Legal
Privacy Policy
Last updated 28 June 2026
This policy explains what we collect when you use this site or apply for After The Bell, why we collect it, how we store it, who we share it with, and the rights you have. We are based in the United Arab Emirates and handle personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). For guests who apply from the UK or EU, we also honour the rights described below as a matter of good practice, whether or not local law strictly requires it.
Who we are
After The Bell is the data controller for personal data collected through this site. You can contact us at hello@afterthebell.net.
What we collect
From the application form
- Your name, email address, phone number and location.
- Your professional role and current work or commitments.
- Free-text responses to questions about your reasons for applying, your values, the room you want to be part of, and what is currently out of balance for you.
- Health and wellbeing information you choose to share (for example, references to burnout, recovery, sleep, mental performance, or physical limitations). This is sensitive personal data and we handle it with extra care. See the next section.
If you place a hold deposit
- Payment is processed by Stripe; we do not receive or store your card details. We receive a payment confirmation and the email address Stripe uses for your receipt.
Automatically, when you use the site
- Basic technical information (browser, device type, IP-derived country) via privacy-friendly, cookie-less analytics. We do not use third-party advertising or tracking pixels.
Why we collect it, and our legal basis
- To assess your application and run the retreat, including arranging your place and your call. Legal basis: performance of a contract you have asked us to take steps to enter into.
- To process the refundable hold deposit and any subsequent payment. Legal basis: performance of a contract; legitimate interests in preventing fraud.
- To send confirmation emails and the small number of cohort-related messages you would expect after applying. Legal basis: legitimate interests in completing your application; explicit consent for any purely promotional messages, which you can withdraw at any time.
- For the special-category (health/wellbeing) information in your answers: we rely on your explicit consent, given when you submit the application. You can withdraw consent at any time by emailing us, in which case we will delete those responses.
- To improve the application process and the retreat. Legal basis: legitimate interests in running and improving our service.
Who we share it with
We use a small number of trusted service providers, each bound by their own data agreements:
- Supabase: secure database hosting for applications and team CRM records.
- Vercel: application hosting (the site itself).
- Resend: transactional email (confirmations and cohort messages).
- Stripe: payment processing for the refundable hold deposit.
We do not sell your data and we do not share it with third parties for their own marketing.
Where it is stored and how long we keep it
Data may be processed in the UAE, UK, EU or US, under the standard contractual clauses or equivalent safeguards used by the providers above. We keep application data for the duration of the cohort cycle plus a reasonable period afterwards (typically up to 24 months) so we can respond to questions, manage refunds and improve future cohorts. After that, applications are deleted or fully anonymised. Financial records are kept for the period required by UAE law.
Your rights
You have the right to:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct anything that is wrong.
- Ask us to delete your data (the right to be forgotten), subject to any legal obligations we still have to retain it.
- Ask us to restrict how we use your data, or to object to specific uses.
- Withdraw consent for any processing that relies on consent.
- Ask for a portable copy of your data.
- Complain to the UAE Data Office, or, if you are a UK/EU resident, your local data protection authority (for the UK, the Information Commissioner's Office at ico.org.uk).
To exercise any of these rights, email hello@afterthebell.net.
Cookies and tracking
This site does not set advertising or analytics cookies. We use a cookie-less, aggregated analytics service to count visits and understand how pages perform. We do not track individuals across sites.
Security
Application data is held in encrypted databases. Access to the applications and CRM tools is protected by individual passwords and signed session cookies. We do not store payment card details; those are handled by Stripe under PCI-DSS Level 1 standards.
Changes to this policy
We will update this page when our practices change. The “Last updated” date at the top tells you when it was most recently reviewed. Material changes will be highlighted on the homepage for at least a fortnight after they take effect.