Privacy Policy: Data Protocols

[LAST UPDATED: SEPTEMBER 2026] | DOMAIN: kundalinienergy.org

At kundalinienergy.org, handling personal data with precision, transparency, and high security standards is fundamental. This Privacy Policy details the exact data collected, the operational objectives behind processing, the security protocols implemented, and your statutory rights under the European General Data Protection Regulation (GDPR).

01. Data Controller Identity

The data controller responsible for the processing of personal data across this domain is:

  • - Arlo Zwijnenburg
  • - Direct Email: info@kundalinienergy.org
  • - Phone: +31615066974
  • - System URL: https://kundalinienergy.org

02. Processed Data Categories and Legal Grounds

We process only the personal data strictly required for operational delivery, client communication, and baseline system integrity.

A. Direct Contact Interface (/contact/)

When initiating an inquiry via https://kundalinienergy.org/contact/, the system collects:

  • - First name
  • - Email address
  • - Transmission payload (inquiry contents and message body)
  • - Objective: Direct routing, answering queries, scheduling, and standard administrative follow-up.
  • - Legal Ground: Legitimate interest to process incoming inquiries and maintain operational communication, or explicit consent upon manual transmission.

B. Intake and Reservation Engine (/agenda-booking/)

When booking a session via https://kundalinienergy.org/agenda-booking/, the system collects:

  • - First name
  • - Email address
  • - Phone number
  • - Current Professional Role / Industry (e.g., Founder, Software Engineer, System Architect)
  • - Formfield: 2. Select your required configuration.
  • - Formfield: 3. Identify your primary systemic bottleneck right now.
  • - Formfield: 4. Rate your current daily cognitive load.
  • - Objective: Direct routing, answering queries, scheduling, and standard administrative follow-up.
  • - Legal Ground: Legitimate interest to process incoming inquiries and maintain operational communication, or explicit consent upon manual transmission.

C. System Updates and Direct Transmissions

When subscribing to technical bulletins, session notifications, or operational updates, the system processes:

  • - First name
  • - Email address
  • - Phone number (if provided)
  • - Objective: Dispatching schedules, systemic updates, and analytical articles.
  • - Legal Ground: Explicit consent. Every outgoing message contains a direct, automated opt-out link in the footer to revoke consent instantly.

03. External Infrastructure and Sub-Processors

We do not sell, rent, or trade personal data under any circumstances. External transmission is limited to verified third-party infrastructure required for core website operations:

  • - Core CMS and Plugins: The platform operates on WordPress. We deploy vetted plugins to handle forms, session scheduling, and hardware-level firewall protection. All third-party providers processing personal data comply with binding GDPR data processing terms.
  • - Hosting and Email Infrastructure: Our server environment and email transit are maintained by enterprise-grade providers (Flexwebhosting, Versio). Inbound and outbound correspondence is archived via encrypted messaging clients (Flexwebhosting, Versio, e.g., Google Workspace / Microsoft 365).
  • - SMS and Instant Messaging Protocols: For session confirmations, automated reminders, and operational logistics, we may transmit messages via SMS or WhatsApp. The transmission of data through these networks remains subject to the privacy protocols and infrastructure standards of the respective telecommunications carriers and vendors (such as Meta for WhatsApp).
  • - Outbound Social Links: This domain contains static reference links to third-party social platforms. Following these outbound links transfers routing to their respective domains, where their individual privacy protocols and tracking behaviors apply.

04. Retention Architecture

Personal records are retained only for the duration required to complete the specified processing objective:

  • - General Inquiries: Retained for a maximum of [e.g., 6 to 12 months] past final transmission, unless a formal client agreement follows.
  • - Accounting and Invoicing Data: Retained for a minimum of 7 years in compliance with statutory tax retention mandates.
  • - Subscription Records: Retained until an automated opt-out signal is received. Upon unsubscribing, contact vectors are purged from active dispatch queues immediately.

05. Technical Safeguards and Security Protocols

We implement rigorous technical and organizational protocols to prevent unauthorized access, manipulation, or exfiltration:

  • - The entire domain routes through end-to-end SSL/TLS encryption (indicated by https:// and active root certificate verification).
  • - Administrative access points, databases, and server panels require high-entropy access credentials and multi-factor authentication (MFA/2FA).
  • - WordPress core files, server configurations, and plugins receive automated patching to remediate known vulnerabilities.

06. Cookie Deployment and Analytics

This platform utilizes minimal cookie implementations:

  • - Functional Cookies: Essential for page routing, session state persistence, and form submission integrity.
  • - Analytical Telemetry: We may deploy privacy-preserving telemetry tools ([e.g., Google Analytics with IP anonymization / Plausible Analytics]) to assess server response, load metrics, and structural navigation patterns without fingerprinting individual users.

Cookies can be inspected, blocked, or purged at any time via your browser security preferences.

07. Statutory GDPR Rights

As a data subject, you hold clear statutory rights regarding your records:

  • 1. Right of Access: The right to obtain confirmation and clear extracts of all personal data held in our systems.
  • 2. Right to Rectification: The right to demand immediate correction of inaccurate or incomplete records.
  • 3. Right to Erasure (Right to be Forgotten): The right to request complete purging of your records, provided retention is not required by statutory legal or fiscal regulations.
  • 4. Right to Restriction of Processing: The right to pause specific processing operations under defined legal conditions.
  • 5. Right to Data Portability: The right to receive personal data you provided in a structured, machine-readable format.
  • 6. Right to Object: The right to challenge data processing based on legitimate interest grounds.

To trigger any of these requests, submit an explicit instruction to info@kundalinienergy.org. We confirm receipt and process verified requests within 30 days.

If you believe data handling violates European regulatory standards, you maintain the right to register a formal complaint with the relevant regulatory authority, such as the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

08. Operational Scope and Participation Parameters

Processing your reservation confirms data transmission for scheduling and intake preparation. Actual participation in a somatic session is subject to operational health prerequisites and boundary terms.

Also review our disclaimer page.

Access your original state...
Access your original state...

Kundalini NRGY allows you to exit the cognitive loop and restore structural clarity to your biology. By choosing trust over control, you clear the system blocks and experience the precise, self-correcting intelligence of a fully unthrottled direct transmission.

Let’s override the static and expand your operational bandwidth.