Privacy
Privacy Policy and Cookie Notice
Last updated: 12 September 2026
This page states what this website collects, who receives it, how long it is kept, and what you can require of us. It is written to be read, not to be survived.
1. The Controller
The controller responsible for the processing of your personal data in connection with this website and the services offered through it is:
Tamas Locher e.U., Joseph-Lister-Gasse 31A/Top 14, Vienna, Austria. Registered as a sole trader (Einzelunternehmer) in Austria.
BrahmaBros is an education and practice offering for men, built on retention and conscious masculinity. It is operated by the same controller as, but is a separate undertaking from, that controller's other businesses. The website is published at brahmabros.com.
Data protection enquiries: privacy@brahmabros.com
2. The Legal Framework
The processing of personal data in connection with this website is governed by Regulation (EU) 2016/679 (GDPR), the Austrian Datenschutzgesetz (DSG), and the Telekommunikationsgesetz 2021 (TKG 2021), which governs cookies and electronic communications.
Where this policy names a legal basis, it refers to Article 6 GDPR and, where relevant, Article 9 GDPR for special categories of data.
3. General Principles
We process personal data only to the extent necessary for clearly defined purposes. We collect only what is needed. We do not sell personal data, and we do not share it except where required to deliver our services, where we are legally obliged to, or where you have given explicit consent.
This site concerns retention, sexuality and compulsion. What a man reads here can imply something intimate about him, so the restraint below is deliberate: no advertising tag runs on this site, no profile is built, and nothing you disclose in a form or a group is ever measured.
4. Categories of Personal Data
Depending on how you use this website, we may process: contact data you submit (name, email address); technical and usage data (truncated IP address, browser and device type, pages visited, session duration, referral source, date and time of access); the content of any message you send us; and your cookie choice.
We do not operate written health intake forms, we do not keep practice notes in any system, and no special category health data under Article 9 GDPR is processed through this website.
5. Contact and Enquiries
When you contact us through a form on this website or by email, we process what you provide in order to answer you.
Legal basis: Article 6(1)(b) GDPR (steps at your request before entering a contract) and Article 6(1)(f) GDPR (our legitimate interest in answering enquiries addressed to us).
We retain correspondence for 12 months from the last message, unless a longer period is legally required or the exchange has become part of a booking or invoicing record.
6. Booking, CRM and Email (GoHighLevel)
Bookings, customer relationship management and outgoing email are handled through GoHighLevel, operated by HighLevel Inc., 400 North Saint Paul St., Suite 920, Dallas, Texas 75201, United States.
HighLevel Inc. has designated an EU representative for data protection matters: Rickert Rechtsanwaltsgesellschaft mbH - HighLevel, Inc., Colmantstrasse 15, 53115 Bonn, Germany. HighLevel acts as a processor on our behalf and processes your data only on our instructions.
Data processed: name, email address, the course or session selected, and anything you write in a form. Legal basis: Article 6(1)(b) GDPR. International transfer: HighLevel processes data in the United States under the EU-U.S. Data Privacy Framework where applicable and Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR.
We retain booking records for 24 months from the date of the session, after which they are deleted unless a statutory retention obligation requires otherwise.
7. Website Hosting (Cloudflare)
This website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, United States, through its global edge network. Requests from visitors in Europe are served from Cloudflare data centres within the EEA.
Cloudflare acts as a processor for hosting and delivery, on the basis of Cloudflare's Data Processing Addendum, which incorporates the Standard Contractual Clauses. Cloudflare is certified under the EU-U.S. Data Privacy Framework. Legal basis: Article 6(1)(f) GDPR (legitimate interest in operating a secure, functioning website).
8. Server Logs
When you visit this website, your browser transmits technical information recorded in server logs maintained by Cloudflare: IP address, date and time, pages requested, browser type and version, and the referring URL. These are processed to keep the site secure and stable, to diagnose errors, and to defend against unauthorised access.
Legal basis: Article 6(1)(f) GDPR. Server log data is not combined with other sources for profiling. Logs are retained for 30 days before deletion.
9. Cookies and Consent
This website uses cookies. Cookies are small text files your browser stores on your device. Non-essential cookies, including analytics, are activated only after you have given valid, freely given, specific and informed consent through the consent banner. No analytics script loads before consent is granted.
Essential: your language and your consent choice are stored in your browser's local storage. These set no cookies, nothing leaves your browser, and they do not require consent under TKG 2021 and GDPR.
Analytics: Google Analytics 4, described below. Activated only on your consent.
Advertising: no advertising tag, pixel or conversion tracker runs on this website. The consent banner offers an advertising category so that a choice made today still binds if one is ever added; until then the category is declared and denied, and nothing is transmitted to any advertising platform.
Your choice is recorded twice: in your browser, and as a consent receipt held by us for 12 months, so that we can demonstrate consent was given as Article 7(1) GDPR requires. The receipt holds your choice, a random identifier, a truncated IP address, your browser's user agent and the page you were on. It does not identify you by itself, and we cannot use it to find you. You may change or withdraw your choice at any time through the cookie link in the footer.
10. Google Tag Manager
This website uses Google Tag Manager (GTM), operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GTM is the sole tag deployment mechanism on this website.
GTM itself does not independently collect personal data; it is a container that activates other tools on trigger conditions. The only tag in our container is Google Analytics 4. All tags are subject to the consent rules in this policy and do not fire before consent. Google Ireland Limited acts as a processor; processing may involve transfers to Google LLC in the United States under Standard Contractual Clauses.
11. Google Analytics 4
We use Google Analytics 4 (GA4), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 collects information about how visitors use this website: pages visited, session duration, device type and approximate geographic location.
IP addresses are not logged in full. Google Signals is not enabled in our property, so no cross-device or interest-based advertising data is derived from your visit. Data is processed by Google LLC on servers in the United States under Standard Contractual Clauses.
Legal basis: Article 6(1)(a) GDPR, your consent, obtained through the consent banner before any analytics cookie or script is activated. Retention: 14 months, as configured in our GA4 property. You may opt out at any time through the cookie link in the footer, or by installing the Google Analytics Opt-out Browser Add-on.
12. Retention Periods
Contact enquiry data: 12 months from the last communication. Booking records: 24 months from the session. Invoicing and accounting data: 7 years from the end of the calendar year the invoice was issued (UGB and BAO). Server logs: 30 days. Google Analytics data: 14 months. Consent receipts: 12 months.
Where no period is listed, data is deleted as soon as the purpose it was collected for has been fulfilled and no legal obligation requires further retention.
13. Recipients and Processors
Cloudflare, Inc.: website hosting and content delivery. HighLevel Inc. (GoHighLevel): booking, CRM, invoicing and email. Google Ireland Limited: analytics (GA4) and tag management (GTM). Each is required to process personal data only on our instructions and in accordance with applicable data protection law. We do not sell personal data to any third party.
No advertising platform is a recipient of data from this website. There is no Meta pixel, no Google Ads conversion tag, and no audience list built from your visit.
14. International Data Transfers
Some processors we use handle data outside the EEA, including in the United States. Where personal data is transferred to a country without an adequacy decision, the transfer relies on Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, and where the recipient is certified, on the EU-U.S. Data Privacy Framework.
15. Your Rights
Under GDPR and the Austrian Datenschutzgesetz you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection where processing rests on legitimate interests (Article 21), and withdrawal of consent at any time without affecting prior lawful processing (Article 7(3)).
To exercise any of these rights, write to us at the address in section 1. We answer within one month, as Article 12 GDPR requires, and we do not charge a fee unless a request is manifestly unfounded or excessive.
16. Right to Lodge a Complaint
If you believe the processing of your personal data infringes data protection law, you may lodge a complaint with the competent supervisory authority. In Austria this is the Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Vienna, Austria, dsb.gv.at, +43 1 52 152-0. You may also complain to the authority in the EU Member State where you live or where the alleged infringement took place.
17. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encrypted transport, access controls, and processors selected with security in mind. Where a breach is likely to result in a risk to your rights and freedoms, we notify the Datenschutzbehörde within 72 hours and, where the risk is high, notify you directly, in accordance with Articles 33 and 34 GDPR.
18. Minors
This website and the offerings described on it are not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted personal data to us, please write to us and we will delete it.
19. Updates to This Policy
We may update this policy to reflect changes in our services, in applicable law, or in the technical infrastructure of this website. The date of the most recent revision appears at the top. Where changes are material, we will take reasonable steps to bring them to your attention.