Legal
Privacy Policy
Last updated: 30 September 2026
This Privacy Policy explains how BreatheHeart (“we”, “us”, “our”) processes personal data when you visit https://radio.breatheheart.com or listen toBreatheHeart Radio. We process data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Controller
Controller: BreatheHeart
Email: privacy@breatheheart.com
General contact: hello@breatheheart.com
Please update this section with your registered legal name, postal address, and (where required) company registration number before go-live.
2. What we collect
- Server and CDN logs — IP address, user agent, referrer, timestamps, requested URLs. Used for security, abuse prevention, and service reliability.
- Stream connection metadata — technical connection data when you play the radio stream (similar to access logs). Not used to build marketing profiles.
- Contact form / email — name, email address, and message content you voluntarily send us.
- Cookie consent choice — stored locally in your browser so we remember your preference.
- Optional analytics — only if you accept non-essential cookies and we enable a privacy-friendly analytics tool. Disabled by default until configured.
3. Purposes and legal bases
- Provide the website and radio stream — Art. 6(1)(b) or (f) GDPR (contract / legitimate interest in operating a public web radio).
- Security and abuse prevention — Art. 6(1)(f) GDPR.
- Respond to messages — Art. 6(1)(b) or (f) GDPR.
- Optional analytics / non-essential cookies — Art. 6(1)(a) GDPR (consent).
- Legal compliance — Art. 6(1)(c) GDPR where we must keep records.
4. Recipients and processors
We may use hosting, CDN, DNS, email, and streaming infrastructure providers (e.g. VPS host, object storage, AzuraCast/Icecast hosting). They process data only on our instructions under Art. 28 GDPR agreements where applicable.
5. International transfers
If a provider stores or processes data outside the EEA/UK, we rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses, plus supplementary measures where needed.
6. Retention
- Server / stream logs: typically 7–90 days, unless needed longer for security incidents.
- Contact emails: as long as needed to handle your request, then deleted or archived per legal duties.
- Cookie consent: until you clear site data or change preference.
7. Your rights
Under the GDPR you may have the right to:
- Access your personal data
- Rectification
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your supervisory authority
To exercise these rights, email privacy@breatheheart.com. We may need to verify your identity.
8. Children
The service is not directed at children under 16. We do not knowingly collect children’s data. If you believe a child provided data, contact us and we will delete it.
9. Cookies
See our dedicated Cookie Policy for details and choices.
10. Changes
We may update this policy. The “Last updated” date will change when we do. Material changes may be highlighted on the site.
11. Disclaimer
Programme descriptions (including “Deep Sleep Frequencies”) describe listening mood only. They are not medical advice or clinical claims.