BeyondThoughts
Legal

Privacy Policy

Last updated: July 2026

This policy explains how Beyond Thoughts (operated by Mayank Mishra, Berlin, Germany) collects, uses and protects personal data in connection with beyondthoughts.net and the sessions offered here.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Who is responsible for your data

Mayank Mishra
Heinrich-Hertz-Str. 6, c/o Mehra, [Postcode] Berlin, Germany
Email: cuttingnoiseswithbets@gmail.com

2. What we collect, and why

When you visit the website

Our hosting providers automatically record standard server log data, IP address, browser type, operating system, pages requested, timestamp. This is used for security and technical operation and is not used to identify you. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

When you create an account or sign in

We store your email address, and your name, date of birth and time zone if you choose to give them. Sign-in is by emailed one-time link or by Google sign-in; we never store a password. Legal basis: Art. 6(1)(b) GDPR (performance of a contract), and Art. 6(1)(f) for account security.

When you pay for a session

Payments are processed by Stripe. Stripe collects your name, email address, card details and billing information. We receive confirmation of payment, your email address and a payment reference, we never see or store your card details. We also record the timestamp of your consent to begin the service within the withdrawal period, because the law requires us to be able to evidence it. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) for the records we are obliged to keep.

When you schedule a session

Scheduling is handled by zcal. When you choose a time, zcal receives your name, email address, time zone and chosen slot, and returns the booking details to us. Legal basis: Art. 6(1)(b) GDPR.

When you attend a session

Sessions take place on Zoom, which processes the connection data needed to host the call. Sessions are not recorded. We take written notes during or after the session for the sole purpose of preparing your written summary; those notes are shared with no one and are deleted within 90 days. Legal basis: Art. 6(1)(b) GDPR.

When you give a testimonial

If you volunteer a testimonial and agree to its use, we may publish it in exactly the form you agree to. Legal basis: Art. 6(1)(a) GDPR (consent), which you may withdraw at any time.

3. Cookies

This site sets no tracking or analytics cookies and runs no analytics product. If you sign in, we set a strictly necessary session cookie so that you stay signed in, without it, signing in cannot work, so no consent banner is required for it (§ 25(2) TDDDG).

Fonts are self-hosted and served from our own domain, so loading a page makes no request to Google. Stripe, zcal and Zoom may set their own cookies once you interact with their services; their policies apply there.

4. Processors we use

  • Stripe Payments Europe, Ltd., payment processing. Some processing takes place outside the EU under EU Standard Contractual Clauses. stripe.com/privacy
  • zcal, appointment scheduling. Processed in the US under EU Standard Contractual Clauses. zcal.co/privacy
  • Zoom Communications, video calls, under EU Standard Contractual Clauses. zoom.us/privacy
  • Supabase, database hosting, EU region.
  • Resend, transactional email: sign-in links, booking confirmations and your written summary.
  • Google, only if you choose Google sign-in, in which case Google confirms your identity and email address to us.
  • [Website and API hosting providers], server logs, as described above.

5. How long we keep it

Only as long as necessary for the purposes above, or as long as the law requires. Payment and invoice records are kept for 10 years under German commercial and tax law (§ 257 HGB, § 147 AO). Session notes are deleted within 90 days. Account data is kept until you ask us to delete it.

6. Your rights

You have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR)
  • Have inaccurate data corrected (Art. 16 GDPR)
  • Have your data deleted (Art. 17 GDPR)
  • Restrict how we process it (Art. 18 GDPR)
  • Receive it in a portable format (Art. 20 GDPR)
  • Object to processing based on legitimate interest (Art. 21 GDPR)
  • Withdraw consent at any time, without affecting processing already carried out

To exercise any of these, write to cuttingnoiseswithbets@gmail.com. You may also complain to a supervisory authority, for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

7. Changes to this policy

We may update this policy from time to time. The current version is always the one at beyondthoughts.net/privacy.

Still to confirm before public launch: the hosting providers named below should be confirmed against what is actually deployed at launch, and a data processing agreement (Art. 28 GDPR) should be in place with each processor listed.