Privacy
How we handle your data.
Last updated: 3 October 2026
This page explains what personal data we collect through this website, why, who helps us handle it, and the rights you have. We collect only what we need, we never sell your data, and we never use it for advertising.
Who is responsible
Vortex Retreats is run by The Dharma Academy OÜ (registry code 17325172, Sepapaja tn 6, 15551 Tallinn, Estonia), which is responsible for the personal data collected through this site. For any privacy question or request, write to [email protected].
What we collect
When you apply. The application form asks for your name, email, where you are based, and your answers about your work, past experiences and what you are looking for. You decide what to write.
When you book. Payments are handled by Wise (bank transfer) and Stripe (card payment plans) on their own pages. We never see or store your card details.
When you visit. Our hosting provider keeps standard technical logs (such as IP address, browser type and pages requested) to keep the site secure. With your permission we also use PostHog analytics, described under Cookies and analytics below.
Why we use it, and the legal basis
- To read your application and contact you about retreats that may be a match, on the basis of your consent and the steps you ask us to take before a booking.
- To understand which pages are useful and how people find this site. With cookies and session recordings, on the basis of your consent. If you decline cookies, anonymous visit counts only, on the basis of our legitimate interests.
- To keep the website secure, available and working, on the basis of our legitimate interests.
Who else handles it
- Cloudflare: website hosting, security, and the database that stores applications.
- Resend: delivers each application to our inbox.
- Google Workspace: the inbox where applications are read.
- PostHog: website analytics, as described below.
- Wise and Stripe: payments, only if you book.
Some of these providers may process data on servers outside the European Economic Area. Where that happens, it is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Cookies and analytics
When you first visit, a small banner asks whether you accept cookies. Nothing is measured until you choose.
If you accept, PostHog sets a first-party cookie so it can tell one visit from the next, and records how you move through the site, including session recordings. Anything you type, and the application form as a whole, are hidden in those recordings. Your IP address is not stored.
If you decline, no cookies are set and no session is recorded. Visits are only counted with an anonymous code that PostHog calculates on its servers and resets every day, so a visit can't be connected to you or followed from one day to the next.
How long we keep it
We keep your application for as long as it helps us match you with a retreat, and delete it sooner if you ask. Analytics data is kept for up to one year, and session recordings for 30 days.
Your rights
Under the GDPR you can access your data, correct it, delete it, restrict or object to its processing, ask for a copy in portable form, and withdraw consent at any time. Write to [email protected] and we will reply within one month. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the data protection authority where you live.
Children
Our retreats and this website are for adults (18+). We don't knowingly collect data from children.
Changes
We may update this page from time to time. The date at the top shows when it last changed.