MasterMyLife

Privacy Policy

This policy explains in detail what personal data may be processed through MasterMyLife, why it is needed, who may receive it, and what rights you have.

Last updated: August 14, 2026

1. Controller and scope of this policy

The operator of the platform and controller for its core functions is AS TRAINING & COACHING SRL, a Romanian VAT-registered company incorporated on January 30, 2002, with unique registration code 14417580, VAT number RO14417580, Trade Registry number J2008003573406, EUID ROONRC.J2008003573406, and registered office at Șos. Colentina nr. 1, bl. 34, sc. 5, et. 2, ap. 170, Sector 2, Bucharest 021151, Romania. In this policy, “MasterMyLife,” “we,” or “the platform” means the digital service available at mastermylife.eu and this company.

For any personal-data request, you can use the platform contact form or the direct contact details stated in the last section.

This policy applies to MasterMyLife public pages, the social network, member and professional accounts, websites built and hosted on the platform, business modules, administrative applications, transactional communications, and support services.

An external website or service opened from MasterMyLife may have its own policy. This policy does not replace the separate privacy information a professional provides for their relationship with their own clients.

2. The roles of MasterMyLife and professionals

MasterMyLife determines the essential purposes and means for data required for accounts, authentication, security, social features, platform administration, its own subscriptions and billing, support, and moderation.

A professional who collects or uses client data through their website, CRM, forms, bookings, courses, events, webinars, or offers may have their own obligations as a data controller. The exact roles for those activities depend on the feature and applicable agreements; they are not changed merely by the label used in this policy.

Where MasterMyLife processes specific data solely on a professional's documented instructions, the terms for that feature may include processor-specific obligations. The professional remains responsible for providing the required information to clients and using data only on a lawful basis.

3. Where data comes from

We receive data directly from you when you create an account, complete a profile, publish content, send a message, submit a form, make a booking or purchase, request support, or configure a website and its modules.

We may receive data from other users or professionals when they add you to a legitimate business relationship, invite or mention you, send you a message, report content, or record an interaction permitted by law.

If you choose an external service, we may receive data from Stripe, a social sign-in provider, a calendar, a video platform, a billing service, or another enabled integration. We also receive technical data generated by your browser, device, and the infrastructure delivering the platform.

4. Categories of data we may process

The data actually processed depends on your role, the features you use, and the information you choose to provide.

  • Account and identity data: email address, phone number, password stored as a hash, display name, username, first and last name, date of birth, gender, language, member type, roles, account status, and versions of legal documents accepted.
  • Profile data: photo, cover image, description, professional headline, city, area of work, interests, public links, preferences, and visibility settings.
  • Content and social activity: posts, comments, reactions, connections, communities, pages, events, stories, bookmarks, shares, searches, messages, files, and related metadata.
  • Website and business data: pages, domains, templates, files, forms, responses, consent source and evidence, CRM contacts, notes, tags, custom fields, tasks, and client-relationship history.
  • Service and participation data: bookings, calendar slots, attendance, cancellations, courses, progress, events, tickets, webinars, recording access, subscriptions, and notifications.
  • Commercial and fiscal data: offers, orders, currency, amounts, discounts, taxes, billing address and details, legal name, tax identifier, invoices, credit notes, payments, refunds, disputes, and transaction status.
  • Support, safety, and moderation data: tickets, attachments, reports, reasons, blocks, measures applied, resolution communications, and audit logs.
  • Technical and security data: IP address and network metadata available to the infrastructure, browser, device, operating system, requested address, referrer, session identifiers, access times, anti-abuse results, errors, and security events.
  • Analytics data: granted or denied consent, language, member type, authentication state, device class, and interactions with pages, sections, plans, and buttons.

5. Purposes and legal bases

We process data only for a defined purpose and on a legal basis permitted by law. Depending on the circumstances, the same type of data may be required for more than one purpose.

  • Performance of a contract or steps before entering one: account creation, authentication, profiles, publishing, communication, websites, bookings, delivery of digital products, subscriptions, payments, and requested support.
  • Legal obligations: accounting and fiscal records, responses to authorities, consumer protection, document retention, and handling legally required requests.
  • Legitimate interests: platform security, fraud and abuse prevention, troubleshooting, protection of rights, moderation, debt recovery, and efficient administration of the service, to the extent that the individual's rights and freedoms do not override those interests.
  • Consent: optional analytics, marketing communications, or integrations for which the law or interface asks for a choice. Consent may be withdrawn for the future without affecting prior lawful processing.
  • Protection of vital interests, only where that legal basis applies. For the establishment, exercise, or defence of legal claims, we rely on the legal basis relevant to the circumstances, such as a legal obligation or legitimate interests, and use an additional lawful condition where special-category data is involved.

6. What becomes public and who can see it

Your profile, username, photo, description, content, and interactions may be public where the feature or audience setting marks them as public. Public data may be viewed by people without an account and indexed or temporarily cached by search engines.

Content intended for a community, connection, client, or conversation is shown to the audience indicated by the feature. Privacy settings reduce access within the platform but cannot recall copies lawfully made by recipients or immediately remove external caches.

Before publishing information about another person, you must have the right to disclose it and respect the audience that person can reasonably expect.

7. Data managed by professionals

Professionals may collect data through the websites, forms, CRM, bookings, courses, events, webinars, and commercial flows they configure. Fields are selected by the professional and may differ from one website to another.

The professional must collect only necessary data, explain the purpose and legal basis, configure access correctly, respond to client requests, and avoid entering information they have no right to process.

A request concerning data in a relationship with a particular professional may require that professional's participation. MasterMyLife may provide export, anonymisation, and erasure tools, but the professional's own legal duties remain separate.

8. Sensitive data and information about others

The platform does not generally ask you to publish health information, racial or ethnic origin, beliefs, religion, sexual orientation, genetic data, or biometric data used for identification. However, free-form content, messages, and forms configured by professionals may reveal such information.

Do not enter sensitive data unless it is strictly necessary, a legal basis and an additional lawful condition apply, and the person has received appropriate information. Do not publish sensitive data about another person without a clear legal justification.

MasterMyLife may restrict collection or remove content where the use of data creates an unjustified risk or violates the law and platform rules.

9. Cookies, analytics, and similar technologies

We use strictly necessary cookies for sessions, social authentication, security, and storing privacy choices. The session cookie may last up to 30 days, while the temporary social-authentication cookie may last up to 30 minutes.

The marketing-analytics choice is stored for up to 180 days. After consent, the platform may create a pseudonymous first-party professional journey identifier lasting up to 30 days and record events such as section, button, destination, language, plan, member type, authentication state, and device class. The IP address may be used to limit abuse but is not written as such to the marketing events dataset.

For each eligible request to a published website, the platform records a first-party page view limited to website, path, language, device class, and referrer category. This operational measurement is independent of consent for optional tools, does not include a name, email address, or raw IP address in the analytics dataset, and relies on the legitimate interest in operating and measuring the service in aggregate, to the extent that the visitor's rights do not override that interest.

A professional may separately enable Google Analytics, Google Tag Manager, or Meta Pixel; these optional tools load only after the visitor makes a choice in the website interface.

Details about platform cookies and how to control them are available in the Cookie Policy.

10. Emails and notifications

MasterMyLife sends transactional emails needed for the service, such as verifications, account recovery, confirmations, order and booking information, security notices, and other requested events. These messages are not marketing merely because they are sent by email.

Promotional email and campaigns configured by professionals require a separate legal basis. Where they rely on consent, that consent must be recorded and the message must provide a simple way to unsubscribe.

For delivery, we may provide the email service with the recipient's name and address, message subject and content, and the required action links.

11. Payments, Stripe, and fiscal data

Payments and subscriptions may be processed through Stripe or Stripe Connect. Complete card details are entered in Stripe's hosted interface; MasterMyLife retains required commercial data and the identifiers, status, amounts, and references received for a customer, payment method, connected account, payment, refund, or dispute.

Stripe determines its own purposes and duties for certain processing, including fraud prevention and payment-service compliance. Stripe's policy applies to information Stripe processes in its own role.

For billing, we may process a name, legal name, address, fiscal country, tax identifier, billing email, and designated contacts. This data may be sent to an enabled invoicing service, such as SmartBill, and retained to meet fiscal obligations.

12. Who may receive data

We disclose only the data required for the applicable purpose and limit access through roles, contracts, and technical measures where appropriate.

  • Other users and the public, depending on the feature and selected audience.
  • The professional, client, or organisation involved in the relevant relationship, booking, event, course, order, or conversation.
  • Cloudflare, for application delivery, databases, storage, queues, anti-abuse protection, technical analytics, and operational logs.
  • Brevo, for transactional email and, only in lawfully configured flows, marketing communications.
  • Stripe and its entities, for payments, connected accounts, subscriptions, refunds, disputes, fraud prevention, and compliance.
  • Enabled invoicing, calendar, video meeting, authentication, analytics, and other integration providers, only where the feature is configured or selected.
  • Advisers and providers delivering security, maintenance, legal, accounting, support, or technical services, within their responsibilities.
  • Authorities, courts, and other recipients where disclosure is required by law or necessary to protect rights and safety.

13. Optional services and integrations

Social sign-in may be available, when enabled, through Google, Facebook, LinkedIn, X, Discord, or Apple. The selected service receives the authentication request and may return the account identifier, name, email, email-verification status, and photo allowed by its settings.

Professionals may enable integrations such as Google, Microsoft, or Zoom for calendars, meetings, and attendance, SmartBill for invoicing, or Google and Meta tools for analytics. Tokens required by integrations are protected using dedicated technical mechanisms, but the external service also processes data under its own terms.

The fact that an integration is technically supported does not mean it is active for every user or website.

14. International transfers

Some providers or recipients may process data outside Romania or the European Economic Area. The location and applicable mechanism depend on the enabled service and the provider entity serving the account.

Where required by law, a transfer must rely on an adequacy decision, standard contractual clauses, binding corporate rules, or another permitted safeguard. You may request information through support about safeguards relevant to a specific activity.

We do not enable an integration on your behalf merely because it appears in the catalogue; activation by a professional may require their own transfer assessment.

15. How long data is retained

We retain data while the account or service is active and afterwards only for as long as required for the applicable purpose, legal obligations, security, fraud prevention, dispute resolution, and defence of rights. The criteria differ by data category and contractual relationship.

Account, profile, content, and message data is retained while required by the feature and until it is deleted by an authorised person or the account is closed, subject to legal exceptions. CRM and client data is retained under the professional's instructions and obligations.

Tickets, reports, moderation measures, and security logs are retained for as long as required for resolution, repeat-abuse prevention, audit, and defence of rights. Consent evidence is retained for as long as required to demonstrate compliance, while commercial and fiscal records are retained for the period required by law.

Sessions and cookies have the durations described in this policy and the Cookie Policy. An account export prepared for download expires after 7 days. Deleted content may remain temporarily in protected logs or caches until their normal rotation.

When an account is deleted, some data is removed and other data is anonymised to break the link to the identity. Orders, invoices, credit notes, payments, refunds, disputes, fiscal documents, subscription records, consent evidence, security logs, and legal holds may be retained for as long as required by their purpose or the law.

Data without a fixed statutory period is reviewed using its volume, nature, sensitivity, risk, purpose, and whether anonymisation can achieve the same purpose.

16. Export, erasure, and account closure

You can request an export of available data through account features or the contact form. An export may include identifiers and information about other people where they form part of the account's relationships or activity; those elements may be limited or redacted where necessary to protect their rights or comply with law.

Closing an account may first require the transfer of an owned business page to protect the activity and data of other participants. Once initiated, access is revoked, sessions and tokens are invalidated, and eligible data is erased or anonymised under the applicable policy.

For a professional's client data, an operation may delete notes, tags, tasks, private assets, and preferences; anonymise profiles, forms, participation, and deliveries; and retain commercial, fiscal, consent, and audit records that cannot be removed.

17. Your rights

Subject to the General Data Protection Regulation, you may request access to and a copy of data, correction of inaccurate data, completion, erasure, restriction of processing, and portability of data you provided in a structured, commonly used, machine-readable format.

You may object to processing based on legitimate interests. You may object to direct marketing at any time, regardless of the legal basis used, and data will no longer be processed for that purpose after the objection. You may withdraw consent for the future at any time and request information about solely automated decision-making that produces legal or similarly significant effects, if such processing applies.

Rights are not absolute. For example, an erasure request does not require deletion of data needed for a legal obligation, dispute, security, or the rights of others.

18. How requests are handled

Submit your request through the support form and describe the relevant account, feature, professional, or website. We may request reasonable information to verify identity and prevent disclosure to another person.

We respond without undue delay and normally within one month of receiving a request. For complex or numerous requests, the period may be extended by a further two months, with notice during the first month.

A request is normally free. Where permitted by law, a manifestly unfounded or excessive request may be refused with reasons or may incur a reasonable fee.

19. Recommendations, profiling, and automated decisions

MasterMyLife does not currently use an automated recommender system to rank content, people, or communities based on individual profiling and does not make solely automated decisions that produce legal or similarly significant effects.

Automated signals may support security, rate limiting, and the detection of spam, fraud, or abuse. These technical measures are not presented as solely automated decisions with legal or similarly significant effects.

If a future feature involves such a decision, we will provide required information about meaningful logic, consequences, and the right to human intervention before data is used in that way.

20. Children and people without full legal capacity

Creating and holding a MasterMyLife account is permitted only for people who are at least 18 years old. The platform collects a date of birth to enforce this eligibility rule.

Professionals offering services to children must establish their own legal basis, obtain required authorisations, minimise data, and apply age-appropriate privacy and safety measures.

A parent or legal representative may contact support if they believe a child's data has been processed without the required basis.

21. Data security and incidents

We apply technical and organisational measures appropriate to risk, including password hashing, HttpOnly cookies, secure connections, access control, website-scoped data separation, anti-abuse protection, audit logs, and encryption of sensitive tokens.

No method of transmission or storage eliminates all risk. Keep sign-in details confidential, use a secure device, and notify support immediately if you suspect unauthorised access.

We investigate incidents and notify the supervisory authority and affected people where legal thresholds and deadlines require it.

22. Changes, contact, and complaints

We may update this policy when features, providers, or legal requirements change. The current version date appears at the top; material changes will be communicated through an appropriate channel before taking effect where the law requires.

For questions, rights requests, or a privacy complaint, use the MasterMyLife contact form, email contact@bootcamp.ro, or call +40 737 447 744. You may also send correspondence to the AS TRAINING & COACHING SRL registered office stated in the first section. If the request concerns data controlled by a professional, identify the professional and relevant service.

You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing or the competent authority where you live or work. We encourage you to contact us first, without limiting your right to approach an authority.