GDPR & Privacy Policy
Your privacy matters to us. Learn how we protect your personal data and respect your rights.
Last Updated: November 7, 2025
Rohini Walia Culinary School ("we," "our," or "us") is committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your personal information. This policy explains your rights under the General Data Protection Regulation (GDPR) and how we comply with these regulations.
Data Controller
What Information We Collect
Newsletter Subscription
- Email address (required) - to send you newsletters
- First name (optional) - to personalize our communications
- Subscription preferences - to respect your content interests
- Consent timestamp - to prove compliance with GDPR
- Email verification status - to ensure valid subscriptions
Booking & Enrollment
- Full name - for class registration
- Email and phone - for booking confirmations
- Payment information - processed securely via Stripe/PayPal
Website Analytics
- IP address (anonymized) - for security and analytics
- Browser type and device - to optimize user experience
- Cookies - see our Cookie Policy for details
How We Use Your Information
Newsletter delivery: Send you cooking tips, recipes, class announcements, and special offers
Class management: Process bookings, send confirmations, and manage attendance
Communication: Respond to inquiries and provide customer support
Legal compliance: Meet legal obligations and protect our rights
Legal Basis for Processing
Under GDPR, we process your data based on:
- Consent: You explicitly agree to receive newsletters (withdrawable at any time)
- Contract performance: Processing bookings and delivering classes you've purchased
- Legitimate interests: Improving our services and preventing fraud
- Legal obligation: Tax records and payment processing compliance
Your GDPR Rights
Right to Access
Request a copy of all personal data we hold about you
Right to Portability
Receive your data in a structured, machine-readable format
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Right to Rectification
Correct inaccurate or incomplete personal information
Right to Restriction
Limit how we process your data in certain circumstances
Right to Object
Object to processing based on legitimate interests or direct marketing
To exercise your rights, contact us at:
We will respond within 30 days as required by GDPR
Data Security & Retention
Security measures: We use industry-standard encryption (SSL/TLS), secure hosting, and access controls to protect your data from unauthorized access, loss, or misuse.
Payment security: All payment data is processed by PCI-DSS compliant providers (Stripe, PayPal). We never store full credit card information.
Retention periods:
- Newsletter data: Until you unsubscribe
- Booking records: 7 years (tax law requirement)
- Payment records: As required by law and payment processors
- Support inquiries: 3 years from last contact
Third-Party Service Providers
We share your data only with trusted service providers necessary for our operations:
- Email delivery: Mailtrap/SendGrid (GDPR compliant)
- Payment processing: Stripe, PayPal (PCI-DSS compliant)
- Website hosting: Cloudflare, Neon.tech (EU/US data centers)
- Analytics: Google Analytics (IP anonymization enabled)
We never: Sell your data to third parties or use it for purposes other than those described.
Unsubscribe from Newsletter
You can unsubscribe from our newsletter at any time:
- Click the "Unsubscribe" link in any newsletter email
- Email us at info@cookwithrohini.com
- Visit your account preferences (if logged in)
After unsubscribing, you'll no longer receive marketing emails, but we may still send transactional emails related to your bookings.
International Data Transfers
Some of our service providers are based outside the European Economic Area (EEA). When we transfer your data internationally, we ensure adequate protection through:
- EU-approved Standard Contractual Clauses (SCCs)
- Privacy Shield certification (where applicable)
- GDPR-compliant data processing agreements
Questions or Concerns?
If you have questions about this policy or wish to exercise your GDPR rights, contact us:
📧 Email: info@cookwithrohini.com
📍 Address: Cook with Rohini, Prague, Czech Republic
Right to lodge a complaint: If you believe we've violated your privacy rights, you have the right to lodge a complaint with your local data protection authority (in Czech Republic: Úřad pro ochranu osobních údajů - ÚOOÚ).