Privacy policy

Jampatha Yoga — In force since 29 August 2026

Lire en français

This is an English translation provided for convenience. Jampatha Yoga is a French business and these terms are governed by French law: the French version is the binding one, and prevails in the event of any discrepancy between the two.

This policy describes how Jampatha Yoga collects and processes your personal data when you use the website https://www.jampathayoga.fr.

1. Data controller

Nutcharin Upacha, a sole trader (entrepreneuse individuelle under French law) operating under the trade name Jampatha Yoga, 69 Chemin des 7 Deniers 31200 Toulouse — SIRET 814 187 274 00034.
Contact: [email protected] — 07 61 89 95 09

2. What we collect, and why

Creating your student account. First name, surname, email address, mobile number, date of birth and password (stored encrypted, never in plain text). This data allows us to identify you, to contact you about your classes, and to check that you meet the minimum age requirement. Legal basis: performance of the contract.

Bookings and class cards. Classes booked and cancelled, cards purchased, remaining credits, validity dates. Legal basis: performance of the contract.

Payments. Online payments are processed by Stripe. No bank card data passes through this site or is stored on it: you enter it directly on Stripe's secure page. The site only retains the amount, the date and the payment method. Legal basis: performance of the contract.

Invoicing. When you request an invoice in your name, your postal address and, where applicable, your company details are recorded. Legal basis: legal obligation to issue invoices.

Communications. You receive messages relating to your classes — confirmations, reminders, cancellations. Legal basis: performance of the contract. Studio news is only sent to you if you consented at registration, or if you are already a customer, in accordance with Article L.34-5 of the French Postal and Electronic Communications Code. The date of your consent is recorded.

Security. Failed login attempts are counted in order to temporarily lock an account after five failures. Legal basis: legitimate interest in protecting accounts.

Audience measurement. See the cookie policy. Legal basis: your consent.

3. Recipients

Your data is neither sold, rented nor transferred. It is shared only with the service providers necessary for the service to operate:

Stripe Payments Europe Ltd (Ireland) — online payment processing.
Tiime (France) — transmission of invoices to bookkeeping.
Make (Czech Republic) — automated invoice processing, when this option is enabled.
OVH SAS (France) — email delivery.
Cloudflare, Inc. (United States) — delivery of the site and protection against attacks. This transfer is governed by the European Commission's standard contractual clauses.

4. Retention periods

Student account: for the duration of the relationship, then three years after your last class or last contact.
Invoices and accounting records: ten years, in accordance with Article L.123-22 of the French Commercial Code.
Newsletter consent: until you unsubscribe, then three years as evidence.
Technical connection logs: one year, in accordance with applicable regulations.

5. Your rights

You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to give instructions concerning what happens to it after your death.

Several of these rights can be exercised directly from your student account: you can change your details there, manage your subscription to studio news, and delete your account. Every news email also contains a one-click unsubscribe link.

For any other request, write to [email protected]. You will receive a reply within one month.

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL, the French data protection authority — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.

6. Security

Exchanges between your browser and the site are encrypted (HTTPS). Passwords are stored as cryptographic hashes and cannot be read back, including by us. Access to administration data is restricted and protected by authentication.

7. Changes

This policy may be updated to reflect changes to the service or to regulations. The date it came into force appears at the top of this page.