We collect only the personal data we need to run our business, coach our clients, and communicate with you. We don’t sell your data. This policy explains what we collect, why, how long we keep it, and the rights you have over it under Swedish and EU law.
Boundless Brilliance AB is the data controller responsible for your personal data collected through this Website and our services.
Contact: [email protected] Company: Boundless Brilliance AB, Magnus Toffelmakares Gränd 7, SE-239 35 Skanör, Sweden
Depending on how you interact with us, we may collect:
• Contact details — name, email, phone number, postal address (e.g., when you book a session, buy a course, sign up for our newsletter, or contact us).
• Payment information — handled securely by our payment processor; we do not store full card details ourselves.
• Coaching and session information — notes, goals, or details you share with us in the course of a coaching relationship. Where this touches on health or wellbeing, it may be considered a special category of data under GDPR, and we handle it with extra care and only with your explicit consent.
• Website usage data — pages visited, device and browser type, and similar technical data, usually via cookies (see Section 8).
• Communications — emails, messages, or comments you send us.
We do not knowingly collect personal data from anyone under 13 years of age.
Purpose
Delivering a course, product, or coaching service you’ve purchased
Responding to enquiries and providing support
Sending newsletters or marketing you’ve opted into
Improving the Website and understanding how it’s used
Keeping accounting and invoicing records
Keeping accounting and invoicing records
Legal basis
Performance of a contract
Performance of a contract / legitimate interest
Consent
Legitimate interest / consent (for cookies)
Legal obligation
Explicit consent
You can withdraw consent at any time (see Section 7), without affecting anything we did based on it beforehand.
We don’t sell or rent your personal data. We share it only with trusted service providers who help us run the business, such as:
• Payment processors (to handle purchases securely)
• Email and newsletter platforms (to send updates you’ve subscribed to)
• Website hosting and analytics providers
• Booking or scheduling tools for sessions and retreats
These providers only receive the data they need to do their job, and are bound by their own data protection obligations. If any of them are located outside the EU/EEA, we make sure appropriate safeguards are in place (such as the EU Standard Contractual Clauses).
We may also disclose data if required by law, for example to a Swedish authority.
We keep personal data only as long as needed for the purpose it was collected:
• Client and coaching records: for the duration of our relationship, plus a reasonable period afterward for legal and record-keeping purposes.
• Invoicing and accounting data: as required under Swedish bookkeeping law, currently seven years.
• Newsletter/marketing data: until you unsubscribe or withdraw consent.
• Website analytics/cookies: per the retention settings described in our cookie banner.
After these periods, data is deleted or anonymized.
Under GDPR, you have the right to:
• Access the personal data we hold about you
• Correct inaccurate or incomplete data
• Delete your data (“right to be forgotten”), where applicable
• Restrict or object to certain processing
• Data portability — receive your data in a portable format
• Withdraw consent at any time, where processing is based on consent
• Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with your local supervisory authority
To exercise any of these rights, contact us at [email protected]. We’ll respond within one month, as required by law.
Our Website uses cookies and similar technologies to remember your preferences, understand how visitors use the site, and, where you’ve consented, support marketing. You can manage or withdraw cookie consent at any time through the cookie banner or your browser settings. Blocking some cookies may affect how the Website functions.
We use reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. No system is completely secure, but we take this responsibility seriously and review our practices regularly.
This Website is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.
We may update this Privacy Policy from time to time, for example to reflect new services or legal requirements. The current version will always be posted here with its last-updated date.
Questions about this policy or how we handle your data? Reach us at [email protected].
© 2026 Liselotte Molander. All rights reserved.