PRIVACY POLICY
ToZ Rituals · tozrituals.org
1. Who we are and how to contact us
1.1 This Privacy Policy explains how Temple of Zeus Foundation (the “Foundation”, “we”, “us”, “our”) handles personal data in connection with the website tozrituals.org (“ToZ Rituals”, the “Site”). The Foundation is the controller of personal data processed through the Site.
1.2 The Foundation is a private interest foundation with legal personality under Law No. 25 of 12 June 1995 of the Republic of Panama.
1.3 For any privacy matter, contact [email protected] (or [email protected]).
2. Our privacy approach in brief
2.1 ToZ Rituals is built to be privacy-protective. We do not use analytics, advertising, marketing, profiling, or third-party tracking of any kind. We set only the cookies strictly necessary to run the Site. We do not sell or share personal data for advertising, and we do not build profiles of visitors.
3. Scope
3.1 This policy covers personal data processed through the Site. Other properties of the Foundation (including templeofzeus.org and the Hall of Osiris) have their own notices, which apply when you use them.
4. The personal data we process, and why
4.1 Technical session data. When your browser loads the Site, our own server creates a session record that stores your IP address and browser user-agent string (standard framework behaviour). We use this to operate and secure the Site and to deliver the content you request. Legal basis: our legitimate interests in providing and securing the Site, and, where relevant, the necessity of processing to deliver a service you have requested. The session record is discarded when the session expires (the session cookie has a two-hour sliding lifetime).
4.2 Communications. If you email us, we process your email address, your message, and anything you choose to include, in order to respond and to keep a record. Legal basis: our legitimate interests in handling correspondence, and, where relevant, your consent.
4.3 Server and security logs. Standard technical logs may record IP address, user-agent, request time, and the pages requested, for security, troubleshooting, and the prevention of abuse. Legal basis: our legitimate interests in the security and integrity of the Site.
4.4 Data revealing religious or philosophical belief. Because ToZ Rituals is a religious resource, the fact that you visit it could, in some circumstances, reveal information about your religious or philosophical beliefs, which is a special category of personal data. We minimise this by not tracking or profiling visitors. Where we knowingly process special-category data (for example, if you tell us about your beliefs when you contact us, or in the context of a staff or membership relationship), we rely on your explicit consent or on another lawful basis available to a not-for-profit body with a religious aim acting with appropriate safeguards, and we do not disclose that data except as described in this policy or as required by law.
5. What we do not do
- No analytics of any kind (no Google Analytics, Google Tag Manager, or alternatives such as Matomo, Plausible, Fathom, Umami, Hotjar, or Mixpanel).
- No advertising, marketing, or remarketing pixels.
- No third-party trackers, social widgets, or embeds that set cookies.
- No device fingerprinting or cross-site tracking.
- No sale of personal data, and no sharing of personal data for cross-context behavioural advertising.
- No automated decision-making that produces legal or similarly significant effects on you.
7. Google Fonts (a third-party data flow)
7.1 The Site loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). This sets no cookie, but each request transmits your IP address and user-agent to Google, which may involve a transfer to the United States. Legal basis: our legitimate interests in presenting the Site consistently. Google’s handling of that data is governed by Google’s own privacy policy.
9. International transfers
9.1 The Foundation is established in Panama, and some of our providers are located elsewhere, including in the EU and the United States. Where personal data is transferred across borders, we rely on appropriate safeguards where these are required (such as an adequacy decision or standard contractual clauses) and take steps intended to keep your data protected.
10. How long we keep data
10.1 We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law. Session records are discarded when the session expires; security logs are kept for a limited period; and correspondence is kept for as long as needed to handle your matter and for a reasonable period afterwards.
11. Security
11.1 We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS with HSTS), server-side session storage, HttpOnly, Secure, and SameSite cookie flags, and cross-site request forgery protection. No method of transmission or storage is completely secure, but we work to protect personal data and to detect and address incidents. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and, where required, affected individuals, in accordance with applicable law.
12. Your rights
12.1 Depending on where you live, you may have the right to: access your personal data; have it corrected; have it erased; restrict or object to its processing (including processing based on legitimate interests); receive it in a portable form; withdraw consent where processing is based on consent; opt out of the sale or sharing of personal data (we do neither); not be discriminated against for exercising your rights; and lodge a complaint with your data-protection or privacy authority.
12.2 To exercise any right, contact [email protected]. We will respond within the period required by applicable law (generally within one month under the GDPR and UK GDPR, or within 45 days under US state privacy laws), and we may need to verify your identity. There is normally no charge.
12.3 If you are in the EEA or the UK, you have the right to complain to your local supervisory authority.
13. Children
13.1 The Site is not directed to children and has no public registration. It is not intended for anyone under the age of 13, and mature devotional materials are intended for adults. We do not knowingly collect personal data from children under 13 (or the higher age set by your local law). If you believe a child has provided us with personal data, contact us and we will delete it as required by law.
14. Changes to this policy
14.1 We may update this policy from time to time. The current version is posted on the Site with its effective date, and material changes take effect when posted.
15. Contact and complaints
Temple of Zeus Foundation, ToZ Rituals
Privacy: [email protected] · General and legal: [email protected]
You have the right to lodge a complaint with your competent data-protection or privacy authority.