Islania Holistics

Privacy Policy (GDPR)

Last updated: 20/07/2026

This policy describes how Islania Holistics (hereinafter "we", "the Platform") collects, uses and protects your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

Important — what we do not do. Islania Holistics is not a healthcare service. We never ask for structured medical information, we do not keep a medical record, and we do not store any diagnosis, prescription or lab result. What you share with a practitioner during a session belongs to the care relationship they have with you, not to a health register kept by the Platform.

1. Data Controller

The data controller is: Virginie Thirion, Route de Limet 10, 4577 Modave, Belgique, company number (BCE) 0722.849.344. Privacy contact: contact@islaniaholistics.com.

2. Data We Collect

Depending on your use, we may process:

  • Identification and account data: surname, first name, email address, password (encrypted), telephone number, language, profile photo.
  • Billing and payment data: address, purchase history, transaction data. Bank card data is processed directly by our payment provider and is not stored by us.
  • Appointment data: chosen practitioner, date, type of session, booking history, cancellations.
  • Information you choose to share with a practitioner: reason for a consultation, feelings, care preferences. We never explicitly ask for such information at Platform level; you may voluntarily convey it in a message or a free-form note addressed to the practitioner. It is not structured as medical data.
  • Recordings, subtitles and transcripts of sessions: where you give your express consent, the audio/video content of an online session may be subtitled live and transcribed for accessibility purposes. A transcript reflects statements exchanged spontaneously — it may incidentally contain feelings or personal mentions, without constituting a medical record. See §4a.
  • Learning data (e-learning): progress through training courses, personal annotations and notes, answers to multiple-choice questions, results, certificates/completion certificates generated.
  • Forum contributions: messages, discussion threads and interactions that you post on the training forums, visible to other members with access to the forum and to the moderating practitioner.
  • Practitioner's free notes ("Grimoire"): personal notes that the practitioner may write after a session, at their sole discretion. They reflect the exchange as experienced, not a formal medical report. They remain available in your personal area and follow the same security and retention policy as the rest of your account.
  • Testimonials: video testimonials that you choose to record and, where applicable, to publish (see the dedicated "Testimonial Consent" document).
  • Prana loyalty program: points balance, earnings history, "wallet" credit, codes and referral relationships.
  • Practitioner data (additional): cabinet address for in-person appointments, content published on their showcase page (firstname.islaniaholistics.com).
  • Push / application notifications (PWA): the notification token of your device if you enable notifications.
  • Technical data: IP address, device type, browser, connection logs, cookies (see Cookie Policy).
  • Data relating to Practitioners: qualifications, diplomas, insurance, company number, bank details (IBAN) for payouts.

3. Purposes and Legal Bases

PurposeLegal basis (Art. 6 / 9 GDPR)
Creation and management of your accountPerformance of the contract (Art. 6.1.b)
Connection, booking and paymentPerformance of the contract (Art. 6.1.b)
Incidental processing of any sensitive information (feelings, spontaneous mentions) shared with the PractitionerExplicit consent (Art. 9.2.a)
Invoicing and accounting obligationsLegal obligation (Art. 6.1.c)
Verification of practitioners' business data (VAT number / company name via the European VIES database)Legal obligation (Art. 6.1.c) and legitimate interest (Art. 6.1.f)
Security, fraud preventionLegitimate interest (Art. 6.1.f)
Marketing, newslettersConsent (Art. 6.1.a) — withdrawable at any time
Service improvement, statisticsLegitimate interest (Art. 6.1.f)

4. Any Sensitive Information: Safeguards

We do not request or collect health data within the meaning of Article 9 GDPR (no medical record, no diagnosis, no lab result, no prescription). It may nevertheless happen that a piece of sensitive information — a feeling, a personal mention — is spontaneously shared by you with a practitioner during an exchange, a booking or a transcript. For such information, we undertake to:

  • process it only on the basis of your explicit consent (Art. 9.2.a) at the moment you choose to share it;
  • strictly limit access to such content (the Practitioner concerned and, where applicable, our authorised technical staff bound by confidentiality);
  • never use it for marketing or commercial profiling purposes;
  • encrypt it at rest and compartmentalise access.

You may withdraw your consent at any time, without this affecting the lawfulness of the processing carried out beforehand, and request deletion of the content concerned.

4a. Recording, Live Subtitling, Transcription and Artificial Intelligence Processing

The Platform offers features based on artificial intelligence (AI) technologies:

  • Live subtitling and transcription of sessions (speech recognition);
  • Multilingual text-to-speech (TTS) and translation of training content;
  • Automatic generation of chapter markers, quizzes (multiple-choice questions) and completion certificates;
  • Extraction and correction of subtitles for videos;
  • AI-based training assistant.

Consent. Live subtitling and transcription of a session, which may incidentally contain personal statements or sensitive feelings, are activated only with your explicit and specific consent, separate from other consents. You may refuse or withdraw this consent at any time; the session then remains possible without subtitling/transcription.

AI processors. Certain features rely on AI models hosted by third-party providers:

  • Google Gemini (Google LLC) — translation of course content, structured extraction of chapters from PDF, quiz generation, embeddings for semantic search in the training AI helper chatbot;
  • Groq (Groq Inc.) — Llama-based model for the conversational assistant that answers student questions about chapter content, for the platform help assistant, and for testimonial subtitle translation;
  • Deepgram (Deepgram Inc.) — automatic speech recognition for live subtitling of sessions and for generating subtitles of testimonials and training videos;
  • Modal Labs (Modal Labs Inc.) — serverless GPU infrastructure on which the Platform runs its Kokoro open-source TTS engine for course chapter voice synthesis. The model and its execution code belong to the Platform; Modal Labs only provides the compute capacity.

Data transmitted to these processors is strictly limited to what the feature requires and is governed by contracts compliant with Article 28 GDPR. Google, Groq, Deepgram and Modal Labs are established in the United States: transfers are covered by standard contractual clauses (SCC 2021/914) signed with each provider.

Reliability. AI-generated content (subtitles, transcripts, quizzes, chapter markers, translations) is produced automatically and may contain errors or inaccuracies. It does not replace the Practitioner's judgement or human verification. The Practitioner may correct the subtitles and transcripts.

No automated decision-making. This processing does not give rise to any decision producing legal effects concerning you without human intervention (Art. 22 GDPR).

Retention period. Session recordings/transcripts are retained for the duration of the follow-up then deleted, unless early deletion is requested.

4ter. Internal Messaging, Appointment Proposals and Attachments

The Platform provides Users with an internal messaging system between Client and Practitioner. The data processed for this purpose includes:

  • The content of messages exchanged (text, emojis), attachments (JPEG/PNG images, PDFs, up to 20 MB per file) and structured appointment proposals (date, duration, format, location, price, status);
  • The associated metadata: sender and recipient identifiers, timestamp, read/unread state, possible reference to a booking or a contact thread;
  • Cancellation logs (date, author, refund rate applied, any admin fee) required for accounting traceability and abuse prevention.

Attached files are stored with our hosting provider Firebase Storage (Google) in the same compliance context as other content. Message content is never analysed for advertising purposes and is accessible only to the two parties of the conversation and to a duly authorised administrator in the event of a report or dispute. The retention period is aligned with that of the account (see §5); upon account deletion, messages are erased or anonymised depending on their nature (see §7 "Your Rights").

5. Recipients and Roles

  • The Practitioners you consult are autonomous data controllers for the information they gather and document within their own practice. The Platform acts as a technical intermediary and/or processor depending on the case (see the Data Processing Agreement concluded with the Practitioners).
  • Our technical processors (host, payment provider, emailing service, video-conferencing tool, support) act on our instructions and are bound by contract in accordance with Article 28 GDPR.

Up-to-date list of processors:

ProcessorRoleLocationTransfer outside EU?
Google Ireland Ltd (Firebase Auth, App Hosting, Firestore, Storage, Cloud Functions, Cloud Messaging FCM, App Check reCAPTCHA Enterprise, Gemini)Main hosting + authentication + anti-abuse protection + AI (translations, extractions, quizzes, embeddings)Ireland (EU HQ) + United States (intra-group transfers)Yes, covered by SCC
Cloudflare Inc. (Cloudflare Stream, Cloudflare Realtime SFU, Email Routing)Video hosting (courses + testimonials) and live-session video infrastructureUnited StatesYes, covered by SCC
Modal Labs Inc. (Modal.com)GPU compute capacity for running the Platform's Kokoro open-source TTS engineUnited StatesYes, covered by SCC
Groq Inc. (Groq)LLM inference (course AI helper, chapter Q&A chat, subtitle translation)United StatesYes, covered by SCC
Deepgram Inc. (Deepgram)Speech recognition for live subtitling and testimonial subtitlesUnited StatesYes, covered by SCC
Resend Inc. (Resend)Transactional emails (confirmations, reminders, newsletter, internal messaging notifications)United StatesYes, covered by SCC
Stripe Payments Europe Ltd (Stripe, once online payments are activated)Online payment processing (courses and sessions)Ireland (EU HQ) + United States (intra-group transfers)Yes, covered by SCC
VIES API (European Commission)Validation of intra-EU VAT numbers entered by PractitionersEuropean UnionNo
HostingerRegistration of the islaniaholistics.com domain name and variantsCyprus (EU HQ)No

This list is kept up to date and published on this page. Users are informed before any addition or replacement of a processor likely to have a significant impact on the processing that concerns them.

6. Transfers Outside the EU

Your data is hosted in the European Union. If a processor involves a transfer outside the European Economic Area, this is governed by appropriate safeguards (standard contractual clauses of the European Commission, adequacy decision).

7. Retention Periods

  • Active account: for the entire duration of the relationship, then 24 months after the last activity.
  • Billing data: 7 years (Belgian accounting obligation).
  • Practitioner's free notes ("Grimoire") and session transcripts: retained for the duration of the relationship, then archived or deleted upon your request or the Practitioner's.
  • Marketing data: until withdrawal of consent.
  • Technical logs: 12 months.

8. Your Rights

In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection, portability, the right to withdraw your consent and to set post-mortem directives.

To exercise them: contact@islaniaholistics.com. We respond within one month.

You may lodge a complaint with the Data Protection Authority (APD): Rue de la Presse 35, 1000 Bruxelles — https://www.autoriteprotectiondonnees.be.

9. Security

We implement appropriate technical and organisational measures: encryption (TLS, at rest for sensitive data), access control, backups, logging, data minimisation. In the event of a breach presenting a risk, we notify the APD within 72 hours and, where applicable, the data subjects.

10. Minors

Sign-up is reserved for people aged 16 or over. A date of birth is requested when creating an account, and the Platform technically refuses sign-up to anyone whose declared date shows a lower age (GDPR Art. 8 and Belgian Act of 30 July 2018). Any inaccurate declaration may result in account closure.

11. Changes

We may amend this policy. Any substantial change will be notified to you. The date of the last update appears at the top of the document.