CONTROLLER
The controller responsible for the processing of your personal data on this website and in connection with our products and services is:
Dr. Marcella Kollmann-Hemmerich, trading as Sovereign Femme
Schwangauer Straße 2387645 Hohenschwangau
Germany
- Telephone
- +49 171 9391066
- [email protected]
- VAT no. (§ 27a UStG)
- DE457506872
Referred to below as "we", "us" or "Sovereign Femme".
DATA PROTECTION OFFICER
We have not appointed a data protection officer, as we are not required to do so under Art. 37 GDPR or § 38 BDSG.
GENERAL INFORMATION
3.1Scope
This policy explains how we collect, use and protect personal data when you visit our website, subscribe to our communications, complete a quiz or download a resource, purchase a product, book a session, or otherwise interact with us.
3.2What personal data means
Personal data is any information relating to an identified or identifiable natural person.
3.3Legal bases
We process personal data on one or more of the following bases:
- Art. 6(1)(a) GDPR — consent. Where you have given us permission, for example for marketing emails, non-essential cookies, or session recording.
- Art. 6(1)(b) GDPR — performance of a contract. Where processing is necessary to deliver a product or service you have purchased, or to take steps at your request before entering a contract.
- Art. 6(1)(c) GDPR — legal obligation. Where we are legally required to process or retain data, for example tax and commercial record-keeping.
- Art. 6(1)(f) GDPR — legitimate interests. Where processing is necessary for our legitimate interests and those interests are not overridden by your rights, for example website security and fraud prevention.
- Art. 9(2)(a) GDPR — explicit consent. Where we process any special category data, including data concerning health, we do so only on the basis of your explicit consent.
3.4Providing data
Providing personal data is generally voluntary. However, where data is necessary to conclude or perform a contract, we cannot deliver the product or service without it. Where a field is required, this is indicated.
3.5No automated decision-making
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
HOSTING AND SERVER LOG FILES
Our website and the platform behind it are hosted by HeyClients, 6223 Hayes Tower Rd, Gaylord, MI 49735, United States (heyclients.io). HeyClients is based in the United States; transfers of personal data to the United States take place on the safeguards described in section 12.
When you visit our website, the hosting provider automatically collects and stores information in server log files that your browser transmits. This includes:
- browser type and version
- operating system
- referrer URL
- host name of the accessing device
- date and time of the request
- IP address
This data is not merged with other data sources. It is processed on the basis of Art. 6(1)(f) GDPR — our legitimate interest in the technically secure and stable presentation of our website. Log data is deleted after seven (7) days.
Our hosting provider processes personal data only on our instructions, as a processor within the meaning of Art. 28 GDPR. Details of the data protection arrangements in place with our processors are available on request.
4.1SSL/TLS encryption
This site uses SSL/TLS encryption for security and to protect the transmission of confidential content. An encrypted connection is indicated by "https://" in the browser address bar and the padlock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.
COOKIES AND SIMILAR TECHNOLOGIES
5.1What we use
Our website uses only those cookies and comparable technologies that are strictly necessary for the website to function — for example to operate the checkout, to keep you signed in to a course area, and to maintain security.
We do not currently use cookies or similar technologies for analysis, advertising or any other non-essential purpose, and no such technologies are active on this website.
5.2Legal basis
Storing information on, or accessing information already stored in, your device requires your consent under § 25(1) TDDDG, except where it is strictly necessary to provide a service you have expressly requested (§ 25(2) TDDDG). The cookies we use fall within that exception, so no consent is required for them. The subsequent processing of personal data is based on Art. 6(1)(f) GDPR, our legitimate interest in operating a functioning and secure website.
5.3If this changes
Should we introduce analysis or advertising technologies in future, we will first put a consent banner in place and will only set those technologies where you have given consent. This policy will be updated at the same time.
5.4Browser settings
You can configure your browser to refuse or delete cookies. Disabling strictly necessary cookies may prevent parts of the website from working.
CONTACTING US
6.1By email or telephone
If you contact us by email or telephone, your enquiry and all associated personal data will be stored and processed for the purpose of handling your request.
Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or pre-contractual steps; otherwise Art. 6(1)(f) GDPR, our legitimate interest in responding to enquiries, or Art. 6(1)(a) GDPR where you have given consent.
6.2Contact forms
Data entered into a contact form on our website is transmitted to us and stored. We do not pass it on without your consent. The same legal bases apply.
6.3Retention
Enquiry data is retained until the request has been dealt with and any applicable statutory retention periods have expired. You may request deletion at any time.
FREE RESOURCES, QUIZZES AND LEAD MAGNETS
7.1What we collect
Where you request a free resource — including a quiz, an audio series, a guide or a download — we collect your email address, your first name where you provide it, and where applicable your responses to the questions asked.
7.2Double opt-in
After you submit the form we send a confirmation email containing a link. Your data is only added to our mailing list once you click that link. Until then it is retained solely to complete the confirmation process. We record the date and time of your registration and confirmation, and the IP address used, in order to demonstrate that consent was given.
7.3Quiz responses
Where you complete a quiz, we process the answers you provide in order to generate and send your result and to tailor subsequent communications.
Quiz answers are submitted through a form built into our own website and are stored on our platform. They are not processed by any separate quiz provider.
Our quizzes are designed so that they do not ask for, and do not require, data concerning health within the meaning of Art. 4(15) GDPR. Please do not enter health information into a quiz. Where you nevertheless provide information that constitutes special category data, we process it only on the basis of your explicit consent under Art. 9(2)(a) GDPR, and you may withdraw that consent at any time with effect for the future.
Your individual quiz responses are not transmitted to advertising platforms. Where we record that a quiz has been completed for advertising measurement purposes, only a generic completion signal is sent, containing no information about your answers.
Quiz responses are retained for three (3) years and are then deleted.
7.4Legal basis
Art. 6(1)(a) GDPR — consent. Additionally Art. 9(2)(a) GDPR where special category data is involved. You may withdraw consent at any time using the unsubscribe link in any email or by contacting us.
THE SOVEREIGN LETTER (NEWSLETTER)
8.1Subscribing
Where you subscribe to The Sovereign Letter we process your email address, your first name where provided, and the date, time and IP address of your subscription and confirmation.
8.2Consent and double opt-in
Subscription is by double opt-in: you receive a confirmation email and are only added to the list once you click the link. Where you opt in at checkout, no separate confirmation email is sent, because your email address has already been verified by the purchase itself.
8.3Purpose
We use your email address to send insights, updates and occasional information about our courses, programmes and offers.
8.4Legal basis
Art. 6(1)(a) GDPR and § 7(2) No. 2 UWG — your consent.
8.5Withdrawing consent
You may unsubscribe at any time using the unsubscribe link in every email, or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Following unsubscription, your email address may be retained on a suppression list for the sole purpose of ensuring you receive no further mailings.
8.6Analysis
Our newsletter emails contain a tracking pixel that allows us to see whether an email was opened and which links were clicked. This is used to understand which content is useful and to improve our communications. This analysis is covered by the consent you give when subscribing. If you do not wish to be tracked, you may unsubscribe, or configure your email client not to load remote images.
8.7Processor
The Sovereign Letter is sent using HeyClients, 6223 Hayes Tower Rd, Gaylord, MI 49735, United States, which processes the data only on our instructions as a processor within the meaning of Art. 28 GDPR.
PURCHASES AND PAYMENT
9.1What we process
When you purchase a product or service we process:
- your name
- your email address
- your billing address and country
- the product purchased, the price and the VAT applied
- the date and time of purchase
- the consents you gave at checkout, and the version of each document you accepted
- payment status
We do not receive or store full payment card details.
9.2Legal basis
Art. 6(1)(b) GDPR — performance of the contract with you — and Art. 6(1)(c) GDPR for the tax and commercial record-keeping obligations to which we are subject.
This processing is not based on consent. The acknowledgment you give at checkout confirms that this information has been provided to you; it is not a consent that can be withdrawn, because the processing is necessary to deliver what you have purchased and to meet our legal obligations.
9.3Payment processing — Stripe
Payments are processed by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, and its affiliates.
Where you pay by card or other supported method, your payment data is transmitted to Stripe. Stripe processes this data as an independent controller for the purposes of fraud prevention and compliance with its own legal obligations, and as our processor for the purpose of executing the payment.
Stripe's privacy policy: https://stripe.com/privacy
Legal basis: Art. 6(1)(b) GDPR.
9.4Platform — Hey Clients
Our checkout, course delivery, booking and customer records are operated using HeyClients, 6223 Hayes Tower Rd, Gaylord, MI 49735, United States. HeyClients is based in the United States; transfers of personal data to the United States take place on the safeguards described in section 12. HeyClients processes the data only on our instructions as a processor within the meaning of Art. 28 GDPR. Details of the data protection arrangements in place with our processors are available on request.
9.5Consent records
For each transaction we record which version of the Terms & Conditions, this Privacy Policy, the withdrawal instruction and the checkout consent block you were shown, together with the date and time. This is retained as evidence of the contract and of the information provided to you, on the basis of Art. 6(1)(c) and Art. 6(1)(f) GDPR.
9.6Retention
Invoices, payment records and contract documentation are retained for ten years in accordance with § 147 AO and § 257 HGB. After the expiry of that period the data is deleted.
COACHING SESSIONS AND BOOKINGS
10.1Booking and delivery
When you book a session we process your name, email address, the appointment date and time, your time zone, and any information you provide when booking or in an intake questionnaire.
Sessions are delivered by video using Zoom, a service of Zoom Communications, Inc. Where a session takes place by Zoom, your name, email address and connection data are processed by Zoom in order to host the meeting. Zoom acts as our processor for this purpose and its privacy statement is available at https://www.zoom.com/en/trust/privacy/
Legal basis: Art. 6(1)(b) GDPR.
10.2What you share in a session
Information you share with us during a session is treated as confidential and is not disclosed to third parties, except where required by law or where necessary to prevent serious harm.
Please note that this confidentiality is contractual. It is not the medical confidentiality that would apply within a doctor–patient relationship, because no such relationship arises. Sovereign Femme is a personal-development and educational business and is entirely separate from any medical practice.
10.3Session notes
We keep brief professional notes for the purpose of delivering the service to you. These are retained for three (3) years and then deleted.
10.4Intake information
Where an intake questionnaire asks whether you are currently under medical or psychological care, this is asked solely so that we can direct you to appropriate support where our services are not suitable. Any such information is data concerning health and is processed only on the basis of your explicit consent under Art. 9(2)(a) GDPR. It is not used for marketing and is not transmitted to any advertising platform.
SESSION RECORDINGS
11.1One-to-one sessions
We may record one-to-one sessions for our own professional notes and for internal quality assurance and team training. Recording takes place only where you have given separate consent by a dedicated tick-box at booking. Accepting our Terms & Conditions does not constitute consent to being recorded.
11.2Voluntary
Consent is voluntary. If you decline, the session takes place as normal and the service you receive is unaffected. You may withdraw your consent at any time, and the recording will then be deleted unless we are legally required to retain it.
11.3Access
Recordings may be accessed by us and by members of our team who are bound by written confidentiality obligations. They are not shared with anyone else, published, or used for marketing.
11.4Retention
Recordings are stored securely and deleted 36 months after the session, or earlier on request.
11.5Group sessions
Where a group session is recorded, participants are informed before recording begins and may take part with camera and microphone switched off.
11.6Legal basis
Art. 6(1)(a) GDPR, and Art. 9(2)(a) GDPR where the content of a session includes data concerning health.
11.7Recording by you
You may not record any session without our prior written consent. Recording the non-publicly spoken word without consent is a criminal offence in Germany under § 201 StGB.
ADVERTISING AND ANALYTICS
12.1Current position
We do not currently run any advertising, analytics or tracking technology on this website. No advertising pixel, conversion tag or analytics tool is installed, and no data about your visit is transmitted to any advertising platform.
We intend to use the Meta Pixel and Conversions API and the LinkedIn Insight Tag in future. Before either is activated we will put a consent banner in place, obtain your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG, and update this policy to describe each tool, the data transmitted and the recipient. Nothing will be set on your device before you have consented.
In no circumstances will we transmit the content of your quiz responses, your intake answers or any health-related information to an advertising platform.
12.2Transfers outside the EU
Some of the providers named in this policy are based in, or transfer data to, the United States. Where this occurs, transfers take place on the basis of the EU–US Data Privacy Framework where the recipient is certified, or on the basis of Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR, together with supplementary measures where appropriate.
You should be aware that the level of data protection in third countries may not correspond to that within the European Union, and that public authorities in those countries may be able to access data. You may obtain a copy of the relevant safeguards by contacting us.
SOCIAL MEDIA
We maintain profiles on Instagram, Facebook and LinkedIn. When you visit or interact with these profiles, the platform operator processes your data according to its own policies, over which we have no control.
For our Facebook and Instagram pages, we are joint controllers with Meta Platforms Ireland Limited in respect of page insights. The essential content of that arrangement is available at https://www.facebook.com/legal/terms/page_controller_addendum
For our LinkedIn page, we are joint controllers with LinkedIn Ireland Unlimited Company in respect of page analytics. The essential content of that arrangement is available at https://legal.linkedin.com/pages-joint-controller-addendum
We process data you send us through these platforms — for example direct messages — in order to respond to you. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in communicating with our audience, or Art. 6(1)(b) GDPR where the exchange relates to a contract.
Where you provide an email address to us through a direct message in order to receive a resource, we process it as set out in section 7.
TESTIMONIALS AND FEEDBACK
Feedback you give us is voluntary. We use feedback publicly only where you have given separate, specific consent, confirming how and where it will be used. Accepting our Terms & Conditions does not constitute consent to publication.
You may withdraw consent at any time and we will remove the testimonial from materials under our control within a reasonable period.
Legal basis: Art. 6(1)(a) GDPR.
RECIPIENTS OF YOUR DATA
We share personal data only where necessary, and only with:
- Processors acting on our instructions under Art. 28 GDPR — HeyClients (hosting, platform, customer records and email), Stripe (payments) and Zoom (video conferencing for sessions)
- Members of our team, who are bound by written confidentiality obligations
- Our tax adviser and auditors, where required for accounting purposes
- Public authorities and courts, where we are legally obliged to disclose
We do not sell personal data and we do not share it for the independent marketing purposes of third parties.
RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as we are legally required to retain it.
| Data | Retention period |
|---|---|
| Server log files | Seven days |
| Enquiry correspondence | Until the matter is resolved, then subject to statutory periods |
| Newsletter subscriber data | Until you unsubscribe; suppression list retained thereafter |
| Consent records | Three years after the consent ends, as evidence |
| Quiz responses | Three years |
| Purchase, invoice and contract records | Ten years (§ 147 AO, § 257 HGB) |
| Session notes | Three years |
| Session recordings | 36 months, or earlier on request |
YOUR RIGHTS
You have the following rights in relation to your personal data:
- Access (Art. 15 GDPR) — to obtain confirmation of whether we process your data, and a copy of it
- Rectification (Art. 16 GDPR) — to have inaccurate data corrected
- Erasure (Art. 17 GDPR) — to have your data deleted, where no legal retention obligation applies
- Restriction (Art. 18 GDPR) — to have processing restricted in certain circumstances
- Data portability (Art. 20 GDPR) — to receive data you provided in a structured, machine-readable format
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future
- Complaint (Art. 77 GDPR) — to a supervisory authority
To exercise any of these rights, contact us at [email protected].
17.1Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing carried out on the basis of Art. 6(1)(f) GDPR. Where we process your data for direct marketing purposes, you have the right to object at any time, without giving reasons. Following such an objection we will no longer process your data for that purpose (Art. 21 GDPR).
17.2Supervisory authority
You may lodge a complaint with the supervisory authority responsible for us:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 2791522 Ansbach
Germany
- Website
- www.lda.bayern.de
You may also complain to the supervisory authority in the EU member state of your habitual residence or place of work.
CHILDREN
Our products and services are directed at persons aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect changes in our processing or in legal requirements. The version in force is the one published on this page. We archive previous versions with the dates on which they were in use.
Version 1.0 — 8 September 2026