top of page

Privacy Policy

Last updated 07-07-2026

Privacy Policy

1. Data Controller

The Data Controller responsible for the processing of personal data is:

Gaja Lakshmi di Andrea Salati
Via delle Gardenie 1
16035 Rapallo (GE) – Italy
VAT No. 02977010996

For any questions regarding the processing of your personal data, you may contact us at: info@whitelotusretreats.com

2. What Data We Collect

When you visit our website or request information about our retreats, we may collect the following information:

  • First and last name;

  • Email address;

  • Phone number;

  • Country of residence;

  • Information necessary for booking and invoicing;

  • Any dietary preferences, allergies, or other information voluntarily provided and strictly necessary for organizing the retreat;

  • Technical browsing data, such as IP address, browser type, device used, pages visited, and information collected through cookies.

We do not collect special categories of personal data (Article 9 GDPR), except where participants voluntarily provide such information to enable us to organize their stay in the best possible way.

3. Purpose of Data Processing

Personal data are processed for the following purposes:

  • Responding to requests for information;

  • Managing retreat bookings;

  • Organizing accommodation and scheduled activities;

  • Sending communications related to bookings;

  • Complying with legal, tax, and administrative obligations;

  • Improving the functionality of the website and analyzing website traffic;

  • Sending newsletters and informational communications, only with the user's prior consent.

4. Legal Basis for Processing

The processing of personal data is based on:

  • The performance of pre-contractual measures requested by the user;

  • The performance of the retreat participation agreement;

  • Compliance with legal obligations;

  • The explicit consent of the data subject (for newsletters, cookies, and marketing communications);

  • The legitimate interest of the Data Controller in ensuring website security and improving its services.

5. How We Process Your Data

Personal data are processed using appropriate electronic and organizational tools designed to ensure their security, confidentiality, and integrity. Suitable measures are adopted to prevent unauthorized access, loss, or unlawful use of personal data.

6. Data Retention

Personal data will be retained for as long as necessary to fulfill the purposes for which they were collected and, in any event:

  • Data relating to information requests will be retained for the time necessary to handle the request;

  • Data relating to bookings will be retained for the period required by contractual, legal, and tax obligations;

  • Data processed for marketing purposes will be retained until consent is withdrawn.

7. Disclosure of Personal Data

Personal data may be shared exclusively with parties involved in organizing the retreat, including:

  • Accommodation providers;

  • Teachers and collaborators involved in organizing the retreat;

  • Administrative, tax, and legal consultants;

  • Technical service providers necessary for operating the website and communications.

Personal data will never be sold or shared with third parties for commercial purposes.

8. Third-Party Services

To provide our services, we use certain third-party platforms, including:

  • Wix, for website hosting and management;

  • Mailchimp, for sending newsletters and informational communications to users who have given their consent;

  • Google Analytics, for collecting anonymous statistical data on website usage in order to improve content and user experience.

The use of these services may involve the processing of personal data by the respective service providers in accordance with their own privacy policies.

9. Transfers of Personal Data Outside the European Union

Some of the service providers we use (such as Mailchimp and Google) may process personal data outside the European Economic Area (EEA).

In such cases, data processing is carried out in compliance with Regulation (EU) 2016/679 (GDPR), using appropriate safeguards provided under European law, including the European Commission's Standard Contractual Clauses (SCCs) or other recognized legal mechanisms.

10. Cookies

The website uses technical cookies that are necessary for the proper functioning of the platform.

Subject to the user's consent, analytical cookies and, where applicable, marketing cookies may also be used.

For more information, please refer to our Cookie Policy.

11. Data Subject Rights

At any time, data subjects may exercise the rights provided for under Articles 15–22 of Regulation (EU) 2016/679 (GDPR), including the right to:

  • Access their personal data;

  • Request the correction of inaccurate data;

  • Request the deletion of their personal data;

  • Request restriction of processing;

  • Object to processing where permitted by law;

  • Receive their personal data in a portable format;

  • Withdraw previously given consent at any time;

  • Lodge a complaint with the competent Data Protection Authority.

Requests may be sent to the email address provided in this Privacy Policy.

12. Updates

This Privacy Policy may be updated from time to time to reflect changes in applicable laws or the evolution of our services.

Any updates will be published on this page.

bottom of page