Privacy
Updated: 23 September 2026
Who is responsible
The controller is Javier Wilfrido Garcia Goyes, a sole trader established in the United Kingdom, trading as ZenOfMe. For privacy enquiries: hola@zenofme.com.
What this version does
You can read and use the practices without an account, payment or subscription. This version has no advertising pixels, Clarity or visitor analytics installed. We do not store a personal history of your meditation sessions.
Letters by email
If you leave your address in the form, we use it to send you a confirmation email (double opt-in). Sending that email already means processing your address: it goes through Resend, our email provider, which keeps a record of the message for a limited time (explained below). We only add you to the list of letters when you press the confirm button; if you don't confirm, we don't add you.
To respect your choice and protect the form from abuse, our server keeps a minimal record: a fingerprint of your address pseudonymised with a secret key (it is not the address itself), your language, and the dates you confirmed, the welcome letter went out and you unsubscribed. If a sign-up or an unsubscribe hasn't yet reached Resend, we keep your address encrypted only until it does, and we retry automatically until it is applied; before sending each letter we check that none is left pending. Before adding you back, we check with Resend whether you unsubscribed from one of its letters or by hand, so that we respect it. To avoid repeated emails we count requests per address and per IP address using pseudonymised fingerprints that are deleted once they are 24 hours old. Backups of this record are kept for at most 7 days; they may include, encrypted, the address of a change that was pending at that moment, and they do not include the sending counters.
The purpose is to send you our occasional letters: practices, ideas for resting better and news about the method. The legal basis is your consent, which you can withdraw at any time using the unsubscribe link in any letter, your email app's unsubscribe option where it offers one, or by writing to hola@zenofme.com. The minimal record and the sending limits rely on our legitimate interest in respecting your choice and preventing abuse. We keep your address on the list while you remain subscribed; when you unsubscribe we mark it as unsubscribed. In the minimal record we keep the fingerprint and the dates for as long as we run the letters list, only to respect your unsubscribe and not write to you again; if we close the list, we delete it.
Your browser requests pages and, when you open a practice, its audio file (a small part on opening and the rest as you listen). To deliver and protect those requests, hosting and network services process technical data such as IP address, requested URL, date and browser type. We use this to operate the website and identify problems or abuse, relying on our legitimate interest in providing a secure service. We do not use it to build advertising profiles.
If you email us, we use your address and the content needed to answer your enquiry, also on the basis of legitimate interests. Please avoid including unnecessary medical or sensitive information. We do not use messages to provide a diagnosis.
Providers and retention
Pages are served from our server at Hetzner (Germany), which also holds the minimal subscription record. Cloudflare runs the domain's DNS, delivers the audio files and forwards the emails you send to hola@zenofme.com to our Gmail (Google) mailbox. That is where we receive your enquiries, your replies to the letters and any unsubscribe you ask for by email, which we record by hand in the minimal record so it is applied like any other. Google LLC may process those emails in the United States and participates in the EU-US Data Privacy Framework and its UK Extension. Resend (United States) sends the letters from servers in the European Union (Ireland) and holds the subscriber list. According to Resend, account data, message content and delivery logs are stored in the United States, and messages and logs are kept for 30 days; that transfer relies on the standard contractual clauses with the UK Addendum and on the EU-US Data Privacy Framework with its UK Extension. Your messages and practice data are not sent to ElevenLabs: the voice is generated beforehand from our scripts.
We retain enquiries for as long as needed to respond and for up to twelve months after closing them, unless a legal obligation or claim justifies longer retention. Technical logs are retained according to security needs, incident investigation and applicable obligations, and should not be kept after that need ends. Providers may operate internationally; you can request information about the processing and safeguards applicable to the relevant service.
Browser preferences
NEXT_LOCALE: a session cookie holding the language of the page you visit, so the home page takes you to that language; it is deleted when you close your browser.zenofme-theme: your theme preference, stored locally in your browser until you change it or clear site data.
These preferences support your requested choices. They are not advertising or tracking across websites. You can clear site data through your browser and still use the website. If we introduce services requiring consent, they will remain inactive until you give it.
Your rights
You can request access, correction or erasure, and restriction or portability where applicable. You can object to processing based on legitimate interests. Use the contact address above. We normally respond within one month, subject to applicable legal exceptions.
You can complain to the UK ICO or the relevant data protection authority. We do not make automated decisions about you with legal or similarly significant effects.