Privacy policy
October 2026
Template text prepared to follow the EU GDPR. Complete the [bracketed] items and have it reviewed by a legal professional before launch.
This policy explains which personal data we process when you use this website, why, on what legal basis, for how long, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
Margaret Birungi (trading as Nurture & Nest), Querallee 13, 34119 Kassel, Germany. Phone: +49 1520 9180700. E-mail: info@nurtureandnest.com.
We are not required to appoint a data protection officer. Please send privacy requests to the e-mail address above.
2. Principles
We collect only the data we need, use it only for the purposes listed here, keep it only as long as necessary and protect it with appropriate technical and organisational measures (TLS encryption in transit, access controls, row-level security in our database).
3. Hosting and server logs
When you visit the site, our hosting provider processes your IP address, date/time, requested URL and browser details to deliver the site and keep it secure.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working website). Retention: according to the provider’s log policy, normally up to 30 days.
4. Account and course
When you sign up we process your name, e-mail address, country, password (stored only as a hash), language, optional phone number and optional due date, plus proof that you accepted the terms and privacy policy. While you use the course we store your lesson progress and membership status.
Legal basis: Art. 6(1)(b) GDPR (contract). Retention: until you delete your account, then deleted within 30 days unless law requires otherwise.
The due date is optional and helps us tailor content. If you share it, it may reveal pregnancy, which is health-related data. We process it only on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time in your account or by e-mail.
5. Payments
Payments are handled by Stripe or Paystack. Card and bank details are entered on their pages and never reach our servers. We receive confirmation of payment, plan, amount and a payment reference.
Legal basis: Art. 6(1)(b) and (c) GDPR (contract; statutory accounting and tax retention duties, normally 6–10 years under German commercial and tax law).
6. Consultations and booking
Bookings are made through Cal.com, which stores your name, e-mail, chosen time and any notes you enter, and synchronises the appointment with our calendar. We store the booking reference, time, service type and your e-mail to show your appointments.
The Cal.com booking widget is loaded only after you click “Load booking calendar”; until then no data is sent to Cal.com. Legal basis for the widget: your consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG). Legal basis for the booking itself: Art. 6(1)(b) GDPR.
If you tell us about your health or pregnancy in a consultation, we process this as a health professional under Art. 9(2)(h) GDPR together with professional confidentiality, or with your explicit consent (Art. 9(2)(a)). Consultation content is not recorded by this website.
Retention: booking data for as long as needed to perform the appointment and for statutory duties (accounting records up to 10 years).
7. Community
Posts and replies are visible to other logged-in members together with the name you registered with. Please do not post data of third parties and avoid sharing sensitive health details; anything you post voluntarily about your own health is processed on the basis of your explicit consent (Art. 9(2)(a) GDPR). You can delete your own posts at any time. Posts can be translated on request: the text is then sent to a translation service (LibreTranslate).
Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete the post or your account.
8. Contact form and e-mail
If you write to us we process your name, e-mail address and message to answer you. Legal basis: Art. 6(1)(b) or (f) GDPR. Retention: until your request is resolved, then up to 12 months unless statutory retention applies.
9. Newsletter and marketing
We only send marketing e-mail if you ticked the optional consent box at sign-up (Art. 6(1)(a) GDPR). You can withdraw consent at any time without giving reasons; withdrawal does not affect earlier processing.
10. Cookies and similar technologies
We use only strictly necessary storage that does not require consent (§ 25(2) no. 2 TDDDG): a login session cookie (Supabase), a language preference (NEXT_LOCALE), your light/dark theme choice (browser localStorage) and, if you load it, a session flag remembering your calendar choice. We do not use analytics or advertising cookies, and fonts are served from our own domain.
Third-party content (Cal.com booking widget) is loaded only after your click as described above. Links to Google (reviews) are plain links: Google receives data only if you follow them.
11. Google reviews
Our reviews section shows our public rating and, where available, review excerpts retrieved from Google by our server (Google Places API). Your browser does not contact Google when this section loads. Legal basis: Art. 6(1)(f) GDPR. If you write a review on Google, your data is processed by Google under Google’s own privacy policy.
12. Recipients and processors
We use the following service providers as processors under data-processing agreements (Art. 28 GDPR), or as independent controllers where indicated:
- Supabase (database, login, realtime): [confirm EU region, e.g. Frankfurt]
- Vercel Inc. (hosting)
- Stripe Payments Europe Ltd. (payments; independent controller for payment processing)
- Paystack (payments for African markets; independent controller for payment processing)
- Cal.com (booking), Google (calendar sync, where you book)
- Resend (sending e-mail from the contact form)
- Cloudflare / Mux (video delivery)
- LibreTranslate (optional translation of community posts)
13. Transfers to third countries
Some providers are based in or process data in the USA or other non-EU countries. Transfers rely on an EU adequacy decision (e.g. the EU–US Data Privacy Framework, where the provider is certified) or on the EU Standard Contractual Clauses (Art. 46 GDPR), with additional safeguards where needed. A copy of the safeguards can be requested from us. For Paystack payments, transfer to Nigeria or another third country is necessary to perform the contract you request (Art. 49(1)(b) GDPR).
14. Your rights
- Access to your data (Art. 15) and a copy of it
- Rectification (Art. 16) and erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time (Art. 7(3)) with effect for the future
To use these rights write to the e-mail address above. We answer within one month. You also have the right to lodge a complaint with a supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, or the authority in your own country.
15. Obligation to provide data; automated decisions
Name, e-mail and password are required to create an account; without them we cannot offer a login. We do not use automated decision-making or profiling.
16. Age
The course and community are intended for adults aged 16 and over.
17. Changes
We update this policy when our processing changes. The current version is always available on this page.