Privacy Policy

1. The Short Version

We collect only the personal data we need to run our business, coach our clients, and communicate with you. We don’t sell your data. This policy explains what we collect, why, how long we keep it, and the rights you have over it under Swedish and EU law.

2. Who We Are

Boundless Brilliance AB is the data controller responsible for your personal data collected through this Website and our services.

Contact: [email protected] Company: Boundless Brilliance AB, Magnus Toffelmakares Gränd 7, SE-239 35 Skanör, Sweden

3. What Personal Data We Collect

Depending on how you interact with us, we may collect:

• Contact details — name, email, phone number, postal address (e.g., when you book a session, buy a course, sign up for our newsletter, or contact us).

• Payment information — handled securely by our payment processor; we do not store full card details ourselves.

• Coaching and session information — notes, goals, or details you share with us in the course of a coaching relationship. Where this touches on health or wellbeing, it may be considered a special category of data under GDPR, and we handle it with extra care and only with your explicit consent.

• Website usage data — pages visited, device and browser type, and similar technical data, usually via cookies (see Section 8).

• Communications — emails, messages, or comments you send us.

We do not knowingly collect personal data from anyone under 13 years of age.

4. Why We Collect It, and Our Legal Basis

Purpose

Delivering a course, product, or coaching service you’ve purchased

Responding to enquiries and providing support

Sending newsletters or marketing you’ve opted into

Improving the Website and understanding how it’s used

Keeping accounting and invoicing records

Keeping accounting and invoicing records

Legal basis

Performance of a contract

Performance of a contract / legitimate interest

Consent

Legitimate interest / consent (for cookies)

Legal obligation

Explicit consent

You can withdraw consent at any time (see Section 7), without affecting anything we did based on it beforehand.

5. Who We Share Data With

We don’t sell or rent your personal data. We share it only with trusted service providers who help us run the business, such as:

• Payment processors (to handle purchases securely)

• Email and newsletter platforms (to send updates you’ve subscribed to)

• Website hosting and analytics providers

• Booking or scheduling tools for sessions and retreats

These providers only receive the data they need to do their job, and are bound by their own data protection obligations. If any of them are located outside the EU/EEA, we make sure appropriate safeguards are in place (such as the EU Standard Contractual Clauses).

We may also disclose data if required by law, for example to a Swedish authority.

6. How Long We Keep It

We keep personal data only as long as needed for the purpose it was collected:

• Client and coaching records: for the duration of our relationship, plus a reasonable period afterward for legal and record-keeping purposes.

• Invoicing and accounting data: as required under Swedish bookkeeping law, currently seven years.

• Newsletter/marketing data: until you unsubscribe or withdraw consent.

• Website analytics/cookies: per the retention settings described in our cookie banner.

After these periods, data is deleted or anonymized.

7. Your Rights

Under GDPR, you have the right to:

• Access the personal data we hold about you

• Correct inaccurate or incomplete data

• Delete your data (“right to be forgotten”), where applicable

• Restrict or object to certain processing

• Data portability — receive your data in a portable format

• Withdraw consent at any time, where processing is based on consent

• Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with your local supervisory authority

To exercise any of these rights, contact us at [email protected]. We’ll respond within one month, as required by law.

8. Cookies

Our Website uses cookies and similar technologies to remember your preferences, understand how visitors use the site, and, where you’ve consented, support marketing. You can manage or withdraw cookie consent at any time through the cookie banner or your browser settings. Blocking some cookies may affect how the Website functions.

9. Security

We use reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. No system is completely secure, but we take this responsibility seriously and review our practices regularly.

10. Children’s Privacy

This Website is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time, for example to reflect new services or legal requirements. The current version will always be posted here with its last-updated date.

12. Contact Us

Questions about this policy or how we handle your data? Reach us at [email protected].

© 2026 Liselotte Molander. All rights reserved.