This Privacy Policy explains how Zoe Zambakides trading as ToTheInvisible® collects, uses, and protects your personal data. It is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
The data controller for ToTheInvisible® is:
Zoe Zambakides trading as ToTheInvisible®
124 City Road, London, EC1V 2NX
We are registered as a Data Controller with the Information Commissioner’s Office (ICO). Our registration number is ZC108710. Any questions regarding our processing of personal data should be directed to zoe@totheinvisible.com.
2. What Data We Collect
We only collect data that is necessary and proportionate to the services we provide. This may include:
When you make a purchase
Name and email address
Payment information — this is processed securely by Stripe and is never stored by us directly (see Section 5)
When you sign up to our mailing list or waiting list
Name and email address
Your communication preferences
When you contact us
Your name, email address, and the contents of your message
When you visit our website
Anonymised analytics data (pages visited, time on site, device type) — only where you have consented to analytics cookies
We do not routinely ask for or require sensitive personal data (known as special category data under UK GDPR). Please do not share medical, psychological or other sensitive information with us beyond what is strictly necessary for your enquiry. If at any point we do need to collect special category data, we will seek your explicit consent at that time.
3. Why We Use Your Data (Legal Basis)
Under UK GDPR, we must have a lawful basis for processing your data. We rely on the following:
Contract performance — to process your purchase and deliver your product
Legitimate interests — to respond to your enquiries and maintain records of transactions
Consent — to send you marketing emails or newsletters (you can withdraw this at any time)
Legal obligation — to retain financial records as required by UK law
4. Email Marketing
If you sign up to our mailing list or waiting list, your details will be stored and managed using Flodesk, our email marketing platform. By subscribing, you consent to receiving emails from us about our work, new offerings and updates.
You can unsubscribe or update your preferences at any time using the link in any email we send you. We will never share your email address with third parties for marketing purposes.
5. Payment Processing
All payments are processed securely through Stripe, a PCI-DSS compliant payment processor. When you make a purchase, your payment details are transmitted directly to Stripe and are never stored on our servers.
Stripe acts as a data processor on our behalf and is bound by its own privacy policy, which can be found at stripe.com/gb/privacy. We receive only a transaction confirmation and the details necessary to fulfil your order.
6. How Long We Keep Your Data
We retain your data only for as long as is necessary:
Purchase records — retained for 7 years in accordance with UK tax and accounting obligations
Email marketing data — retained for as long as you remain subscribed, or until you request deletion
Audio product access records — retained for the duration of your access period
Enquiry correspondence — retained for up to 2 years
Anonymised analytics data — retained as configured in our analytics platform
7. The Platforms We Use & What They Do With Your Data
We are committed to being transparent about exactly which platforms handle your data and why. Below is a full account of every third-party service we use that processes personal information, what they use it for, and how your data is protected.
WordPress — Website
Our website is built and hosted on WordPress. WordPress processes your IP address and browser data as part of normal site operation. We use WordPress to present our content and to connect you to the checkout process. WordPress itself does not store your payment details.
Flodesk — Email Marketing & Checkout
We use Flodesk both to manage our email list and as our checkout platform for purchasing PAUSE. When you buy through our site or sign up to our mailing list, your name and email address are stored securely in Flodesk. Flodesk is used to send you your purchase confirmation, your access details, and any newsletters or updates you have subscribed to.
Flodesk is GDPR compliant and operates under a Data Processing Agreement. Your data is stored on secure servers and is never sold or shared with third parties by Flodesk for their own purposes. You can unsubscribe from our emails at any time using the link in any message we send.
Stripe — Payment Processing
All payments are processed securely through Stripe. When you enter your payment details at checkout, that information goes directly to Stripe — we never see, store, or have access to your card details at any point. Stripe is PCI-DSS Level 1 certified, the highest standard of payment security and is fully GDPR compliant.
We receive from Stripe only a confirmation that payment has been made and the information needed to fulfil your order (your name and email address). Stripe’s privacy policy can be found at stripe.com/gb/privacy.
Zapier — Automation
We use Zapier to connect Flodesk and Hello Audio. When you complete a purchase of PAUSE through Flodesk, Zapier automatically passes your name and email address to Hello Audio to grant you access to your audio content. This handoff happens securely and automatically — your data is passed in transit only and is not stored within Zapier beyond what is necessary to complete the automation.
Zapier is GDPR compliant and operates under a Data Processing Agreement. It does not use your data for any purpose other than executing the automation we have configured.
Hello Audio — Private Podcast Delivery
PAUSE is delivered as a private podcast through Hello Audio. Your name and email address are passed to Hello Audio by Zapier upon purchase, and Hello Audio uses these details solely to create your private feed and grant you access to your content. Hello Audio does not use your data for marketing or share it with third parties.
Hello Audio is GDPR compliant and stores your data securely. Your private podcast feed is unique to you and should not be shared with others.
Meta & Google — Advertising
We may use Meta (Facebook and Instagram) and Google advertising tools to help people who may value our work find their way to it. This may involve retargeting people who have visited our site, or reaching new audiences with similar interests. This only occurs where you have consented to marketing cookies. See Section 8 for full details.
CookieYes — Cookie Consent Management
We use CookieYes to manage your cookie preferences on our site. CookieYes stores a record of your consent so that your preferences are remembered across visits. It does not process any personal data beyond what is necessary to record and honour your choices.
All platforms listed above are required to handle your data in accordance with UK GDPR and operate under Data Processing Agreements where required by law.
8. Advertising & Finding Our Tribe
ToTheInvisible® is a small, independent body of work. We retain the right to use advertising to help people who may genuinely value what we offer find their way to us.
To do this, we may use advertising tools provided by Meta (Facebook and Instagram) and Google. This may involve:
Retargeting — showing relevant adverts to people who have previously visited our website. This is enabled by a tracking pixel placed on our site, which is only activated where you have consented to marketing cookies.
Audience matching — uploading your email address to Meta or Google to identify similar audiences. This allows us to reach new people with interests and values aligned with our existing community. Your data is used only for this matching process and is not retained by those platforms beyond what is necessary for delivery.
You can opt out of seeing our adverts at any time through your own Meta or Google account settings. Opting out of our ads does not affect your access to any product you have purchased.
9. Our Position on AI Training
We will not actively consent to, or facilitate, the use of your personal data for the training or development of artificial intelligence models by any third party.
We recognise that advertising platforms including Meta and Google use machine learning to optimise the delivery of adverts — for example, to determine which people are most likely to find our content relevant. We consider this a necessary and proportionate part of ad delivery and distinct from broader AI model training. We do not consent to your data being used by any platform beyond what is necessary for this purpose.
We will never share your data — including your name, email address, purchase history, or any content you share with us — with any party for the purpose of training large language models, generative AI systems, or similar technologies.
10. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
The right to access — you can request a copy of the data we hold about you
The right to rectification — you can ask us to correct inaccurate data
The right to erasure — you can ask us to delete your data (subject to legal retention obligations)
The right to restrict processing — you can ask us to limit how we use your data
The right to data portability — you can request your data in a machine-readable format
The right to object — you can object to processing based on legitimate interests or for direct marketing
The right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at zoe@totheinvisible.com. We will respond within one calendar month.
11. Data Security
We take reasonable technical and organisational steps to protect your personal data against unauthorised access, loss, or disclosure. All third-party platforms we use — WordPress, Flodesk, Stripe, Zapier, Hello Audio, CookieYes, and our advertising partners — are required to maintain appropriate security standards and operate under Data Processing Agreements where required.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you directly where required.
12. Transfers Outside the UK
Some of the platforms we use, including Stripe, Flodesk, Zapier, and Hello Audio, are based in the United States and may process your data outside the UK. Where this is the case, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms recognised under UK data protection law.
13. Links to Other Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of any site you visit.
14. Complaints
If you have concerns about how we handle your personal data, please contact us first at zoe@totheinvisible.com and we will do our best to resolve the matter.
You also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office (ICO):
ico.org.uk · 0303 123 1113
Governing Law
All four parts of this document are governed by English law. Any dispute arising from your use of this site or any purchase made through it shall be subject to the exclusive jurisdiction of the courts of England and Wales.
ToTheInvisible® is the registered trademark of Zoe Zambakides. All rights reserved.