top of page

Privacy Policy

Privacy Policy

Effective date: July 11, 2026
Last updated: July 11, 2026

1. Who We Are

This Privacy Policy explains how POPA MARIA-SUSANA PERSOANĂ FIZICĂ AUTORIZATĂ (PFA), trading as Keto Reset by Shine™ (“Keto Reset by Shine,” “we,” “us,” or “our”), collects, uses, stores, discloses, and protects personal data when you visit ketoshine.com, purchase a digital product, enroll in a coaching program or membership, participate in a corporate wellness program, communicate with us, or otherwise use our services.

Our registered office is:

POPA MARIA-SUSANA PFA
Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215
Sector 1, Bucharest, Romania

Romanian Tax Identification Number (CUI): 54000506
Trade Register Number: F2026008899

We are established in Romania and act as the controller of the personal data described in this Policy, except where we expressly state otherwise.

The EU General Data Protection Regulation (“GDPR”) applies to our processing because we are established in the European Union, regardless of where a customer lives.

For privacy requests, contact:

Email: shine@ketoshine.com
Phone: +40 724 987 956
Postal address: POPA MARIA-SUSANA PFA, Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215, Sector 1, Bucharest, Romania

2. Scope and Separate Health Data Notice

This Policy covers general personal data.

Because our services may involve information about weight, medical conditions, medications, menstrual cycles, and other health-related matters, we also publish a separate Consumer Health Data Privacy Policy.

That separate policy provides additional disclosures and rights, including disclosures intended for residents of Washington State under the Washington My Health My Data Act.

Where the two policies differ regarding consumer health data, the provision that gives the consumer greater protection will apply.

3. Personal Data We Collect
3.1 Information You Provide Directly

We may collect the following categories of information.

Identity and contact data

This may include your name, email address, telephone number, billing address, country, state or region, language, and account credentials.

We use this information to create and administer accounts, communicate with you, deliver products and services, provide support, prevent fraud, and comply with legal obligations.

Order and transaction data

This may include products purchased, subscription status, transaction date, amount, currency, tax location, invoices, refund or cancellation history, and limited payment information supplied by our payment provider.

We do not intentionally store full payment-card numbers or card security codes.

Communications

This may include emails, contact-form submissions, support messages, survey responses, WhatsApp or Telegram messages, Zoom scheduling details, coaching check-ins, and notes created while providing the service.

Program and preference data

This may include goals, dietary preferences, food restrictions, lifestyle information, program start date, preferred communication channel, progress entries, and feedback.

Health-related data

This may include:

Weight and weight history
Symptoms
Diagnoses or suspected diagnoses
Medications and supplements
PCOS
Hashimoto’s thyroiditis
Perimenopause
Insulin resistance
Diabetes-related information
Pregnancy or lactation status
Menstrual-cycle information
Eating-disorder history
Allergies
Food intolerances
Other health-related information you choose to share

Health-related information is special-category personal data under the GDPR and may also constitute consumer health data under applicable U.S. state laws.

Corporate-participant data

This may include an employer or sponsoring organization, eligibility confirmation, voluntary enrollment, attendance, resource usage, and any health information a participant voluntarily provides directly to us.

We do not provide an employer with individually identifiable health data.

Consent and preference records

This may include records of:

Acceptance of our Terms and Conditions
Acceptance of our Refund and Cancellation Policy
Recurring-billing consent
Health-data consent
Digital-delivery consent
Email-marketing preferences
Cookie choices
Withdrawal of consent

Please do not send medical records, laboratory results, identification documents, or other highly sensitive information unless we specifically request them through an approved secure process.

WhatsApp, Telegram, ordinary email, and general contact forms should not be treated as medical-record systems.

3.2 Information Collected Automatically

When you use our website, we and our service providers may collect:

IP address
Browser type and version
Device type
Operating system
Approximate location derived from your IP address
Language
Referring page
Pages viewed
Timestamps
Session identifiers
Security logs
Cookie identifiers
Cookie consent preferences
Website interaction information
Website performance and diagnostic information
Order attribution and campaign information where you have consented to the relevant non-essential technology

We use essential technical information to operate and secure the website.

We use non-essential analytics or marketing technology only after obtaining the consent required by applicable law.

3.3 Information From Other Sources

We may receive information from:

Wix, our website, commerce, CRM, forms, email-automation, and hosting provider
Our payment processor, such as Stripe when enabled through Wix
Zoom, WhatsApp, and Telegram when you choose those communication channels
A corporate client that provides only the minimum information required to confirm participant eligibility or administer a program
Referral partners, but only where the partner lawfully obtained permission to share the information
Publicly available sources where necessary to prevent fraud, protect our rights, or perform legitimate business due diligence

We do not purchase medical profiles or health-data lists from data brokers.

4. Why We Use Personal Data and Our GDPR Legal Bases

We process personal data only when we have a valid legal basis.

4.1 To Perform a Contract or Take Steps at Your Request

We use identity, contact, order, account, scheduling, communication, and program information to:

Process a purchase and deliver the Keto Reset Guide
Enroll you in Kickstart, Super, Extra, or Shine Monthly
Arrange check-ins or Zoom sessions
Deliver educational materials
Provide customer support
Administer cancellations, refunds, subscription access, and invoices
Manage a corporate wellness engagement

The legal basis is Article 6(1)(b) GDPR: processing necessary for the performance of a contract or to take steps at your request before entering into a contract.

4.2 With Explicit Consent for Health-Related Data

We process health-related information only where it is necessary for the educational wellness service you request and you have provided explicit consent, or another narrow legal exception applies.

The principal legal bases are Article 6(1)(a) GDPR and Article 9(2)(a) GDPR.

You may withdraw your consent at any time.

Withdrawal does not affect processing that occurred before consent was withdrawn. However, withdrawing consent may prevent us from continuing a service that depends on the health information concerned.

We do not use health-related data for:

Targeted advertising
Lookalike advertising audiences
Data brokerage
Unrelated product profiling
Cross-context behavioral advertising
4.3 To Comply With Legal Obligations

We process order, billing, tax, refund, complaint, and consent records where necessary to comply with accounting, tax, consumer-protection, privacy, and legal-record obligations.

The legal basis is Article 6(1)(c) GDPR.

4.4 For Legitimate Interests

Where our interests are not overridden by your rights and interests, we may process limited personal data to:

Secure the website
Prevent fraud, abuse, unauthorized access, and chargeback misuse
Maintain appropriate business records
Establish, exercise, or defend legal claims
Improve service reliability using privacy-protective operational analytics
Respond to non-marketing questions
Understand aggregate business performance without using health data for advertising

The legal basis is Article 6(1)(f) GDPR.

You may object to processing based on legitimate interests.

4.5 For Email Marketing

We send promotional email only where you have consented or where another applicable legal rule expressly permits it.

Marketing consent is optional, separate from acceptance of our services, and may be withdrawn at any time by using the unsubscribe link contained in a marketing email or by emailing shine@ketoshine.com.

Service messages, purchase receipts, security notices, order confirmations, and communications necessary to perform a purchase or provide a requested service are not marketing messages.

5. How We Disclose Personal Data

We do not sell personal data.

We disclose only the personal data reasonably necessary to the following categories of recipients.

Wix

Wix.com Ltd. and applicable Wix group entities may process data for website hosting, the online store, checkout, forms, CRM functions, member accounts, automations, email functions, website security, and website analytics.

Cookie Consent Provider

Usercentrics GmbH, or another consent-management provider made available through Wix, may process cookie preferences and records of consent.

Payment Processor

Stripe group entities may process information if Stripe is the active payment processor.

Stripe may process payment authorizations, fraud-prevention information, refunds, and transaction records.

The exact Stripe entity involved may depend on the customer’s location and the transaction route.

If another payment processor is activated, we will update this Policy before that provider begins processing personal data.

Zoom

Zoom Communications, Inc. and its affiliates may process video-meeting information, scheduling integrations, and session metadata.

Sessions are not recorded by default.

If we introduce session recording, we will provide advance notice, request any legally required consent, explain the purpose of the recording, and state the applicable retention period.

WhatsApp

WhatsApp service providers, including Meta Platforms Ireland Limited or WhatsApp LLC, as applicable, may process messages and related metadata when you choose to communicate with us through WhatsApp.

Telegram

Telegram Messenger Inc. and relevant Telegram service entities may process messages and related metadata when you choose to communicate with us through Telegram.

Professional Advisers

Accountants, legal advisers, insurers, and IT or security specialists may receive limited information where necessary to provide professional services.

These recipients are subject to professional, legal, or contractual confidentiality obligations.

Public Authorities and Courts

We may disclose information where required by law, necessary to protect rights or safety, or needed to establish, exercise, or defend legal claims.

Corporate Clients

Corporate clients receive only aggregated and anonymized participation or engagement information.

An employer does not receive identifiable information such as:

Individual health data
Personal messages
Individual weight
Diagnoses
Medication information
Menstrual-cycle information
Individual program results
Business Transfers

If the business is reorganized, sold, transferred, or otherwise succeeds to another operator, relevant data may be disclosed subject to confidentiality protections, due-diligence controls, and applicable notice or consent requirements.

We do not disclose consumer health data to advertising networks or use consumer health data to build advertising audiences.

6. International Data Transfers

We are located in Romania, but some service providers may process personal data in:

The European Economic Area
The United Kingdom
The United States
Israel
Other countries where the provider or its subprocessors operate

Where the GDPR requires an international data-transfer mechanism, we rely on one or more of the following, as applicable:

An adequacy decision issued by the European Commission
The EU-U.S. Data Privacy Framework, where valid and applicable
European Commission Standard Contractual Clauses
Supplementary technical and organizational safeguards
Another transfer mechanism permitted by applicable law

The privacy and security practices of WhatsApp and Telegram are also governed by their respective terms and privacy notices.

Choosing to use those channels may result in personal data being processed in additional jurisdictions.

You may request email or another available communication channel instead, although ordinary email should not be treated as a secure medical-record system.

7. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable legal and operational requirements.

Our standard retention schedule is as follows.

Account and Customer Profile Data

We retain account and customer profile information while the account or active customer relationship continues and for up to 24 months after the last substantive interaction, unless a longer retention period is legally required.

Coaching Communications and Health Intake Information

We retain coaching communications and health intake information for the duration of the program and for up to 24 months after the program ends, unless you request earlier deletion and no legal exception requires continued retention.

Zoom Session Notes

We retain Zoom session notes for up to 24 months after the program ends.

Zoom sessions are not recorded by default.

Contact-Form and Non-Customer Inquiries

We retain contact-form submissions and non-customer inquiries for up to 12 months after the inquiry has been resolved.

Marketing Records

We retain marketing-consent records and suppression records for as long as needed to honor your preferences and demonstrate compliance.

After you unsubscribe, we may retain a minimal suppression record to ensure that you are not unintentionally added back to a marketing list.

Cookie Records and Technical Logs

Cookie-consent records and routine technical logs are generally retained for up to 13 months, unless a shorter vendor setting applies or certain security logs are reasonably required for an investigation.

Invoices, Tax, and Transaction Records

Invoices, payment records, tax records, accounting information, and core transaction records are retained for the period required by Romanian tax and accounting laws.

This period may be longer than the duration of the customer relationship.

Complaints, Refunds, Chargebacks, and Legal Claims

We retain relevant records until the applicable limitation period and any related investigation or legal proceeding have expired.

Corporate Program Records

Corporate records are retained for the duration of the applicable agreement and for any period stated in the relevant Data Processing Agreement.

Where no different period has been agreed, participant-level service records are generally retained for up to 24 months, while contracts and invoices are retained for the legally required period.

When a retention period expires, we delete, anonymize, or securely isolate the information unless continued retention is required by law.

8. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

Obtain confirmation as to whether we process your personal data
Receive a copy of your personal data
Correct inaccurate or incomplete personal data
Request deletion of personal data
Request restriction of processing
Receive personal data you provided in a structured, commonly used, machine-readable format
Transmit eligible data to another controller
Object to processing based on legitimate interests
Object to direct marketing
Withdraw consent at any time
Request information about recipients of your data
Request information about international-transfer safeguards
Opt out of certain sale, sharing, targeted-advertising, or profiling practices under applicable U.S. laws
Submit a complaint to a competent supervisory authority or regulator

To exercise a privacy right, email shine@ketoshine.com with the subject line:

Privacy Request

Describe the right you wish to exercise and identify the account or email address concerned.

We may request proportionate information to verify your identity and protect your personal data from unauthorized access or deletion.

We will respond within the period required by applicable law. Under the GDPR, we ordinarily respond within one month, subject to a legally permitted extension for complex or multiple requests.

Authorized agents may submit a request where applicable, but we may require proof of authority and appropriate identity verification.

We will not discriminate against you for exercising a privacy right.

Some information cannot be deleted immediately where retention is required for tax, accounting, fraud prevention, legal claims, or another lawful exception.

9. California and Other U.S. State Privacy Disclosures

We do not currently represent that we meet every statutory threshold for application of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”).

Nevertheless, where reasonably practicable, we voluntarily apply the following baseline principles to U.S. consumers:

We disclose the categories and purposes of personal information collected
We do not sell personal information
We do not use health data for targeted advertising
Consumers may request access, correction, deletion, and a copy of personal information
Consumers may opt out of any future sale, sharing for cross-context behavioral advertising, or targeted advertising if such practices are introduced
We honor legally valid browser-based opt-out preference signals, such as Global Privacy Control, where legally required and technically applicable

During the preceding 12 months, the categories of personal information we may have collected include:

Identifiers
Customer records
Commercial information
Internet or electronic activity
Approximate geolocation
Professional or employment information supplied in connection with a corporate program
Inferences limited to service preferences
Sensitive personal information, including health-related information, collected only with explicit consent

The sources and recipients of this information are described in Sections 3 and 5 of this Policy.

We do not use sensitive personal information to infer characteristics for advertising purposes.

Washington residents should also read our separate Consumer Health Data Privacy Policy.

10. Cookies, Analytics, and Targeted Advertising

Our Cookie Policy explains the categories of cookies and similar technologies used on our website and how you may change your preferences.

Essential cookies may operate without consent where they are strictly necessary for:

Website security
Checkout
Session management
Account login
Fraud prevention
Providing a service you specifically request

In the European Economic Area, the United Kingdom, and other jurisdictions requiring consent, optional analytics and advertising technologies remain disabled until you make an affirmative choice.

Our cookie banner provides the following options:

Accept All
Reject All
Manage Preferences

No optional category is preselected.

You may reopen and change your preferences at any time through the “Cookie Settings” link in the website footer.

We do not place advertising pixels or session-replay tools on:

Health questionnaires
Coaching intake forms
Private member pages
Pages where health information is entered
Private messaging content

If we introduce targeted advertising, we will update this Policy and obtain the consent or provide the opt-out mechanism required by applicable law before activating the relevant technology.

11. Security

We use reasonable technical and organizational safeguards appropriate to the nature of the personal data processed.

These safeguards may include:

Access restrictions
Unique user accounts
Multi-factor authentication where available
Encrypted transmission provided by our vendors
Vendor and processor review
Data minimization
Retention controls
Confidentiality obligations
Security monitoring
Incident-response procedures

No internet transmission or storage system is completely secure.

Please do not use our website, ordinary email, WhatsApp, Telegram, or Zoom to report an emergency or to transmit unnecessary medical records.

12. Children

Our website and services are intended only for adults aged 18 or older.

We do not knowingly collect personal data from children.

If you believe that a person under 18 has provided personal data to us, contact shine@ketoshine.com.

We will investigate and delete the information where required by applicable law.

13. Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects using solely automated processing.

Recommendations, educational content, program messages, and coaching communications are not medical decisions.

14. Complaints

Please contact us first at shine@ketoshine.com so that we may review and address your concern.

You may also submit a complaint to the Romanian National Supervisory Authority for Personal Data Processing:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP

You may also contact the competent supervisory authority in your habitual residence, workplace, or the location of the alleged infringement.

15. Changes to This Policy

We may update this Policy to reflect legal, technical, commercial, or operational changes.

The current version will be published on this page with a revised “Last updated” date.

Where a change materially affects the way we use health data or another consent-based purpose, we will provide additional notice and obtain new consent where required.

16. Contact

Privacy questions and requests may be sent to:

POPA MARIA-SUSANA PFA
Trading as Keto Reset by Shine™
Str. Virgil Madgearu, Nr. 25-27, Bl. Corp B, Et. 1, Ap. 215
Sector 1, Bucharest, Romania

Email: shine@ketoshine.com
Phone: +40 724 987 956

Medical Notice & Consent

By using this site, you acknowledge that Keto Reset by Shine is an educational program and not a substitute for professional medical advice. Consistent with our footer notice, you must consult your physician before starting any hormonal or nutritional protocol.

bottom of page