Privacy Policy
Privacy Policy
Last updated: 1 September 2026
The protection of your personal data is important to us. This Privacy Policy explains what personal data we collect through the Bright Mind website (the “Website”), why we collect it, how we process and protect it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
The controller responsible for the processing of your personal data is:
Marios Michail
Ayia Napa, Cyprus
Email: marios.mix20@gmail.com
2. Personal Data We Collect
Depending on how you use our Website, we may collect the following personal data:
- Contact information: your name, email address and telephone number when you complete a contact form or book an appointment/session.
- Comment data: if you leave a comment on an article, we may collect the content of your comment, your name and email address, as well as your IP address and browser user agent for security and spam prevention purposes.
- Browsing data: information collected through cookies and similar technologies (see Section 6 below).
- Data collected through embedded content: videos, images or other third-party content, such as YouTube videos, may collect information independently from us.
We do not intentionally collect special categories of personal data, such as health data, through the Website, except for information that you may voluntarily provide when contacting us in relation to coaching or related services.
3. Purposes and Legal Bases for Processing
We may process your personal data for the following purposes and on the following legal bases under Article 6 of the GDPR:
| Purpose | Legal Basis |
|---|---|
| Responding to enquiries and arranging appointments | Taking steps at your request prior to entering into a contract |
| Publishing and managing comments | Your consent |
| Sending newsletters or informational material, if you subscribe | Your consent |
| Website security and spam prevention | Our legitimate interests |
| Compliance with tax and accounting obligations | Compliance with a legal obligation |
Where processing is based on your consent, you may withdraw your consent at any time.
4. Sharing Your Personal Data
We do not sell or rent your personal data to third parties.
Your personal data may, where necessary, be shared with:
- our website hosting and maintenance providers;
- Gravatar, where used to display profile images in connection with comments;
- automated spam detection services used in connection with comments;
- appointment scheduling services, such as Calendly, where such a service is used to book an appointment;
- public authorities or other competent bodies where disclosure is required by law.
If you request a password reset for a user account, your IP address may be included in the password reset email.
Third-party service providers may process personal data in accordance with their own privacy policies and applicable data protection legislation.
5. How Long We Retain Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected and in accordance with applicable legal requirements.
In particular:
- Comments: may be retained indefinitely so that follow-up comments can be recognised and approved automatically.
- Contact and appointment information: may be retained for as long as necessary to provide the requested service and for up to five years thereafter, where necessary for record-keeping, evidential, tax or accounting purposes, unless earlier deletion is requested and we are legally permitted to delete the information.
- User accounts, where applicable: personal information associated with an account is retained for as long as the account remains active or as otherwise required by law.
6. Cookies
Our Website uses cookies to ensure its proper operation and to improve the browsing experience.
These may include:
- Comment cookies: if you choose to save your name, email address and website when leaving a comment, these cookies may remain for one year.
- Login cookies: these generally remain for two days, or for two weeks if you select “Remember Me”.
- Screen preference cookies: these may remain for one year.
- Temporary browser-check cookie: a temporary cookie may be set when you visit the login page and is deleted when you close your browser.
You can manage, restrict or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.
7. Media
If you are able to upload images to the Website, for example through a comment or form, you should avoid uploading images containing embedded location data such as EXIF GPS information, as other visitors may be able to download and extract such information.
8. Embedded Content from Other Websites
The Website may include embedded content from third-party websites, such as YouTube videos or social media posts.
Embedded content behaves in substantially the same way as if you had visited the third-party website directly. These websites may collect data about you, use cookies, embed additional third-party tracking and monitor your interaction with their content.
Such processing is carried out independently by the relevant third party and may be subject to its own privacy policy.
9. Your Rights Under the GDPR
Subject to the conditions and limitations provided by applicable data protection law, you may have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request erasure of your personal data (“right to be forgotten”), subject to our legal, tax and accounting obligations.
- Request restriction of processing or object to the processing of your personal data.
- Receive your personal data in a structured, commonly used and machine-readable format where the right to data portability applies.
- Withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus if you believe that the processing of your personal data infringes the GDPR.
To exercise any of these rights, please contact us at:
Email: marios.mix20@gmail.com
10. Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, accidental loss, misuse, alteration or disclosure.
However, no method of transmission or storage of information over the internet can be guaranteed to be completely secure.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, services or applicable legal requirements.
Any changes will be published on this page together with an updated “Last updated” date.
12. Contact
If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact:
Marios Michail
Ayia Napa, Cyprus
Email: marios.mix20@gmail.com