
Last updated: December 5th, 2025.
Zen in the City ETS (“we”, “us”, “our”) is committed to protecting your personal data and ensuring transparency in how we process it. This Privacy Policy explains how we collect, use, store, and protect your personal data when you access our website, use our services, or interact with us in any way.
1. Data Controller
The Data Controller responsible for processing your personal data is:
Zen in the City ETS
Viale XXI Aprile, 21
00162 Rome – Italy
Tax Code: 96587620582
VAT No.: 17905881003
Email: [email protected]
2. Categories of Personal Data We Process
We may process the following categories of personal data:
2.1 Data provided voluntarily
- First name and last name
- Email address
- Physical address
- Tax code (Codice Fiscale)
- Data necessary for processing payments and issuing invoices (processed via third-party providers)
2.2 Data collected through your use of our services
- Login data and account information for members
- Data related to online course access and community participation
- Usage data related to interactions with our content (e.g., accessed pages, meditation sessions, course progress)
2.3 Technical data
- IP address
- Device type and browser information
- Cookies and similar technologies
- Log files and usage analytics (via Google Analytics GA4)
3. Purposes and Legal Bases for Processing
Your personal data is processed for the following purposes and legal bases:
3.1 Provision of free content and website access
To allow users to access freely available articles, meditations, and resources.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
3.2 Membership management and association services
To manage membership, provide access to exclusive content, online courses, and community services.
Legal basis: Contractual necessity (Art. 6(1)(b) GDPR).
3.3 Sale of online courses and paid services
To enable the purchase of online courses and paid offerings.
Legal basis: Contractual necessity (Art. 6(1)(b) GDPR).
3.4 Payment processing
Payments are handled through external processors such as Stripe, PayPal, GoCardless and Systeme.io.
Legal basis: Contractual necessity (Art. 6(1)(b) GDPR).
3.5 Sending newsletters and informative emails
To send communications to users who explicitly subscribe to the newsletter.
Legal basis: Consent (Art. 6(1)(a) GDPR).
3.6 Zoom sessions, webinars, and online events
To deliver live meditation sessions, webinars, and training activities via Zoom and Zoho Webinar.
Legal basis: Contractual necessity (Art. 6(1)(b) GDPR).
3.7 Analytics and improvement of services
To understand how users interact with our website and improve user experience.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
3.8 Automated emails and service communications
Systeme.io may send automated messages related to courses, membership, or community activities.
Legal basis: Contractual necessity (Art. 6(1)(b) GDPR).
4. Data Recipients (Data Processors)
We may share personal data with the following categories of third-party service providers, strictly for the purposes described above:
4.1 Membership, courses, CRM, and email automation
- Systeme.io
4.2 Website hosting
- SiteGround
4.3 Payments and invoicing
- Stripe
- PayPal
- GoCardless
4.4 Communication tools
- Zoom
- Zoho Webinar
4.5 Analytics and advertising
- Google (GA4, Gmail, Drive)
- Meta (Facebook/Instagram advertising)
4.6 WordPress plugins
- The Newsletter Plugin
- Contact Form 7
- Indeed Ultimate Membership Pro
- User Login History
All Data Processors operate under GDPR-compliant Data Processing Agreements (DPAs).
5. International Data Transfers
Some of our service providers may process data outside the European Economic Area (e.g., in the United States).
Where such transfers occur, they take place in accordance with:
- the European Commission’s Standard Contractual Clauses (SCCs), or
- other appropriate safeguards as required under Art. 46 GDPR.
These measures ensure that your data receives a level of protection essentially equivalent to that guaranteed within the EU.
6. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected:
- Account and membership data: retained for the duration of your membership or account and deleted upon request.
- Newsletter subscribers: retained until consent is revoked.
- Payment and invoicing data: retained for up to 10 years in compliance with legal obligations.
- Analytics data: retained according to Google Analytics GA4 default retention settings.
After these periods, data is securely deleted or anonymized.
7. User Rights
Under the GDPR, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interest
- Right to withdraw consent at any time (for consent-based processing)
- Right not to be subject to automated decision-making, including profiling, where applicable
To exercise any of these rights, contact us at [email protected]
.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
8. Cookies
We use cookies and similar technologies to:
- enable website functionality
- remember user preferences
- perform statistical analysis
- support advertising campaigns
- analyze website usage through Google Analytics GA4
You can manage or disable cookies via your browser settings. Some features of the website may not function properly without certain cookies.
For more details, please refer to our Cookie Policy.
9. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version is always available at:
https://zeninthecity.org/privacy/
We encourage you to review this page periodically.
