Privacy policy

  1. Overview of data protection

General information
The following notice provides a clear overview of what happens to your personal data when you visit the reblume website or engage with our services. Personal data is any information that can be used to identify you personally.

Scope of services & health disclaimer
reblume offers wellness consulting, educational workshops, and lifestyle coaching. We do not provide medical diagnosis, clinical treatment, or psychotherapy.

Quick summary of data processing

Data Controller
reblume, operated by Inbal Mizrach (Berlin, Germany). Contact: hello@reblume.eu.

How we collect data
Directly when you voluntarily provide it (booking calls, subscribing to newsletters, enrolling in programs) and automatically through necessary website cookies and server logs.

Tools & processors used
We use third-party providers to deliver our services, including Framer (hosting), Kit (newsletters), Square & Google Calendar (booking), Zoom & Fathom AI (video sessions and transcripts), WhatsApp & Telegram (messaging/community), and Stripe (payments).


Your rights
You have full rights under the GDPR to access, rectify, or delete your personal data, object to processing, or withdraw consent (e.g., opting out of marketing emails or AI call summaries) at any time.

For full details on legal bases, storage durations, and individual processing activities, please read the complete policy sections below.

General information
The following notice provides a clear overview of what happens to your personal data when you visit the reblume website or engage with our services. Personal data is any information that can be used to identify you personally.

Scope of services & health disclaimer
reblume offers wellness consulting, educational workshops, and lifestyle coaching. We do not provide medical diagnosis, clinical treatment, or psychotherapy.

Quick summary of data processing

Data Controller
reblume, operated by Inbal Mizrach (Berlin, Germany). Contact: hello@reblume.eu.

How we collect data
Directly when you voluntarily provide it (booking calls, subscribing to newsletters, enrolling in programs) and automatically through necessary website cookies and server logs.

Tools & processors used
We use third-party providers to deliver our services, including Framer (hosting), Kit (newsletters), Square & Google Calendar (booking), Zoom & Fathom AI (video sessions and transcripts), WhatsApp & Telegram (messaging/community), and Stripe (payments).


Your rights
You have full rights under the GDPR to access, rectify, or delete your personal data, object to processing, or withdraw consent (e.g., opting out of marketing emails or AI call summaries) at any time.

For full details on legal bases, storage durations, and individual processing activities, please read the complete policy sections below.

General information
The following notice provides a clear overview of what happens to your personal data when you visit the reblume website or engage with our services. Personal data is any information that can be used to identify you personally.

Scope of services & health disclaimer
reblume offers wellness consulting, educational workshops, and lifestyle coaching. We do not provide medical diagnosis, clinical treatment, or psychotherapy.

Quick summary of data processing

Data Controller
reblume, operated by Inbal Mizrach (Berlin, Germany). Contact: hello@reblume.eu.

How we collect data
Directly when you voluntarily provide it (booking calls, subscribing to newsletters, enrolling in programs) and automatically through necessary website cookies and server logs.

Tools & processors used
We use third-party providers to deliver our services, including Framer (hosting), Kit (newsletters), Square & Google Calendar (booking), Zoom & Fathom AI (video sessions and transcripts), WhatsApp & Telegram (messaging/community), and Stripe (payments).


Your rights
You have full rights under the GDPR to access, rectify, or delete your personal data, object to processing, or withdraw consent (e.g., opting out of marketing emails or AI call summaries) at any time.

For full details on legal bases, storage durations, and individual processing activities, please read the complete policy sections below.

  1. Responsible party (Data controller)

The party responsible for processing data on this website and for reblume services (the "Data Controller") pursuant to Art. 4 No. 7 GDPR is:

Inbal Mizrach
Schefferweg 2
12249 Berlin
Germany

Email: hello@reblume.eu
Phone: +49 155 67640245

  1. Website hosting, cookies, and embedded forms (Framer & Kit)

Hosting provider (Framer)
Our website is hosted on the Framer platform (Framer B.V., Netherlands). Framer automatically processes server log files (IP address, browser type, operating system, access time) to ensure the technical security and reliable delivery of the site pursuant to Art. 6(1)(f) GDPR (legitimate interest).

Cookies and third-party embeds
This website uses essential technical cookies required for Framer to operate securely. Additionally, when you interact with embedded features on our site, such as email subscription forms provided by Kit (Kit, Inc.), cookies, pixels, or local storage technologies may be deployed to manage form submissions, recognize returning subscribers, and prevent spam.

Legal basis
Where cookies are strictly necessary for core site functionality, they are processed under § 25(2) No. 2 TDDDG. For functional or preference-based tracking technologies associated with third-party tools like newsletter forms, we rely on your prior consent (Art. 6(1)(a) GDPR / § 25(1) TDDDG), collected via our site interface where applicable.

  1. Newsletter and updates (Kit Inc.)

Newsletter and updates (Kit)
If you subscribe to our newsletter or field notes, we collect your email address and optional name. We use Kit Inc. as our email delivery service provider.

Purpose & processing
Kit stores your subscriber details and tracks engagement metrics (such as email opens and link clicks) to help us deliver and improve our content.

Legal basis
Processing is based on your explicit consent (Art. 6(1)(a) GDPR) via a Double Opt-In process.

Unsubscribing
You can withdraw your consent and unsubscribe at any time by clicking the "Unsubscribe" link at the bottom of any email.

International transfers
Kit processes data in the United States. Data transfers are safeguarded under Data Processing Agreements (DPAs) incorporating EU Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.

  1. Communication via WhatsApp Business

We use WhatsApp Business and/or Telegram to communicate with clients regarding bookings, inquiries, and session-related information, as well as to host early-stage community channels. With your explicit prior consent, we may also send you occasional updates or offers.

Data processing
When you message us or join our community spaces, WhatsApp Ireland Limited (Meta Platforms Ireland Ltd.) or Telegram (Telegram FZ-LLC) processes your phone number, message content, profile details, and related metadata. These data are processed on servers that may be located outside the EU, including in the United States.

Community privacy
For group updates and community broadcasts, we utilize WhatsApp Community Announcement Channels or Telegram channels, where member phone numbers and personal contact details remain hidden from other community participants.

International transfers
WhatsApp is part of Meta Platforms, Inc. (USA). Data processed via WhatsApp may be transferred to the US. Meta Platforms Ireland Ltd. participates in the EU-US Data Privacy Framework, which provides safeguards for such transfers. Transfers to Telegram are safeguarded under EU Standard Contractual Clauses (SCCs) and relevant data privacy frameworks.

Legal basis For communicating about your bookings, inquiries, and sessions
Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures). For sending you optional promotional broadcasts or community updates: Art. 6(1)(a) GDPR (your explicit consent).

Revoking consent
You can revoke your consent to promotional communications or leave community channels at any time by messaging us "STOP" or opting out directly within the messaging app. This will not affect the lawfulness of processing based on consent before its withdrawal. You can also ask us at any time not to contact you via instant messaging for service-related matters; in that case, we will use other contact channels you have provided.

  1. Call booking and scheduling (Square)

When you schedule a discovery call or paid 1:1 session through our website, you are using our integrated external booking service provided by Square.

Data collected
Name, email address, phone number, payment details (for paid sessions), and any notes or background information you choose to provide prior to the call.

Purpose & legal basis
This data is processed pursuant to Art. 6(1)(b) GDPR to execute pre-contractual measures, organize our consultation session, and fulfill paid service contracts.

Third-party processing & calendar synchronization
Booking requests, payment transactions, and appointment details are processed by Square (Block, Inc.). Confirmed appointments are synchronized with Google Calendar (Google Ireland Limited / Google LLC) to manage availability and prevent scheduling conflicts (Art. 6(1)(f) GDPR). Payments are processed securely via Square; we do not store raw credit card details on our servers.

  1. Live sessions, community platforms, cohorts and labs (Zoom, Fathom AI, Skool / Circle)

For our workshops, community interaction, live group sessions, 1:1 coaching calls, and member platforms, we utilize Zoom (Zoom Video Communications, Inc.), Fathom AI (Fathom Video Inc.), and dedicated community software providers including Skool (Skool Games Inc.) or Circle (CircleCo, Inc.).

Data collected Profile details (name, email address, profile photo), program participation data, video/audio metadata, community posts and comments, free-trial eligibility records, recurring subscription status, and transcript or chat text during live calls.

Legal basis
Data processing for live sessions, community participation, free-trial access management, and membership management is conducted pursuant to Art. 6(1)(b) GDPR for the execution and fulfillment of your reblume cohort, trial, or paid membership contract.

Live Session Recording & AI Summary Policy

Group cohort calls & lectures Group cohort sessions and lectures may be recorded or transcribed using integrated platform features to generate automated session summaries, key takeaways, and replay access exclusively for registered participants of that specific cohort (Art. 6(1)(b) GDPR). Audio or video recordings will display an automated consent pop-up notification prior to recording.

Private 1:1 coaching sessions & Fathom AI
Private 1:1 coaching calls are never recorded, transcribed, or processed using AI summary tools (such as Fathom AI) unless you give explicit verbal or prompt-based consent at the start of the session (Art. 6(1)(a) GDPR). Transcripts and summaries generated via Fathom AI are used solely to deliver your personal recap notes. You may decline recording or request the removal of the AI assistant at any time during a call.

Breakout rooms
Peer-to-peer breakout rooms and private interactions between participants during live group sessions are strictly excluded from all recording and AI analysis.

Strict access and no AI model training
Automated summaries, session recordings, and community spaces are kept within secure, non-redistributable channels for your cohort or community access. Neither reblume nor our platform providers (Zoom / Fathom AI / Skool / Circle) use participant personal data, audio, video, or transcripts to train public artificial intelligence models.

Security & compliance
All platform providers process data under Data Processing Agreements (DPAs) incorporating EU Standard Contractual Clauses (SCCs) and encryption standards to ensure full GDPR data protection compliance.

  1. Off-site onboarding, contracts & billing (Stripe)

If you enroll in or purchase any paid reblume service (including 1:1 coaching, workshops, or paid community memberships), we collect personal and billing data (such as full legal name, physical/company address, email address, phone number, and payment details) to execute service contracts, issue legal invoices, and process payments.

Payment processing via Stripe
For billing and transactions executed outside the website interface (e.g., direct payment links or invoice links sent via contract), we use Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.). Stripe processes your payment details, billing address, and transaction metadata securely. We do not store raw credit card details on our servers.

Legal basis
Art. 6(1)(b) GDPR (Performance of a Contract) and Art. 6(1)(c) GDPR (Compliance with legal obligations under German commercial and tax law, e.g., invoice retention requirements under § 14b UStG). Transfers to Stripe, Inc. (USA) are safeguarded under the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs).

  1. Your rights under the GDPR

Under the EU General Data Protection Regulation (GDPR), you have the following rights:

Right of access (Art. 15 GDPR):
Request details regarding any personal data stored about you.

Right to rectification (Art. 16 GDPR):
Request correction of inaccurate or incomplete data.

Right to erasure (Art. 17 GDPR):
Request deletion of your personal data, provided statutory retention periods do not apply.

Right to restriction of processing (Art. 18 GDPR):
Request restriction of processing under legal conditions.

Right to data portability (Art. 20 GDPR):
Receive your personal data in a structured, machine-readable format.

Right to object (Art. 21 GDPR):
Object to processing based on legitimate interests.

Right to withdraw consent (Art. 7(3) GDPR):
Withdraw any previously given consent with future effect.

Right to file a complaint:
File a complaint with a supervisory authority. The competent authority for Berlin is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany.

10. Data retention & storage duration

Personal data is retained only for as long as necessary to fulfill the intended purpose, or as required by statutory German retention periods:

Tax and commercial financial records
Legal invoices, payment records, and contract documents are retained for up to 10 years in accordance with § 147 Abgabenordnung (AO) and § 14b UStG, and up to 6 years for commercial correspondence under § 257 Handelsgesetzbuch (HGB).

Direct general inquiries (email, telephone)
Deleted once your inquiry has been fully resolved, typically within 6–12 months, unless a contractual relationship results.

WhatsApp & messaging data
Retained only as long as necessary to handle your active booking or ongoing client relationship, then deleted from active devices.

Newsletter subscribers (Kit, Inc.)
Retained for as long as you remain subscribed to our mailing list. Once you unsubscribe, your email address is removed from active broadcast lists.

Live call recordings & cohort material
Stored securely for the duration of the active cohort/program and deleted or archived in accordance with program access terms.

11. Scope of coaching & health disclaimer

The services, content, and programs offered by reblume are intended solely for educational, preventative lifestyle, and personal wellness coaching purposes. They do not constitute medical advice, medical diagnosis, clinical treatment, or psychotherapy, and are not intended to replace professional medical care or treatment by a licensed physician, psychotherapist, or licensed alternative medicine practitioner (Heilpraktiker).

Create a free website with Framer, the website builder loved by startups, designers and agencies.