Legal

Privacy Policy

Last updated: 27 July 2026

This privacy policy explains how we collect, use and share your information when you use our website or work with us, what your privacy rights are, and how the law protects you.

By using our website or booking a session with us, you agree to your information being handled as described here.

Definitions

A few terms used throughout this policy:

Client means anyone who books, attends or takes part in a breathwork session, workshop, retreat or coaching programme delivered by us.

Cookies are small files placed on your computer or device by a website, which record things like your browsing activity on that site.

Health data means information about your physical or mental health, including the health screening you complete before working with us and any notes we make about your wellbeing during or after a session. In law this is treated as special category data.

Personal data means any information that relates to an identified or identifiable person.

Service provider means a third-party company or individual we engage to help us run the business — for example our payment processor or email platform. They process data on our behalf and on our instructions.

Session means any one-to-one, group, online or in-person breathwork or coaching session we deliver.

Special category data means the categories of personal data listed in Article 9 of the UK GDPR, which receive extra protection in law. It includes data about health, which means it includes your health screening.

Usage data means data collected automatically when you use our website, such as how long you spent on a page.

We, us, our refers to The Breath Manifest, operated by Ryan Samtani as a sole trader, of [insert business address], United Kingdom.

Website refers to https://thebreathmanifest.com.

Who we are

The Breath Manifest is a breathwork facilitation and coaching practice run by Ryan Samtani as a sole trader in the United Kingdom.

We are the data controller for the information described in this policy, which means we decide how and why it is used. Ryan Samtani is responsible for data protection and is your point of contact for anything relating to your data.

Email: ryan@thebreathmanifest.com

This policy is written to comply with the UK GDPR and the Data Protection Act 2018. Where we send marketing messages we also follow the Privacy and Electronic Communications Regulations.

The information we collect

Information you give us

Contact and booking details. Your first and last name, email address, phone number, billing address, and — if you attend a retreat or in-person intensive — an emergency contact.

Health screening. Before your first session, and periodically afterwards, we ask you to complete a health screening. Depending on the work we are doing together this may cover your cardiovascular health, respiratory health, blood pressure, pregnancy, epilepsy or seizure history, recent surgery or injury, current medication, mental health history, and any history of trauma relevant to how we work together.

We ask for this because certain breathing techniques carry real contraindications. Sustained or rapid breathing practices are not appropriate for everyone, and we cannot facilitate safely without knowing what we are working with. This is not administrative box-ticking — it is the basis on which we decide what is safe to offer you and how to adapt it.

Because this is special category data, we ask for your explicit consent before collecting it, and we ask separately and specifically rather than bundling it into a general agreement. You can withdraw that consent at any time. We should be straightforward with you, though: if you do, we will usually be unable to keep working with you, because facilitating without a current screening is neither safe nor covered by our insurance.

Session notes. After a session we may record brief notes on what we worked on, what came up for you, and anything relevant to your safety, comfort or progress. These may contain health information and are protected the same way. You can ask for a copy of your notes at any time.

Recordings, photography and video. Some sessions, workshops and events may be recorded, photographed or filmed. This happens only where you have given separate, opt-in consent, which is always genuinely optional — declining will never affect your ability to take part or the quality of what you receive. Consent to have a session recorded for your own use is a separate question from consent for us to use that material publicly, and we will ask about each separately.

Testimonials. If you offer a testimonial, we will agree with you in writing beforehand how you would like to be credited — full name, first name only, initials, or fully anonymous. We will not publish anything that reveals health information unless you have specifically agreed to it.

Payment information. Payments are handled by our payment provider. We do not receive or store your full card details. We hold only the billing name and address, the amount, the date and a transaction reference, which we need for our accounts and for tax.

Information collected automatically

When you visit our website we may collect your IP address, browser type and version, the pages you visit, the date and time of your visit, how long you spend on each page, your device type and operating system, and other diagnostic data. This comes through cookies and similar technologies.

Cookies

Cookies can be either persistent, meaning they stay on your device after you go offline, or session cookies, which are deleted when you close your browser. We use both:

Essential cookies are needed for the website, booking and payment functions to work, and to prevent fraudulent use. These are the only cookies we set without asking you first, as the law permits.

Cookie consent cookies record whether you have accepted cookies, so we do not ask you repeatedly.

Functionality cookies remember choices you have made, such as your preferences or booking details, so you do not have to re-enter them.

Analytics cookies help us understand how the website is used so we can improve it. These are set only after you consent through our cookie banner, and you can withdraw that consent at any time.

You can also refuse or delete cookies through your browser settings, though blocking them may stop parts of the site working.

[Insert your full cookie table — name, provider, purpose, duration — once you have run a cookie scan on the live site.]

How we use your information, and our legal basis

Under the UK GDPR we need a lawful basis for everything we do with your data. Where health information is involved we need a second basis on top of the first.

What we do Article 6 basis Article 9 basis (health data)
Respond to your enquiry Legitimate interests
Health screening and adapting sessions Contract; legitimate interests in safe practice Explicit consent
Session notes Legitimate interests Explicit consent
Deliver the sessions you booked Contract
Take payment Contract
Keep financial records Legal obligation
Send newsletters and marketing Consent
Record sessions, take photos or video Consent Explicit consent where health information features
Publish testimonials Consent Explicit consent where health information features
Website analytics Consent
Defend a legal or insurance claim Legitimate interests Establishment, exercise or defence of legal claims

Where we rely on consent, you can withdraw it at any time. Doing so does not affect the lawfulness of anything we did before you withdrew it.

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. You can ask us to explain that reasoning, and you can object.

We may also contact you about your bookings — confirmations, changes to a session, safety information — which is part of delivering what you have paid for rather than marketing.

Who we share it with

We do not sell your personal data. We never share health information for marketing purposes, and we never use anything you disclose in a session as promotional content without your specific, separate, written consent.

We share data with the following service providers, who act only on our instructions under a written contract:

  • Payment processing — Stripe Payments Europe Ltd
  • Booking and scheduling — Cal.com, Inc.
  • Email marketing and newsletters — MailerLite (UAB Mailerlite, Lithuania)
  • Website contact form delivery — Web3Forms
  • File storage and business records — Google Workspace (Google Ireland Ltd) and Notion Labs, Inc.
  • Website hosting — Vercel Inc.
  • Health screening and intake forms — [insert the form platform you use]
  • Online session delivery — [insert if you deliver sessions online, e.g. Zoom]
  • Website analytics — [insert if you use analytics, e.g. Google Analytics, Fathom, Plausible]
  • Accounting — [insert your accounting software and accountant, if any]

We may also share information with our insurers or legal advisers where necessary to deal with a claim, and with public authorities where we are legally required to — for example in response to a court order or a valid request from HMRC or the police.

If something disclosed in a session gives us serious concern about a risk of harm to you or someone else, we may need to share limited information with an appropriate third party such as a GP or emergency service. Wherever it is safe and possible to do so, we will talk to you about it first.

If the business is ever sold or transferred, your data may transfer with it. We will give you notice before that happens.

How long we keep it

Category How long
Enquiries that do not lead to a booking 12 months
Client records, health screening and session notes 7 years from your last session
Records for clients under 18 Until their 25th birthday, or 7 years from the last session, whichever is longer
Financial and payment records 6 years after the end of the relevant tax year
Newsletter subscriptions Until you unsubscribe, then a minimal suppression record so we do not contact you again

Client records are held for an extended period because our insurance and professional obligations require it, not because we need them day to day. At the end of these periods we securely delete or anonymise the data.

Sending data outside the UK

Some of our providers store data outside the United Kingdom, including in the United States. Where that happens we make sure an appropriate safeguard is in place — either a UK adequacy decision covering that country, or the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

You can ask us for details of the safeguards that apply to any particular transfer.

Your rights

Under the UK GDPR and the Data Protection Act 2018 you have the right to:

Be informed about how we use your data, which is what this policy is for.

Access the personal data we hold about you, including your health screening and session notes.

Have inaccurate data corrected, or incomplete data completed.

Have your data erased. This right is not absolute — we may need to keep financial records to comply with tax law, or client records to defend a potential claim. We will tell you clearly if that applies.

Restrict how we use your data while a dispute about its accuracy or lawfulness is resolved.

Receive your data in a portable format that is structured, commonly used and machine-readable.

Object to processing based on legitimate interests. You have an absolute right to object to direct marketing, and we will stop immediately.

Withdraw consent at any time, where consent is our basis.

Not be subject to automated decision-making. We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects.

To make a request, email ryan@thebreathmanifest.com. We will respond within one calendar month. If your request is particularly complex we may extend that by up to two further months, and we will tell you within the first month if so. There is no charge. We may ask you to confirm your identity before releasing information.

Marketing

We send marketing emails only where you have opted in — for example by ticking the optional checkbox on our newsletter or meditation signup forms. Transactional emails (booking confirmations, venue details, free meditation delivery) are sent separately and do not count as marketing unless you also opted in to updates.

Where you are an existing client we may contact you about similar services — in which case you were given the chance to opt out when we collected your address, and you can opt out in every message.

Every marketing email has an unsubscribe link. You can also just email us. We will action it promptly and keep a minimal suppression record so you are not added back by mistake.

Security

We protect your information using encrypted storage and transmission, strong unique passwords with two-factor authentication on all business accounts, access limited to those who need it, health information stored separately from general contact data, secure deletion at the end of retention periods, and written data protection terms with every provider we use.

No method of transmitting or storing information is completely secure, so while we take these steps seriously we cannot guarantee absolute security.

If a breach happens that is likely to put your rights and freedoms at risk, we will report it to the Information Commissioner's Office within 72 hours and, where the risk is high, tell you directly without undue delay.

Children

Our services are intended for adults aged 18 and over. We do not knowingly collect data from anyone under 18 without the involvement and written consent of a parent or guardian.

Where we do work with a young person, we obtain written consent from a parent or guardian before any health screening, and we hold the records for the longer period set out above.

If you are a parent or guardian and believe your child has given us their data, please contact us and we will remove it.

Links to other websites

Our website may link to sites we do not operate. If you click through, we would encourage you to read the privacy policy of any site you visit. We have no control over, and take no responsibility for, the content or privacy practices of third-party sites.

Complaints

Please raise any concern with us first at ryan@thebreathmanifest.com. We would much rather hear about it and put it right directly.

You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at any time:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk

Changes to this policy

We may update this policy from time to time. The current version is always on our website with the date it was last updated at the top. Where a change materially affects how we use your data, we will let you know by email or a prominent notice on the site before it takes effect.

Contact us

Email: ryan@thebreathmanifest.com
Online: https://thebreathmanifest.com/contact