RELUMINARA.

Privacy Policy

Reluminara & The Levity Room • Last Updated: August 2026

1. General Information & Joint Controllership

The protection of your personal data is our highest priority. This Privacy Policy informs you how we collect and process your data when you visit reluminara.com and enroll in our programs, including The Levity Room.

According to Art. 26 GDPR, this website and the "Reluminara" programs are managed under a Joint Controllership between:

The Coach & Lead Controller:
Katherina Aldunate Kunstmann
Römerstraße 1, 55276 Dienheim, Germany
Email: [email protected]

The Technical & IP Partner:
Bálint Kurucz / Wolfhead Digital
Hévízi út 9.4, 1033 Budapest, Hungary
Email: [email protected]

Both parties have entered into a Joint Controller Agreement to determine their respective responsibilities for compliance with GDPR. Katherina remains your primary contact for any data privacy inquiries.

2. What Data Do We Collect?

We process personal data necessary to provide our digital programs, tools, and lead magnets cleanly and securely:

  • Personal & Identity Data: First name, last name, email address, phone number.
  • Lead Magnet & Marketing Data: Name and email address submitted via forms on reluminara.com to receive digital downloads, tools, and automated email sequences.
  • Payment & Transaction Data: Billing address, payment verification details (processed securely via encrypted gateways).
  • Coaching & Portal Data: Course progress, session attendance dates, program feedback, and portal engagement.

3. Legal Basis for Processing

We process your data based on the following legal grounds under the General Data Protection Regulation (GDPR):

  • Contractual Necessity (Art. 6(1)(b) GDPR): To process your purchase, provide access to the CC360 membership portal, deliver digital tools/PDF lead magnets, and facilitate live coaching calls.
  • Consent (Art. 6(1)(a) GDPR): For marketing tracking pixels (Meta/LinkedIn), analytics cookies, and newsletter subscriptions.
  • Legitimate Interest (Art. 6(1)(f) GDPR): To protect our shared Intellectual Property, secure our digital infrastructure, and optimize program performance.
  • Explicit Consent (Art. 6(1)(a) / Art. 9 GDPR): For processing any special category data voluntarily shared during coaching interactions (e.g., lifestyle, stress, or mental load insights).

4. Tech Infrastructure & Third-Party Services

To provide a seamless, executive-level experience, we utilize vetted third-party service providers:

Service / Vendor Purpose Legal Basis
Stripe / PayPal Payment Processing & Invoicing Contract (Art. 6.1b)
GoHighLevel (CC360) CRM, Portal Hosting & Email Workflows Contract (Art. 6.1b)
Zoom Live Interactive Coaching Sessions Contract (Art. 6.1b)
WhatsApp (Meta) Private Cohort Group Communication Contract / Consent (Art. 6.1a)
Meta (FB / IG) Pixel Ad Optimization & Tracking Consent (Art. 6.1a)
LinkedIn Insight Tag Conversion Tracking & Professional Retargeting Consent (Art. 6.1a)
Google Analytics 4 Website Usage Analysis Consent (Art. 6.1a)

5. Detailed Advertising & Analytics Disclosures

Cookies: We use cookies for functional necessity, analytics, and advertising. You can manage or revoke cookie consent at any time via your browser settings or opt-out tools. For detailed information, visit allaboutcookies.org.

LinkedIn Insight Tag: We use the LinkedIn Insight Tag to track conversion events, retarget website visitors, and gain professional insights into users who interact with our LinkedIn campaigns. LinkedIn collects data such as URL, referrer, IP address, device/browser characteristics, and timestamps. You can manage your ad preferences directly in your LinkedIn Account Settings.

Meta (Facebook & Instagram) Pixel: We use the Meta Pixel to measure ad effectiveness and deliver targeted content to visitors who have expressed interest in our programs. Data is hashed and processed by Meta Platforms Ireland Ltd. You can adjust your ad preferences within your Facebook or Instagram Ad Settings.

6. Data Storage & Retention

Data related to commercial transactions and course purchases is retained for 10 years to comply with German tax and commercial laws (AO / HGB). Marketing tracking data (pixels) is automatically anonymized or deleted within 180 days. Individual coaching progress records are retained for up to 2 years post-completion. All data is encrypted at rest and in transit.

7. Special Category Data

Any lifestyle or stress-related insights shared voluntarily during live integration calls or intake questionnaires are processed strictly under explicit consent (Art. 9 GDPR) for the sole purpose of delivering tailored coaching reframes.

8. Data Sharing Exceptions

We do not sell or rent personal data to third parties. Data sharing is limited to:

  • Professional coaching body audits (e.g., ICF verification logs restricted to name, contact details, and dates/hours).
  • Corporate employer billing verification if your program seat is sponsored or paid directly by your company.

9. Security Measures

We implement robust technical and organizational security measures (TOMs), including 256-bit SSL encryption, strict role-based access controls, and secure EU-compliant data routing.

10. Your Rights Under GDPR

As a data subject, you have the following enforceable rights:

  • Right of Access (Art. 15 GDPR): Request confirmation of what data we process.
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate data.
  • Right to Erasure (Art. 17 GDPR): Request deletion of your personal data ("Right to be Forgotten").
  • Right to Restriction & Object (Art. 18/21 GDPR): Restrict processing or object to direct marketing.
  • Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format.

To exercise any of these rights, contact us at [email protected]. We respond to all verified requests within one month.

11. Supervisory Authorities & Contacts

For inquiries, updates, or privacy concerns, please reach out to:

Lead Controller: Katherina Aldunate Kunstmann
Römerstraße 1, 55276 Dienheim, Germany
Email: [email protected]

You also maintain the right to lodge a formal complaint with a competent Data Protection Supervisory Authority:

  • The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate (LfDI RLP): [email protected]
  • Federal Officer for Data Protection and Freedom of Information (BfDI): [email protected]

12. International Data Transfers

Where non-EU technical infrastructure or software tools are utilized (e.g., US-based payment processors or infrastructure nodes), transfers are safeguarded through standard contractual clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR.

Home • Privacy Policy • Terms of Service • Legal Notice / Impressum

© 2026 Reluminara (reluminara.com). All Rights Reserved.