Privacy Policy
Your trust matters to us. Please review how we handle your data in accordance with global privacy regulations.
Quick Navigation
1. Definitions
Personal Data means any information relating to an identified or identifiable individual. Processing means any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion. Data Subject refers to the individual whose personal data is processed. Controller and Processor have the meanings assigned under GDPR. Protected Health Information (PHI) refers to health information regulated under HIPAA.
2. Scope and Applicability
This Policy applies to all personal data processed by Healing School across its websites, applications, platforms, APIs, products, services, and internal systems. It applies to customers, employees, contractors, partners, vendors, website visitors, and any other individuals whose data we process.
3. Categories of Personal Data Collected
Healing School may collect the following categories of data: identification data (name, date of birth, government-issued identifiers where legally permitted), contact data (email address, phone number, physical address), technical data (IP address, device identifiers, browser type), usage data (interaction logs, access times), financial data (payment card tokens, transaction references), and health-related data where applicable and lawfully permitted.
4. Data Processing Principles
Healing School processes personal data in accordance with the principles of lawfulness, fairness, and transparency. Data is collected for specified, explicit, and legitimate purposes and is adequate, relevant, and limited to what is necessary. We ensure accuracy, storage limitation, integrity, confidentiality, and accountability in all processing activities.
5. Legal Basis for Processing
Personal data is processed based on one or more lawful grounds, including the data subject's consent, performance of a contract, compliance with legal obligations, protection of vital interests, performance of tasks carried out in the public interest, or Healing School's legitimate interests, provided such interests do not override data subject rights.
6. Consent Management
Where consent is required, Healing School ensures that consent is freely given, specific, informed, and unambiguous. Consent records are maintained and data subjects may withdraw consent at any time without affecting prior lawful processing.
7. Cookies and Tracking Technologies
Healing School uses cookies, web beacons, pixels, and similar technologies to ensure platform functionality, enhance user experience, perform analytics, and support marketing activities. Cookies may be strictly necessary, functional, performance-based, or targeting cookies. Users may manage cookie preferences through browser or platform settings.
8. Data Usage and Purpose Limitation
Personal data is used solely for defined business purposes, including service delivery, customer support, system security, fraud prevention, regulatory compliance, analytics, and service improvement. Data is not processed in a manner incompatible with these purposes.
9. Credit Card and Payment Data Processing
Healing School processes payment-related data in strict compliance with the Payment Card Industry Data Security Standard (PCI DSS). We do not store full credit or debit card numbers, CVV codes, or magnetic stripe data. Payment transactions are handled through PCI-compliant third-party payment processors using encryption, tokenization, and secure transmission protocols.
10. Special Category Data and HIPAA Compliance
Where Healing School processes health or medical data, such data is handled in accordance with HIPAA. Access to PHI is restricted to authorized personnel only and used solely for permitted healthcare operations. Administrative, technical, and physical safeguards are implemented to protect PHI.
11. Third-Party Data Sharing
Personal data may be shared with trusted third parties such as cloud service providers, payment processors, analytics vendors, and legal or regulatory authorities where required. All third parties are subject to contractual obligations ensuring confidentiality, data protection, and compliance with applicable laws.
12. International Data Transfers
Where personal data is transferred outside its country of origin, Healing School ensures appropriate safeguards are in place, including adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms recognized by data protection authorities.
13. Data Retention and Disposal
Personal data is retained only for as long as necessary to fulfill its intended purposes or to meet legal, regulatory, accounting, or reporting obligations. Secure deletion and anonymization procedures are applied when data is no longer required.
14. Data Subject Rights
Data subjects have the right to access, rectify, erase, restrict processing, object to processing, and request data portability. Requests are handled within legally mandated timelines.
15. Security Measures
Healing School employs industry-standard security controls including encryption, access control, multi-factor authentication, network monitoring, audit logging, vulnerability management, and regular security assessments.
16. Data Breach Management and Notification
Healing School maintains incident response procedures to detect, investigate, and remediate personal data breaches. Where required, supervisory authorities and affected individuals will be notified within statutory timeframes.
17. Children's Data Protection
Healing School does not knowingly collect personal data from children without verifiable parental or guardian consent. Additional safeguards are applied where children's data is processed.
18. Automated Decision-Making and Profiling
Where automated decision-making or profiling is used, Healing School ensures transparency and provides data subjects with the right to request human intervention and contest decisions.
19. Governance, Audits, and Training
Healing School maintains internal governance structures, data protection training programs, and periodic audits to ensure ongoing compliance with applicable privacy regulations.
20. Policy Updates and Contact Information
This Policy may be updated periodically to reflect legal or operational changes. For questions, complaints, or data subject requests, please contact Healing School's Data Protection Officer or Privacy Office through official communication channels.
Thank you for trusting Healing Streams. We are committed to protecting your privacy and serving you with integrity.
Back to Top