Last Updated: May 12, 2026
This Privacy Policy explains how Camille Barrios (“we,” “us,” “our”) collects, uses, and protects your personal data when you visit and use camillebarrios.com. We’ve tried to write it in plain language wherever possible, while still covering everything the law requires us to disclose.
Who’s Responsible for Your Data
The data controller is Camille Barrios, P.IVA 12390730153, based in Italy. If you ever have a question or request, you can reach out at cmllbarrios@yahoo.com or camille@camillebarrios.com.
Our Commitment
We’re committed to protecting your privacy and handling your data in line with the GDPR (EU Regulation 2016/679), the Italian Privacy Code (D.Lgs. 196/2003, as amended), and the ePrivacy Directive (2002/58/EC). In the sections below, we’ll walk through what personal data we collect, why we collect it, how we use and protect it, how long we keep it, and what rights you have over it.
The Personal Data We Collect
What you give us directly. When you purchase services or products from us, we collect your first and last name, your email address, your country of residence, and payment information (which is actually processed by third parties — more on that in the sharing section below). If you ask us for an invoice, Italian tax law requires us to also collect your full legal name or business name, your complete postal address, and either your Codice Fiscale or P.IVA. If you subscribe to our newsletter, we collect your name and email — this is entirely optional and requires its own separate consent. If you email us, we naturally end up with your email address, your name if you share it, whatever you write in your message, and the history of our correspondence. And if you book a session through Cal.eu, we collect your name, email, the date and time you selected, and any notes you add to the booking form.
What gets collected automatically. Simply by visiting our website, some technical information is gathered: your IP address (anonymized before it reaches our analytics), your browser type and version, basic device information, which pages you visit and how long you spend on them, the site that referred you here, and the date and time of your visit. Cookies are part of this too — you can find the full breakdown in our separate Cookie Policy. We also get a general sense of how you interact with the site: which pages you click through to, and whether you watch any embedded YouTube videos.
Why We’re Allowed to Process Your Data
GDPR requires us to have a valid legal basis for everything we do with your data, and different activities rest on different grounds. Processing your purchases and delivering services is based on the performance of our contract with you. Issuing and storing invoices is based on our legal obligation under Italian tax law. Booking and delivering sessions is again based on contract performance. Newsletter subscriptions and website analytics both rely on your consent — the newsletter through an opt-in checkbox, and analytics through our cookie banner. Responding to your emails rests on our legitimate interest in actually answering the people who write to us, and the same goes for customer support generally, where we have a legitimate interest in keeping service quality high. Payment processing, like purchases, is based on contract performance. Whatever the basis, you always retain the right to withdraw consent, object to processing based on legitimate interest, and exercise the other rights described later in this policy.
How We Actually Use Your Data
Processing your purchases and sessions. When you buy something or book a session, we use your name, email, payment details, and booking information to confirm your order, send session confirmations, hand you the video link for online sessions, send receipts, and provide support if something goes wrong. This runs through WooCommerce, PayPal, and Cal.eu.
Issuing invoices. Because Italian tax law (D.P.R. 633/1972) requires it, we use your full name or business name, address, and Codice Fiscale or P.IVA to issue electronic invoices. These are stored for 10 years, as the law requires, transmitted through the Sistema di Interscambio (SDI) where applicable, and we’re happy to provide copies on request.
Sending our newsletter. If you’ve opted in, we use your first name, last name, and email to send monthly newsletters, announce events and new offerings, and share resources — all through Mailchimp. You’re always in control here: subscribing requires a separate opt-in checkbox, every email includes an unsubscribe link, and you can manage your preferences directly through Mailchimp’s preference center.
Understanding how the site is used. Through Google Analytics 4, we use your anonymized IP address, browsing behavior, and device information to see which pages get the most traffic, understand how people navigate the site, catch technical issues, and improve the design and content over time. This requires your opt-in through the cookie banner, and you can withdraw that consent anytime through the cookie settings or Google’s own opt-out tool at https://tools.google.com/dlpage/gaoptout.
Replying to your emails. When you write to us, we use your email address, name, and message content — stored on our email servers, which run through both Yahoo Mail and our website’s own email hosting via SupportHost (camillebarrios.com) — simply to respond to you, provide support, keep track of context in ongoing conversations, and maintain a record for reference.
Handling your session bookings. For anyone who books a session, we use your name, email, and session details (through Cal.eu, and Zoom or Skype for the call itself) to send confirmations and reminders, provide the video link and any access instructions, and follow up afterward if needed.
How Long We Hold On to Your Data
We only keep personal data for as long as it’s genuinely needed for the purpose it was collected for. Invoice data and purchase records are kept for 10 years, as Italian tax and accounting law requires. Email correspondence is generally kept for up to 5 years, or until you ask us to delete it. Session booking data is kept for 2 years after your last session. Newsletter subscriber data is kept for as long as you remain subscribed. Website analytics data follows Google Analytics’ default retention of 26 months. Cookie consent records are kept for 12 months. And any booking data held by Cal.eu follows Cal.eu’s own retention policy, since that’s outside our direct control. Once a retention period ends, we securely delete or anonymize the data — though we may occasionally need to hold onto something longer if the law requires it, or if it’s needed for legal proceedings or to defend a legal claim.
Who We Share Your Data With
To actually run our business, we rely on a number of trusted third-party services, each of which is contractually bound to protect your data on our behalf.
For payments, we use PayPal (PayPal Holdings, Inc.), which receives your name, email, and transaction amount; it’s based in the United States and relies on Standard Contractual Clauses for the transfer, and its privacy policy is at https://www.paypal.com/privacy. For higher-value services, we sometimes handle payment via direct bank transfer instead, in which case bank details are simply exchanged by email between us, through the Italian banking system.
For our online store, we use WooCommerce (Automattic Inc.), which receives your name, email, order details, and country; it’s US-based and uses Standard Contractual Clauses, with its privacy policy at https://automattic.com/privacy/. Our website itself is hosted by SupportHost, based in Tallinn, Estonia, which naturally has access to all website data as part of running the infrastructure.
For scheduling, we use Cal.eu (Cal.com, Inc.), which is EU-based and receives your name, email, chosen date and time, and any booking notes; its privacy policy is at https://cal.com/privacy.
For video sessions, we use Zoom Video Communications, Inc., which receives your name, email, and meeting participation data, is based in the US, and relies on Standard Contractual Clauses (privacy policy at https://zoom.us/privacy). As an alternative, we sometimes use Skype (Microsoft Corporation), which receives your Skype username and call data, also under Standard Contractual Clauses (privacy policy at https://privacy.microsoft.com/).
For our newsletter, we use Mailchimp (The Rocket Science Group, LLC, part of Intuit Inc.), which receives your first name, last name, email, and subscription preferences; it’s US-based under Standard Contractual Clauses, its privacy policy is at https://www.intuit.com/privacy/statement/, and you can unsubscribe anytime via the link in any email.
For managing cookie consent, we use CookieYes (CookieYes Limited), based in Ireland, which receives your consent choices, IP address, and browser information; its privacy policy is at https://www.cookieyes.com/privacy-policy/.
For website analytics and tag management, we use Google Analytics 4 and Google Tag Manager (both Google LLC), which receive anonymized IP addresses, pages visited, device information, and general browsing behavior. Both are based in the United States and rely on the EU-U.S. Data Privacy Framework plus Standard Contractual Clauses. Analytics anonymizes your IP by removing the last portion before processing; you can opt out at https://tools.google.com/dlpage/gaoptout, and Google’s privacy policy is at https://policies.google.com/privacy.
For embedded content, we use YouTube (Google LLC) to display videos on our site — which can collect your IP address, cookies, and viewing behavior even if you don’t press play, under the same Data Privacy Framework and Standard Contractual Clauses protections. We use YouTube’s privacy-enhanced mode where we can, to limit this. We also use Google Fonts (Google LLC) to display custom typography, which involves sharing your IP address and browser information under the same safeguards. Both link to https://policies.google.com/privacy.
Finally, for email correspondence, we use two providers. Personal email runs through Yahoo Mail, based in the United States, whose privacy policy is at https://legal.yahoo.com/privacy/. Our website email (the camillebarrios.com addresses) is hosted through SupportHost, based in Tallinn, Estonia — the same provider that hosts our website itself. Both naturally hold the content of email exchanges sent to those addresses.
When Your Data Crosses Borders
Some of our service providers — mostly Google-related services — process data outside the European Union and European Economic Area, particularly in the United States. To keep that transfer lawful and secure, we rely on a few layers of protection: Google LLC participates in the EU-U.S. Data Privacy Framework, which you can read more about at https://www.dataprivacyframework.gov/; we use Standard Contractual Clauses approved by the European Commission under GDPR Article 46 with providers like PayPal, WooCommerce, Mailchimp, Zoom, and Skype; and on top of that, we apply additional technical and organizational measures like encryption in transit and at rest, access controls, regular security audits, and data minimization. You’re entitled to ask us for more information about any of these transfers, request a copy of the relevant safeguards, object to a transfer under certain circumstances, or lodge a complaint with the Italian Data Protection Authority. Just email cmllbarrios@yahoo.com if you’d like to look into any of this.
Your Rights Under GDPR
As someone based in the EU or EEA, data protection law gives you a meaningful set of rights over your own information, and we want to make exercising them as easy as possible.
You can ask us to confirm what data of yours we hold and get a copy of it — just email cmllbarrios@yahoo.com with the subject “Data Access Request,” and we’ll share the categories of data we process, why we process it, who it’s shared with, how long we keep it, and a copy of the data itself. We aim to respond within a month, though complex requests may take up to three.
You can ask us to correct anything inaccurate or incomplete. One exception: invoice data can’t be edited after it’s issued, since Italian tax law requires a formal amendment procedure instead.
You can ask us to delete your data — often called the “right to be forgotten” — in situations where it’s no longer needed, where you’ve withdrawn consent, where you object to processing based on legitimate interest, where it was processed unlawfully, or where deletion is itself a legal obligation. That said, there are limits: we can’t delete invoice data during its mandatory 10-year retention, data needed to defend a legal claim, or data processed for public-interest archiving. To request erasure, email cmllbarrios@yahoo.com with the subject “Data Erasure Request.”
You can ask us to restrict how we use your data — for example, while we verify a disputed accuracy claim, or where processing turns out to be unlawful but you’d prefer restriction to outright deletion. Just email us and explain the reason.
You can ask for your data in a portable, commonly used format (we provide JSON, CSV, or PDF) so you can move it elsewhere — this applies to data based on consent or contract that we process by automated means. Email cmllbarrios@yahoo.com with the subject “Data Portability Request.”
You can object to processing based on legitimate interest at any time for reasons specific to your situation, and we’ll stop unless we have compelling grounds to continue. You can also object to marketing at any time — every newsletter has an unsubscribe link, and we’ll stop immediately once you use it.
You can withdraw consent whenever processing is based on it, such as your newsletter subscription or cookie consent. For the newsletter, just click unsubscribe; for cookies, adjust your preferences in the banner; for anything else, email us. Withdrawing consent doesn’t affect the lawfulness of anything we did before you withdrew it.
And if you ever feel your rights haven’t been respected, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at https://www.garanteprivacy.it, by email at garante@gpdp.it, or by post at Piazza Venezia, 11, 00187 Roma, or by phone at (+39) 06.696771. You’re also free to complain to the supervisory authority in whichever EU country you live or work in.
One more thing worth noting: we do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
How We Keep Your Data Secure
We take a layered approach to security. On the technical side, we use HTTPS/SSL encryption for data in transit, store data on secured servers with access controls, enforce strong password policies, keep regular encrypted backups, and apply security patches and updates as they come out. On the organizational side, we limit data access to personnel who genuinely need it, bind everyone with confidentiality agreements, collect only the data we actually need, periodically review our security and privacy practices, and maintain procedures for responding to incidents.
If a data breach ever occurred that posed a risk to your rights and freedoms, we would notify the Italian Data Protection Authority within 72 hours and inform affected individuals without undue delay, explaining the nature of the breach, its likely consequences, and the steps we’ve taken.
Third-Party Links and Embedded Services
Our website sometimes links to external sites or embeds third-party content like YouTube videos and Google Fonts. We’re not responsible for how those third parties handle privacy, and they may collect data independently of us — we’ve detailed the ones we actively use in the sharing section above. If you interact with any external site or service we link to, whether a social media profile, a recommended resource, or a partner site, we’d encourage you to check their own privacy policy as well.
Cookies, Briefly
We use cookies and similar tracking technologies, and we’ve written a dedicated Cookie Policy covering the details. In short: essential cookies are always active because the site needs them to function; analytics cookies require your consent through the cookie banner; and third-party cookies set by services like Google and YouTube also require consent. You can manage all of this through the cookie banner on your first visit, the preferences link in our footer, or your browser’s own settings.
Children’s Privacy
Our services aren’t directed at anyone under 18, and we don’t knowingly collect data from children under 18. By using our services, you’re confirming that you’re at least 18 years old. If you believe we’ve somehow collected data from someone underage, please let us know right away at cmllbarrios@yahoo.com and we’ll investigate and delete it promptly.
Keeping This Policy Current
We may update this Privacy Policy from time to time to reflect changes in our practices, new legal requirements, feedback from supervisory authorities, or changes to the service providers we use. You’ll always find the current “Last Updated” date at the top of this page, and for significant changes, we’ll post a notice on our website or, for material changes, email you directly if we have your contact details. We’d encourage you to check back periodically. If we ever plan to use your data for a new purpose that requires consent, we’ll ask for your explicit agreement before making that change.
When We Might Be Legally Required to Share Your Data
There are certain situations where the law requires us to disclose your data regardless of the other protections in this policy — for example, in response to court orders or legal proceedings, requests from law enforcement or government authorities, Italian tax audits, or to protect our own legal rights. Where we’re not legally prohibited from doing so, we’ll try to notify you when this happens.
If our business were ever sold or transferred, your personal data could be transferred to the new owner as part of that process. You’d be notified of any change in data controller, and this Privacy Policy would continue to apply.
Sensitive Data
We don’t intentionally collect what GDPR calls “special categories” of personal data — things like racial origin, religious beliefs, or health information. That said, if you voluntarily share health-related information with us, for instance a medical condition that might affect your participation in a session, we process that based on your explicit consent and in order to protect your wellbeing during the session, and we keep it confidential and securely stored. For clarity: things you share during coaching or movement sessions about emotions or personal experiences generally aren’t considered “special category data” under GDPR, unless they reveal an actual health condition — in which case explicit consent is required.
Professional Supervision and Confidentiality
As part of standard practice in the coaching profession, topics discussed during sessions may occasionally be shared with a professional supervisor or mentor for the sake of professional development, ethical guidance, and quality improvement. These discussions are always kept anonymous, with no identifying information shared, and the supervisor is bound by the same professional confidentiality standards.
We’re also a member of the International Conscious Movement Teachers Association (ICMTA) and adhere to its Code of Ethics. ICMTA may review complaints if any arise, sharing data only where necessary, and is itself bound by professional confidentiality agreements.
Keeping Records (Accountability)
In line with GDPR’s accountability principle, we maintain internal records of our processing activities, data protection impact assessments where required, records of consent, records of any data subject requests and how we responded, documentation of our security measures, and data processing agreements with each of our processors. These are available to supervisory authorities upon request.
Getting in Touch
For any privacy-related question or request, you can reach the data controller, Camille Barrios (P.IVA 12390730153), at cmllbarrios@yahoo.com or camille@camillebarrios.com. We aim to respond to privacy requests within a month, though complex requests may take up to three, and we’ll let you know if we need the extra time. There’s no fee for handling your requests, except in cases that are manifestly unfounded, excessive, or repetitive, where we may charge a reasonable amount.
Filing a Complaint
If you ever feel we haven’t handled your data properly, you’re entitled to file a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), based at Piazza Venezia, 11, 00187 Roma, Italy. You can reach them by phone at (+39) 06.696771, by fax at (+39) 06.69677.3785, by email at garante@gpdp.it, by certified email (PEC) at protocollo@pec.gpdp.it, or through the online complaint form on their website at https://www.garanteprivacy.it.
This Privacy Policy complies with the GDPR (EU Regulation 2016/679), the Italian Privacy Code (D.Lgs. 196/2003, as amended), and the ePrivacy Directive (2002/58/EC).
