Privacy Policy
1. Controller
Kirstin Sharon Troeger (operating under the name Sharon Kirstin)
c/o POSTFLEX PFX-109-578, Emsdettener Straße 10, 48268 Greven, Germany
Email: sheritesherself@gmail.com
A Data Protection Officer (Datenschutzbeauftragter) is not appointed for this business. Under German law (§38 BDSG), one is required only once around 20 people regularly process personal data by automated means, or for specific high-risk/large-scale processing — neither applies to a solo practice running an email list and a guide site. Worth re-checking if that changes.
2. General principles
Personal data (any information relating to an identified or identifiable person) is only processed here in line with GDPR principles: lawfulness, purpose limitation, data minimization, and storage limitation. Each processing activity below states its purpose, its legal basis, and — where known — how long the data is kept.
3. Hosting and server log files
This site is hosted by Netlify, Inc., a US-based company, and served through Netlify's global content delivery network rather than from a single fixed server location. Every time you visit, Netlify automatically records a server log entry: IP address, date and time of access, browser type and version, operating system, referring URL, and amount of data transferred. This happens automatically and is not tied to a form you fill in. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating and securing the site.
Because Netlify is a US company, this involves a transfer of personal data outside the EU/EEA. Netlify's Data Processing Addendum (incorporated into its terms of service) uses Standard Contractual Clauses to govern this transfer, which is the standard, GDPR-recognized mechanism for exactly this situation. See Netlify'sprivacy policyand GDPR/CCPA page.
This site is served over HTTPS (TLS encryption) end to end.
4. Cookies
This site currently sets no cookies and runs no analytics, advertising, or tracking scripts of any kind — no Google Analytics, no Meta Pixel, no social media plugins. If that changes (for example, adding privacy-respecting analytics later), this section will be updated first, and a cookie-consent mechanism will be added before any non-essential cookie is set.
5. Contact
The contact form at /contact/ collects your name, email address, and message, and sends them directly to Sharon's inbox via Netlify Forms (operated by Netlify, Inc., which also hosts this site — see Section 3). This data is used only to respond to your inquiry. Legal basis: legitimate interest in responding to messages sent to us, or steps taken at your request prior to entering into a contract (Art. 6(1)(b) or (f) GDPR). Submissions are retained only as long as needed to handle the inquiry, then deleted.
6. Email list
The email list is operated using MailerLite, which acts as a processor on our behalf under a Data Processing Agreement (Art. 28 GDPR). When you sign up, your email address is transmitted to MailerLite and stored there.
Double opt-in is enabled. After signing up you will receive a confirmation email, and you are only added to the list once you confirm. Legal basis: your consent (Art. 6(1)(a) GDPR). Your address is retained for as long as your subscription is active, plus a record of your consent for as long as required to evidence it.
Subscribers receive new guides and essays. Your address is not sold, rented, or used for anything else.
As an EEA-based customer, this account is served by MailerLite Limited (an Irish company, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland), and subscriber data does not leave the EEA/UK/Switzerland. MailerLite's servers are EU-based (Germany and Belgium), and the Data Processing Agreement (Art. 28 GDPR) is incorporated directly into MailerLite's Terms of Use — see theirlegal documents pageand privacy policy. No third-country transfer or Standard Contractual Clauses are involved.
You can unsubscribe at any time via the link in every email. Unsubscribing stops future emails; a separate erasure request is needed to remove the underlying record entirely (see Section 9).
7. Health-related data — special category data
Coaching and hypnotherapy work can surface health-related information (mental health, trauma history, medical conditions). Under Art. 9 GDPR this counts as a "special category" of personal data, requiring a higher bar than ordinary data: explicit, specific consent naming the exact data type and purpose — a general "I agree to the privacy policy" checkbox is not sufficient on its own.
This website does not collect any health-related information, and does not ask for it — there is no intake form, booking form, or client questionnaire live on the site, and none is planned that would request this category of data without the safeguard described below being built in first.Before any such form is added (an intake form, a booking flow, a client questionnaire), this section needs a real Art. 9(2)(a) explicit-consent mechanism built into that form itself, not just a mention here — a checkbox at the bottom of a long form does not meet the bar the law sets for this category of data. Flagging this now so it isn't missed later, since it's the single highest-stakes gap for a practice like this one.
Separately: any health-related information shared with Sharon directly (by email, by phone, or in a session) is governed by professional confidentiality and the same GDPR principles, but is outside what a website privacy policy covers — that belongs in a client-facing intake/consent document, not this page.
8. AI transparency disclosure
Required under Article 50 of the EU AI Act, applicable from August 2, 2026.
How AI is used on this site: Interpretation, clinical judgment, voice, and the final word on every published piece are Sharon's. AI tools accelerate research, drafting, and site operations, under her direct review at every stage — nothing is published without her editing and approving it.
AI-generated imagery: the hero image on the home page is AI-generated. Any future imagery on this site will be labeled the same way if it is AI-generated; photographs of Sharon or real, unaltered photography will not carry this label.
The Claude Prompt tool: guides on this site may include a companion prompt that readers can run in Claude (a third-party AI system not operated by She Rites Herself). Readers interacting with that tool are interacting directly with an AI system, and are told so at the point of use, not only here — it does not diagnose, and does not tell a reader what to decide.
AI-assisted text: guide drafts are AI-assisted but undergo full human editorial review before publication — every guide is edited and approved by Sharon before it goes live. Essays are written by Sharon; AI is used only as an interactive sparring partner during drafting, never as an autonomous author.
9. Your rights
Under the GDPR, you have the right to:
- Access the personal data held about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data erased ("right to be forgotten") (Art. 17)
- Restrict processing in certain circumstances (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing, including — specifically and at any time — to direct marketing such as the email list (Art. 21)
- Withdraw consent at any time, without affecting processing that already happened lawfully before the withdrawal (Art. 7(3))
- Lodge a complaint with a supervisory authority — based on the Greven (NRW) address above, this would be the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). Worth a final confirmation that this is the correct authority for a mail-forwarding business address before publishing, rather than assuming it from geography alone.
To exercise any of these rights, contact sheritesherself@gmail.com.
10. Retention
Data is kept only as long as needed for the purpose it was collected for, or as required by law. Netlify server logs (Section 3) are retained on Netlify's own short rolling window, not by us directly. Email-list records (Section 6) are kept for the duration of an active subscription, plus a record of consent for as long as needed to evidence it. Contact-form submissions (Section 5) are kept only as long as needed to handle the inquiry, then deleted. Any future client records from one-to-one work would follow separate professional retention obligations, outside the scope of this website policy.
11. Children
This site and its services are not directed at, and are not intended for use by, anyone under 16.
12. Changes to this policy
This policy will be updated as the site's actual data practices change — for example, once the email list is technically connected, once hosting is confirmed live, or if any new data collection (like a contact or intake form) is added. The date of the current version: 24 August 2026.