Last updated: 2 September 2026
privacy.
Here's what happens with your data when you visit, contact, book a session, or sign up for the newsletter on this site. I've tried to write it the way I'd want it written for me — plain English, no jargon, no surprises.
who I am.
Fiona Flecken — owner of Off the Mat, a small body-based practice for movement, breath, and rest at 21 Triq John F. Marks, San Gwann SGN2212, Malta. I am the data controller for everything that happens on this site within the meaning of Article 4 (7) GDPR.
- Email: hello@off-the-mat.com
- Phone / WhatsApp: +356 79520661
- Postal: 21 Triq John F. Marks, San Gwann SGN2212, Malta
when you simply visit this site.
You don't see a cookie banner because I don't set tracking or marketing cookies. There's nothing to consent to before you can read the page.
Two things still happen quietly in the background, and you have a right to know about them:
- Server logs. My host (Vercel) records each request to the site — your IP address (truncated for storage), the page you asked for, your browser's user agent, and the time. This is operational data needed to keep the site online and to defend against abuse. Legal basis: legitimate interest under Article 6 (1)(f) GDPR. Kept for up to 30 days, then deleted.
- Vercel Web Analytics. A small, cookieless script that counts page views per route. It does not set any cookies, does not build a profile of you, and does not share data with advertisers. Legal basis: legitimate interest under Article 6 (1)(f) GDPR.
when you write to me.
The contact form sends me whatever you type into it — your name, your email, and your message. I receive it as a normal email through a service called Resend, which exists only to deliver the message to my inbox.
Two background checks help keep spam out of the form: Cloudflare Turnstile (an invisible bot check that doesn't use cookies, per Cloudflare's published policy) and a very short-lived rate-limit counter in Upstash Redis (a hashed version of your IP address, kept for ten minutes, so the same machine can't blast the form a thousand times).
Legal basis: your request to be in touch — Article 6 (1)(b) GDPR for pre-contractual steps, and legitimate interest (Article 6 (1)(f)) for the anti-spam checks. I keep your message in my inbox while it makes sense to — usually up to two years — then archive or delete it. You can ask me to delete it earlier at any time.
when you book a class or a session.
Bookings are handled by a service called Zenamu. The booking widget on this site does not load automatically — you'll see a small placeholder first, and only when you tap "load booking" does the iframe appear and Zenamu begin to receive your IP address and browser data. This is a deliberate choice so nothing is shared with Zenamu unless you actively ask for it.
Once you complete a booking inside the widget, Zenamu holds the details of that booking (your name, email, the class or session, the date). For details on how Zenamu handles your data, see their own privacy notice at zenamu.com/privacy.
Legal basis: performance of a contract (Article 6 (1)(b) GDPR — your booking with me) and your consent to load the widget (Article 6 (1)(a)).
when you subscribe to the newsletter.
The newsletter is delivered through a service called Flodesk, based in the United States. Like the booking widget, the sign-up form does not load until you tap "load newsletter" — nothing is transferred to Flodesk before you opt in.
Once you subscribe, Flodesk stores your email address, the date you signed up, and basic engagement data (whether you opened a newsletter, whether you clicked a link). You'll receive a confirmation email first (double opt-in) — the subscription only becomes active after you confirm.
Because Flodesk processes data in the United States, this is a transfer to a third country in the sense of Article 44 ff. GDPR. The transfer is covered by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). The current US legal landscape (FISA 702 etc.) means I cannot guarantee the exact same level of protection as inside the EU — by subscribing, you accept this risk for the limited purpose of receiving my newsletter. You can unsubscribe at any time with one click in any email, and I will delete your address from Flodesk on request.
Legal basis: your consent (Article 6 (1)(a) GDPR and, for the US transfer, Article 49 (1)(a) GDPR).
the full list of sub-processors.
These are the only third parties that ever touch your data on this site. Each has its own privacy notice — linked below — and I review the list whenever I add or remove a tool.
-
Purpose: Site hosting and web analytics (cookieless)
Region: EU (Frankfurt, fra1) for functions; global CDN for static assets
Data touched: IP (anonymised in logs), user agent, request paths
-
Purpose: Delivery of contact-form messages to my inbox
Region: EU and US infrastructure
Data touched: Name, email, message — only what you put in the form
-
Purpose: Content management (the words and images on this site)
Region: United States (third-country transfer under EU Standard Contractual Clauses, 2021/914)
Data touched: None from visitors — Sanity stores my content, not your data
-
Purpose: Webfont delivery (IvyMode display + Sofia Pro body)
Region: United States (third-country transfer under EU Standard Contractual Clauses, 2021/914)
Data touched: IP address and basic browser info on each page load
-
Purpose: Newsletter sign-up and sending
Region: United States (third-country transfer under EU Standard Contractual Clauses, 2021/914)
Data touched: Email address, sign-up date, opens/clicks of newsletters you receive
-
Purpose: Booking widget for classes and 1:1 sessions
Region: See Zenamu privacy notice
Data touched: Name, email, phone, booking date — when you complete a booking
-
Purpose: Bot protection on the contact form (no CAPTCHA puzzle)
Region: Global edge network
Data touched: Browser signals (no cookies, no personal identifiers per Cloudflare)
-
Purpose: Short-lived rate-limit counters on the contact form (prevents abuse)
Region: EU (eu-central-1)
Data touched: A hashed IP address, kept for ten minutes, then deleted
your rights.
Under the GDPR you have a set of rights you can use at any time, free of charge. In plain English, you can ask me to:
- Tell you what I hold about you — the right of access (Article 15 GDPR).
- Fix anything that's wrong — the right to rectification (Article 16).
- Delete it — the right to erasure (Article 17), unless I'm required by law to keep it.
- Pause its use — the right to restriction (Article 18).
- Receive a copy in a machine-readable format — the right to data portability (Article 20).
- Object to processing based on legitimate interest — Article 21.
- Withdraw a consent you previously gave — Article 7 (3). Withdrawing doesn't affect what already happened lawfully before.
- Complain to a supervisory authority. In Malta that's the Information and Data Protection Commissioner — idpc.org.mt. You can also complain to the authority in your own country of residence.
To use any of these rights, email hello@off-the-mat.com and I'll get back to you within a month, usually much sooner.
cookies.
I don't use tracking or marketing cookies — no Google Analytics, no Meta Pixel, no Hotjar. The only thing this site stores in your browser is a small entry in local storage when you say "load booking" or "load newsletter", so you don't have to confirm the same choice twice. You can clear that at any time from your browser settings.
changes.
If I add a new tool or change how data flows on this site, I'll update this page and move the "last updated" date at the top. Substantive changes — for example a new sub-processor — will be flagged here for at least a month before they take effect.
get in touch.
For any question about your data, the fastest way is to write to hello@off-the-mat.com. I read everything personally.