This Privacy Policy explains how Galighticus collects, uses, stores, and protects your personal data. We are committed to your privacy and comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Who is responsible for your data
Galighticus acts as the data controller for personal data collected through our website, shop, programmes, events, and community platform. As data controller, we determine how and why your personal data is processed.
Galighticus is headquartered in New York, United States, and serves a worldwide audience. Our contact details for all data protection matters are available on our Contact page. If you have privacy concerns or wish to exercise your rights, please contact us there.
Personal data we collect
Identity and contact data: name, email address, telephone number, billing and shipping address, and account username.
Transaction data: order history, purchases, payment method type (we do not store full card numbers), refund records, and subscription history.
Programme and service data: enrolment records, session notes shared with us, progress data, certificates, and your correspondence with our team.
Community and event data: posts, comments, profile information, event registrations, attendance records, and any accessibility or dietary preferences you provide.
Technical data: IP address, browser type, device identifiers, operating system, pages visited, time on page, referral source, and cookie identifiers.
Marketing data: your communication preferences and responses to our marketing communications.
How we collect your data
Directly from you when you create an account, place an order, enrol in a programme, register for an event, participate in our community, or contact our support team.
Automatically through cookies, analytics tools, and similar technologies when you visit our website. Our Cookie Policy provides full details.
From third-party services where you choose to connect social accounts or where we receive necessary data from payment processors and shipping partners to fulfil your orders.
Why we use your data (legal basis)
Performance of a contract: to process orders, deliver products and digital content, provide programme access, fulfil service bookings, and manage your account. This processing is necessary to perform our contract with you and we cannot provide our services without it.
Legal obligation: to comply with tax, accounting, and other legal requirements. We retain certain transaction and financial records as required by law, regardless of account status.
Legitimate interests: to send you service-related communications (order confirmations, programme reminders, important platform updates), improve our platform, ensure security, prevent fraud, and manage our community. Error monitoring (for example Sentry) helps us diagnose failures when something goes wrong — not to track routine browsing. We balance our legitimate interests against your rights and do not override your fundamental privacy interests.
Consent: to send you marketing communications, newsletters, or promotional offers; and to place analytics cookies and similar technologies when you choose Accept analytics on our cookie banner (product usage metrics — not continuous session replay). You can withdraw consent at any time using Cookie settings in our website footer, by clearing site data for Galighticus in your browser, or by contacting us. Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal.
We will not use your personal data for purposes that are incompatible with those described here without first notifying you.
How long we keep your data
Account data is retained for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 90 days, except where we are legally required to retain it.
Transaction and financial records are retained for 7 years to comply with applicable tax and accounting obligations.
Marketing data is retained until you withdraw consent or request deletion.
Technical and analytics data is retained for up to 26 months, after which it is deleted or fully anonymised.
Community content may be retained in anonymised form after account deletion to preserve the integrity of conversations, where removing it would affect others.
International data transfers
Our platform and some of our service providers may process personal data outside your country of residence, including in the United States. Galighticus is based in New York, USA.
When you opt in to analytics on our website or community app, usage data may be processed by PostHog (PostHog Inc.) on PostHog's US cloud infrastructure (https://us.posthog.com). Where personal data is transferred from the European Economic Area (EEA), United Kingdom, or other jurisdictions that require safeguards, we rely on appropriate mechanisms — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement where applicable, or transfers to countries with an adequacy decision — together with PostHog's Data Processing Agreement and contractual protections with our subprocessors.
You may request information about the specific safeguards applied to any international data transfer by contacting us.
Your rights under GDPR
Right of access: you may request a copy of the personal data we hold about you at any time.
Right to rectification: you may ask us to correct inaccurate or complete incomplete data.
Right to erasure ("right to be forgotten"): you may ask us to delete your personal data, subject to our legal retention obligations.
Right to restriction of processing: you may ask us to limit how we use your data in certain circumstances (for example, while a dispute is being resolved).
Right to data portability: you may receive your data in a structured, commonly used, machine-readable format to transfer to another service.
Right to object: you may object to processing based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will stop immediately.
Right to withdraw consent: where processing relies on your consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us via our Contact page. We will respond within 30 days. If your request is complex or numerous, we may extend this by a further 60 days with notice. You also have the right to lodge a complaint with your national data protection authority.
Children's privacy
Our platform is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 16, please contact us and we will delete it promptly.
Participation in certain events or programmes may require parental or guardian consent for users aged 16–17 where required by applicable local law.
Security measures
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. Measures include encryption of data in transit and at rest, strict access controls, and regular security reviews.
No method of data transmission or storage over the internet is completely secure. While we work hard to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Article 34.
Changes to this policy
We may update this Privacy Policy periodically to reflect changes in our data practices or legal requirements. We will notify you of significant changes by email or by posting a prominent notice on our website before the changes take effect.
The date shown at the top of this page indicates when the policy was last updated.
Questions about this document?
Contact support →