaught Road, Central, Hong Kong

Email: support@mystikaschool.com

Subject line: Privacy Request

We aim to respond to all privacy-related enquiries within 5 business days and to resolve requests within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority:

© 2026 Mystika School Limited · All rights reserved

Terms & Conditions  ·  TTC Sacred Agreement  ·  High Tantra Sacred Agreement