Privacy Policy

For jonedenkhan.com
Effective date: 1 September 2026

1. Controller

The controller responsible for the processing described in this Privacy Policy is:

Jonathan Darrall-Rew
trading as Aquarius Consultancy
professionally known as Jon Eden Khan
Chausseestraße 119
c/o Kalodion Gruppe
10115 Berlin
Germany

Email: jonathan@synergyforum.org
Telephone: +49 176 56925215

No data protection officer has been appointed because the legal requirements for mandatory appointment are not currently met.

2. Scope

This Privacy Policy explains how personal data is processed when you:

  • visit https://www.jonedenkhan.com/;

  • contact me through the website or by email;

  • submit a mentorship application through Google Forms;

  • participate in mentorship or related services; or

  • provide a testimonial, photograph or other material for publication.

“Personal data” means information relating to an identified or identifiable person.

3. Website hosting and technical data

The website is hosted by Squarespace Ireland Limited / Squarespace, Inc. When you access the website, Squarespace and its infrastructure providers may process technical data needed to deliver and protect the site, including:

  • IP address;

  • date and time of access;

  • requested page or file;

  • referrer URL;

  • browser type, language and version;

  • operating system and device information; and

  • server and security logs.

The purpose is to provide the website reliably, maintain security, diagnose technical problems and prevent misuse. The legal basis is Article 6(1)(f) GDPR (legitimate interests in secure and reliable website operation). Squarespace may also process certain information as an independent controller for its own security and service purposes.

Squarespace privacy information: https://www.squarespace.com/privacy

4. Contact and enquiries

If you contact me by email or another communication channel, I process the information you provide, normally your name, contact details, message and any related correspondence. My email or communications provider may process the resulting communication.

The purposes are to answer your enquiry, arrange a call, assess whether a service is suitable and take steps at your request before entering into a contract. The legal bases are Article 6(1)(b) GDPR (pre-contractual steps or performance of a contract) and, for general enquiries, Article 6(1)(f) GDPR (legitimate interest in communicating with people who contact me).

Please do not include health information or other highly sensitive information in a general enquiry unless it is genuinely necessary.

If no engagement follows, enquiry records are normally deleted within 12 months after the last substantive contact, unless legal claims or another legal obligation require longer storage.

5. Mentorship applications through Google Forms

The website links to separate mentorship applications for individual and group programmes hosted by Google Forms, provided by Google. Depending on the form and your answers, an application may collect:

  • email address, name, nationality, cultural or ethnic background, age, location and time zone;

  • astrological information you provide;

  • website links and how you heard about my work;

  • the mentorship programme in which you are interested;

  • the support you seek, your personal-development and trauma-work experience, perceived strengths, vulnerabilities and open-ended personal answers;

  • information about spiritual or philosophical beliefs, practices, sacred values or purpose;

  • information about employment, income, affordability and your relationship with money;

  • information concerning relationships, sexuality or other aspects of your private life that you choose to provide;

  • information about smoking, alcohol, drugs and medication; and

  • information about mental health and any other health information you choose to provide.

The purposes are to assess your application, determine whether the requested mentorship is appropriate, communicate with you and, if you are accepted, prepare and deliver the service.

For ordinary personal data, the legal basis is Article 6(1)(b) GDPR (steps at your request before entering into a contract). Health information and information that may reveal racial or ethnic origin, religious or philosophical beliefs, sexual orientation or other special-category data are processed only with your explicit consent under Article 9(2)(a), together with Article 6(1)(a), GDPR. You may withdraw that consent at any time by contacting me. Withdrawal does not affect processing already carried out lawfully. If sensitive information is genuinely necessary to assess suitability or deliver the requested service safely, withdrawing or withholding consent may mean I cannot assess or continue the application.

Google may process account, device, network and usage information under its own terms when you use Google Forms. Application responses may also be stored in Google Forms, Google Drive or Google Sheets.

Google privacy information: https://policies.google.com/privacy

Unsuccessful applications are normally deleted within 12 months after the decision or last substantive contact. For accepted applicants, application information that remains relevant to the service may be retained with the client record for up to 3 years after the mentorship ends, unless a longer period is required for legal claims or by law. Data no longer needed for the service should be deleted earlier.

6. Mentorship and related communications

Depending on the programme, communications may take place by email, Signal, Telegram, video-conferencing software such as Zoom, or another channel agreed with you. These services may process:

  • identity and contact details;

  • usernames, profile information and telephone numbers;

  • scheduling and attendance information;

  • messages, attachments and call metadata;

  • audio and video during live calls; and

  • personal or sensitive information that you choose to discuss.

The purposes are to organise and deliver the agreed mentorship, provide support and maintain appropriate business records. The legal basis is Article 6(1)(b) GDPR. Where communications contain health information, religious or philosophical beliefs, sexual-life information or other special-category data, the additional legal basis is your explicit consent under Article 9(2)(a) GDPR.

Calls are not recorded unless you are informed in advance and give separate consent. In group programmes, other participants may see your chosen profile details, messages and anything you voluntarily share with the group. Please share only what you are comfortable making visible to those participants.

Provider information:

Relevant client communications and service records are normally retained for up to 3 years after the service ends. Messages held in third-party applications may be deleted earlier under operational deletion routines or the provider's settings.

7. Invoices, payments and legal records

No purchases or card payments are completed directly on this website. If you become a client, I may separately process your name, billing address, payment status, bank-transfer reference, invoice details and tax records to perform the contract and comply with accounting and tax obligations.

The legal bases are Article 6(1)(b) GDPR (contract) and Article 6(1)(c) GDPR (legal obligations). Tax and accounting records may be retained for up to 10 years, as required by applicable German law.

8. Adobe Fonts

The website uses fonts supplied through Adobe Fonts. When these fonts are loaded, Adobe may receive technical information such as your IP address, browser information and the page requesting the font. The purpose is to present the website consistently.

Where Adobe Fonts is loaded from Adobe's servers, it should be activated only after any legally required consent. The legal basis for consent-based loading is Article 6(1)(a) GDPR and section 25(1) TDDDG. If the fonts are locally hosted and no information is transmitted to Adobe when a visitor loads a page, this consent requirement does not apply to the font delivery itself.

Adobe privacy information: https://www.adobe.com/privacy/policy.html

9. Cookies and similar technologies

Squarespace may use cookies or similar technologies that are strictly necessary to provide and secure the website. Necessary technologies are used under section 25(2) TDDDG; associated personal-data processing is based on Article 6(1)(f) GDPR.

Non-essential analytics, embedded media, external fonts or other optional technologies are used only after you have given consent through the website's consent settings. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. You can refuse or withdraw consent at any time through the site's cookie or privacy settings without affecting the lawfulness of processing before withdrawal.

At the effective date, the site does not intentionally use advertising pixels or behavioural advertising. If additional analytics, advertising tools or embedded media are introduced, this Privacy Policy and the consent configuration must be updated before they are activated.

10. External links and social media

The site contains ordinary links to third-party websites and social-media profiles. Unless content is embedded, no connection to the linked provider is initiated merely because the link appears on the page. If you click a link, the provider will process data under its own privacy terms.

11. Testimonials, photographs and public material

If you provide a testimonial, photograph, name or other material for publication, I process and publish it only within the scope agreed with you. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw consent for future use at any time. Published material will then be removed within a reasonable period, unless a separate legal basis permits continued use. Copies may remain temporarily in backups or third-party caches beyond my direct control.

12. Recipients and service providers

Personal data is disclosed only where necessary. Recipients may include:

  • Squarespace for website hosting, security, forms and site administration;

  • Google for Google Forms, Drive, Sheets and email services;

  • Adobe for remotely delivered fonts, if enabled;

  • Signal, Telegram and Zoom where used to provide the service;

  • professional advisers, accountants or IT providers bound by confidentiality; and

  • courts, public authorities or other recipients where disclosure is legally required.

Service providers acting on my instructions are selected and contracted as required by Article 28 GDPR.

13. Transfers outside the EEA

Some providers are based in, or use infrastructure or subprocessors in, countries outside the European Economic Area, including the United States. Where a transfer is not covered by an adequacy decision, the provider or I rely on safeguards such as the European Commission's Standard Contractual Clauses and, where appropriate, supplementary technical and organisational measures. Information about a provider's transfer mechanism is available in its privacy documentation.

14. Security

I use reasonable technical and organisational measures appropriate to the risk, including encrypted website connections, access controls, password protection, account-security settings and limiting access to those who need the data. No internet transmission or storage system can be guaranteed completely secure.

15. Your rights

Subject to the conditions in the GDPR, you may have the right to:

  • obtain access to your personal data (Article 15);

  • correct inaccurate data (Article 16);

  • request deletion (Article 17);

  • restrict processing (Article 18);

  • receive certain data in a portable format (Article 20);

  • object to processing based on legitimate interests (Article 21); and

  • withdraw consent at any time for the future (Article 7(3)).

To exercise your rights, contact jonathan@synergyforum.org. I may need to verify your identity before acting on a request.

You also have the right to complain to a data-protection authority. The authority responsible for Berlin is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de/

16. Changes to this Privacy Policy

This Privacy Policy may be updated when the website, services, providers or legal requirements change. The current version and its effective date will be published on this page. Where a change materially affects processing based on consent, renewed consent will be obtained where legally required.