How I handle your data
Plain language, no legal fog. Here's exactly what I collect, why I collect it, and what you can ask me to do about it.
The short version. This website doesn't identify you or follow you around the internet. There are no cookies, no advertising pixels and no cross-site tracking. I count visits using a privacy-first analytics tool that stores nothing on your device. The only personal data I hold is what you hand me directly, by joining the waitlist, booking a call, or working with me as a client. I don't sell it, I don't share it for marketing, and you can ask me to delete it whenever you like.
Who's responsible for your data
I'm Katie Hudson, and I run For Good Nutrition as an independent nutrition coach based in Barcelona, Spain. I'm the data controller for everything described on this page, which means I'm the one deciding what gets collected and why, and I'm the one accountable for it.
You can reach me any time at hello@forgoodnutrition.co. That's the fastest way to reach me about anything on this page, including requests to see or delete your data.
What this website collects on its own
Almost nothing, and nothing that identifies you.
- No cookies of any kind
- No advertising or social media trackers
- No cross-site tracking, and no profile built about you
- All fonts and images load from this domain, not from Google or anyone else
You can read this entire site without giving me a single piece of information about yourself, and without anything being stored on your device.
Counting visits
I use Cloudflare Web Analytics to see how many people visit, roughly which countries they're in, and which sites they arrived from, so I know whether my writing is reaching anyone. It's the only third-party script on this site.
It doesn't use cookies and doesn't store anything on your device. It doesn't build a profile of you, doesn't follow you to other websites, and doesn't let me identify individual visitors. What I see are aggregate counts: 40 people this week, mostly from Spain and the UK, mostly arriving from LinkedIn. Not who you are.
Loading that script means your IP address reaches Cloudflare, which is how any request on the internet works. Cloudflare processes it to produce those counts and doesn't use it to track you.
Legal basis: legitimate interest under Article 6(1)(f). Because nothing is stored on your device and you aren't identified, this doesn't need a cookie banner. If I ever switch to a tool that does, I'll ask for your consent properly first.
Server logs
My hosting provider keeps standard server logs, which include visitor IP addresses, so the site stays online and secure. That's also legitimate interest under Article 6(1)(f).
If you join the waitlist
What I collect: your email address, plus your first name if you choose to give it. The name field is optional and the form works fine without it.
Why: so I can email you when a program opens.
Legal basis: your consent, under Article 6(1)(a). The form uses double opt-in, so nothing reaches you until you've confirmed by clicking a link in your inbox.
Where it goes: Kit, my email provider, which is based in the United States.
Changed your mind: every email I send has an unsubscribe link, and you can email me instead if you'd rather. Unsubscribing removes you completely.
Kit's data processing agreement is built into their terms of service. It covers standard contractual clauses and the UK international data transfer addendum for moving data to the United States.
If you book a consult
My booking page collects your name, email address, time zone and anything you type into the notes field. I use it to prepare for the call and to follow up afterwards.
Legal basis: taking steps at your request before entering into a contract, under Article 6(1)(b).
If you become a coaching client
This is the sensitive part, so I want to be direct about it.
To coach you well, I process information about your health. That includes what you eat, your energy levels, sleep, training, body measurements, your goals, and any medical context you choose to share with me.
Under the GDPR that's special category data (Article 9). It carries stronger protection than ordinary personal data, and I process it only on the basis of your explicit consent, which you give in your coaching agreement before we start working together. You can withdraw that consent at any point, and I'll stop.
What I don't do: I don't diagnose, I don't interpret bloodwork or lab results, and I don't treat eating disorders. I'm a PN1-certified nutrition coach, not a dietitian or a doctor. If something you bring me sits outside my scope, I'll say so and refer you to someone qualified.
Who sees it: only me. I don't share client information with anyone, and I don't use identifiable client details in marketing without asking first and getting a clear yes.
Where it lives: your records sit in two places. Shared documents live in Google Drive, on a paid Google Workspace account that carries a data processing agreement. My working notes live in Obsidian, synced through Obsidian Sync with end-to-end encryption, so the contents can't be read by Obsidian or anyone else holding the files. The laptop those notes sit on is encrypted too.
Who else touches your data
These are my processors. They handle data on my instructions and for no other purpose.
- Kit — email and waitlist. United States.
- Cal — consult bookings. European Union.
- Netlify — website hosting and server logs. United States.
- Cloudflare — cookieless visit counting. United States.
- Google Workspace — shared client documents in Drive. United States.
- Obsidian Sync — my encrypted coaching notes. Operated by Dynalist Inc. in Canada, synced through servers in Frankfurt.
Where data leaves the European Economic Area, that transfer needs a legal safeguard. Here's what each one relies on:
- Kit, Cloudflare, Netlify and Google are all certified under the EU-US Data Privacy Framework, and their data processing agreements also include the European Commission's standard contractual clauses.
- Obsidian is Canadian, and Canada holds an EU adequacy decision for commercial organizations, so no extra safeguard is needed. The notes are end-to-end encrypted regardless.
- Cal is in the EU, so nothing leaves.
How long I keep things
- Waitlist: until you unsubscribe, or until I close the list.
- Consult enquiries that don't become coaching: 12 months, then deleted.
- Client records: 2 years after we stop working together, then deleted. If you'd like yours removed sooner, ask and I'll do it.
Your rights
Under the GDPR you can ask me to:
- Give you a copy of the data I hold about you
- Correct anything that's wrong
- Delete it
- Restrict how I use it
- Send it to you, or another provider, in a portable format
- Stop processing it, where I'm relying on legitimate interest
- Withdraw your consent, at any time, without needing a reason
Email hello@forgoodnutrition.co and I'll respond within one month. There's no charge, and you don't have to justify the request.
If you're not happy with how I've handled it
Tell me first and I'll do my best to sort it out. But you have the right to go straight to the supervisory authority if you'd rather. In Spain that's the Agencia Española de Protección de Datos (AEPD), at aepd.es.
Changes to this policy
If I change how I handle your data, I'll update this page and change the date at the top. If the change is significant and I have your email address, I'll tell you directly rather than hoping you check.
Getting in touch
Questions about any of this are welcome, including the awkward ones. hello@forgoodnutrition.co.