Ben Biao Patterns LLC
Privacy Policy
Last updated: 6 September 2026
1. Who We Are and How to Contact Us
Ben Biao Patterns LLC is a limited liability company registered in New Mexico, United States. We provide non-clinical wellbeing advisory and coaching services delivered online and in person. Our registered address is 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States. Our website is https://benbiaopattern.com. For privacy matters or to exercise any of your rights under this policy, please contact us by email at info@benbiaopattern.com. This is our only published contact channel; we do not publish a telephone number or business hours.
2. What Information We Collect and How
We collect information from three sources: the contact form on our website, engagement records created during our work with you, and server access logs maintained by our web hosting provider.
Contact form. When you submit the contact form on our website, we collect your name, your email address, and the free-text message you choose to write. This information is transmitted directly to our email address at info@benbiaopattern.com and stored as email. We receive it and may contact you in response.
Engagement records. When you purchase and participate in our advisory and coaching services, we create and keep session notes and correspondence. Session notes record the content of our conversations and a short written summary sent to you after each session. Sessions are not recorded by us. We also keep any email correspondence you send to us or that we send to you in connection with your engagement. This includes scheduling, content discussed, materials we provide, and follow-up.
Server access logs. Our web server, operated by our hosting contractor in Germany, automatically records technical information about your visit to our website. This includes your Internet Protocol address, your user agent (the type and version of your browser and operating system), the date and time of your request, and the specific page or resource you requested. These logs are retained by our hosting contractor for 30 days and are deleted afterwards.
3. How We Use Your Information
We use the information we collect for the following purposes:
Responding to your enquiry. If you submit the contact form, we use your name, email address, and message to understand your request and to contact you with a response, quotation, or further information about our services.
Delivering our services. Once you are engaged with us, we use your session notes and correspondence to plan, prepare, and deliver your advisory and coaching sessions; to create the written summaries we send to you after each session; to maintain continuity of our work with you; and to provide you with follow-through materials or sessions.
Payment and billing. We use the information necessary to process your payment, invoice you, and comply with tax and accounting obligations. This may include your name, email address, payment method, and service dates.
Legal compliance and defence. We retain your engagement records to comply with applicable tax law and to preserve evidence for the defence of legal claims that may arise during our relationship or afterwards. We also retain server access logs for this purpose.
Providing technical support. We use server logs to investigate technical issues with our website, to diagnose problems, and to maintain and improve the security and performance of our website.
4. Legal Bases for Processing Under UK and EU GDPR
Our legal bases for processing your personal data are set out in Article 6 of the GDPR. This section explains the legal foundation for each type of processing we perform.
Contract. We process your name, email address, session notes, and correspondence on the basis of Article 6(1)(b) GDPR—the performance of a contract with you. When you purchase an engagement and participate in sessions with us, you enter into a contract with us, and we must process your personal data to fulfil our obligations under that contract and to enable you to benefit from it.
Legal obligation. We retain engagement records on the basis of Article 6(1)(c) GDPR—compliance with a legal obligation. We are required by tax law in New Mexico and the United States to keep financial and transactional records. We also retain records to defend against legal claims that may arise, which is a legal obligation under common law and statute.
Legitimate interests. We process server access logs on the basis of Article 6(1)(f) GDPR—legitimate interests. Our legitimate interest is to maintain a secure, stable, and well-functioning website and to detect and investigate misuse, fraud, and security incidents. We balance this against your interest in privacy by limiting log retention to 30 days, not performing real-time analytics or third-party tracking, and limiting access to logs to our practice and our hosting contractor's administrator. This balance is proportionate, and we conclude that our interest in website security and compliance investigation outweighs your privacy interest in the absence of logs of this kind.
Consent for optional analytics. We present an optional "analytics" consent category in our cookie consent banner. This category is offered to allow you to consent to the use of analytics tools should they be installed in the future. At present, no analytics tool is installed on our website. Selecting "yes" to analytics currently has no effect because there is nothing to track. We are transparent about this. Any future installation of an analytics service would operate only with your prior consent under Article 6(1)(a) GDPR, and you would retain the right to withdraw that consent at any time. The analytics banner itself is a mechanism for us to track your preference; this preference is stored only in your browser's localStorage, is not sent to any third party, and is not used for any other purpose.
Special category data. Information you voluntarily provide in the free-text message field of the contact form may contain health-related information or other sensitive data. We do not solicit this information. We are a non-clinical wellbeing advisory service and are not a healthcare provider or a mental health service. If you include clinical detail, diagnosis, prescription information, or sensitive personal data in your contact form message, you should be aware that (a) you are doing so of your own choice and at your own risk, (b) email is not an encrypted or secure channel by default, and (c) we recommend that you do not send clinical information or sensitive personal health information by web form. However, if you do send such information to us, you consent under Article 9(2)(a) GDPR by the act of sending it, and we will treat it as sensitive data. It will be stored as email, retained in accordance with our retention policy, and accessed only by our practitioner and, if necessary, by our hosting provider to maintain the server. If you believe you have sent sensitive information in error, please notify us immediately at info@benbiaopattern.com so we can take steps to delete or secure it.
5. Cookies and Browser Storage
Our website sets only two types of browser storage, both stored in your browser's localStorage. Neither is a cookie set for tracking purposes.
First-party language preference. We store your choice of interface language (if you select a non-default language) in a first-party localStorage entry on your device. This is used only to remember your preference when you return to our website. It is not transmitted to our server or to any third party, and it expires only when you manually clear your browser's localStorage or cache.
First-party cookie consent choice. We store your response to our cookie consent banner in a first-party localStorage entry. This remembers whether you have chosen to enable or disable optional analytics consent. This entry is used only to display the correct consent state on your next visit and is not transmitted to any third party.
No other cookies or browser storage are set. We do not use tracking pixels, web beacons, fingerprinting, or any form of cross-site tracking. We do not use a content delivery network that tracks you, and we do not use tag managers or third-party analytics services.
6. Third-Party Services and Data Processors
We do not use third-party analytics services, advertising networks, tag managers, embedded maps, embedded videos, social media plug-ins, or chat widgets. We do not use a third-party form processor; our contact form posts directly to our own server. We do not use a third-party content delivery network (CDN) for user-facing content. Fonts are self-hosted on our server. Nothing is loaded from external CDNs at page load, meaning your browsing behaviour on our website is not disclosed to third-party content delivery networks.
However, we do work with two data processors:
Web hosting contractor. Our website is hosted on a HestiaCP server operated by our web hosting contractor, located in Germany. Our hosting contractor acts as a data processor under contract with us. They have access to server logs, email storage, and website files. They may also have limited access to view server status and configuration for administrative purposes. Our contract with our hosting contractor includes Standard Contractual Clauses under Article 46(2) GDPR to govern the transfer of personal data from the EEA/UK to the United States, and supplementary technical and organisational measures including encryption in transit via TLS. Access is limited strictly to the practitioner and the hosting contractor's system administrators.
Email service provider. The email account info@benbiaopattern.com is accessed via the mail transfer agent (Exim) on our server and via standard protocols. Email is stored on our server. While our hosting contractor provides the underlying infrastructure, no third party processes the content of your email on our behalf. Your email is stored on servers in Germany under contract with our hosting contractor, and the same Standard Contractual Clauses and supplementary measures apply.
7. Data Retention
Contact form messages. If you submit the contact form and we do not enter into an engagement with you, we delete your contact form message (name, email, and message text) within 12 months of receipt. If your contact form leads to an engagement, it is retained as part of your engagement record under the engagement retention policy below.
Engagement records. We retain your session notes, correspondence, and all engagement records for the duration of your engagement and for 6 years afterwards, if and to the extent required by tax law (New Mexico and US federal tax obligations) or to preserve evidence for defence against legal claims. After the expiry of the 6-year period, or if no legal obligation to retain applies, we delete engagement records on request or upon the expiry of any applicable statute of limitations. If you request deletion and no legal obligation to retain applies, we will delete your records sooner upon confirmation from you.
Server access logs. Our hosting contractor retains server access logs for 30 days from the date the access occurs. After 30 days, they are automatically deleted. We do not have the ability to retain server logs beyond the 30-day period set by our hosting contractor.
8. International Data Transfers
Our practice is located in the United States, and our data is processed partly in the United States and partly in Germany (where our web hosting contractor's server is located). This means your personal data may move between the European Economic Area and the United Kingdom on one hand, and the United States on the other.
The European Commission has not adopted an adequacy decision covering transfers to the United States generally. Therefore, transfers of personal data from the EEA or UK to the United States rely on appropriate safeguards: specifically, the Standard Contractual Clauses (also known as Standard Contractual Clauses or Model Clauses) approved under Article 46(2)(c) GDPR, and the International Data Transfer Addendum (IDTA) approved under the UK GDPR. Our contract with our hosting contractor incorporates these clauses and addenda by reference.
We have also implemented supplementary technical and organisational measures to protect your data in transit and at rest: encryption using Transport Layer Security (TLS) for all data transmitted between your browser and our server; limited access to your personal data, restricted to our practitioner and our hosting contractor's system administrators; and contractual limitations on how the hosting contractor may use or disclose your data.
These measures are designed to provide an appropriate level of protection equivalent to that which you would receive in the EEA or UK. However, we acknowledge that law enforcement or national security authorities in the United States may have broader access to data stored or processed in the United States than you would expect in the EEA or UK. If you have concerns about this, please contact us to discuss your options before providing personal data to us.
9. Your Rights
Rights under UK and EU GDPR. If you are located in the European Economic Area or the United Kingdom, you have the following rights under the GDPR:
Right of access. You have the right to obtain confirmation of whether we hold personal data about you, and if we do, to obtain a copy of that data in a portable, commonly used format. You may exercise this right by writing to us at info@benbiaopattern.com.
Right to rectification. If personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct or complete it. You may exercise this right by writing to us at info@benbiaopattern.com.
Right to erasure. You have the right to ask us to delete personal data about you, subject to certain exceptions (for example, if we are required to retain it by law or to defend a legal claim). You may exercise this right by writing to us at info@benbiaopattern.com.
Right to restrict processing. You have the right to ask us to limit the way we use your personal data, for example, if you believe it is inaccurate or if you object to our use of it. You may exercise this right by writing to us at info@benbiaopattern.com.
Right to data portability. You have the right to receive a copy of personal data you have provided to us in a portable, machine-readable format, and to transmit that data to another controller. You may exercise this right by writing to us at info@benbiaopattern.com.
Right to object. You have the right to object to our processing of your personal data for legitimate interests, including profiling. If you do object, we must stop processing unless we can demonstrate that our interests outweigh yours, or unless processing is required for legal reasons. You may exercise this right by writing to us at info@benbiaopattern.com.
Right to withdraw consent. To the extent we process your personal data on the basis of your consent (for example, optional analytics), you have the right to withdraw that consent at any time by adjusting your consent preferences on our website or by writing to us at info@benbiaopattern.com.
Right to lodge a complaint. If you believe we have violated your rights under the GDPR, you have the right to lodge a complaint with the supervisory authority in your country. For residents of the European Union, the European Data Protection Board website lists the contact details of all Data Protection Authorities. For residents of the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), and you may lodge a complaint at https://ico.org.uk.
Rights under US state privacy laws. If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you have the following rights under state law:
Right to know. You have the right to know whether we have collected personal information about you, and to access and receive a copy of the personal information we hold, including the categories of personal information, the sources from which it was collected, our business purpose for collecting it, and the categories of third parties with whom we share it.
Right to delete. You have the right to request that we delete personal information we have collected from you, except in certain circumstances (for example, if we need to retain it to complete the transaction you requested, to comply with legal obligations, or to establish or defend legal claims).
Right to correct. You have the right to request that we correct inaccurate personal information we hold about you.
Right to opt out of sale or sharing. We do not sell personal information. We do not share personal information with third parties for cross-context behavioural advertising or any other purpose that constitutes "sale" or "sharing" under state privacy laws. We have not sold or shared personal information in the preceding 12 months and do not intend to do so.
Right to limit use of sensitive personal information. If we process sensitive personal information about you (such as health information you voluntarily provide via the contact form), you have the right to limit our use of that information to what is necessary to provide you with the services you request, unless you give us additional consent. You may exercise this right by writing to us at info@benbiaopattern.com.
Non-discrimination. We will not discriminate against you for exercising any of your rights. We will not deny you services, charge you different prices, or offer you a different quality of service solely because you have exercised a privacy right.
Authorised agents. You may designate an authorised agent to exercise privacy rights on your behalf. Your authorised agent must be a person you have formally authorised in writing, or an entity authorised by a power of attorney or similar legal document. Your authorised agent should contact us at info@benbiaopattern.com and provide proof of their authorisation.
Explicit statement on sale and sharing. Ben Biao Patterns LLC does not sell or share personal information as defined under the California Consumer Privacy Act (CCPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Virginia Consumer Data Protection Act (VCDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), the Montana Consumer Data Privacy Act (MCDPA), or any comparable state law. We have not sold or shared such information in the preceding twelve months. We do not use personal information for cross-context behavioural advertising or targeted advertising in the manner restricted by these laws.
Extension to other US state residents. If you are a resident of another US state with a comprehensive privacy law that grants privacy rights similar to those listed above—including but not limited to rights of access, deletion, correction, opt-out, and the right to appeal or appeal to a regulator—we recognise those rights and will process your request in accordance with the same principles and timelines we apply to residents of the states named above. These laws typically grant you the right to lodge an appeal with the state's attorney general or privacy regulator if you believe your request has been wrongly denied or improperly handled. We will provide you with information on how to do so if you ask us to review a decision.
10. Children
Our services are intended for adults. We do not knowingly collect personal information from children under 18 years of age. If we become aware that a child has provided us with personal information without parental consent, we will promptly delete that information. If you believe a child has provided us with information, please contact us immediately at info@benbiaopattern.com.
11. Security
We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
Encryption in transit. All data transmitted between your browser and our web server is encrypted using Transport Layer Security (TLS).
Limited access. Your personal data is accessible only to our practitioner and, where necessary for technical support or maintenance, to our hosting contractor's system administrators.
Secure mail storage. Your email and engagement records are stored on our server, which is protected by firewall and access controls.
Server location and contract protections. Our server is located in Germany and managed by our hosting contractor under a contract that includes data protection obligations, Standard Contractual Clauses, and audit rights.
However, no system is completely secure. We cannot guarantee absolute security of your personal data. If you believe there has been a breach or unauthorised access to your data, please notify us immediately at info@benbiaopattern.com.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, law, or other factors. If we make material changes to the way we collect, use, or process your personal data, we will notify you by posting the revised policy on our website and updating the effective date. Your continued use of our website or services after such changes constitutes your acceptance of the revised policy. We recommend that you review this policy periodically to stay informed about how we protect your information.
13. How to Exercise Your Rights and Response Deadlines
To exercise any of the rights described in this policy, please submit a written request to us at info@benbiaopattern.com. Your request should include your name, email address, and a clear description of the right you wish to exercise and the personal data to which it applies.
We will respond to your request as follows:
GDPR (European Economic Area and United Kingdom). We will respond to your request within 30 days of receipt. If your request is complex or we receive many requests at once, we may extend the response period by up to two further months. If we extend the deadline, we will notify you of the extension and the reason for it.
CCPA, CPRA, and other US state privacy laws. We will respond to your request within 45 days of receipt. If we cannot fulfil your request within 45 days, we may extend the deadline by up to 45 additional days if necessary. If we require an extension, we will notify you of the extension and the reason for it.
If we cannot fulfil your request, we will explain the reason to you in writing. For example, we may be unable to delete data if we are required by law to retain it, or if deletion would prevent us from defending a legal claim.
If you believe we have failed to respond to your request or have not provided sufficient assistance, you may lodge a complaint with the appropriate regulatory authority, as described in Section 9 above.
Effective date: 6 September 2026
Contact: info@benbiaopattern.com
Back to the home page