Legal

GDPR Compliance

MysticsPortal's commitments to users in the European Economic Area, UK, and beyond.

This page applies to users in the European Economic Area (EEA), the United Kingdom, and other jurisdictions with comprehensive data-protection laws. If you are in California, please also see our Privacy Policy for CCPA rights.

MysticsPortal, Inc. acts as a data controller for account, billing, and usage data. When you (a practitioner) store client data on MysticsPortal, you act as a data controller and we act as a data processor on your behalf.

Lawful Bases for Processing

Processing PurposeLawful Basis
Providing the ServiceContract performance
Sending booking confirmationsContract performance
Processing paymentsContract performance
Marketing emailsConsent (opt-in)
Analytics & product improvementLegitimate interests
Legal compliance & fraud preventionLegal obligation

International Data Transfers

MysticsPortal is headquartered in the United States. When we transfer personal data from the EEA/UK to the US, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Sub-processors contractually bound to equivalent data-protection standards

Your GDPR Rights

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten").

Right to Restrict Processing (Art. 18)

Ask us to pause processing your data in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a machine-readable format to transfer to another provider.

Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent (Art. 7)

Withdraw consent at any time where processing is consent-based.

To exercise any right, email hello@mysticsportal.com. We will respond within 30 days. We may need to verify your identity before fulfilling a request.

Data Processing Agreement (DPA)

If you are a practitioner subject to GDPR and process EU/UK client data through MysticsPortal, you may require a Data Processing Agreement. Our DPA is available upon request and covers:

Subject matter and duration of processing
Nature and purpose of processing
Types of personal data and categories of data subjects
Obligations and rights of the controller
Sub-processor list and conditions
Technical and organisational security measures

Request our DPA

We'll send you a signed DPA within 2 business days.

Request DPA