Privacy Policy
Last updated: July 2026
This policy explains how Beyond Thoughts (operated by Mayank Mishra, Berlin, Germany) collects, uses and protects personal data in connection with beyondthoughts.net and the sessions offered here.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Who is responsible for your data
2. What we collect, and why
When you visit the website
Our hosting providers automatically record standard server log data, IP address, browser type, operating system, pages requested, timestamp. This is used for security and technical operation and is not used to identify you. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
When you create an account or sign in
We store your email address, and your name and time zone if you choose to give them. We ask for your date of birth to confirm you are 18 or over, as our Terms require, and to record your age range against anonymised notes on the themes people bring to sessions, so we can understand the work better over time. Those notes are not linked back to you. Sign-in is by emailed one-time link or by Google sign-in; we never store a password. Legal basis: Art. 6(1)(b) GDPR (performance of a contract, including confirming you are old enough to enter it), and Art. 6(1)(f) (legitimate interest) for account security and for understanding the service.
When you pay for a session
Payments are processed by Stripe. Stripe collects your name, email address, card details and billing information. We receive confirmation of payment, your email address and a payment reference, we never see or store your card details. We also record the timestamp of your consent to begin the service within the withdrawal period, because the law requires us to be able to evidence it. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) for the records we are obliged to keep.
When you schedule a session
Scheduling is handled by zcal. When you choose a time, zcal receives your name, email address, time zone and chosen slot, and returns the booking details to us. Legal basis: Art. 6(1)(b) GDPR.
When you attend a session
Sessions take place on Zoom, which processes the connection data needed to host the call. Sessions are not recorded. We take written notes during or after the session for the sole purpose of preparing your written summary; those notes are shared with no one and are deleted within 90 days. Legal basis: Art. 6(1)(b) GDPR.
When you give a testimonial
If you volunteer a testimonial and agree to its use, we may publish it in exactly the form you agree to. Legal basis: Art. 6(1)(a) GDPR (consent), which you may withdraw at any time.
3. Sensitive information
Beyond Thoughts is not a medical, psychological or therapeutic service and does not seek information about your health. We ask you not to share medical or clinical information with us, and we do not record any.
If you nevertheless share information that falls within Art. 9 GDPR, we process it only to prepare your written summary, only with your explicit consent under Art. 9(2)(a) GDPR, and we delete it with the rest of the session notes within 90 days.
4. Cookies
This site sets no tracking or analytics cookies and runs no analytics product. If you sign in, we set a strictly necessary session cookie so that you stay signed in, without it, signing in cannot work, so no consent banner is required for it (§ 25(2) TDDDG).
Fonts are self-hosted and served from our own domain, so loading a page makes no request to Google. Stripe, zcal and Zoom may set their own cookies once you interact with their services; their policies apply there.
5. Processors we use
- Stripe Payments Europe, Ltd., payment processing. Some processing takes place outside the EU under EU Standard Contractual Clauses. stripe.com/privacy
- zcal, appointment scheduling. Processed in the US under EU Standard Contractual Clauses. zcal.co/privacy
- Zoom Communications, video calls, under EU Standard Contractual Clauses. zoom.us/privacy
- Supabase, database hosting, EU region.
- Resend, transactional email: sign-in links, booking confirmations and your written summary.
- Google, only if you choose Google sign-in, in which case Google confirms your identity and email address to us.
- Vercel Inc., website hosting, server logs as described above. Processed in the US under EU Standard Contractual Clauses. vercel.com/legal/privacy-policy; Render Services, Inc., API hosting, server logs as described above. Processed in the US under EU Standard Contractual Clauses. render.com/privacy
6. How long we keep it
Only as long as necessary for the purposes above, or as long as the law requires. Payment and invoice records are kept for 10 years under German commercial and tax law (§ 257 HGB, § 147 AO). Session notes are deleted within 90 days. Your written summary remains in your own email account and is yours to keep or delete. Our copy is deleted with the session notes. Account data is deleted after 24 months of inactivity, or sooner if you ask us to delete it.
7. Your rights
You have the right to:
- Access the personal data we hold about you (Art. 15 GDPR)
- Have inaccurate data corrected (Art. 16 GDPR)
- Have your data deleted (Art. 17 GDPR)
- Restrict how we process it (Art. 18 GDPR)
- Receive it in a portable format (Art. 20 GDPR)
- Object to processing based on legitimate interest (Art. 21 GDPR)
- Withdraw consent at any time, without affecting processing already carried out
To exercise any of these, write to hello@beyondthoughts.net. You may also complain to a supervisory authority, for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
8. Automated decision-making and minors
Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
Minors
Sessions are for adults only. We do not knowingly collect data from anyone under 18.
9. Changes to this policy
We may update this policy from time to time. The current version is always the one at beyondthoughts.net/privacy.