Privacy Policy
Privacy Policy
Effective date: July 11, 2026
Last updated: July 11, 2026
1. Who We Are
This Privacy Policy explains how POPA MARIA-SUSANA PERSOANĂ FIZICĂ AUTORIZATĂ (PFA), trading as Keto Reset by Shine™ (“Keto Reset by Shine,” “we,” “us,” or “our”), collects, uses, stores, discloses, and protects personal data when you visit ketoshine.com, purchase a digital product, enroll in a coaching program or membership, participate in a corporate wellness program, communicate with us, or otherwise use our services.
Our registered office is:
POPA MARIA-SUSANA PFA
Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215
Sector 1, Bucharest, Romania
Romanian Tax Identification Number (CUI): 54000506
Trade Register Number: F2026008899
We are established in Romania and act as the controller of the personal data described in this Policy, except where we expressly state otherwise.
The EU General Data Protection Regulation (“GDPR”) applies to our processing because we are established in the European Union, regardless of where a customer lives.
For privacy requests, contact:
Email: shine@ketoshine.com
Phone: +40 724 987 956
Postal address: POPA MARIA-SUSANA PFA, Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215, Sector 1, Bucharest, Romania
2. Scope and Separate Health Data Notice
This Policy covers general personal data.
Because our services may involve information about weight, medical conditions, medications, menstrual cycles, and other health-related matters, we also publish a separate Consumer Health Data Privacy Policy.
That separate policy provides additional disclosures and rights, including disclosures intended for residents of Washington State under the Washington My Health My Data Act.
Where the two policies differ regarding consumer health data, the provision that gives the consumer greater protection will apply.
3. Personal Data We Collect
3.1 Information You Provide Directly
We may collect the following categories of information.
Identity and contact data
This may include your name, email address, telephone number, billing address, country, state or region, language, and account credentials.
We use this information to create and administer accounts, communicate with you, deliver products and services, provide support, prevent fraud, and comply with legal obligations.
Order and transaction data
This may include products purchased, subscription status, transaction date, amount, currency, tax location, invoices, refund or cancellation history, and limited payment information supplied by our payment provider.
We do not intentionally store full payment-card numbers or card security codes.
Communications
This may include emails, contact-form submissions, support messages, survey responses, WhatsApp or Telegram messages, Zoom scheduling details, coaching check-ins, and notes created while providing the service.
Program and preference data
This may include goals, dietary preferences, food restrictions, lifestyle information, program start date, preferred communication channel, progress entries, and feedback.
Health-related data
This may include:
Weight and weight history
Symptoms
Diagnoses or suspected diagnoses
Medications and supplements
PCOS
Hashimoto’s thyroiditis
Perimenopause
Insulin resistance
Diabetes-related information
Pregnancy or lactation status
Menstrual-cycle information
Eating-disorder history
Allergies
Food intolerances
Other health-related information you choose to share
Health-related information is special-category personal data under the GDPR and may also constitute consumer health data under applicable U.S. state laws.
Corporate-participant data
This may include an employer or sponsoring organization, eligibility confirmation, voluntary enrollment, attendance, resource usage, and any health information a participant voluntarily provides directly to us.
We do not provide an employer with individually identifiable health data.
Consent and preference records
This may include records of:
Acceptance of our Terms and Conditions
Acceptance of our Refund and Cancellation Policy
Recurring-billing consent
Health-data consent
Digital-delivery consent
Email-marketing preferences
Cookie choices
Withdrawal of consent
Please do not send medical records, laboratory results, identification documents, or other highly sensitive information unless we specifically request them through an approved secure process.
WhatsApp, Telegram, ordinary email, and general contact forms should not be treated as medical-record systems.
3.2 Information Collected Automatically
When you use our website, we and our service providers may collect:
IP address
Browser type and version
Device type
Operating system
Approximate location derived from your IP address
Language
Referring page
Pages viewed
Timestamps
Session identifiers
Security logs
Cookie identifiers
Cookie consent preferences
Website interaction information
Website performance and diagnostic information
Order attribution and campaign information where you have consented to the relevant non-essential technology
We use essential technical information to operate and secure the website.
We use non-essential analytics or marketing technology only after obtaining the consent required by applicable law.
3.3 Information From Other Sources
We may receive information from:
Wix, our website, commerce, CRM, forms, email-automation, and hosting provider
Our payment processor, such as Stripe when enabled through Wix
Zoom, WhatsApp, and Telegram when you choose those communication channels
A corporate client that provides only the minimum information required to confirm participant eligibility or administer a program
Referral partners, but only where the partner lawfully obtained permission to share the information
Publicly available sources where necessary to prevent fraud, protect our rights, or perform legitimate business due diligence
We do not purchase medical profiles or health-data lists from data brokers.
4. Why We Use Personal Data and Our GDPR Legal Bases
We process personal data only when we have a valid legal basis.
4.1 To Perform a Contract or Take Steps at Your Request
We use identity, contact, order, account, scheduling, communication, and program information to:
Process a purchase and deliver the Keto Reset Guide
Enroll you in Kickstart, Super, Extra, or Shine Monthly
Arrange check-ins or Zoom sessions
Deliver educational materials
Provide customer support
Administer cancellations, refunds, subscription access, and invoices
Manage a corporate wellness engagement
The legal basis is Article 6(1)(b) GDPR: processing necessary for the performance of a contract or to take steps at your request before entering into a contract.
4.2 With Explicit Consent for Health-Related Data
We process health-related information only where it is necessary for the educational wellness service you request and you have provided explicit consent, or another narrow legal exception applies.
The principal legal bases are Article 6(1)(a) GDPR and Article 9(2)(a) GDPR.
You may withdraw your consent at any time.
Withdrawal does not affect processing that occurred before consent was withdrawn. However, withdrawing consent may prevent us from continuing a service that depends on the health information concerned.
We do not use health-related data for:
Targeted advertising
Lookalike advertising audiences
Data brokerage
Unrelated product profiling
Cross-context behavioral advertising
4.3 To Comply With Legal Obligations
We process order, billing, tax, refund, complaint, and consent records where necessary to comply with accounting, tax, consumer-protection, privacy, and legal-record obligations.
The legal basis is Article 6(1)(c) GDPR.
4.4 For Legitimate Interests
Where our interests are not overridden by your rights and interests, we may process limited personal data to:
Secure the website
Prevent fraud, abuse, unauthorized access, and chargeback misuse
Maintain appropriate business records
Establish, exercise, or defend legal claims
Improve service reliability using privacy-protective operational analytics
Respond to non-marketing questions
Understand aggregate business performance without using health data for advertising
The legal basis is Article 6(1)(f) GDPR.
You may object to processing based on legitimate interests.
4.5 For Email Marketing
We send promotional email only where you have consented or where another applicable legal rule expressly permits it.
Marketing consent is optional, separate from acceptance of our services, and may be withdrawn at any time by using the unsubscribe link contained in a marketing email or by emailing shine@ketoshine.com.
Service messages, purchase receipts, security notices, order confirmations, and communications necessary to perform a purchase or provide a requested service are not marketing messages.
5. How We Disclose Personal Data
We do not sell personal data.
We disclose only the personal data reasonably necessary to the following categories of recipients.
Wix
Wix.com Ltd. and applicable Wix group entities may process data for website hosting, the online store, checkout, forms, CRM functions, member accounts, automations, email functions, website security, and website analytics.
Cookie Consent Provider
Usercentrics GmbH, or another consent-management provider made available through Wix, may process cookie preferences and records of consent.
Payment Processor
Stripe group entities may process information if Stripe is the active payment processor.
Stripe may process payment authorizations, fraud-prevention information, refunds, and transaction records.
The exact Stripe entity involved may depend on the customer’s location and the transaction route.
If another payment processor is activated, we will update this Policy before that provider begins processing personal data.
Zoom
Zoom Communications, Inc. and its affiliates may process video-meeting information, scheduling integrations, and session metadata.
Sessions are not recorded by default.
If we introduce session recording, we will provide advance notice, request any legally required consent, explain the purpose of the recording, and state the applicable retention period.
WhatsApp service providers, including Meta Platforms Ireland Limited or WhatsApp LLC, as applicable, may process messages and related metadata when you choose to communicate with us through WhatsApp.
Telegram
Telegram Messenger Inc. and relevant Telegram service entities may process messages and related metadata when you choose to communicate with us through Telegram.
Professional Advisers
Accountants, legal advisers, insurers, and IT or security specialists may receive limited information where necessary to provide professional services.
These recipients are subject to professional, legal, or contractual confidentiality obligations.
Public Authorities and Courts
We may disclose information where required by law, necessary to protect rights or safety, or needed to establish, exercise, or defend legal claims.
Corporate Clients
Corporate clients receive only aggregated and anonymized participation or engagement information.
An employer does not receive identifiable information such as:
Individual health data
Personal messages
Individual weight
Diagnoses
Medication information
Menstrual-cycle information
Individual program results
Business Transfers
If the business is reorganized, sold, transferred, or otherwise succeeds to another operator, relevant data may be disclosed subject to confidentiality protections, due-diligence controls, and applicable notice or consent requirements.
We do not disclose consumer health data to advertising networks or use consumer health data to build advertising audiences.
6. International Data Transfers
We are located in Romania, but some service providers may process personal data in:
The European Economic Area
The United Kingdom
The United States
Israel
Other countries where the provider or its subprocessors operate
Where the GDPR requires an international data-transfer mechanism, we rely on one or more of the following, as applicable:
An adequacy decision issued by the European Commission
The EU-U.S. Data Privacy Framework, where valid and applicable
European Commission Standard Contractual Clauses
Supplementary technical and organizational safeguards
Another transfer mechanism permitted by applicable law
The privacy and security practices of WhatsApp and Telegram are also governed by their respective terms and privacy notices.
Choosing to use those channels may result in personal data being processed in additional jurisdictions.
You may request email or another available communication channel instead, although ordinary email should not be treated as a secure medical-record system.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal and operational requirements.
Our standard retention schedule is as follows.
Account and Customer Profile Data
We retain account and customer profile information while the account or active customer relationship continues and for up to 24 months after the last substantive interaction, unless a longer retention period is legally required.
Coaching Communications and Health Intake Information
We retain coaching communications and health intake information for the duration of the program and for up to 24 months after the program ends, unless you request earlier deletion and no legal exception requires continued retention.
Zoom Session Notes
We retain Zoom session notes for up to 24 months after the program ends.
Zoom sessions are not recorded by default.
Contact-Form and Non-Customer Inquiries
We retain contact-form submissions and non-customer inquiries for up to 12 months after the inquiry has been resolved.
Marketing Records
We retain marketing-consent records and suppression records for as long as needed to honor your preferences and demonstrate compliance.
After you unsubscribe, we may retain a minimal suppression record to ensure that you are not unintentionally added back to a marketing list.
Cookie Records and Technical Logs
Cookie-consent records and routine technical logs are generally retained for up to 13 months, unless a shorter vendor setting applies or certain security logs are reasonably required for an investigation.
Invoices, Tax, and Transaction Records
Invoices, payment records, tax records, accounting information, and core transaction records are retained for the period required by Romanian tax and accounting laws.
This period may be longer than the duration of the customer relationship.
Complaints, Refunds, Chargebacks, and Legal Claims
We retain relevant records until the applicable limitation period and any related investigation or legal proceeding have expired.
Corporate Program Records
Corporate records are retained for the duration of the applicable agreement and for any period stated in the relevant Data Processing Agreement.
Where no different period has been agreed, participant-level service records are generally retained for up to 24 months, while contracts and invoices are retained for the legally required period.
When a retention period expires, we delete, anonymize, or securely isolate the information unless continued retention is required by law.
8. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
Obtain confirmation as to whether we process your personal data
Receive a copy of your personal data
Correct inaccurate or incomplete personal data
Request deletion of personal data
Request restriction of processing
Receive personal data you provided in a structured, commonly used, machine-readable format
Transmit eligible data to another controller
Object to processing based on legitimate interests
Object to direct marketing
Withdraw consent at any time
Request information about recipients of your data
Request information about international-transfer safeguards
Opt out of certain sale, sharing, targeted-advertising, or profiling practices under applicable U.S. laws
Submit a complaint to a competent supervisory authority or regulator
To exercise a privacy right, email shine@ketoshine.com with the subject line:
Privacy Request
Describe the right you wish to exercise and identify the account or email address concerned.
We may request proportionate information to verify your identity and protect your personal data from unauthorized access or deletion.
We will respond within the period required by applicable law. Under the GDPR, we ordinarily respond within one month, subject to a legally permitted extension for complex or multiple requests.
Authorized agents may submit a request where applicable, but we may require proof of authority and appropriate identity verification.
We will not discriminate against you for exercising a privacy right.
Some information cannot be deleted immediately where retention is required for tax, accounting, fraud prevention, legal claims, or another lawful exception.
9. California and Other U.S. State Privacy Disclosures
We do not currently represent that we meet every statutory threshold for application of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”).
Nevertheless, where reasonably practicable, we voluntarily apply the following baseline principles to U.S. consumers:
We disclose the categories and purposes of personal information collected
We do not sell personal information
We do not use health data for targeted advertising
Consumers may request access, correction, deletion, and a copy of personal information
Consumers may opt out of any future sale, sharing for cross-context behavioral advertising, or targeted advertising if such practices are introduced
We honor legally valid browser-based opt-out preference signals, such as Global Privacy Control, where legally required and technically applicable
During the preceding 12 months, the categories of personal information we may have collected include:
Identifiers
Customer records
Commercial information
Internet or electronic activity
Approximate geolocation
Professional or employment information supplied in connection with a corporate program
Inferences limited to service preferences
Sensitive personal information, including health-related information, collected only with explicit consent
The sources and recipients of this information are described in Sections 3 and 5 of this Policy.
We do not use sensitive personal information to infer characteristics for advertising purposes.
Washington residents should also read our separate Consumer Health Data Privacy Policy.
10. Cookies, Analytics, and Targeted Advertising
Our Cookie Policy explains the categories of cookies and similar technologies used on our website and how you may change your preferences.
Essential cookies may operate without consent where they are strictly necessary for:
Website security
Checkout
Session management
Account login
Fraud prevention
Providing a service you specifically request
In the European Economic Area, the United Kingdom, and other jurisdictions requiring consent, optional analytics and advertising technologies remain disabled until you make an affirmative choice.
Our cookie banner provides the following options:
Accept All
Reject All
Manage Preferences
No optional category is preselected.
You may reopen and change your preferences at any time through the “Cookie Settings” link in the website footer.
We do not place advertising pixels or session-replay tools on:
Health questionnaires
Coaching intake forms
Private member pages
Pages where health information is entered
Private messaging content
If we introduce targeted advertising, we will update this Policy and obtain the consent or provide the opt-out mechanism required by applicable law before activating the relevant technology.
11. Security
We use reasonable technical and organizational safeguards appropriate to the nature of the personal data processed.
These safeguards may include:
Access restrictions
Unique user accounts
Multi-factor authentication where available
Encrypted transmission provided by our vendors
Vendor and processor review
Data minimization
Retention controls
Confidentiality obligations
Security monitoring
Incident-response procedures
No internet transmission or storage system is completely secure.
Please do not use our website, ordinary email, WhatsApp, Telegram, or Zoom to report an emergency or to transmit unnecessary medical records.
12. Children
Our website and services are intended only for adults aged 18 or older.
We do not knowingly collect personal data from children.
If you believe that a person under 18 has provided personal data to us, contact shine@ketoshine.com.
We will investigate and delete the information where required by applicable law.
13. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects using solely automated processing.
Recommendations, educational content, program messages, and coaching communications are not medical decisions.
14. Complaints
Please contact us first at shine@ketoshine.com so that we may review and address your concern.
You may also submit a complaint to the Romanian National Supervisory Authority for Personal Data Processing:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP
You may also contact the competent supervisory authority in your habitual residence, workplace, or the location of the alleged infringement.
15. Changes to This Policy
We may update this Policy to reflect legal, technical, commercial, or operational changes.
The current version will be published on this page with a revised “Last updated” date.
Where a change materially affects the way we use health data or another consent-based purpose, we will provide additional notice and obtain new consent where required.
16. Contact
Privacy questions and requests may be sent to:
POPA MARIA-SUSANA PFA
Trading as Keto Reset by Shine™
Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215
Sector 1, Bucharest, Romania
Email: shine@ketoshine.com
Phone: +40 724 987 956
Medical Notice & Consent
By using this site, you acknowledge that Keto Reset by Shine is an educational program and not a substitute for professional medical advice. Consistent with our footer notice, you must consult your physician before starting any hormonal or nutritional protocol.