LEGAL

Privacy Policy

Last updated: January 2026

1. Scope & controller

This Privacy Policy describes how [LEGAL NAME], registered under [REGISTRATION NUMBER] ("Free Hearts Foundation", "we"), processes personal data collected on freehearts.co, in the Free Hearts Foundation Immersion and in Free Hearts Foundation Council.

We follow GDPR principles and other applicable frameworks in the jurisdictions we operate.

2. Data we collect

Depending on your interaction: account data (name, email, phone), application data (professional history, approximate revenue, motivation), payment data (processed by a certified gateway — we never store cards) and browsing data (IP, device, pages visited).

3. Purposes

To execute contracts and deliver contracted services; assess Immersion applications; process payments; send operational communications and, upon consent, marketing communications; comply with legal and regulatory duties; and prevent fraud.

5. Sharing

We share data only with operators necessary to the operation (hosting, email delivery, payment gateways, analytics), under contract and confidentiality obligation, or when required by competent authority.

6. Retention

We keep data only for the time necessary to the stated purposes and to comply with legal, contractual and defense obligations.

7. Your rights

You may at any time: confirm processing; access your data; correct incomplete or outdated data; request anonymization, blocking or deletion; portability; consent withdrawal; and information on sharing.

To exercise, write to [CONTACT EMAIL]. We reply within legal timeframes.

8. Security

We adopt technical and administrative measures to protect your data: in-transit encryption, access controls, monitoring and periodic vendor review.

9. Updates

We may update this policy. The current version is always the one published on this page, with the update date at the top.

10. Data Protection contact

Data Protection Officer: [DPO NAME][CONTACT EMAIL].