Legal
Privacy
Effective 1 August 2026
We wrote this to be read, not to be survived. It says what personal data we handle when you use sestala.com, book a session or use the Sestala app, why we handle it, who else sees it, and what you can make us do about it.
Who is responsible
The controller for this website and for the Sestala booking pages and app is:
Leon & Vera OÜ
Sepapaja tn 6, 15551 Tallinn, Estonia
Estonian Business Register, registry code 17303070
hello@sestala.com
Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. You can reach them directly at datenschutz@heydata.eu or at heydata.eu.
The one thing to understand first
Every Sestala studio is independently owned and operated by a local licence partner under a licence from us. That split runs through this whole policy.
We are responsible for this website, for the city waitlist, and for the booking pages and the app as a service.
Your studio is responsible for you as a member. We run the software that holds your booking and your membership, and we run it on your studio’s instructions, as their processor. Your studio decides what happens to that record. We do not.
So if you want your member record changed or deleted, ask either of us. The app has buttons for it. Whichever way you ask, the request is carried out on your studio’s authority. Your studio’s name and address are on its studio page, and we will tell you who it is if you ask.
Three things that never reach us
These are not statements about our intentions. They are properties of how the business is built.
Your health information never reaches us. Before your first session your studio takes you through a health screening. It happens on paper, at the studio, and you sign it. That sheet stays in the studio’s own files. It is never entered into any Sestala software, at any point. We do not hold your answers, we do not hold the result, and there is no screen anywhere in our system where anyone could look either of them up, because neither exists in anything we run. The screening is your studio’s process and your studio’s responsibility, and it is a condition of their licence with us.
Your card and your money never reach us. You pay your studio, on your studio’s own arrangements. No card details reach us, no payment ever passes through our accounts, and we never charge you or refund you anything.
The machine’s data never reaches us. The machine that gives you your session is your studio’s equipment. It is not connected to us in any way. Whatever it records during your session, including anything about your body, stays with the machine and your studio.
What we handle as the controller
Visiting this website. Our host records standard server logs, including your IP address, to keep the site up and to defend it from attack. Legal basis: our legitimate interest in operating and securing the site, Art. 6(1)(f) GDPR. They are kept briefly and then deleted.
Measuring how the site is used. Nothing measures how you use this site. There is no analytics tool, no measurement cookie, and nothing stored on your device beyond what the page needs to load. If we add one, we will ask you first, and this page will name the tool, what it records and how long it is kept. Legal basis then: your consent, Art. 6(1)(a) GDPR, together with the national rules on storing information on your device.
The city waitlist. If you ask us to tell you when a studio opens in your city, we store the email address and postcode you type, the wording you agreed to, the time you agreed it, and, if you arrived through a campaign link, which campaign it was. The postcode is used to count how many people live within reach of a possible studio, which is how we decide where to open next. We write to you when there is something to say about your city, and we use the address for nothing else. Legal basis: your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time with one click or one reply. We delete the record once the city is decided either way, or sooner if you ask.
Writing to us. If you email us we keep the correspondence as ordinary business records. Legal basis: our legitimate interest in answering you, Art. 6(1)(f) GDPR.
What we handle for your studio, as their processor
Your studio decides these purposes and we run the software. Their own privacy information covers the legal basis. We list it here because you deserve to know what the software holds.
What
What it is for
Your mobile number, verified once by a code we text you
It is how you are recognised. There is no password and no account to create. It is how your booking link reaches you, and your reminder if you asked for one
Your first name, if you give it
So you are greeted by name. It is optional
The device you booked on
So you do not have to enter a code again on the same phone. Kept for 12 months
Your booking
Which studio, which session, when, and a six-character code
A reminder, only if you tick the box
One message, 24 hours before. Never a second one, and never marketing
Your membership and the sessions you have left, if you are a member
So your studio knows what you are entitled to this month
A paid or unpaid flag
Your studio sets it from their own records. We are never told how or when you paid
An agreed pause, if you arrange one
Which whole months you are resting. Whether your studio charges you during a pause is between you and them
One tap after your session
“Everything okay” or “something was off”, with an optional note. It goes to your studio
In the app: your contact details, your language, and your comfort preferences
Comfort preferences are noted by staff at your first session so you do not have to explain yourself again
Your booking link is a key. The web address on your booking confirmation is what gets you in at the door, and anyone holding that link can see and cancel that booking. Do not forward it. It is short-lived, it is rate-limited against guessing, and it reveals nothing beyond that one booking.
What we never do
We never sell personal data. Not to anyone, not ever.
We never run advertising trackers.
We never send marketing without your consent, and consent is revocable with one click.
We never ask you a health question online.
We never ask for a card online.
Who else sees your data
We use a small number of service providers who process data strictly on our instructions, under Art. 28 GDPR contracts.
Purpose
Provider and region
Database and storage
Supabase · European Union, Frankfurt
Website and application hosting
Vercel · European Union
That is the whole list today. If we add a provider, this page names them before they start.
Beyond that, your studio sees your member record, because it is theirs. Where your studio sits inside a host venue such as a gym or a practice, the host sees only what its own role requires and nothing more.
We choose European processing wherever it exists. If a provider ever processes data outside the EEA, the transfer will rest on an adequacy decision or on Standard Contractual Clauses, and you can ask us for a copy of the safeguards.
Conversion measurement (Meta)
When you reach us through a Meta ad, we tell Meta Platforms Ireland Ltd. server-side which funnel steps that ad led to (for example an analysis run, a registration, a booked consultation), so we can measure and pay for advertising honestly. This includes your IP address, browser information and the ad’s click ID; your email address is included only as a cryptographic hash and only if you allowed it at registration. Legal bases: Art. 6(1)(f) GDPR (measuring our own advertising) and Art. 6(1)(a) GDPR (email matching, revocable any time). Meta processes this data partly in the USA under the EU-US Data Privacy Framework. No pixel and no Meta cookie runs on this site.
Consultation booking (Cal.com)
When you book the consultation on the partner portal, the booking calendar is provided by Cal.com, Inc. It loads only when you open it, and the details you enter to book - your name, email address and the chosen time - are processed by Cal.com to make the appointment and send the video link. Legal basis: Art. 6(1)(b) GDPR (arranging the call you requested).
How long we keep things
Data
Kept
Server logs
Briefly, for security, then deleted
Waitlist record
Until your city is decided either way, or immediately if you ask
Member record, bookings, membership
For as long as you are a member of that studio, then under your studio’s own retention rules
The device you booked on
12 months
Correspondence
As ordinary business records
Your rights
You can ask for access, correction, deletion, restriction and portability. You can object to anything we do on the basis of legitimate interest. You can withdraw consent at any time, and that does not affect anything done before you withdrew it.
If you use the app, export and delete are buttons on your profile. Otherwise write to hello@sestala.com and we will route it to the right place and tell you where it went.
You can complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You can also complain to the authority in the country you live in or where the studio is.
Age
Sestala sessions are for adults. You must be 18 or over to book a session or to use the Sestala app, and your studio checks this.
Decisions made by the software
There is one, and it is worth naming. If your membership has no sessions left for the month, or your studio has recorded that your account is unpaid, the software will refuse a new booking. That is a rule applied to a recorded fact, not a profile built about you, and your studio can always review it.
We do not profile you, and we make no other decisions about you by automated means.
Changes
When this policy changes, the new version appears here with a new date. We do not change it quietly in ways that would surprise you.