Privacy policy
1. Controller
Taipan Consulting GmbH, Neue Mainzer Str. 66, 60311 Frankfurt am Main, Germany — represented by Frank Welsch-Lehmann.
Privacy enquiries: privacy@gardensofzen.com
General contact: zee@gardensofzen.com
2. What data we process
Gardens of Zen is deliberately built to be data-minimal. We only process what the service needs:
- Email address (required to deliver the program emails)
- First name (optional, for personal salutation)
- Program choice, language, timezone and preferred delivery time
- Program progress (current day) and replies you send to Zee by email
- Delivery and bounce information from our email service provider
3. Double opt-in
Sending only starts after you confirm your signup via a confirmation link sent by email (double opt-in). Unconfirmed signups are deleted automatically. The legal basis for processing is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time with effect for the future.
4. Unsubscribing and deletion (30-day erasure)
You can unsubscribe at any time — via the link in every email or via the settings page. Sending stops immediately upon unsubscribing. 30 days after unsubscribing we delete your personal data completely. On request we delete immediately (settings → unsubscribe, or an informal email to us).
While you are subscribed we store your program emails and your replies so Zee can build on earlier conversations. When we delete your data, these contents go with it.
5. Processors
We use the following service providers as processors:
- Postmark (ActiveCampaign, LLC) — sending and receiving the program emails
- Anthropic (Anthropic, PBC) — AI processing: creation of the daily routine texts, and processing of your reply emails so Zee can understand and answer them. This transfers the content of your message along with your first name, language, chosen program and current program day.
- Railway (Railway Corp.) — hosting of the website and platform
- Hindsight (Vectorize) — conversational memory: storage of content from your replies so Zee can refer back to it in later emails. These memories are deleted together with the rest of your data.
Data processing agreements pursuant to Art. 28 GDPR are in place with all providers. Where data is transferred to third countries, this is based on EU standard contractual clauses or the EU-US Data Privacy Framework.
6. Automated safety screening
Zee is not a therapy service and not an emergency service. So that we can respond when you are doing badly, every incoming reply is screened automatically for crisis signals — using a fixed keyword list and the AI evaluation of your message. If the system detects such a signal, you automatically receive an email pointing to professional support services, and our operations team is notified. That internal notification contains only a technical identifier for your account, not the text of your message. We record that a signal was detected, with a timestamp.
This screening may allow conclusions about your health (Art. 9 GDPR). The legal basis is your explicit consent, given at sign-up (Art. 9(2)(a) GDPR). You can withdraw it at any time; since the screening cannot be switched off separately, withdrawal means unsubscribing from the service.
7. Cookieless analytics
We use cookieless, self-hosted web analytics (Umami). No cookies are set, no cross-device profiles are built and no personal data is stored; IP addresses are not retained here. That is why this website works without a cookie banner. The legal basis is our legitimate interest in privacy-preserving analytics (Art. 6(1)(f) GDPR).
8. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a data protection supervisory authority. Just write to us:zee@gardensofzen.com.
9. Version
This privacy policy is dated August 2026.
