LEGAL
Privacy Policy
Last Updated: May 2026
The Feminine Principle Limited (trading as "mamma.earth") is fully committed to providing exceptional digital environments while respecting and safeguarding your privacy. We protect your personal data and uphold your explicit rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (the “UK Privacy Laws”), the European Union General Data Protection Regulation (EU 2016/679) (“GDPR”), and all other relevant regional privacy legislation.
This Privacy Policy outlines how we collect, use, process, store, share, and protect your Personal Information across our entire corporate presence.
1. The Corporate Ecosystem and Scope
2. What is Personal Information?
3. When and How We Collect Personal Information
4. The Kinds of Personal Information We Collect
5. Purposes and Legal Basis for Processing
6. Disclosure of Data and Authorized Sub-processors
7. International Data Transfers
8. Data Security and Account Retention
9. Your Legal Rights (UK and EU Residents)
10. Contact Information and Regulatory Complaints
1. The Corporate Ecosystem and Scope
1.1. Legal Entity: This policy applies directly to all personal data processing activities executed by The Feminine Principle Limited, a company registered in England and Wales under Company Number 14079889, with its registered office situated at Manchester House, Bridge Street, Ceredigion, Wales, Cardigan, SA43 1HY, United Kingdom (collectively referred to as "the Company," "we," "us," or "our").
1.2. Ecosystem Operational Footprint: The Feminine Principle Limited operates a unified digital home and managed partnership ecosystem comprising multiple interconnected sister brands, web properties, and custom domains. This privacy policy governs data transactions across all assets within our ecosystem, including but not limited to:
- https://thefeminineprinciple.com (Private Practice - Shadow Work for Women)
- https://mamma.earth (All-in-one digital home builds, calendar systems, and workflows).
- https://pollen.earth (Strategic network extensions and brand partnerships).
- https://myceliumgrove.earth (Interactive collective spaces and client community portals).
1.3. Service Touchpoints: This policy governs all data interacted with via our operational websites (“Websites”), our centralized client relationship management accounts, directories, databases, and platform interfaces built using enterprise-grade software (“Platform”), our custom migration, setup, and engineering solutions (“Services”), and any ongoing dashboard, email, or telephone correspondences (“Communications”).
2. What is Personal Information?
2.1. Definition: The term "Personal Information" (or personal data) used within this policy represents any information relating to an identified or identifiable natural person, or as otherwise explicitly specified under applicable UK and EU Privacy Laws.
2.2. Exclusions: It does not include completely anonymized, de-identified, or aggregated business metrics where individual identities have been irreversibly scrubbed.
3. When and How We Collect Personal Information
We gather data through distinct interaction points across our operational ecosystem:
- Account Provisioning & Onboarding: Collected when you book an initial consultation call, finalize a subscription tier, submit payment details, or complete our mandatory pre-flight onboarding questionnaires.
- Directory Submissions: Collected when you furnish certification logs, practitioner modalities, geo-locations, and profile graphics to establish custom searchable public directories.
- Platform Configurations: Collected when you connect external communication channels, authorize operational calendar links, or customize dashboard reporting structures.
- Direct Partner Engagements: Collected when you exchange messages with our team via internal dashboard chat, submit a support ticket, or participate in strategic review calls.
- Automated Device Telemetry: Collected automatically via background cookies, pixels, and web beacons when you browse or navigate our ecosystem domains.
4. The Kinds of Personal Information We Collect
We collect and manage distinct categories of data to fulfill our partnership commitments:
4.1. Identity and Contact Data: Full names, corporate business titles, email addresses, physical mailing coordinates, telephone contact details, and specialized practitioner modalities.
4.2. Billing and Financial Transaction Data: Bank details, card data metadata, invoicing parameters, and transactional history.
Financial Security Note: All financial transactions are processed securely by our certified third-party transaction provider, Stripe, Inc.. The Company never stores raw card or financial credentials on its local hardware infrastructure.
4.3. Directory and Public Profile Data: Visual portraits, biographical copy, location metrics, and training histories utilized to render functional graduate search matrices.
4.4. Technical Usage Data: IP profiles, account access timestamps, browser specifications, operating system versions, and telemetry analyzing your interactions with your platform dashboard.
4.5. Client Customer Data (Processed on Your Behalf): Data, records, information, or files submitted by your end-clients, course students, or event attendees through the specific forms, funnels, scheduling tools, and membership areas engineered for your business.
Data Processing Roles: In respect to this specific data layer, you act as the Data Controller, and The Feminine Principle Limited acts strictly as the Data Processor. Your own unique, user-facing privacy policy dictates your clients' rights over that information.
5. Purposes and Legal Basis for Processing
We process your Personal Information using only clear, valid legal justifications under UK and EU Privacy Laws:
- Delivering Ecosystem Architecture: Account creation, pipeline structuring, web hosting, and structural platform deployment matching your chosen tier. (Categories: Identity, Contact, Platform Usage. Legal Basis: Performance of a Contract).
- Constructing Graduate Registries: Building, formatting, and executing searchable geographic directories powered by external database technologies. (Categories: Identity, Contact, Directory Profile Data. Legal Basis: Performance of a Contract / Legitimate Interests).
- Financial Accounting Management: Invoicing, processing monthly partnership fees, tracking PAYG communication volumes, and handling partner commissions. (Categories: Identity, Financial Data, Transaction History. Legal Basis: Performance of a Contract and Legal Obligation).
- Technical Support and Optimization: Debugging external tool integrations, analyzing system uptime, and resolving setup configurations via dashboard messaging. (Categories: Contact, Technical Data, Communications. Legal Basis: Performance of a Contract and Legitimate Interests).
- Ecosystem Security & Oversight: Reviewing account behavior to avoid spam vectors over PAYG systems, monitoring unauthorized intrusions, and shielding our digital frameworks. (Categories: Technical Telemetry, Account Metadata. Legal Basis: Legitimate Interests).
6. Disclosure of Data and Authorized Sub-processors
We do not sell, lease, or distribute your personal information to third-party marketing brokers. We disclose data only to trusted sub-processors necessary to run our infrastructure, bound by strict processing agreements:
6.1. Core Infrastructure Providers: We utilize enterprise-grade software frameworks to deliver your central CRM, automated messaging channels, visual student pipelines, and system dashboards. These systems handle data strictly under our direct engineering authorization.
6.2. Directory Database Infrastructure (Supabase): Advanced, searchable practitioner directory applications are built and securely housed using Supabase database infrastructure.
6.3. Payment Processing Partners: All automated card clearing, setup transactions, and subscription processing flows are securely executed via Stripe, Inc..
6.4. Telemetry and System Verification: Non-identifying technical metadata is shared with Google LLC (via Google Analytics and Tag Manager) to maintain site health and observe ecosystem traffic.
6.5. Statutory Enforcement: We may share personal data if required to do so under the explicit mandate of English law, court orders, or binding regulatory decrees.
7. International Data Transfers
To maintain high-availability cloud hosting networks, automated communication channels, and secure database architectures, your Personal Information may be transferred to and stored by our enterprise-grade software providers in cloud data centers located outside the United Kingdom and the European Economic Area (EEA), primarily in the United States.
We guarantee that all such international transfers are protected by legally approved compliance safeguards. This includes utilizing the UK International Data Transfer Agreement (IDTA), the UK Addendum, and the EU Standard Contractual Clauses (SCCs), enforcing data security standards identical to those required within the United Kingdom and EEA.
8. Data Security and Account Retention
8.1. Technical Safeguards: We deploy strict electronic, physical, and administrative security measures to protect against the accidental loss, alteration, unauthorized access, or disclosure of data. This includes modern encryption for data both at rest and in transit (SSL/TLS protocols), segregated client database access, and restricted internal system permissions.
8.2. Operational Retention: We retain your Personal Information exclusively for the timeframe required to deliver your active subscription tier or to satisfy mandatory business accounting rules and legal dispute limits.
8.3. Termination and Archive Protocol: In full alignment with our Terms, once a 30-day notice cancellation window finishes, active administrative access is terminated. It is your sole responsibility to export your contact records, content, and student lists prior to the final termination date. Upon closure, production database parameters are systematically purged or anonymized, except for components we are legally required to retain for tax or regulatory compliance.
9. Your Legal Rights (UK and EU Residents)
If you operate your business within the United Kingdom or the EEA, you possess comprehensive statutory controls over your personal data under current Privacy Laws:
- Right of Access: You can request a clear breakdown and copy of all personal information we hold regarding your corporate identity.
- Right to Rectification: You can demand the prompt update or modification of incorrect or incomplete information.
- Right to Erasure ("Right to be Forgotten"): You can request the complete erasure of your data from our systems, provided it is no longer needed for active contract execution or regulatory retention rules.
- Right to Restrict or Object: You can halt or object to specific processing models, such as analytical tracking or promotional newsletters.
- Right to Data Portability: You can request your data in a structured, commonly used, machine-readable format. In alignment with our data trust guarantees, we ensure your client data and copy remain completely exportable upon your exit.
10. Contact Information and Regulatory Complaints
10.1. Data Management Enquiries: To update your personal information, request data exports, or submit formal requests regarding your privacy rights, please connect with our internal data management desk:
Email: support@mamma.earth
10.2. Regulatory Oversight: We aim to address all data concerns quickly and directly. However, you always preserve the legal right to file a report with the relevant supervisory body if you feel our data processing breaches privacy laws.
For individuals within the United Kingdom, please contact the Information Commissioner’s Office (ICO) (www.ico.org.uk).