Privacy Policy
Version 02 · July 2026 · Effective 20.07.2026
Who We Are and How to Reach Us
The controller responsible for the processing of your personal data in connection with this website and the services offered through it is:
Tamas Locher e.U.
Joseph-Lister-Gasse 31A/Top 14, Vienna, Austria. Registered as a sole trader (Einzelunternehmer) under the trade category Humanenergetik pursuant to the Austrian Gewerbeordnung (GewO).
Email: hello@sacredtou.ch · Telephone: +43 677 64 72 44 08
Sacred Touch is a private somatic bodywork practice operating from Vienna, Austria, offering consent-led bodywork sessions exclusively to women. The website is published at sacredtou.ch.
If you have any questions about how your personal data is handled, or if you wish to exercise any of your rights under applicable data protection law, you are welcome to reach us at the contact details above.
The Legal Framework
The processing of personal data in connection with this website and our services is governed by:
- Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR)
- Bundesgesetz zum Schutz natürlicher Personen bei der Verarbeitung personenbezogener Daten (Datenschutzgesetz, DSG), as in force in Austria
- Telekommunikationsgesetz 2021 (TKG 2021), governing electronic communications and cookies
Where we refer to a legal basis for processing in this policy, we refer to the bases set out in Article 6 GDPR and, where relevant, Article 9 GDPR for special category data.
General Principles
We process personal data only to the extent necessary for clearly defined purposes. We collect only what is needed. We do not sell personal data. We do not share personal data with third parties except where required to deliver our services, where we are legally obliged to do so, or where you have provided explicit consent.
Where data is shared with service providers, we ensure that appropriate safeguards are in place and that those providers process data only on our documented instructions.
Categories of Personal Data We Process
Depending on how you interact with this website and our services, we may process the following categories of personal data:
- Name
- Email address
- Telephone number (where provided)
- Session date, time, and type
- Booking history
- Communications related to bookings and session preparation
- IP address (anonymised; see Section 12)
- Browser type and version
- Device type
- Pages visited and session duration
- Referral source
- Date and time of access
- Content of emails or contact form submissions you send to us
Sacred Touch does not collect written health intake forms and does not keep session notes. No special category health data is processed in connection with our services.
Contact Form and Email Enquiries
When you contact us through the website contact form or by email, we process the personal data you provide in order to respond to your enquiry and, where relevant, to initiate a booking.
Legal basis: Article 6(1)(b) GDPR (steps at your request prior to entering a contract) and Article 6(1)(f) GDPR (our legitimate interest in responding to enquiries addressed to us).
We retain correspondence data for 12 months from the date of the last communication, unless a longer retention period is required by applicable law or the data has been incorporated into a booking or invoicing record.
We do not pass your contact enquiry to third parties other than our email hosting provider and, where relevant, our booking system provider, both operating under appropriate contractual arrangements.
Booking Process and Appointment Management
Session bookings will be managed through GoHighLevel, a cloud-based client relationship and appointment management platform operated by HighLevel Inc., 400 North Saint Paul St., Suite 920, Dallas, Texas 75201, United States. This system is being prepared and is not yet in use. Until it is, booking requests are handled as described in Section 6a.
HighLevel Inc. has designated the following EU representative for data protection matters: Rickert Rechtsanwaltsgesellschaft mbH – HighLevel, Inc., Colmantstrasse 15, 53115 Bonn, Germany.
HighLevel Inc. acts as a data processor on our behalf, processing your booking data only in accordance with our instructions. A formal Data Processing Agreement with HighLevel Inc. has been reviewed and signed.
Legal basis: Article 6(1)(b) GDPR (performance of a contract or pre-contractual steps at your request).
Data processed in connection with bookings includes: name, email address, telephone number (if provided), session date and type, and any information you voluntarily provide through a session preparation communication.
HighLevel Inc. processes data in the United States and potentially other countries outside the EEA. Such transfers are carried out on the basis of the EU-U.S. Data Privacy Framework (where applicable) and, where required, Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR.
We retain booking records for 24 months from the date of the session, after which they are deleted unless a statutory retention obligation requires otherwise.
Booking Requests Submitted Through This Website
When you complete the request form on this website, the information you provide is transmitted to a private spreadsheet held in our Google Workspace account, so that Thomas can read your request and reply to you. This is an interim arrangement while the booking system described in Section 6 is being prepared.
The data processed consists of: your name, your email address and telephone number, the session, date and time you selected, whether you asked for a session at the studio or a visit, the address you provide if you asked for a visit, and anything you choose to write in the final step of the form.
The final step of the form is free text. You decide what to write there, and you may leave it empty. If you choose to write about your health or your body, that information constitutes a special category of personal data under Article 9 GDPR, and it is processed only on the basis of your explicit consent, which you give by submitting the form.
Legal basis: Article 6(1)(b) GDPR (steps taken at your request prior to entering into a contract), and Article 9(2)(a) GDPR for any health-related information you choose to share.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as provider of Google Workspace, acting as a data processor on our behalf.
The spreadsheet is private to the practice. It is not shared with anyone outside it.
Booking requests are transferred into the booking system and the spreadsheet record is deleted within 30 days.
If you enter your email address in the newsletter field in the footer, that address is stored in the same spreadsheet on the basis of your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time by writing to hello@sacredtou.ch.
Invoicing
This website does not process payment card data or any other payment information online. No payment transactions are completed through this website.
Invoices are issued digitally through GoHighLevel. No separate accounting software is used. Invoicing data retained in connection with sessions is kept for seven years from the end of the calendar year in which the invoice was issued, in accordance with the retention obligations under the Unternehmensgesetzbuch (UGB) and the Bundesabgabenordnung (BAO).
Website Hosting
This website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, United States, through its global edge network. Requests from visitors in Europe are served from Cloudflare data centres within the EEA. Technical data, including server logs, is processed on Cloudflare’s infrastructure in connection with the operation of this website.
Cloudflare, Inc. acts as a data processor for the purposes of hosting and delivering this website, on the basis of Cloudflare’s Data Processing Addendum, which incorporates the Standard Contractual Clauses. Cloudflare is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in operating a functioning and secure website).
Server Logs
When you visit this website, your browser automatically transmits technical information that is recorded in server logs maintained by Cloudflare. This includes your IP address, the date and time of your visit, the pages requested, the browser type and version, and the referring URL.
Server logs are processed for the purpose of ensuring the security and technical stability of the website, diagnosing errors, and defending against unauthorised access.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in maintaining a secure and functional website).
Server log data is not combined with other data sources for profiling purposes. Logs are retained for 30 days before deletion.
Cookies and Consent Management
This website uses cookies and comparable tracking technologies. Cookies are small text files stored by your browser on your device when you visit a website. They serve different purposes, ranging from technically essential functions to analytics and advertising.
Non-essential cookies and tracking technologies, including analytics and marketing tools, are only activated after you have provided valid, freely given, specific, and informed consent through our cookie consent tool. No tracking pixel or analytics script is loaded before consent is granted.
Certain cookies are strictly necessary for the technical operation of the website and the booking system. These do not require your consent under TKG 2021 and GDPR. They are set solely to provide the service you have requested.
We use Google Analytics 4 to understand how visitors interact with this website. Google Analytics sets cookies that collect anonymised usage data. Analytics cookies are only set after you have provided valid consent through our cookie consent tool.
We use Meta Pixel and Google Ads conversion tracking for advertising measurement and audience building. These tools set marketing cookies and use related tracking technologies. Marketing cookies are only activated after you have provided explicit, informed consent. Consent is collected through the website's consent banner. You may withdraw your consent at any time by adjusting your cookie preferences through the cookie settings link in the website footer.
When you first visit this website, you will be presented with a cookie consent notice. You may accept all cookies, reject non-essential cookies, or customise your preferences by category. Your preferences are stored and applied on subsequent visits. You may also control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the booking system or other features of the website.
Google Tag Manager
This website uses Google Tag Manager (GTM), a tag management system operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is the sole tag deployment mechanism on this website. It is used to deploy and manage tracking scripts, including Google Analytics 4 and the Google Ads conversion pixel. GTM itself does not independently collect personal data. It operates as a container that activates other tracking tools based on trigger conditions we have defined.
All tracking tools deployed through GTM are subject to the consent rules described in this policy. Non-essential tags are only triggered after valid consent has been provided through the website's consent banner.
Google Ireland Limited acts as a data processor for GTM. Processing may involve data transfers to Google LLC servers in the United States. Such transfers are subject to Standard Contractual Clauses.
Google Analytics 4
We use Google Analytics 4 (GA4), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics collects information about how visitors use this website, including pages visited, session duration, device type, and approximate geographic location.
IP anonymisation is confirmed as enabled in our GA4 property. IP addresses are not logged in full. Please note that Google Signals is enabled in our GA4 configuration. When Google Signals is active, Google may use aggregated and anonymised data from signed-in Google users to provide cross-device reports and interest-based advertising insights. This data is not associated with individual identifiable visitors in our GA4 account, but is processed by Google in connection with its own advertising products. If you wish to prevent this, you may adjust your Google account’s ad personalisation settings.
Data collected through GA4 is processed by Google LLC on servers in the United States. Such transfers are governed by Standard Contractual Clauses.
Legal basis: Article 6(1)(a) GDPR (your consent, obtained through the website's consent banner before any analytics cookie or tracking script is activated).
Retention: Google Analytics data is retained for 14 months, as configured in our GA4 property. You may opt out by installing the Google Analytics Opt-out Browser Add-on.
Meta Pixel and Meta Conversions API
We use the Meta Pixel, provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The Meta Pixel is implemented via Meta’s fbevents.js library (browser-based tracking), with event tracking including PageView and configured conversion events.
In addition to the browser-based Meta Pixel, we use the Meta Conversions API (CAPI). The Conversions API transmits event data directly from our server to Meta’s servers, in parallel with or independently of the browser-based pixel. The purpose of both tools is to measure the effectiveness of advertising on Meta platforms (including Facebook and Instagram) and to build audiences for future advertising campaigns.
IP address, browser information, device identifiers, information about your interactions with this website (pages visited, events triggered), and where applicable, hashed identifiers such as email address or telephone number. Hashed data is processed in an irreversible format before transmission to Meta.
Data collected by the Meta Pixel and Conversions API is processed by Meta Platforms Ireland Limited in the EEA and may be transferred to Meta Platforms, Inc. in the United States. Such transfers are subject to Standard Contractual Clauses.
Legal basis: Article 6(1)(a) GDPR (your consent, obtained before the Meta Pixel or Conversions API is activated). The Conversions API involves server-to-server data transmission; consent granted through the website's consent banner governs whether this transmission is triggered.
Google Ads Conversion Tracking
We use Google Ads conversion tracking, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This tool allows us to measure the effectiveness of advertising campaigns served through Google Ads by identifying visits and actions on this website that follow from a click on one of our advertisements.
The Google Ads conversion tag is deployed through Google Tag Manager and is only activated after you have provided consent. Data collected through this tool may be processed by Google LLC in the United States, subject to Standard Contractual Clauses.
Legal basis: Article 6(1)(a) GDPR (your consent, obtained before the advertising tag is activated).
Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following retention periods apply:
- Contact enquiry data: 12 months from the date of last communication, unless incorporated into a booking or invoicing record
- Booking and appointment records: 24 months from the date of the session
- Booking requests held in the interim submissions spreadsheet: 30 days
- Newsletter subscriptions: until you withdraw your consent
- Invoicing and accounting data: 7 years from the end of the calendar year in which the invoice was issued (UGB / BAO)
- Server logs: 30 days
- Google Analytics data: 14 months, as configured in our GA4 property
- Meta and Google advertising data: as governed by Meta’s and Google’s own retention policies, subject to your consent preferences
Where no specific retention period is listed above, data is deleted as soon as the purpose for which it was collected has been fulfilled and no legal obligation requires further retention.
Recipients and Data Processors
We share personal data only where necessary to deliver our services or comply with legal obligations. The following categories of recipients may receive your data:
- HighLevel Inc. (GoHighLevel): booking, CRM, invoicing, and communication management. EU representative: Rickert Rechtsanwaltsgesellschaft mbH, Bonn. DPA signed.
- Cloudflare, Inc.: website hosting and content delivery (DPA with Standard Contractual Clauses; EU-U.S. Data Privacy Framework certified)
- Google Ireland Limited: analytics (GA4), tag management (GTM), advertising measurement (Google Ads), and Google Workspace, where booking requests submitted through this website are stored
- Meta Platforms Ireland Limited: advertising measurement and audience building (Meta Pixel and Conversions API)
Each third-party service provider is required to process personal data only in accordance with our instructions and applicable data protection law. We do not sell personal data to any third party.
International Data Transfers
Some of the service providers we use process data in countries outside the EEA, including the United States. Where personal data is transferred to countries not recognised by the European Commission as offering an adequate level of data protection, such transfers are carried out on the basis of:
- Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) GDPR; and/or
- The EU-U.S. Data Privacy Framework, where the recipient is a certified participant
Cloudflare, Inc. serves this website from its global network and requests from Europe are handled within the EEA, but Cloudflare may process limited technical data outside the EEA. Such transfers are covered by Cloudflare’s Data Processing Addendum, incorporating the Standard Contractual Clauses, and by Cloudflare’s certification under the EU-U.S. Data Privacy Framework.
Your Rights Under GDPR
Under GDPR and the Austrian Datenschutzgesetz, you have the following rights in relation to your personal data:
- Right of access (Article 15): confirmation of whether we process your data, and a copy of that data.
- Right to rectification (Article 16): correction of inaccurate or incomplete data.
- Right to erasure (Article 17): deletion where processing is no longer necessary or consent is withdrawn.
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20): your data in a structured, machine-readable format.
- Right to object (Article 21): where processing is based on legitimate interests.
- Right to withdraw consent (Article 7(3)) at any time, without affecting prior lawful processing.
To exercise any of these rights, please contact us at hello@sacredtou.ch or by telephone at +43 677 64 72 44 08. We will respond within one month, as required by Article 12 GDPR. We do not charge a fee unless requests are manifestly unfounded or excessive.
Right to Lodge a Complaint
If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Austria, the competent authority is:
Datenschutzbehörde (DSB)
Barichgasse 40–42, 1030 Vienna, Austria · dsb.gv.at · +43 1 52 152-0
You may also lodge a complaint with the supervisory authority of the EU Member State where you are habitually resident or where the alleged infringement took place.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include secure hosting on German-based infrastructure, access controls, and encrypted communications where applicable.
Our service providers are selected with data security in mind and are contractually required to maintain appropriate security standards.
Where a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Datenschutzbehörde within 72 hours and, where the risk is high, notify you directly, in accordance with Articles 33 and 34 GDPR.
Children
This website and the services offered through it are not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If you believe that a minor has submitted personal data to us without appropriate consent, please contact us and we will delete the data promptly.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in applicable law, or in the technical infrastructure of this website. The date of the most recent revision appears at the top of this document.
Where changes are material, we will take reasonable steps to bring them to your attention. Your continued use of the website following the publication of an updated policy constitutes acceptance of those changes to the extent permitted by applicable law.
A Final Note
Sacred Touch is a private practice built on discretion, care, and clarity. Your personal data is handled in the same spirit in which this work is offered: with precision, with respect, and only to the extent that it serves the purpose for which it was given.
If anything in this policy is unclear, or if you have a concern about how your data is handled, you are welcome to write to hello@sacredtou.ch. A question here is not an intrusion.
What Are Cookies
Cookies are small text files that websites store on your browser or device when you visit them. They serve a range of purposes: some are technically essential for a website to function, others help us understand how the site is used, and others support advertising.
This website uses cookies and comparable tracking technologies. This notice explains what is in use, what purpose each serves, and how you can manage your choices.
Our Consent Approach
No analytics, marketing, or advertising cookie or tracking script is loaded on this website before you have provided valid consent. Strictly necessary cookies are the only exception; these are required for the website to function and do not require consent under TKG 2021.
Your consent is collected through this website's own consent banner. You may accept all categories, accept only strictly necessary cookies, or customise your preferences. You may change your preferences at any time from the cookie settings link in the website footer. A record of each choice (a random identifier, the time, and the selections made) is kept for 12 months as proof of consent.
Strictly Necessary Cookies
These cookies and browser storage entries are required for the website to operate: preferred_language (a cookie set only when you choose a language, used for routing between the language versions of the site, 180 days) and st-consent (a browser storage entry holding your cookie choices, 12 months). Neither is used for tracking.
Legal basis: TKG 2021, Section 96(3); Article 6(1)(f) GDPR. Consent is not required for strictly necessary cookies.
Analytics Cookies (Google Analytics 4)
We use Google Analytics 4 to understand how visitors navigate this website. GA4 sets cookies that collect anonymous or pseudonymised data about page visits, session duration, device type, and approximate location. IP addresses are anonymised. Google Signals is enabled; see Section 12 of the Privacy Policy for the implications of this. These cookies are only set after you have provided your consent.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users | 2 years |
| ga[ID] | Google Analytics | Maintains session state for GA4 | 2 years |
| _gid | Google Analytics | Distinguishes unique users | 24 hours |
Marketing and Advertising Cookies
We use Meta Pixel and Google Ads conversion tracking to measure advertising effectiveness and, where you have consented, to serve relevant advertising on Meta and Google platforms. These cookies and tracking technologies are only activated after you have provided explicit consent.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _fbp | Meta Platforms | Identifies browser for ad delivery and attribution | 3 months |
| _fbc | Meta Platforms | Stores last ad click attribution data | 3 months |
| gclaw | Google Ads | Conversion tracking from Google Ads clicks | 90 days |
| gcldc | Google Ads | Cross-domain conversion tracking | 90 days |
Server-Side Tracking (Meta Conversions API)
In addition to browser-based cookies, we use the Meta Conversions API to send event data directly from our server to Meta. This server-side transmission occurs independently of your browser cookie settings. It is, however, governed by your consent: the Conversions API is only triggered when you have provided consent to marketing tracking through the website's consent banner.
No individually identifying personal data is transmitted to Meta without first being processed to reduce the risk of identification (hashing).
Managing Your Preferences
When you first arrive at this website, a cookie consent notice will appear. You may accept all categories of cookies, accept only strictly necessary cookies, or customise your choices by category.
You may update your preferences at any time by selecting the cookie settings option in the website footer. You may also use your browser settings to block or delete cookies.
Third-Party Opt-Out Tools
- Google Analytics: tools.google.com/dlpage/gaoptout
- Google Ads personalisation: adssettings.google.com
- Meta advertising preferences: facebook.com/ads/preferences
- Digital Advertising Alliance (DAA): optout.aboutads.info
- European Interactive Digital Advertising Alliance (EDAA): youronlinechoices.eu