Privacy Policy

Last updated: 8 August 2026

Who We Are

Enneagram Café is operated by De Novo Arts London Limited. If you have any questions about how we handle your data, you can contact us at [email protected].

The Main Website

This website (enneagramcafe.com) is an informational site. The public pages do not require an account, and we do not collect personal data through forms on them. Enneagram Café membership does involve an account — see “The Members’ Area” below. We do not use analytics or tracking scripts, and we do not track your behaviour across pages or build any profile of your browsing activity.

Cookies

This website does not set any marketing, analytics, or advertising cookies. Our content delivery network, Cloudflare, may set a small number of strictly necessary cookies to provide security and performance services. These are not used for tracking and cannot be used to identify you personally. You can read more in Cloudflare’s privacy policy.

Third-party services

None of these services are used for advertising or behavioural tracking on this website.

Joining a waiting list

If you register your interest in the Introduction programme or in membership, we store your name, your email address, and your Enneagram type and subtype if you choose to give them. We use this to let you know when places open and to send occasional updates about the programme.

Our legal basis is your consent. You can unsubscribe at any time using the link in any email, or by emailing [email protected], and we will remove you from the list. These lists are held by EcoSend.

Discover Your Type

The Discover Your Type tool at discover.enneagramcafe.com collects and processes personal data as described below. The tool does not use cookies, analytics trackers, or advertising pixels.

What we collect

When you complete the questionnaire, we collect your name and email address, your responses to the questionnaire (open-ended text), your age range and how you heard about us (both optional), and your IP address (for fraud prevention).

When you purchase an extended report, debrief session, or voice coaching programme, we also collect your confirmed Enneagram type, responses to follow-up questions about challenges and goals, and payment details (processed securely by Stripe — we never see or store your card number).

Your questionnaire progress is saved in your browser’s local storage so you can return later. This stays on your device and is cleared after 7 days or when you submit.

Sensitive information in your answers

The questionnaire asks you to describe yourself in your own words. People often mention things that UK data protection law treats as special category information: their health, their religious or philosophical beliefs, their racial or ethnic origin, their sexuality, or details of their relationships. We do not ask for any of this and you do not need to include it, but it comes up often enough that we need to be straightforward with you about it.

Because your answers may contain this kind of information, we ask for your explicit consent before you begin. Our legal basis is Article 9(2)(a) of the UK GDPR, explicit consent. You give it on the screen before the first question, not at the end.

Nothing you write leaves your browser until you submit at the end. Progress you save partway through stays on your own device.

You can withdraw your consent at any time by emailing [email protected].

How we use your information

How your report is produced

Your report is generated automatically by analysing what you have written. A person does not review it before it reaches you. The result is an interpretation intended to support your own reflection. It is not a diagnosis, an assessment of your character, or a judgement about you, and no decision about you is made on the basis of it.

Emails from us

When you submit the questionnaire, you’ll receive your personalised report (immediately) and a short series of follow-up emails to help you explore your results. These follow-up emails record which links you click, so we can tell which material people find useful; we do not use this for anything else. You can unsubscribe at any time using the link in any email. Unsubscribing will not affect your ability to download your report.

How long we keep your information

Questionnaire responses and reports. We currently keep these indefinitely, so that we can support you, reissue your report, and regenerate an improved version as the tool develops. We are introducing defined retention periods and will update this policy when they take effect. You can ask us to delete your information at any time by emailing [email protected].

Questionnaire progress saved partway through. Stored in your own browser, not on our servers. Clearing your browser data removes it.

Purchase and payment records. Kept for 6 years, as UK tax law requires.

Security

Payment processing is handled entirely by Stripe using industry-standard encryption. Access to your data is restricted to authorised personnel only.

The Members’ Area

If you join Enneagram Café, we hold an account for you and process information to run the community. We do not use analytics or tracking in the members’ area, and we do not build any profile of your browsing.

Your account

We store your name and email address, a display name you can change, your Stripe customer reference, your membership status, the dates of your membership, and — if you choose to add them — your Enneagram type and subtype. Our legal basis is the contract between us: your membership.

Logging in

We use passwordless login. When you ask to log in, we email you a single-use link that expires after 15 minutes, and we only ever store that link as a secure hash rather than the link itself. Staying signed in relies on a session cookie lasting up to 30 days.

We keep a short record of login attempts — your email address and a timestamp — to protect your account from abuse, and delete it after 7 days.

Session recordings

Enneagram Café sessions are recorded through Google Meet and hosted on Vimeo, embedded in the members’ area only and restricted so they cannot be played anywhere else. Patterns in Practice sessions are never recorded.

We do not log who watches which recording. Google and Vimeo keep their own records as part of providing those services.

How recording works, what you agree to, and how to have a recording taken down are all set out in our Terms of Service.

Requesting earlier recordings

You can ask to watch a recording from before you joined. When you do, everyone who was a member at the time that session was recorded is emailed and given 72 hours to object. We store the request, who was asked, and the outcome.

If someone objects, we tell you that a member objected. We never tell you who. Only Kieran sees both names.

Access requests and the tokens behind the objection emails are deleted automatically once they have expired.

The members’ tools

If you use the reflection tools in the members’ area, what you write is analysed by AI to produce your result, and the result is saved to your account so you can come back to it. This uses the same provider as Discover Your Type, under the same agreement, which means your input is not used to train their models.

The WhatsApp community

The WhatsApp group is optional and your membership does not depend on it. It runs on WhatsApp, so Meta’s own terms and privacy policy apply to anything shared there, and we have no ability to retrieve or delete messages from Meta’s systems. Other members can see your phone number and display name.

There is more about the group in our Terms of Service and Community Guidelines.

How long we keep member information

We currently keep member accounts and history indefinitely, including membership dates, recording requests and saved tool results. When you cancel, your account is closed rather than deleted, so we can restore it if you come back. We are introducing defined retention periods and will update this policy when they take effect.

Login links, login-attempt records and expired access requests are all deleted automatically, as described above.

You can ask us to delete your information at any time by emailing [email protected].

Where your data goes

Your data is stored on servers in Amsterdam, in the European Economic Area, operated by Railway. The UK recognises the EEA as providing adequate data protection.

Some of the services we use are based in the United States, which means some information is transferred outside the UK. Those services fall into two groups.

Services acting on our instructions. These handle your information only as we tell them to, under a written data processing agreement:

Services responsible for your information in their own right. These are not acting on our instructions. They decide how they handle your information and their own privacy notices apply:

We do not sell your data to anyone. If you would like more detail about the safeguards applying to any particular transfer, email [email protected].

Your Rights

Under UK data protection law (UK GDPR), you have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

Changes to This Policy

We may update this policy from time to time. The date at the top of this page shows when it was last revised. We will not reduce your rights under this policy without your consent.