Privacy Policy
Information on how personal data is collected, processed, and protected in compliance with the EU General Data Protection Regulation (GDPR) and international privacy standards.
1. Controller Information
The data controller responsible for the processing of personal data on this website pursuant to Article 4(7) of the General Data Protection Regulation (GDPR) is:
Andreas Horvath
Business Form: Sole Proprietor (Freelancer)
Business Correspondence Address: Hausmanning 1, 94099 Ruhstorf, Germany
Email: contact@raiseyourlight.com
Website: https://raiseyourlight.com
2. Security Measures & Technical Architecture
We maintain technical and organizational measures to ensure data confidentiality, integrity, and availability in accordance with Article 32 GDPR.
SSL/TLS Transport Encryption
All communications between your browser and our application are encrypted using industry-standard TLS encryption protocol to prevent unauthorized interception.
Server-side API Architecture
All external AI integrations and communications are routed exclusively through secure server-side API endpoints in Next.js. Authentication credentials and API keys remain strictly server-side and are never exposed to client browsers.
3. Web Hosting & Server Log Files
This website is hosted on infrastructure provided by Hostinger (Hostinger International Ltd.). When accessing our website, web servers automatically collect technical access data sent by your web browser in server log files.
Information collected includes:
- Browser type, browser version, and operating system
- Referrer URL (previously visited website)
- Host name and IP address of the accessing device
- Date, time, and status code of the server request
Legal Basis: Processing is carried out pursuant to Article 6(1)(f) GDPR based on our legitimate interest in ensuring technical stability, system performance, error diagnostics, and defense against malicious attacks. Server log data is automatically deleted after standard technical security retention periods.
4. Soul Mirror AI Questionnaire & Processing
Our platform offers an interactive self-reflection tool named Soul Mirror. Users may voluntarily submit responses to reflective prompts regarding emotional states, personal growth, life themes, limiting beliefs, relationships, and self-inquiry.
Purpose of Processing
When you submit the Soul Mirror questionnaire, your written entries are transmitted through an encrypted server-side API route to our AI service providers (OpenAI API and/or Google Gemini API) solely to generate your requested personalized reflection.
Soul Mirror provides AI-generated reflections intended solely for personal reflection and informational purposes. The generated content does not constitute medical, psychological, psychotherapeutic, legal, financial, or other professional advice and should not be relied upon as a substitute for qualified professional guidance.
AI Model Training Commitments
Our application does not use submitted questionnaire data to train custom AI models. According to the published policies of OpenAI and Google, customer content submitted through their commercial API services is not used to train their foundation models.
Special Category Data (Art. 9 GDPR)
Depending on your responses, you may voluntarily include personal details touching upon mental wellbeing, emotional health, personal beliefs, or philosophical reflections. Where information falls under special categories of personal data (Article 9(1) GDPR), processing is conducted based on your explicit consent pursuant to Article 9(2)(a) GDPR provided through voluntary submission.
International Data Transfers
Processing by AI providers may involve secure server infrastructure outside the European Economic Area (EEA), including in the United States. Where applicable, transfers rely on recognized GDPR safeguards such as the EU-U.S. Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) adopted by the European Commission.
Retention & Logging
Questionnaire responses are processed dynamically to generate the requested reflection. Unless required for temporary security logging, abuse prevention, or statutory compliance obligations, submissions are not retained by the application after processing.
Legal Basis
Processing is conducted pursuant to Article 6(1)(b) GDPR (necessary to perform the requested service) or, where applicable, Article 6(1)(a) GDPR and Article 9(2)(a) GDPR based on explicit voluntary submission consent.
5. Recipients of Personal Data and Service Providers
We engage carefully selected third-party service providers (recipients) to support hosting, communications, analytics, and AI features. All recipients process data strictly in accordance with applicable data protection laws.
Hostinger
Hostinger International Ltd. – Web hosting and server infrastructure.
OpenAI
OpenAI, LLC (San Francisco, CA, USA) – AI text generation via server API endpoint.
Google (Gemini API & Analytics)
Google LLC / Google Ireland Limited – Fallback AI model provider and web analytics.
Microsoft Clarity
Microsoft Corporation (Redmond, WA, USA) – Pseudonymized session heatmap and usability interaction analysis.
Meta Pixel (Facebook / Instagram)
Meta Platforms Ireland Ltd. – Conversion measurement for lead magnet referrals from social media campaigns (consent-based).
Brevo (Sendinblue)
Brevo SAS (Paris, France) – Newsletter distribution and double opt-in email management.
6. Web Analytics & Usability Optimization
Subject to your explicit consent via our cookie banner (Article 6(1)(a) GDPR), we utilize web analytics tools to understand usage patterns and optimize our digital experience.
Google Analytics 4
Google Analytics 4 processes event and usage data to help us understand how visitors use our website. IP addresses are processed only as necessary to derive approximate location information and are not retained in analytics reports, in accordance with Google's published documentation.
Microsoft Clarity
Microsoft Clarity records pseudonymized user interaction data such as clicks, scrolling movement, and page navigation. This information helps us identify technical usability bottlenecks and refine site layout.
7. Cookies & Consent Management
Necessary cookies are required for the secure operation of the website and cannot be disabled through our consent manager. Analytics and marketing cookies are only placed after you provide your consent. You may withdraw or modify your consent at any time via the cookie preferences panel.
For full details regarding specific cookie names, durations, and providers, please consult our dedicated Cookie Policy.
8. Contact Forms & Direct Inquiries
When contacting us via contact forms, email, or direct messages regarding coaching, retreats, or general inquiries, your submitted details (such as name, email address, message content) are processed to handle your request.
Legal Basis: Article 6(1)(b) GDPR (performance of pre-contractual steps or service inquiries) or Article 6(1)(f) GDPR (legitimate interest in communicating with users).
Retention: Inquiries are stored for as long as necessary to fulfill the request and deleted thereafter unless statutory commercial or tax retention obligations apply.
9. Newsletter & Email Communications (Brevo)
If you subscribe to our newsletter, your email address is processed using a confirmed double opt-in procedure. Subscriptions are dispatched via Brevo (Brevo SAS, France).
Double Opt-In: After submitting your email, you will receive a confirmation link to verify ownership of the address.
Unsubscribe Right: You may unsubscribe at any time using the link in any newsletter or by contacting us directly.
Legal Basis: Article 6(1)(a) GDPR (Consent).
10. Your Rights Under GDPR
Under Chapter III of the GDPR, you have the following rights regarding your personal data:
Art. 15 – Right of Access
Obtain confirmation and information regarding data processed about you.
Art. 16 – Right to Rectification
Request immediate correction of inaccurate or incomplete personal data.
Art. 17 – Right to Erasure
Request deletion of personal data ("Right to be forgotten").
Art. 18 – Right to Restriction
Request restriction of data processing under certain statutory conditions.
Art. 20 – Right to Data Portability
Receive your personal data in a structured, commonly used machine-readable format.
Art. 21 – Right to Object
Object to processing based on legitimate interests (Art. 6(1)(f) GDPR).
Art. 7(3) – Right to Withdraw Consent
Withdraw any previously granted consent at any time with future effect.
Art. 77 – Right to Lodge a Complaint
Lodge a complaint with a competent data protection supervisory authority.
To exercise your rights or for questions concerning data protection, please contact us directly at contact@raiseyourlight.com.
Last Updated: July 2026
