Privacy policy
A retreat is built on trust, so we say plainly what data we take, why, how long we keep it and how you can delete it. If anything stays unclear, write to [email protected] and a person will answer.
Who we are
The website ibogajourney.net is operated by George Gache, a private individual. He decides what data is collected and why, so he is the data controller under the GDPR. For any question or request about your data, write to [email protected].
What we take, and why
When you apply or join the waiting list through the form on the site: your email address (required) and, if you choose to write them, your name, phone number and a message. Along with them we keep the edition you applied for, the language you filled the form in and the IP address you sent it from, to stop automated sign-ups. We use them to contact you for an interview and to tell you about the edition you chose.
At the interview. Every applicant is met personally, in a video interview, before the retreat. There we may ask about your health (including your heart), the medication you take, your use of substances and your psychological history, because whether the retreat is safe for you depends on them. If you are accepted, we also ask for an ECG and medical documents. This is health data, which is sensitive data. We process it only with your explicit consent and only to decide whether the retreat suits you and to prepare you safely. We do not publish it, we do not use it in marketing, and we pass it only to the people on the team who need it for your safety.
If you take part: the data needed to organise travel and your stay (name, contact details, flight details, room preferences) and, on site, the information needed for your safety.
When you write to us by email or WhatsApp: we receive your address or number and what you tell us, and we use it to answer you.
When you visit the site: our hosting provider, Cloudflare, sees your IP address and basic technical data from your browser, as any web server does, to deliver the site and keep it safe.
If you press “Accept all” in the cookie banner, Google Analytics, Microsoft Clarity and Meta Pixel are switched on: they receive data about your visit (pages viewed, device type, length of the visit and, for Clarity, clicks and scrolling on the page). Without “Accept all” these services are not loaded at all. We also use aggregate statistics that store no cookies and do not identify you: Cloudflare Web Analytics, Umami and Plausible.
What we don't do: we don't ask for data we don't use, we don't make automated decisions about you, and we never sell or rent data to anyone.
Meta Pixel and the form. If you pressed “Accept all”, Meta Pixel sends Meta your visit and the fact that you submitted the application form. For this collection we are joint controllers with Meta; what Meta then does with the data is Meta's responsibility (facebook.com/privacy/policy). Without “Accept all”, nothing is sent.
Research. The study at ibogaresearch.eu is a separate project with its own information notice. The notice on that site applies to it.
Legal basis
- Applying, the interview and organising the retreat: taking steps at your request before a contract (Art. 6(1)(b) GDPR).
- Health information: your explicit consent (Art. 9(2)(a) GDPR). You can withdraw it at any time; if you withdraw it during selection, we can no longer assess your application.
- Invitations to future editions, if you joined the waiting list: your consent (Art. 6(1)(a)), which you can withdraw at any time.
- Running and protecting the site (hosting, security): our legitimate interest in keeping the site working and safe (Art. 6(1)(f)). No consent is needed for strictly necessary storage.
- Statistics, visit recordings and ad measurement (Google Analytics, Microsoft Clarity and Meta Pixel): basis: your consent, given through “Accept all” (Art. 6(1)(a) GDPR); you can withdraw it at any time from the Cookie policy.
- Aggregate statistics without cookies: our legitimate interest in understanding how the site is used (Art. 6(1)(f)); they contain no data that identifies you.
Where it goes
The request sent from the form passes through a function of the site and lands in our registration system, on a server run by ai-AI on our behalf. If our server cannot be reached at that moment, the request waits in Cloudflare storage until we pick it up, so it is not lost. Emails to you are sent from [email protected].
The providers who touch the data, each with their role:
- Cloudflare: hosts the site, carries the traffic, and briefly holds a request if our server is unreachable
- Google (Gmail): the emails you write to us and the ones we send you
- Telegram: internal notification to our team, with the email, name, phone number and message from the form
- Google LLC (Google Analytics): visit statistics, only if you press “Accept all”
- Microsoft Corporation (Clarity): on-page behaviour analysis, only if you press “Accept all”
- Meta Platforms (Meta Pixel): ad measurement, only if you press “Accept all”
- The retreat team: facilitators receive the medical information needed for your safety; the hosts of the venue, only your name, flight and room preferences
- ai-AI (FUNKTASTIC SRL): hosts and runs the site and the registration system technically, on our behalf, so it has access to applications and to the visit statistics
- WhatsApp (Meta): only if you choose to write to us there
- Public authorities: only when the law requires it
Some of these providers are based outside the European Economic Area, mostly in the United States, and the retreat takes place in Tanzania. Where that is the case, the transfer relies on the safeguards the provider offers (the EU–US Data Privacy Framework or standard contractual clauses). The data the team in Zanzibar (Tanzania) needs reaches them because it is necessary for you to take part in the retreat you asked for (Art. 49(1)(b) GDPR); for health data we ask for your explicit consent to this transfer as well (Art. 49(1)(a)), after we have told you that Tanzania does not have a level of protection recognised by the EU. Telegram is not covered by the safeguards above: we use it only for internal notifications, and if you don't want your details to pass through it, write to us by email instead of using the form.
How long we keep it
- Applications and the waiting list: for as long as selection and the organisation of the retreat you take part in last, and afterwards only as long as necessary (for example for legal obligations or, if you asked, to tell you about later editions).
- Health data: only as long as needed to decide whether the retreat suits you and to prepare you safely. You can ask us to delete it at any time.
- Payment documents, if you end up paying: as long as the law requires.
- Traffic statistics: according to the providers' retention (Google: 2 or 14 months, depending on the account setting; Microsoft: between 30 days and 13 months); aggregate statistics without cookies contain no data that identifies you.
What you can ask for
You have the right to know what data we hold about you, to correct it, to have it deleted, to ask us to stop using it, to receive it in a file you can take elsewhere, and to object to processing. You can withdraw a consent at any time, without affecting what happened before.
Write to [email protected]. We answer within a month at the latest, usually much sooner, and it is free.
If we answer badly or not at all, you can complain to the Romanian data protection authority, ANSPDCP, Bd. G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or to the authority of your own country. We would rather sort it out with you directly, but the right is yours.
Children
The site and the retreat are for adults. We don't knowingly collect children's data. If you believe we hold any, tell us and we will delete it.
When this page changes
The date at the top is the last change. If we change something that matters (what we collect, why, or who receives it), we won't count on you coming back to check: we will announce it on the site.
See also the cookie policy and the terms of use.