Privacy Policy
Kyra Spira | kyraspira.com | Last updated: May 2025
Kyra Spira understands that your privacy is important to you and that you care about how your personal data is used. I respect and value the privacy of all clients, participants, and website visitors. This Privacy Policy explains what personal data I collect, why I collect it, and how I use it. I encourage you to read it carefully.
Who Am I?
Kyra Spira is a sole trader offering online educational services, including guided meditations and structured learning programs. My website is kyraspira.com and you can contact me at kyra@kyraspira.com.
As a UK-based sole trader, I am subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. I am the data controller for the personal data described in this policy.
What Is Personal Data?
"Personal data" is defined by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (collectively, "the Data Protection Legislation") as any information relating to an identifiable person who can be directly or indirectly identified, in particular by reference to an identifier.
In simpler terms, personal data is any information about you that enables you to be identified. This covers obvious information such as your name and contact details, but also less obvious information such as IP addresses and online identifiers.
What Personal Data Do I Collect?
I may collect personal data about clients, program participants, event attendees, newsletter subscribers, and website visitors. The personal data I collect may include your name, email address, phone number (if provided), and information about how you use my website.
How Do I Collect Your Data?
I collect personal data about you when you:
Book a free meditation session, private session, or program via Calendly
Complete an intake survey as part of joining a private or group program
Make a payment for a private session or program via Stripe
Subscribe to my newsletter on Substack
Attend one of my online events or sessions via Zoom
Join a Telegram chat as part of a program
Contact me directly via email
Visit my website at kyraspira.com
How Is Your Data Used?
I collect and use your personal data to operate my business and to provide you with a high-quality educational experience. I may use your data:
To deliver sessions, programs, and events to you
To communicate with you about your booking, program, or session
To process payments for private sessions and programs
To send you articles and event announcements via Substack, if you have subscribed
To share session recordings with you for your personal use
To understand your background via intake surveys, so I can better support you
To respond to your enquiries
To maintain the security of my systems
I believe these purposes are justified on the basis of my legitimate interests in running my business, my contractual obligations to deliver services you have requested, and — where relevant — your consent. More detail is provided in the sections below.
Detailed Information by Category
Free Meditation Attendees
When you book onto one of my free live meditation sessions, I collect the following via Calendly:
Name
Email address
Phone number (optional — only if you choose to share it)
These sessions take place live on Zoom. I record the sessions — capturing only my own voice and image, not participants — and share the recording on my YouTube channel for free public access. No recording of participants is made or shared.
Your booking data is stored within Calendly, whose servers are based in the USA. I will retain your booking information for a period of up to 2 years.
Private Session Clients
When you book and attend a one-to-one private session, I collect the following:
Name and email address (via Calendly at booking)
Phone number (optional — only if you choose to share it via Calendly)
Payment information (processed via Stripe — I do not have access to your full card details)
Communications between us relating to your session
Sessions take place on Zoom and are recorded. The recording is shared with you personally for your own use only and is not shared with any other party. You will be informed of this recording at the time of booking.
Your booking data is stored in Calendly and your payment data is processed by Stripe, both based in the USA. I will retain records of your sessions and communications for up to 10 years, and financial records for 6 years following the end of the current financial year, as required by law.
Private 12-Week Program Participants
When you join my private 12-week program, I collect the following:
Name and email address (via Calendly at booking)
Phone number (optional — only if you choose to share it via Calendly)
Payment information (processed via Stripe)
Intake survey responses, including general background information such as your location and prior experience with meditation
Communications between us via email and Telegram (1:1 chat)
Sessions take place on Zoom and are recorded. Recordings are shared with you personally for your own use only. As part of the program, I use Telegram for 1:1 messaging between us. Your use of Telegram is subject to Telegram's own privacy policy.
I will retain your data for the duration of the program and for up to 10 years afterward. Financial records are retained for 6 years following the end of the current financial year.
Group 12-Week Program Participants
When you join my group 12-week program, I collect the following:
Name and email address (via Calendly at booking)
Phone number (optional — only if you choose to share it via Calendly)
Payment information (processed via Stripe)
Intake survey responses, including general background information such as your location and prior experience with meditation
Communications between us via email
Sessions take place on Zoom and are recorded. Recordings are shared with all participants in that group for personal use only and are not shared with any other party. You will be informed of this at the time of booking.
I also offer an optional Telegram group chat for program participants. Joining this group chat is entirely your choice. If you join, please be aware that messages in a group chat are visible to all members of that group, and Telegram's own privacy policy applies to how Telegram processes your data.
I will retain your data for the duration of the program and for up to 10 years afterward. Financial records are retained for 6 years following the end of the current financial year.
Newsletter Subscribers (Substack)
If you subscribe to my newsletter on Substack, I will hold the following information about you:
Name and email address
Information about the content you open and engage with (managed by Substack)
You subscribe directly via Substack, and your data is managed and stored by Substack on servers in the USA. I use Substack to share articles and to announce upcoming events. I will continue to send you the newsletter until you unsubscribe. Substack's own privacy policy applies to how they process your data.
Website Visitors
When you visit kyraspira.com, certain data may be automatically collected, including:
IP address and device information
Pages visited and time spent on the site
Browser type and settings
My website is hosted by Squarespace, which uses cookies and may include built-in analytics. Please see the Cookies section below for more detail. Squarespace's servers are based in the USA.
Session Recordings
I record sessions for the following purposes:
Free meditation sessions: I record my own voice and face only. Participant audio and video are not recorded. Recordings are shared publicly on YouTube.
Private sessions and the private 12-week program: Sessions are recorded and shared with the individual client for their personal use only.
12-week group program: Sessions are recorded and shared with the participants of that group for their personal use only.
You will always be informed that recording will take place at the time of booking. If you have concerns about being recorded, please contact me at kyra@kyraspira.com before your session.
Who Has Access to Your Data?
I do not sell or rent your personal data to any third party, and I do not share your data with third parties for their marketing purposes.
In some limited circumstances, I may be legally required to share certain personal data if I am involved in legal proceedings or complying with legal obligations, a court order, or the instructions of a government authority.
I use a number of trusted third-party service providers to help me run my business. I share only the personal data necessary for them to perform their services, and I require that they keep your data secure and do not use it for any other purposes.
Transfers Outside of the UK
Several of my third-party service providers — including Calendly, Zoom, Stripe, Substack, Squarespace, and YouTube — are based in the United States. This means your personal data may be transferred outside of the UK and European Economic Area (EEA).
Where I transfer your data to a third party based in the USA or another country outside the UK/EEA, I take steps to ensure your data is treated just as safely and securely as it would be in the UK, including by:
Only using providers whose levels of data protection are deemed adequate, or
Relying on Data Processing Agreements based on standard contractual clauses approved by the relevant authorities, which require equivalent data protection standards.
If you would like more information about the specific safeguards applied to any transfer of your data, please contact me at kyra@kyraspira.com.
What Are Your Rights?
Under UK Data Protection Legislation, you have the following rights, which I will always work to uphold:
The right to be informed about how I collect and use your personal data. This Privacy Policy is intended to provide that information, but please contact me if you have any questions.
The right to access the personal data I hold about you (see 'How Can I Access My Personal Data?' below).
The right to have your personal data corrected if it is inaccurate or incomplete.
The right to be forgotten — to ask me to delete or dispose of your personal data in certain circumstances.
The right to restrict my processing of your personal data.
The right to object to my use of your personal data for a particular purpose.
The right to withdraw consent at any time, where I am relying on your consent as the legal basis for processing.
The right to data portability, where applicable.
Rights relating to automated decision-making and profiling. I do not use your personal data in this way.
For more information about your rights, or to exercise any of them, please contact me using the details at the end of this policy.
Further information about your rights can also be obtained from the Information Commissioner's Office (ICO) at ico.org.uk, or your local Citizens Advice Bureau.
If you have any concerns about how I use your personal data, you have the right to lodge a complaint with the ICO. I would welcome the opportunity to address your concerns directly first, so please do contact me before doing so.
How Can I Update My Information?
If your contact details change, or you would like to update any information I hold about you, please email me at kyra@kyraspira.com.
How Can I Access My Personal Data?
If you would like to know what personal data I hold about you, you can make a subject access request. This can be made in writing by email or verbally. There is normally no charge for a subject access request, unless your request is manifestly unfounded or excessive, in which case a reasonable administrative fee may be charged.
I will respond to your subject access request within one month of receiving it. In some cases, particularly where the request is complex, this may be extended by up to two further months. I will keep you informed of my progress.
Keeping Your Data Secure
The security of your personal data is important to me. To protect your data, I take the following measures:
Limiting access to your personal data to those who have a legitimate need to know it
Using reputable, secure third-party providers for booking, payment, communication, and storage
Having procedures in place for handling data breaches, including notifying you and/or the ICO where legally required
If you contact me by email, please be aware that email is not always a fully secure method of communication. I use standard email security practices, but I recommend you avoid including highly sensitive personal information in emails where possible.
Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work more efficiently and to provide information to website owners.
My website (kyraspira.com) is hosted by Squarespace, which automatically places certain cookies on your device to enable the site to function. Squarespace may also collect analytics data through its built-in analytics tools. These may include:
Necessary cookies — required for basic site functionality (no consent needed)
Analytics cookies — used to understand how visitors use the site
You may be able to control cookies through your browser settings. For more information about cookies and how to manage them, visit www.aboutcookies.org or www.allaboutcookies.org.
For full details about the cookies Squarespace uses, please refer to Squarespace's Cookie Policy at squarespace.com.
Links to Other Websites
My website may contain links to other websites operated by third parties. This Privacy Policy applies only to kyraspira.com. I encourage you to read the privacy policies of any other websites you visit. I am not responsible for the privacy practices of third-party sites, even if you access them via a link from my website.
How to Contact Me
To contact me about anything relating to your personal data or this Privacy Policy, including to make a subject access request, please use the following details:
Kyra Spira
Email: kyra@kyraspira.com
Website: www.kyraspira.com
Changes to This Privacy Policy
I keep this Privacy Policy under regular review and will update it as needed. The date of the most recent update is shown at the top of this document.