Privacy Policy

How we collect, use, and protect your information, including the sensitive health and wellbeing context you trust us with.

Last Updated: 26 July 2026

1. Who we are

Heart iQ runs services through two legal entities, working together. Heart iQ Network LLC is the contracting party for every Heart iQ programme worldwide. New Eden B.V. owns the Sanctuary in the Netherlands and processes payment for retreats held there. Both are described in our Terms & Conditions.

  • Heart iQ Network LLC (a Wyoming, USA limited liability company, operational address 2239 11th Street, Baker City, OR 97814) is the data controller for programme-related personal data: the Application Form you complete to enrol, intake conversations, programme participation, session recordings used for replays, course progress, community posts, the AI Oracle, and the newsletter. This applies to all programmes whether online (90-Day Challenge, Fellowship, Academy practicum, Heart iQ Experience) or in-person (retreats at New Eden in the Netherlands and at partner venues in the United States).
  • New Eden B.V. (a Netherlands private limited company, registered office Sparjeburd 2, 8409 CK Hemrik, KvK 64284328, BTW NL855599261B01) is the data controller for venue and payment-agent activities for retreats held at the New Eden venue: the Dutch tax invoice, accommodation logistics, on-site rooming, dietary requirements at the venue, accessibility needs at the venue, and (for the Sanctuary segment of a retreat booking) the payment record. New Eden is not involved in online programmes or in retreats held in the United States.

For a retreat booking at the Sanctuary, both entities process the same booking record. We operate as joint controllers under Article 26 GDPR for the booking record itself; New Eden alone is the controller for the venue-side activity above; Heart iQ Network LLC alone is the controller for the programme-side activity above. To make things simple, you can exercise any data right against either entity by emailing [email protected] and the request will be routed to whichever entity holds the relevant data.

2. What we collect

Account and contact information

Name, email, phone, billing address, country, time zone, and similar identifiers. We use this to register your account, send you account and service emails, and (for retreats) issue the Dutch tax invoice for your booking.

Application Form and intake

For every Heart iQ programme we ask you to complete an Application Form so the facilitation team can decide whether the programme is a good fit for you and how to support you during it. Some questions are optional and are clearly marked. We may also invite you to a short intake conversation online before approving an application; we keep brief notes from that conversation. Both the Application Form and the intake notes are processed by Heart iQ Network LLC.

Health and wellbeing context (special category data)

Several fields are about your physical or mental health: the booking wizard's optional "mental health and wellbeing" field, the "accessibility needs" field, the dietary requirements field, the relevant sections of the Application Form, and any health context you share during an intake conversation. The Terms also ask you to inform us promptly if your physical or mental condition materially changes between application and the start of a programme; whatever you share in that follow-up is treated the same way. Anything you submit to the ethics grievance form is also treated to the same standard.

Everything in this category is special category data under Article 9 GDPR and held to a higher protection standard. We collect it only when you actively choose to share it. The legal basis is your explicit consent under Article 9(2)(a) GDPR, separate from the consent you give for general booking processing. You can withdraw that consent at any time by emailing [email protected] and we will delete the field from your record. The surrounding booking or application is retained where we are still legally obliged to keep it (for example, the Dutch tax invoice on a confirmed retreat booking); only the special category fields are removed.

Session recordings and replay videos

Live online programme calls (and selected segments of in-person retreats) are recorded so participants who cannot attend live, or who want to revisit the material, can watch the replay inside the member portal. Recordings are stored on Vimeo and are accessible only to enrolled participants of that programme. Where you appear on a recording, the facilitator will name the recording at the start of the session and you can choose to keep your camera off or request edits before the replay is published. We do not publish recordings outside the member portal without explicit consent from the participants who appear on them.

Payment information

Card details are collected and processed by Stripe Payments Europe Ltd. We never see or store your full card number; we store only a tokenised reference issued by Stripe so that we can charge the deferred 75% balance for retreat bookings 30 days before the retreat begins, and so that you can be issued a refund if you are entitled to one.

Course progress and community activity

If you are enrolled in an online program, we record which lessons you have completed and any comments or community posts you publish. Your community profile (name, avatar, bio) is visible to other logged-in members of spaces you have joined.

The Z Oracle and its memory of you

Z is the AI Oracle inside the member portal. So that it can offer continuity instead of starting over every time, Z keeps a history of your conversations with it and builds a small, private memory of the recurring themes, intentions, and preferences you share. This applies to both written chats and spoken (voice) sessions.

This memory is on by default, and you stay in control of it:

  • It is stored securely on our servers in the European Union (Ireland) and is visible only to you.
  • You can turn it off at any time with the “Z’s memory” toggle in your account Settings. With it off, your conversations stay only on the device you used and Z stops building a memory.
  • You can read, edit, or delete any individual memory, or erase your entire Z history, in Settings; it is also included in the data export described below.
  • Your Z conversations are never used to train AI models, and are never sold or shared beyond the processors named in section 4 (Anthropic generates the replies under commercial terms that do not train on your data).

Material from group calls (Heart iQ Dojo, Accelerated Awakening, and replays) that is used to inform Z’s wider teaching knowledge is de-identified first: personal names are removed so the wisdom is kept without identifying who shared what.

Usage and device data

Server logs, IP address, browser type, pages visited. We use this for security (rate limiting, abuse detection) and for short-term server-side diagnostics. We do not currently run third-party analytics (no Google Analytics, no Facebook pixel, no advertising SDKs). If we add cookie-based analytics in future, we will only enable them after you give consent.

3. Why we process it, and on what legal basis

PurposeLegal basis (Art. 6)Article 9 basis if applicable
Process retreat bookings, charge deposits and balances, issue invoices6(1)(b) Contract
Application Form screening: decide whether a programme is a fit for you6(1)(b) Pre-contractual measures at your request9(2)(a) Explicit consent (for any health information you share)
Online intake conversation, including notes the facilitator takes6(1)(b) Pre-contractual measures at your request9(2)(a) Explicit consent (for any health information you share)
Hold optional health, wellbeing, accessibility disclosures so the facilitation team can support you safely6(1)(a) Consent9(2)(a) Explicit consent
Record live programme sessions and host them as replays inside the member portal6(1)(b) Contract (you booked a programme that includes replays)
Use a recording for promotional purposes outside the member portal6(1)(a) Consent (separate, per-recording)
Process and follow up on ethics grievance reports6(1)(f) Legitimate interest (safety of participants)9(2)(a) Explicit consent at submission
Send transactional and account emails6(1)(b) Contract
Newsletter and marketing emails6(1)(a) Consent (opt-in checkbox)
Run online courses, track progress, host community6(1)(b) Contract
Comply with Dutch tax and accounting obligations (retreat invoices)6(1)(c) Legal obligation (Article 52 AWR, 7-year retention)
Detect, prevent, and respond to fraud, abuse, and security incidents6(1)(f) Legitimate interest

4. Who we share your data with (named processors)

We never sell your data. We share it only with the following processors, each acting under a written data processing agreement. The country listed is where the processor primarily stores or processes the data.

  • Supabase (Ireland, EU — eu-west-1): Primary database, authentication, file storage. Holds bookings, profiles, course progress, community content, and the messages you send in the Heart iQ app.
  • Netlify (USA): Web hosting and CDN.
  • Stripe Payments Europe Ltd (Ireland, EU) and Stripe, Inc. (USA): Payment processing.
  • Resend (USA): Transactional email delivery (bookings, account, ethics intake).
  • Anthropic, PBC (USA): The AI Oracle inside the member portal sends your queries to Anthropic Claude under their commercial terms.
  • ElevenLabs, Inc. (USA): Real-time voice for the Oracle (Practice with Z). When you choose to start a voice session, your speech audio is streamed to ElevenLabs to transcribe what you say and synthesise the spoken reply. Voice is optional; the Oracle works in text without it. ElevenLabs is also used to transcribe a chat voice note into text, but only when a member of that conversation taps Transcribe on it. Nothing is sent automatically, and a voice note nobody asks to transcribe is never sent at all.
  • Airtable, Inc. (USA): Operations mirror used by the retreat team for guest list, dietary and rooming logistics. Mental health, accessibility, and emergency-contact fields are not mirrored to Airtable; they remain only in Supabase.
  • HighLevel, Inc. (USA): CRM used for marketing automation. Stores your email and lifecycle tags only.
  • Vimeo, Inc. (USA): Video hosting for course lessons.
  • Expo (650 Industries, Inc., USA): Delivers push notifications to the Heart iQ app. A notification carries the sender’s name, the first part of the message, and the sender’s profile picture, so it passes through Expo on its way to Apple or Google.
  • Apple Inc. (USA) and Google LLC (USA): The push services built into iOS and Android (APNs and FCM) that deliver a notification to your device. Neither receives your account data beyond the notification itself and an anonymous device token.

We may also disclose information when required by law, court order, or to protect the safety of participants, staff, or the public.

5. International transfers

Some of the processors above are based in the United States. Where personal data leaves the European Economic Area (EEA), we rely on the European Commission's Standard Contractual Clauses (2021) and, where applicable, the EU-U.S. Data Privacy Framework. The DPA we hold with each US processor includes those clauses.

The health, wellbeing and grievance information you give us through our forms is not transferred outside the EEA. Those fields stay inside the EU-hosted Supabase database.

One channel deserves to be called out plainly, because we would rather you knew than assumed. When someone messages you in the Heart iQ app, the notification sent to your phone contains their name, their profile picture and the opening of what they wrote, and it reaches you through push services based in the United States (see section 4). Whatever a person chooses to type travels in that preview. If you would rather notifications did not show message content on your lock screen, iOS and Android both let you hide previews for an app in your device settings.

6. How long we keep it

  • Retreat invoices and booking records: 7 years from issue (Dutch tax law, Article 52 AWR).
  • Application Form and intake notes: for the duration of the programme, plus up to 24 months after completion to support follow-up programmes; deleted on request thereafter unless we are still legally obliged to keep it.
  • Health, wellbeing, accessibility disclosures: deleted within 90 days of the retreat end date, or sooner on request.
  • Session recordings used as replays: for as long as the programme they belong to is offered, plus 12 months grace for late catch-up; recordings are deleted on the same schedule as the programme's archive.
  • Ethics grievance submissions: retained for the duration of the investigation plus 5 years for the protection of all parties; anonymised summaries may be kept longer for safeguarding policy review.
  • AI Oracle query log (used only to surface popular prompts): 30 days, then automatically deleted.
  • Z conversation memory (your chat history and Z’s memory of you), while the feature is on: kept until you turn it off or delete it, and erased when you do or when you close your account.
  • Course progress and community posts: for the lifetime of your account, plus 12 months after closure.
  • Server access logs: 30 days.
  • Audit trail of admin reads of sensitive data: 2 years (used for breach forensics).
  • Marketing email contact records: until you unsubscribe, plus a suppression record indefinitely so we do not email you again.

7. Your rights

If we hold personal data about you, GDPR gives you the following rights. We will respond within one month of a verified request.

  • Access the personal data we hold about you (Article 15)
  • Have inaccurate data corrected (Article 16)
  • Have your data erased, subject to our retention obligations above (Article 17)
  • Restrict processing while a dispute is resolved (Article 18)
  • Receive a portable copy of the data you provided (Article 20)
  • Object to processing based on legitimate interest (Article 21)
  • Withdraw consent for processing that relies on it (Article 7), including special category data
  • Not be subject to a solely automated decision with legal or significant effects (Article 22). We do not make such decisions.

To exercise any of these rights, email [email protected]. We will verify your identity before acting and will not charge a fee unless your request is manifestly unfounded or excessive.

8. Cookies and similar technologies

We use only strictly necessary cookies for authentication, session continuity, and CSRF protection. Without them the site cannot function, so they do not require consent. We do not currently set analytics, advertising, or third-party tracking cookies. If that changes, we will publish an updated policy and add a consent prompt before any non-essential cookie is set.

9. How we protect your data

We use TLS for data in transit, encryption at rest in Supabase, role-based access control on admin functions, row-level security policies on the database, audit logging of sensitive reads, and rate limiting on public endpoints. The retreat team accesses health and grievance data only through admin routes that are server-side authenticated; access is logged.

One thing we want to be straightforward about: messages in the Heart iQ app are not end-to-end encrypted. They are encrypted in transit and at rest, and the database only ever serves a conversation to someone who is a member of it. But unlike WhatsApp or Signal, we hold the keys, which means a small number of authorised Heart iQ staff could technically read a conversation, and we would have to hand one over if compelled by law. We do not read members’ messages as a matter of course, and we access them only where safeguarding or a legal obligation requires it. We are telling you this because the conversations people have here are often deeply personal, and you deserve to choose what you share knowing how it is held.

If a breach happens that is likely to result in a risk to your rights and freedoms, we will notify the Dutch supervisory authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware, and we will notify you directly without undue delay.

10. The Heart iQ app: messages, notifications and pictures

Who can see your messages

The app carries three kinds of conversation: a one-to-one with another member, a practice circle, and the group chat for an event you are attending. In every case the database will only serve a conversation to someone who belongs to it. Being an administrator does not open other people’s one-to-one messages or practice circles. Please see section 9 for the plain facts about encryption.

Notifications

When a message arrives we send a notification showing who it is from, the beginning of what they said, and their profile picture alongside the Heart iQ icon, so you can see at a glance whether it needs you. Delivering that means passing it through the push services described in sections 4 and 5. You can turn notifications off entirely in your device settings, or keep them and hide the preview.

Profile and circle pictures

Your profile picture, and any picture chosen to represent a practice circle, are stored so that they can be displayed quickly wherever they appear, including inside a notification on your phone. That means they are served from a public web address that is not itself behind a login: the address is long and unguessable, and it is not listed or indexed anywhere, but anyone who was given the exact link could open the image. Please choose a picture you are comfortable being seen, and use a picture you have the right to use. You can change or remove either at any time, and removing it takes it out of the app straight away.

Photos, video and voice notes you send

Anything you attach to a message is different: it is kept in private storage and can only be opened through a short-lived link issued to a member of that conversation.

A voice note can be turned into text by tapping Transcribe underneath it. This is never automatic. When someone taps it, that recording is sent to ElevenLabs (see section 5) to be written out, and the language is detected from the recording itself so a note spoken in your own language is transcribed in it. The text is then saved on that message and shown to everyone in the conversation, so a note is only ever transcribed once rather than separately for each person. Deleting the message deletes the transcript with it.

Human Design and Gene Keys (optional)

If you choose to, you can switch on Human Design in the app and give your time and place of birth. This is entirely optional, it is off unless you turn it on, and nothing about it is collected or worked out until you do.

What we do with it: your birth date, time and place are used to calculate your chart, and nothing else. The calculation runs on our own servers using astronomical data, so your birth details are not sent to any third party for this. That includes looking up your birth town: we hold our own copy of a public list of world cities, so searching for your birthplace does not tell a mapping or geocoding company where you were born. Your chart is stored on your profile and, while the setting is on, is given to Z as background so it can take your design into account. Your birth details and your chart are never shown to other members.

Why we ask for the town and not just the country: a chart is worked out from the exact moment of birth, and the moment depends on the time zone of the place. Several countries span more than one, so the town is what makes the time correct. The city list is from GeoNames, used under a Creative Commons Attribution 4.0 licence.

Turning it off deletes it. The switch does not merely hide your chart: your chart, your birth time and your place of birth are erased, and Z stops being told any of it. Your date of birth stays on your profile, because it is also used for other things such as retreat paperwork, and you can clear that separately.

Human Design and Gene Keys are interpretive systems, not scientific or medical ones. We offer them because members find them useful, not as fact about who you are, and nothing in the app should be read as advice from them.

Closing your account

You can delete your account from within the app, under Settings. Doing so removes your profile, your profile picture, and the messages you have sent, including the ones sitting in other people’s conversations. Where a message of yours has been replied to, the reply may still show that a message existed without showing what it said. Anything we are legally obliged to keep, such as booking and invoice records, is listed in section 6 and is kept for the periods stated there.

11. Children

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from children. Where a booking is made for a child, the booking adult is the data subject and provides the child's information under their parental responsibility.

12. Changes to this policy

We may update this policy. The "Last Updated" date at the top reflects the most recent version. Material changes are notified by email to active users.

13. Contact and complaints

For privacy questions or to exercise any of your rights:

The fastest way to reach the right team is [email protected] — this inbox is monitored for both entities and a privacy request will be routed to whoever holds the relevant data. If you would like to address a specific entity directly, their details are below.

Heart iQ Network LLC (programmes, content, community, online courses)

2239 11th Street, Baker City, OR 97814, USA

Wyoming limited liability company

Email: [email protected]

New Eden B.V. (New Eden retreat venue, accommodation, payment agent)

Sparjeburd 2, 8409 CK Hemrik, the Netherlands

KvK 64284328 · BTW NL855599261B01

Venue and accommodation queries: [email protected]

Privacy and data requests: [email protected]

If your concern is about safety, conduct, or an ethics matter rather than data, please use the grievance form — we acknowledge formal grievances within 5 business days.

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

© 2026 New Eden B.V. and Heart iQ Network LLC. All rights reserved.