Last updated: 15th of September 2026

This Privacy Policy explains how Gaëtan Klein (« we », « us », « our »), trading as Peak States® Coaching by Gaëtan Klein, collects, uses, discloses and protects personal information when you visit our websites, subscribe to our mailing list, purchase our programs, or receive our services.

We provide services to clients in many countries. This Policy is written to meet our obligations under the EU/French General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés, applicable United States federal and state privacy laws (including the California Consumer Privacy Act as amended), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws, the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), and Singapore’s Personal Data Protection Act 2012 (PDPA).

Where a law applicable to you grants you rights greater than those described here, that law prevails.


1. Who we are and how to contact us

Data controller / organisation responsible: Gaëtan Klein 45 rue du Placier, 37550 Saint-Avertin, France – Phone : +33 6 03 28 43 58 or +61 485 021 941 – Email : [email protected]
Registration number (SIRET) : 527 515 464 00016 

Privacy contact / Data Protection Officer: Gaëtan Klein – [email protected]

Postal address for privacy requests: 45 rue du Placier, 37550 Saint-Avertin, France

For Singapore PDPA purposes, the individual above is our designated Data Protection Officer. For GDPR purposes, [if applicable: our EU representative under Article 27 is above mentioned.


2. The information we collect

2.1 Information you give us

  • Identity and contact details: name, email address, telephone number, postal address, country of residence, time zone, preferred language.
  • Account and booking information: appointment times, session history, correspondence with us.
  • Payment information: billing name and address, and transaction records. Card details are collected and stored by our payment processors, not by us.
  • Intake and session information: the responses you give in intake forms, questionnaires, assessments and during sessions, including information about your emotional state, psychological history, symptoms, wellbeing, relationships and life circumstances.
  • Correspondence: messages you send us by email, messaging apps, contact forms or social media.

2.2 Sensitive information

Some of the information above is treated as sensitive under the laws described in this Policy — for example, « special category data » under the GDPR, « sensitive information » under the Australian Privacy Act, and « sensitive personal information » under certain US state laws. This includes information concerning your health, mental health and wellbeing.

We collect sensitive information only with your explicit, informed consent, given before or at the start of our work together, and we use it only for the purposes you consented to. You may withdraw that consent at any time (see Section 8), though doing so may mean we can no longer provide the service.

2.3 Information we collect automatically

  • Technical and usage data: IP address, approximate location derived from IP, device and browser type, operating system, pages viewed, referring page, time spent, and interactions with our emails (opens and clicks).
  • Cookies and similar technologies: see Section 10.

2.4 Information from third parties

We may receive information from payment processors, our email and course platform, scheduling tools, and advertising or analytics platforms where you have interacted with our content. We may also receive information from a person who refers you to us, where they have your permission to share it.

2.5 Children

Our services are intended for adults aged 18 and over. We do not knowingly collect personal information from children. Where we work with a minor at the request of a parent or legal guardian, we do so only with that guardian’s documented consent and in accordance with applicable law. If you believe a child has provided us with personal information, contact us and we will delete it.


3. How we use your information, and our legal basis for doing so

PurposeLegal basis (GDPR)Notes for other jurisdictions
Responding to your enquiriesSteps taken at your request prior to entering a contract; legitimate interestsConsent implied by your enquiry (PIPEDA, PDPA, APP 3)
Delivering coaching, sessions and programsPerformance of a contract; for health-related information, your explicit consent (Art. 9(2)(a))Express consent required for sensitive information
Taking payment, invoicing, accountingPerformance of a contract; legal obligation
Keeping session records and client notesExplicit consent; legitimate interests in maintaining a professional recordRetention rules in Section 7
Sending service emails (booking confirmations, access details)Performance of a contractTransactional, not marketing
Sending marketing emails and newslettersYour consent, or our legitimate interests where permittedOpt-in required in France, Canada (CASL), Singapore (PDPA) and for existing-customer marketing in Australia (Spam Act)
Website analytics and improving our contentYour consent (for non-essential cookies); legitimate interests
Advertising and audience targetingYour consentUS state laws may treat this as a « sale » or « sharing » — see Section 9.2
Publishing testimonialsYour separate written consentAlways optional; can be withdrawn
Complying with law, responding to lawful requests, establishing or defending legal claimsLegal obligation; legitimate interests; Art. 9(2)(f)

We do not use your information for automated decision-making that produces legal or similarly significant effects on you.


4. Testimonials and case material

We will never publish your name, image, voice, video or story without your separate, specific, written consent, given independently of your decision to work with us. Consent to a testimonial is not a condition of receiving our services, and you may withdraw it at any time by writing to us. On withdrawal we will remove the material from our own websites and channels within a reasonable period, though we cannot always control copies held on third-party platforms or by search engines.

Where we use anonymised examples for teaching or research, we remove or alter identifying details so that you cannot reasonably be identified.


5. Who we share your information with

We do not sell your personal information for money.

We share information with the following categories of recipients, who act as our service providers or processors and are bound by contract to protect it:

  • Payment processing: Stripe, PayPal
  • Website, funnel, email and course hosting: systeme.io
  • Video hosting and delivery: Vimeo, Youtube
  • Video conferencing for sessions: Zoom
  • Scheduling: Koalendar, OnceHub
  • Cloud storage, email and productivity: none
  • Analytics and advertising: Google Analytics, Meta
  • Professional advisers: accountants, lawyers, insurers, and our clinical supervisor where applicable

We may also disclose information where we are required or permitted to do so by law, including to courts, regulators, or law enforcement, and where disclosure is necessary to prevent a serious and imminent threat to the life, health or safety of you or another person (see Section 11 of our Terms and Conditions).

If our business is sold or reorganised, personal information may transfer to the acquirer, subject to this Policy.


6. International transfers

We operate from France and our service providers are located in several countries, including the United States, the European Economic Area, Australia and Singapore. This means your information will be transferred across borders.

Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on one of the following: an adequacy decision by the European Commission; the European Commission’s Standard Contractual Clauses; or your explicit consent, where no other mechanism is available. A copy of the safeguards we use is available on request.

For Australian clients: by engaging us you acknowledge that we disclose personal information to overseas recipients as described above. We take reasonable steps to ensure those recipients handle your information consistently with the Australian Privacy Principles, but APP 8.1 accountability may not apply where you have consented to the disclosure after being informed of this.

For Singapore clients: we transfer personal data overseas only where the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA.

For Canadian clients: your information may be processed in jurisdictions whose courts and authorities may be able to access it under their own laws.


7. How long we keep your information

CategoryRetention period
Enquiries that do not become clients[24] months from last contact
Client records, intake forms and session notes[7] years from the end of our professional relationship, or longer where a specific legal or insurance requirement applies
Financial and tax recordsAs required by applicable tax law, typically [7–10] years
Marketing list membershipUntil you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again
Website analytics data[14–26] months
TestimonialsUntil consent is withdrawn

We keep client records for an extended period because they may be needed to defend a professional complaint or legal claim, and because clients sometimes return after a long gap. When a retention period expires, we securely delete or irreversibly anonymise the information.


8. Your rights

Subject to the conditions and exceptions in the law that applies to you, you have the right to:

  • Access the personal information we hold about you and receive a copy;
  • Correct information that is inaccurate, out of date, incomplete or misleading;
  • Delete your information (« right to erasure » / « right to be forgotten »);
  • Restrict or object to certain processing, including direct marketing, which you may object to at any time and without giving a reason;
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • Data portability — receive information you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • Complain to a supervisory authority (Section 12);
  • Not be discriminated against for exercising any of these rights.

8.1 How to exercise them

Write to [email protected]. We will respond within the period required by the law that applies to you — one month under the GDPR (extendable by two further months for complex requests), 30 days under PIPEDA and the Australian Privacy Act, and 45 days under the CCPA (extendable once). We may ask you to verify your identity before we act, and we may charge a reasonable fee only where the law permits it and a request is manifestly unfounded or excessive.

There are limits. We may refuse to delete or disclose information where doing so would breach a legal obligation, reveal information about another person, or compromise our ability to defend a legal claim. If we refuse a request in whole or in part, we will tell you why and how to challenge that decision.

8.2 Additional rights for residents of California and other US states

If you are a California resident, you have the rights described above under the CCPA/CPRA, including the right to know the categories of personal information collected, the sources, the business purpose, and the categories of third parties to whom it is disclosed. You may also opt out of the « sale » or « sharing » of personal information and limit the use of sensitive personal information.

We do not sell personal information for monetary consideration. However, our use of advertising and analytics cookies may constitute « sharing » for cross-context behavioural advertising under California law. You can opt out by [adjusting your cookie preferences here / emailing us]. We honour Global Privacy Control signals where our platform supports them.

You may use an authorised agent to submit a request on your behalf, with proof of authorisation.

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with comprehensive privacy laws have comparable rights, including the right to appeal a refused request. To appeal, reply to our decision with the word « Appeal » and we will review it within the statutory period.

8.3 Additional notes for Singapore

Under the PDPA you may withdraw consent to our collection, use or disclosure of your personal data by giving us reasonable notice. We will tell you the likely consequences of withdrawal before acting on it. If you do not wish to receive marketing messages to a Singapore telephone number, you may also register with the Do Not Call Registry.


9. How we protect your information

We use organisational and technical measures appropriate to the sensitivity of the information, including encrypted transmission (TLS), access controls and strong authentication on all accounts, encrypted storage of session notes, confidentiality obligations in our contracts with service providers, and a policy of collecting only what we need.

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm or a risk to your rights, we will notify you and the relevant authority as required — within 72 hours of becoming aware, under the GDPR; as soon as practicable under Australia’s Notifiable Data Breaches scheme; within 3 calendar days of assessing a notifiable breach under Singapore’s PDPA; and as required under PIPEDA and applicable US state law.


10. Cookies and tracking

Our websites use cookies and similar technologies. Strictly necessary cookies make the site work and cannot be switched off. Analytics cookies help us understand how the site is used. Advertising cookies allow us to show relevant content on other platforms.

We ask for your consent before setting analytics or advertising cookies, and you can change your choice at any time. You can also block or delete cookies in your browser, though parts of the site may then not work.

Our video player does not load until you click to play, which means no video-hosting cookies are set before that point.


11. Third-party links

Our sites link to other websites and platforms. We are not responsible for their privacy practices, and this Policy does not apply to them. Read their policies before providing personal information.


12. Complaints

Please raise any concern with us first at [email protected] — we would prefer the chance to put it right. You may also complain to a regulator:

  • France: Commission Nationale de l’Informatique et des Libertés (CNIL) — cnil.fr
  • Other EU/EEA states: your national data protection authority
  • Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca, or your provincial commissioner
  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • Singapore: Personal Data Protection Commission (PDPC) — pdpc.gov.sg
  • United States: your state Attorney General, or the Federal Trade Commission

13. Changes to this Policy

We may update this Policy. We will post the revised version here with a new « last updated » date, and where the change is material we will notify active clients and subscribers by email before it takes effect.


Questions: [email protected]