KAMI PERFORMANCE WORKS
  • ABOUT KAMI
  • BOOK KAMI
    • COACHING & CREATION
    • THE ALEXANDER TECHNIQUE
    • TESTIMONIALS
  • CONTACT
  • ABOUT KAMI
  • BOOK KAMI
    • COACHING & CREATION
    • THE ALEXANDER TECHNIQUE
    • TESTIMONIALS
  • CONTACT

GDPR Compliance & Data Privacy Policy

Last Updated: August 20, 2026
Effective Date: DECEMBER 15, 2014
 1. PURPOSE & SCOPE
This GDPR Compliance & Data Privacy Policy ("Policy") supplements our Privacy Policy and outlines how Kajsa Ingemansson / KAMI Performance Works complies with the General Data Protection Regulation (GDPR) (EU 2016/679) and other applicable Swedish and EU data protection laws.
This Policy applies to all personal data we collect, process, or store in relation to:
  • Visitors to our Website.
  • Customers of our Services.
  • Subscribers to our email lists or communities.


2. KEY DEFINITIONS
             Term                                                                             Definition

Personal Data                Any information relating to an identified or identifiable natural person (e.g., name, email, IP address).
Data Subject                   An identified or identifiable natural person (e.g., you, our Client).
Controller                        Kajsa Ingemansson (determines the purposes and means of processing personal data).
Processor                         Third-party services (e.g., Stripe) that process personal data on our behalf.
Processing                       Any operation performed on personal data (e.g., collection, storage, use, disclosure).
Consent                             Freely given, specific, informed, and unambiguous indication of your wishes (e.g., opt-in checkbox).


3. LEGAL BASIS FOR PROCESSING
Under GDPR Article 6, we process your personal data only if at least one of the following applies:
     Legal Basis                                               When It Applies                                                          Example

Consent (Art. 6(1)(a))              You have explicitly consented to                       Marketing emails, cookies, 
                                                              the processing for one or more                            sensitive data (e.g., health 
                                                              specific purposes.                                                         info for coaching).

Contract Performance          Processing is necessary to fulfill                         Delivering Services,  processing 
(Art. 6(1)(b))                                 a contract with you or take steps                        payments,  scheduling sessions.
                                                             at your request.                                                             
Legal Obligation                       Processing is required by law.                              Tax reporting, court orders.
(Art. 6(1)(c))                           

Vital Interests                            Processing is necessary to protect                   Rare (e.g., medical emergencies 
(Art. 6(1)(d))                                 your life or physical integrity.                             during retreats).

Public Interest                           Processing is necessary for a                               Not applicable to our business.
(Art. 6(1)(e))                                 task carried out in the public
                                                             interest
.
 
Legitimate Interest                 Processing is necessary for our                         Improving Services, fraud 
(Art. 6(1)(f))                                  legitimate interests and does not                    prevention, analytics.
                                                             
override your rights.


4. DATA PROTECTION PRINCIPLES
We adhere to the GDPR principles for processing personal data:
                      Principle                                                                                 How We Comply

Lawfulness, Fairness, Transparency               We process data legally, fairly, and transparently (see Section 3 for legal bases).
Purpose Limitation                                                   We collect data only for specified, explicit, and legitimate purposes (see 
                                                                                                Section 5 of Privacy Policy).

Data Minimization                                                    We collect only the data we need for the intended purpose.
Accuracy                                                                          We keep your data accurate and up to date. You can request corrections.
Storage Limitation                                                     We retain data no longer than necessary (see Section 8 of Privacy Policy).
Integrity & Confidentiality                                   We implement security measures to protect your data (see Section 7 of Privacy
                                                                                                Policy).

Accountability                                                              We document our compliance with GDPR and can demonstrate it upon request.


5. DATA PROTECTION BY DESIGN & DEFAULT
We implement technical and organizational measures to ensure GDPR compliance:

5.1 Technical Measures
  • Pseudonymization: Where possible, we pseudonymize data (e.g., using unique IDs instead of names).
  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256).
  • Access Controls: Role-based permissions, multi-factor authentication (MFA), and regular access reviews.
  • Automated Deletion: Data is automatically deleted after the retention period (e.g., 2 years for inactive accounts).

5.2 Organizational Measures
  • For GDPR-related inquiries, contact Kajsa Ingemansson at: [email protected].
  • As a sole practitioner, I ensure my own compliance with GDPR through ongoing education. 
  • We conduct Data Protection Impact Assessments (DPIAs) where required by law 
  • We ensure third-party processors (if any) comply with GDPR and require Data Processing Agreements (DPAs)." 


6. RECORDS OF PROCESSING ACTIVITIES (ROPA)
Under GDPR Article 30, we maintain internal records of our processing activities, including:
  • Purpose of processing (e.g., deliver coaching, send emails).
  • Categories of data subjects (e.g., Clients, subscribers).
  • Categories of personal data (e.g., name, email, payment info).
  • Recipients of data (e.g., Stripe).
  • Retention periods (see Section 8 of Privacy Policy).
  • Technical/organizational measures (see Section 5).
Note: These records are not public but are available to supervisory authorities upon request.


7. DATA SUBJECT RIGHTS (GDPR CHAPTER III)
As a data subject, you have the following rights under GDPR. To exercise any of these rights, email us at [email protected]:
              Right                                     Description                               Our  Response                         Exceptions
                                                                                                                                  Time 

Right to Access                      Request a copy of your                  30 days                         We may request proof of 
(Art. 15)                                      personal data we hold.                                                             identity to verify your request.

Right to Rectification        Request corrections to                  30 days                        None
(Art. 16)                                      inaccurate or incomplete
                                                         data.


Right to Erasure                    Request deletion of your             30 days                        We may retain data for legal compliance
("Right to Be                            data if it is no longer                                                                 (e.g., tax records) or exercising legal claims.
Forgotten") (Art. 17)          necessary or you withdraw
                                                         consent.


Right to Restrict                   Request that we limit                     30 days                       None
Processing (Art. 18)           processing of your data ​
                                                        (e.g., for marketing).

Right to Data                         Request your data in a                    30 days                       Only applies to automated processing 
Portability (Art. 20)
           machine-readable format                                                   
based on consent or contract.
                                                       (e.g., CSV, JSON).

Right to Object                   Object to direct marketing           30 days                      We may continue processing if we
(Art. 21)                                   or 
profiling based on                                                                demonstrate compelling legitimate grounds.
                                                      legitimate interests.


Right to Withdraw           
Withdraw consent for                        Immediate             Does not affect the lawfulness of
Consent (Art. 7(3))           
 marketing or cookies                                                              processing before withdrawal.
                                                       at any time.


Right to Lodge a                 File a complaint with a                           N/A                        None
Complaint (Art. 77)         
supervisory authority (e.g., 
                                                     Swedish Data Protection
                                                     Authority (IMY)
).



8. DATA BREACH NOTIFICATION
Under GDPR Article 33 & 34, we are required to notify you and the supervisory authority of a data breach if it is likely to result in a high risk to your rights and freedoms.

8.1 Our Procedure
  1. Detection: We monitor for breaches 24/7 using automated tools and manual reviews.
  2. Investigation: We assess the risk within 72 hours of detection.
  3. Notification to Authority: If the breach poses a high risk, we notify the Swedish Data Protection Authority (IMY) within 72 hours.
  4. Notification to You: If the breach poses a high risk to you, we notify you without undue delay via:
    • Email (to the address on file).
    • Website banner (for widespread breaches).
    • Direct mail (if email is compromised).

8.2 What We Include in Notifications
  • Nature of the breach (e.g., unauthorized access, data leak).
  • Categories of data affected (e.g., names, emails, payment info).
  • Likely consequences (e.g., risk of identity theft, fraud).
  • Measures taken or proposed to address the breach.
  • Contact information for our DPO.


9. INTERNATIONAL DATA TRANSFERS
As a Swedish-based business, we primarily process data within the EU/EEA. However, some of our service providers (e.g., Stripe, Kajabi, ConvertKit) are based in the US or other third countries.

9.1 Safeguards for Transfers
We ensure adequate protection for international transfers using:
  • Standard Contractual Clauses (SCCs): Approved by the European Commission (Decision 2021/914).
  • Binding Corporate Rules (BCRs): For multinational processors.
  • Privacy Shield: For US-based providers (where applicable).
  • Adequacy Decisions: For countries with equivalent data protection laws (e.g., UK, Canada).

9.2 Your Rights for Transfers
You have the right to:
  • Request a copy of the safeguards we have in place (e.g., SCCs).
  • Lodge a complaint with the Swedish Data Protection Authority (IMY) if you believe your rights have been violated.


10. DATA RETENTION & DELETION
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
       Data Type                                       Retention Period                                                   Legal Basis

Account Data                           
Active account + 2 years                           Legitimate Interest (Art. 6(1)(f))
Payment Data                           7 years                                                                  Legal Obligation (Art. 6(1)(c))
Program Data                           Duration of program + 1 year                 Contract Performance (Art. 6(1)(b))
Marketing Data                       Until you unsubscribe                                 Consent (Art. 6(1)(a))
Technical Data                         26 months (Google Analytics)                Legitimate Interest (Art. 6(1)(f))

Deletion Process:
  • We automatically delete data after the retention period.
  • You can request deletion at any time (subject to legal obligations).
  • We verify deletion through audits and logs.


11. AUTOMATED DECISION-MAKING & PROFILING
We do not use fully automated decision-making (e.g., AI-driven decisions without human intervention) that has legal or significant effects on you.

We
do use limited profiling for:
  • Marketing: To send you targeted emails or ads based on your interests (e.g., performers vs. directors).
  • Analytics: To improve our Website and Services (e.g., Google Analytics).

Your Rights:
  • You can opt out of profiling for marketing by:
    • Clicking "Unsubscribe" in emails.
    • Adjusting cookie settings in your browser.
  • You can request human review of any automated decision by contacting us at [email protected].


12. CONTACT INFORMATION
For
GDPR-related inquiries,
 contact Kajsa Ingemansson at:
Email: [email protected]
Address: Flygelvägen 231, 224 72, Sweden
Phone: +46 (0)703828961


For
general privacy questions, contact us at:
Email: [email protected]



13. SUPERVISORY AUTHORITY
If you believe we have violated GDPR, you may lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten, IMY):

Website:
www.imy.se ​Email: [email protected] Phone: +46 8 657 61 00
Address: 
Integritetsskyddsmyndigheten (IMY)
Box 8114
104 20 Stockholm
Sweden


Terms & Conditions
Privacy Policy
GDPR Compliance
© Copyright 2014 | All Rights Reserved