Privacy Policy
Version 5.0 | Last updated: June 2026
This Privacy Policy applies to all users of the Zouris Platform across all jurisdictions, including UAE, GCC countries (Saudi Arabia, Bahrain, Qatar, Oman, Kuwait), and the European Union. Where local law imposes stricter requirements, those requirements apply to users in that jurisdiction.
1. Who We Are
Zouris FZE (“Zouris”, “we”, “us”, “our”) operates the Zouris wellness platform, including the website at www.zouris.io and the Zouris mobile application available on iOS and Android (together, the “Platform”).
Zouris acts as the data controller for all personal data collected through the Platform.
Registered name: Zouris FZE
Registered address: Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
Corporate Tax registration: registered under UAE Federal Decree-Law No. 47 of 2022
VAT: Zouris is not currently registered for VAT
Privacy contact: admin@zouris.io
UAE Data Office registration: [to be completed upon registration]
2. Scope of This Policy
This Policy covers all personal data collected through or in connection with:
The Zouris website (www.zouris.io)
The Zouris mobile application (iOS and Android)
Email, contact forms, and other communications with Zouris
Practitioner onboarding, verification, and profile management
Any booking, payment, or in-app activity on the Platform
It applies to all categories of data subject:
Website visitors
Registered app users (“Clients”) who book and attend sessions
Practitioners and Coaches who operate on the Platform
Individuals who submit enquiries, applications, or communications
3. Personal Data We Collect
3.1 Website Visitors
Name and email address (if submitted via contact or signup forms)
IP address, browser type, operating system, and device information
Usage data: pages visited, time on page, referral source
Cookie identifiers and session data (see Section 17)
3.2 Registered App Users (Clients)
Account data: full name, email address, password (hashed), profile photo
Session booking history, appointment records, and session notes shared with Practitioners
Payment information (processed via Stripe for 1:1 sessions and Apple Pay for subscriptions/courses; Zouris does not store full card numbers)
In-app communications and messages with Practitioners
Wellness preferences, goals, and intentions voluntarily shared
Journal entries, if you use the journaling feature (stored privately; not accessed by Zouris except as required by law or to prevent imminent harm)
Community content: posts, comments, and reactions in the Zouris community feed, groups, and events
Reviews and ratings submitted for Practitioners following completed sessions
Device identifiers, push notification tokens, app usage data, crash reports
Location data (only if you grant permission; used to suggest local Practitioners or relevant content)
3.3 Practitioners / Coaches
Full name, contact details, and professional biography
Certification documents and credentials (uploaded for verification)
Banking and payout details (for session payment disbursement via Stripe)
Profile content, photos, modality descriptions, and service listings
Session and booking records
Onboarding communications and signed Practitioner Agreement
Reviews and ratings received from Clients
4. Sensitive and Health-Related Data
Zouris operates in the wellness sector. Some data processed on our Platform — particularly data shared voluntarily between Clients and Practitioners — may constitute sensitive or special-category personal data under applicable law, including health-related information, spiritual beliefs, and content from trauma-informed or subconscious-access sessions.
The Platform hosts modalities including hypnosis-based coaching, subconscious exploration and regression work, somatic healing, breathwork, energy healing, shadow work, inner child work, Akashic Record reading, and spiritual practices. Sessions involving these modalities may involve the following categories of sensitive data:
Information relating to physical or mental health and wellbeing
Psychological history, trauma disclosures, or emotional processing content
Content disclosed during hypnosis-based, regression, or somatic sessions
Spiritual, religious, or belief-related information
Journal entries containing sensitive personal disclosures
Biometric data (voice, if used in session recordings with explicit prior consent)
We process such data only where one or more of the following applies:
You have given your explicit, informed consent for the specific purpose
Processing is strictly necessary for the service you have expressly requested
We are required to process it by applicable law
Where sensitive data is shared directly between you and a Practitioner through the Platform, Zouris acts as a technology intermediary and does not review, use, or share that content except for the limited purposes of platform operations (e.g., resolving a formal dispute or complying with a legal obligation or court order).
Zouris is not a medical provider, mental health service, or emergency support service. Content shared on the Platform does not constitute clinical advice or therapy. Certain modalities — particularly hypnosis-based coaching, regression work, and trauma-based somatic work — may not be suitable for individuals with active psychiatric conditions. See our Terms & Conditions Section 9.3 for full contraindication guidance. If you are in crisis, contact a qualified professional or emergency services immediately.
5. Why We Process Your Data
We process personal data for the following purposes:
Creating and managing user and Practitioner accounts
Facilitating session bookings between Clients and Practitioners
Processing payments via Stripe (1:1 sessions) and Apple Pay (subscriptions and courses) and disbursing Practitioner payouts
Verifying Practitioner credentials during onboarding
Delivering Platform features: community feed, groups, events, journaling, meditation and sound healing content library
Managing and displaying the reviews and ratings system
Sending service-related notifications (booking confirmations, reminders, policy updates)
Responding to customer support enquiries and complaints
Conducting anonymised analytics to improve Platform performance and user experience
Detecting and preventing fraud, abuse, and unauthorised access
Administering our licensed audio content library and enforcing usage restrictions
Complying with legal, regulatory, and financial obligations including UAE Corporate Tax
Enforcing our Terms & Conditions, Practitioner Agreement, and community standards
Where consent is given: sending marketing communications and personalised recommendations
6. Legal Basis for Processing
6.1 UAE PDPL (Federal Decree-Law No. 45 of 2021)
We rely on the following lawful bases under the UAE PDPL:
Consent — for marketing communications, optional features, sensitive data processing, and where otherwise required by law. Consent may be withdrawn at any time.
Performance of a contract — to deliver the Platform services you have signed up for
Legal obligation — to comply with UAE law, regulatory requirements, and lawful orders
Legitimate interests — for analytics, fraud prevention, security, and Platform improvement, where not overridden by your fundamental rights
6.2 GCC Jurisdictions
For users in GCC countries, we rely on equivalent lawful bases under applicable national law:
Saudi Arabia (PDPL, fully enforced September 2024): consent, contractual necessity, and legal obligation. Note: legitimate interest does not apply to sensitive data processing under Saudi PDPL.
Bahrain (PDPL, Law No. 30 of 2018): consent, contractual necessity, and legitimate interests
Qatar (Law No. 13 of 2016): consent and contractual necessity; regulatory permission required for certain sensitive data categories
Oman (Royal Decree No. 6 of 2022, in full effect February 2026): consent and contractual necessity
Kuwait: we comply with the E-Transactions Law (Law No. 20 of 2014) and Cybercrime Law (Law No. 63 of 2015)
6.3 GDPR (EU/EEA/UK Users)
For users in the EU, EEA, or UK, we rely on:
Article 6(1)(a) — Consent
Article 6(1)(b) — Performance of a contract
Article 6(1)(c) — Compliance with a legal obligation
Article 6(1)(f) — Legitimate interests
Article 9(2)(a) — Explicit consent for special-category (health/sensitive) data
You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal, by contacting admin@zouris.io.
7. Who We Share Your Data With
We do not sell personal data. We may share data with:
Stripe — for processing 1:1 session payments and Practitioner payouts; your payment data is governed by Stripe’s privacy policy
Apple Pay / App Store — for processing subscription and course purchases; your payment data is governed by Apple’s privacy policy
Cloud hosting and infrastructure providers — who store and operate the Platform on our behalf
Analytics and crash reporting tools — to monitor Platform performance (aggregated or pseudonymised where possible)
Customer support platforms — to enable us to respond to enquiries
Licensed audio content providers — aggregated usage data only, as required under licensing agreements; no personal data identifying individual users is shared
Practitioners — limited to data necessary to facilitate a session you have booked (name, contact, booking details)
Other users — where you choose to post in public community spaces on the Platform, or where your review of a Practitioner is published
Legal or regulatory authorities — where required by law, court order, or regulatory request
Professional advisors — legal, financial, or technical advisors under strict confidentiality obligations
All third-party processors are bound by written data processing agreements requiring them to: process data only on our instructions; implement appropriate security measures; assist in fulfilling data subject rights; and notify us promptly of any breach.
8. Banking and Payment Information
Practitioner banking details are collected solely for processing session payouts, accounting, and fraud prevention. This data is:
Encrypted in transit and at rest
Access-restricted to authorised personnel only
Shared only with our authorised payment processors and financial partners
Zouris does not store full card numbers. Client payment data for 1:1 sessions is handled by Stripe, and for subscriptions and courses by Apple Pay, each under their own security and compliance framework.
9. Practitioner Credentials and Verification Documents
Practitioners upload certifications and credentials during onboarding. These are reviewed internally and, where approved, relevant professional information is displayed on public Practitioner profiles. Zouris does not independently guarantee the authenticity of submitted documents. Practitioners remain solely responsible for the accuracy and ongoing validity of their credentials. Zouris reserves the right to suspend or remove any Practitioner profile where credential concerns arise.
10. Reviews and Ratings Data
When Clients submit a review or rating following a completed session, this constitutes user-generated content that Zouris processes as follows:
The review text and star rating are stored on Zouris systems and associated with your account
Approved reviews are displayed publicly on the Practitioner’s profile, visible to all Platform users
Reviews may be removed by Zouris in accordance with our Reviews and Ratings Policy in the Terms & Conditions (Section 14)
You may request deletion of a review you submitted by contacting admin@zouris.io; we will assess deletion requests in line with our data subject rights obligations and our legitimate interest in maintaining an authentic review system
Legal basis: Legitimate interests (operating a fair and transparent marketplace) and, where applicable, your consent at the time of submission.
11. Licensed Audio Content and Usage Data
The Zouris content library includes meditation tracks and sound healing compositions licensed from independent composers and rights holders. In connection with this content, we process:
Play history and content interaction data — to deliver the service and provide personalised content recommendations
Aggregated usage data — shared with licensors in anonymised form as required under licensing agreements (e.g., to report total play counts for royalty purposes)
DRM compliance data — to detect and prevent unauthorised downloading or redistribution of licensed content
No personally identifiable information is shared with content licensors. Usage data shared with licensors is aggregated and cannot identify individual users.
Legal basis: Performance of a contract (delivering the content service you have accessed) and legitimate interests (protecting the rights of content licensors and enforcing our intellectual property obligations).
12. Data Flows and Cross-Border Transfers
12.1 Primary Processing Location
Our primary production environment is hosted in cloud infrastructure located in the United Arab Emirates. This stores and processes: account and profile data, app and website usage data, booking and transaction records, and wellness-related information voluntarily shared on the Platform.
12.2 When Cross-Border Transfers Occur
In certain circumstances, data may be transferred and processed outside the UAE. We ensure all such transfers comply with:
UAE PDPL — through contractual safeguards, adequacy assessments, or explicit consent
Saudi PDPL — we do not transfer KSA resident data outside KSA without adequate safeguards or consent
Bahrain PDPL — we use written agreements and adequacy assessments for cross-border transfers
GDPR — Standard Contractual Clauses (SCCs) for transfers outside the EU/EEA where no adequacy decision exists
We do not authorise processors to use personal data for their own independent purposes.
12.3 Backup and Disaster Recovery
Encrypted backup copies of production data are maintained primarily in the UAE, with secondary encrypted copies potentially in the EMEA region for redundancy. Backups are not used for marketing, profiling, or analytics, and are deleted on a defined rotation schedule.
13. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purpose for which it was collected:
Active account data: retained for the duration of your account, then deleted within 30 days of closure (subject to legal holds)
Session booking records: minimum 5 years for legal and financial compliance
Practitioner credential documents: duration of the Practitioner relationship plus 2 years
Banking and payout records: minimum 5 years as required by UAE financial regulations and Corporate Tax obligations
Reviews and ratings: retained while your account is active and the Practitioner profile exists; deletable on request subject to legitimate interest assessment
Community content: retained until deleted by you or removed by Zouris under Community Guidelines
Journal entries: retained until you delete them or close your account
Licensed audio usage data: retained for the duration required by our licensing agreements (typically 12 months)
Marketing data: retained until you withdraw consent or unsubscribe
Anonymised analytics data: indefinitely (cannot identify individuals)
Backup copies: rotated and permanently deleted on a schedule not exceeding 90 days from creation
When data subject deletion rights are exercised, we remove data from active systems within 30 days, subject to legal retention obligations. Backup copies are not actively used and are overwritten on schedule.
14. Your Rights
14.1 Rights Under UAE PDPL and GCC Laws
UAE PDPL and equivalent GCC laws give you the right to:
Access: request a copy of the personal data we hold about you
Rectification: request correction of inaccurate or outdated data
Erasure: request deletion of your personal data (“right to be forgotten”)
Restriction: request that we limit how we use your data
Objection: object to processing based on legitimate interests or for direct marketing
Data portability: receive your data in a structured, machine-readable format
Withdrawal of consent: withdraw consent at any time for consent-based processing
UAE PDPL requires us to respond to data subject requests within 30 days (extendable in certain cases).
14.2 Additional Rights Under GDPR (EU/EEA/UK Users)
If you are in the EU, EEA, or UK, you additionally have:
The right not to be subject to solely automated decision-making with legal or significant effects
The right to lodge a complaint with your national data protection supervisory authority
14.3 How to Exercise Your Rights
Submit requests to: admin@zouris.io
We will respond within 30 days. We may request proof of identity before responding. We will not charge a fee for reasonable requests.
15. Data Breach Notification
In the event of a personal data breach that poses a risk to the privacy, confidentiality, or security of your data, Zouris will:
Notify the UAE Data Office without undue delay — and within 72 hours of discovery where feasible (consistent with PDPL Article 9 and GDPR Article 33)
Notify affected individuals promptly where the breach poses a high risk to their rights
Comply with equivalent breach notification requirements under Saudi PDPL (SDAIA), Bahrain PDPL, and other applicable GCC laws
Notification will include the nature of the breach, categories and approximate number of affected individuals, likely consequences, and measures taken or proposed.
16. Security
Zouris implements technical and organisational security measures appropriate to the risk, including:
Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
Role-based access controls and multi-factor authentication for administrative systems
Network protections including firewalls and private connectivity where applicable
Security monitoring, logging, and incident response processes
Regular security assessments and vulnerability management
Digital rights management (DRM) controls on licensed audio content
No system can guarantee absolute security. Data transmission over the internet carries inherent risk, which you acknowledge by using the Platform.
17. Cookies
The Zouris website uses cookies and similar tracking technologies. We use:
Strictly necessary cookies — required for the website to function; cannot be disabled
Analytics cookies — to understand how visitors interact with the site; disabled unless you consent
Preference cookies — to remember your settings and language
On your first visit, you will be presented with a consent banner. You may manage preferences at any time via “Cookie Settings” in the website footer. For full details, see our Cookie Policy at www.zouris.io/cookie-policy.
18. Data Protection Impact Assessments
Where we introduce new processing activities that may pose a high risk to the rights of data subjects — for example, large-scale processing of health-related data, new automated features, or profiling — we conduct a Data Protection Impact Assessment (DPIA) before commencing that processing, in compliance with UAE PDPL Article 21 and GDPR Article 35.
19. Children’s Privacy and Child Digital Safety
The Zouris Platform is intended exclusively for users aged 18 and over. We do not knowingly collect personal data from minors. In line with UAE Federal Decree-Law No. 26 of 2025 on Child Digital Safety and equivalent provisions in other jurisdictions, if we become aware that a minor has registered or submitted data, we will delete that data immediately and close the account. If you believe a minor has provided us with personal data, please contact admin@zouris.io immediately.
20. Platform Role and Practitioner Disclaimer
Zouris is a technology platform only. Practitioners are independent service providers and are not employees, agents, or representatives of Zouris. Zouris does not supervise, direct, or take responsibility for the services delivered by Practitioners or the outcomes of sessions.
Zouris is not a healthcare provider, therapy service, or emergency support service. All modalities offered on the Platform — including hypnosis-based coaching, subconscious exploration and regression work, somatic healing, breathwork, energy healing, Reiki, sound healing, Akashic Record reading, shadow work, inner child work, moon rituals, and other spiritual or holistic practices — are delivered independently by Practitioners who hold sole responsibility for their professional conduct and regulatory compliance.
21. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated by updating the version number and “Last updated” date above, and by direct notification to registered users by email or in-app notification. Continued use of the Platform after changes are posted constitutes acceptance of the updated Policy.
22. Contact and Complaints
For questions, data subject requests, or complaints regarding this Privacy Policy or your personal data:
Zouris FZE
Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
Email: admin@zouris.io
For data-related disputes not resolved through this contact, you may escalate through the dispute resolution process set out in the Zouris Terms & Conditions (Section 19).
If you are an EU/EEA/UK user and not satisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority.
If you are a Saudi Arabia user, you may contact the Saudi Data & Artificial Intelligence Authority (SDAIA).
If you are a Bahrain user, you may contact the Bahrain Personal Data Protection Authority.
Connect
admin@zouris.io
© Copyright 2025
Zouris FZE. Sharjah, UAE.
