Privacy Policy

Effective Date: Feb 8, 2025

Summary:

  • We collect personal data (name, email, and optional medication details) to deliver coaching services.

  • We rely on third-party services like Stripe (payments), Calendly (scheduling), Google Meet (virtual sessions), Google Forms (client onboarding), BoldSign (electronic signatures) and Squarespace (analytics).

  • We keep coaching records for up to 5 years to satisfy insurance requirements.

  • You have rights under the GDPR (e.g., access, erasure, objection).

By using our website and services, you agree to the collection and use of your data as outlined in this Privacy Policy.

1. Who We Are

We are with Flow in Mind (“we,” “us,” or “our”), a coaching service provider registered in Ireland. If you have any questions about this Privacy Policy or wish to exercise any of your data protection rights, you can contact adina@withflowinmind.com.

2. Data We Collect

2.1 Personal Data

  • Name and Email Address: Collected when you book coaching sessions or make an enquiry.

  • Medication History (Optional): You may choose to share health-related details if relevant to your coaching goals.

2.2 Payment Information

  • We primarily use Stripe to process online payments and do not store your credit card or banking details on our servers. However, you may also opt to pay by bank transfer. In this case, we may briefly see personal details (e.g., your name and the payment reference) on our bank statements. This information is only used to reconcile payments, fulfil our contractual obligations, and maintain financial records. We do not share these details with any unauthorised third parties.

2.3 Technical & Usage Data

  • Squarespace Analytics: Collects IP addresses, browser types, and browsing behaviour to help us understand how visitors use our website.

3. Purposes & Legal Bases for Processing

Under the EU General Data Protection Regulation (GDPR), we must have a valid legal basis for each type of data processing we undertake. Here’s how we use your data and the relevant legal basis:

3.1 Coaching Services

  • Purpose: To provide you with coaching sessions, schedule appointments, and maintain communication throughout the coaching process. To gather background information, including past coaching experience, to tailor our sessions effectively.

  • Data Processed: Name, email address, optional health/medication information you voluntarily share and other answers to onboarding questions (if applicable).

  • Tools/Services:

    • Calendly for scheduling (see their Privacy Policy).

    • Google Meet for virtual sessions (see their Privacy Policy).

    • Google Forms for client onboarding when conducting more than one session (same policy as above).

  • Legal Basis:

    • Article 6(1)(b) – Performance of a Contract: We need your contact details to perform our coaching services.

    • Article 6(1)(a) – Consent: If we process sensitive data (e.g., medication history), we do so only with your explicit consent, which you provide by choosing to share that information with us.

3.2 Payment Processing

  • Purpose: To process payments for coaching sessions or packages.

  • Data Processed: Payment details (card number, billing address), though these are generally handled directly by Stripe.

  • Tools/Services:

  • Legal Basis:

    • Article 6(1)(b) – Performance of a Contract: Processing your payment is necessary to provide our paid services.

    • Article 6(1)(f) – Legitimate Interests: Maintaining accurate records for financial and administrative purposes.

3.3 Analytics (Squarespace)

  • Purpose: To analyse website traffic and usage patterns, enabling us to improve user experience and site functionality.

  • Data Processed: IP address, browser type, and general browsing behaviour on our site.

  • Tools/Services:

  • Legal Basis:

    • Article 6(1)(f) – Legitimate Interests: We have a legitimate interest in understanding how visitors interact with our site so we can enhance and tailor our services.

3.4 Communication & Enquiries

  • Purpose: To respond to your messages, emails, or any other direct enquiries you send us.

  • Data Processed: Name, email address, and any information you include in your correspondence.

  • Legal Basis:

    • Article 6(1)(b) – Performance of a Contract: Where your enquiry relates to our services or pre-contractual discussions.

    • Article 6(1)(f) – Legitimate Interests: For general queries not directly tied to a service contract, we have a legitimate interest in responding to potential clients or website users.

3.5 Contract Management

  • Purpose: Securely obtaining electronic signatures via BoldSign for coaching agreements.

  • Data Processed: Name, email address, electronic signature.

  • Tools/Services:

  • Legal Basis:

    • Article 6(1)(b) – Performance of a Contract: Collecting these details is necessary to form a legally binding coaching agreement and provide the services you have requested.

3.6 Record-Keeping (5-Year Retention)

  • Purpose: We retain session notes and relevant data for professional insurance requirements (5 years).

  • Data Processed: Coaching session records, including any notes taken during sessions.

  • Tools/Services:

  • Legal Basis:

    • Article 6(1)(f) – Legitimate Interests: Maintaining records is essential to comply with professional insurance obligations and to handle any disputes or issues that may arise.

4. Data Sharing

4.1 Third-Party Processors

  • We use multiple third-party platforms (Stripe, Calendly, Google Meet, BoldSign, Google Docs/Forms, and Squarespace) as outlined above. Each has its own privacy policy.

4.2 ICF Verification

  • If necessary for International Coaching Federation (ICF) credential verification, we may share only your name, contact details, and the dates of our coaching relationship to confirm you are/were a client. We will not share any sensitive notes.

4.3 No Data Selling

  • We do not sell, rent, or trade your personal data.

4.4 Legal Requirements

  • We may disclose personal data if required by law, court order, or governmental regulation.

5. Your GDPR Rights

Under the GDPR, you have several rights regarding your personal data:

  1. Right of Access – You can request a copy of your data.

  2. Right of Rectification – You can ask us to correct inaccurate or incomplete data.

  3. Right to Erasure (‘Right to be Forgotten’) – You can request the deletion of your personal data under certain circumstances.

  4. Right to Restrict Processing – You may ask us to limit how we use your data in certain cases.

  5. Right to Data Portability – You have the right to receive your data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

  6. Right to Object – You can object to processing based on legitimate interests.

  7. Right to Withdraw Consent – If processing is based on your consent, you may withdraw that consent at any time.

If you wish to exercise any of these rights, please contact us at [Your Email]. We will respond within a reasonable timeframe, in accordance with GDPR requirements.

6. Security Measures

We take reasonable precautions to protect your personal data from unauthorised access, alteration, disclosure, or destruction. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. International Transfers

If you access our services from outside the European Economic Area (EEA), your data may be transferred internationally. We ensure appropriate safeguards (such as Standard Contractual Clauses) are in place if data is transferred to third-country service providers.

8. Retention Period

We retain coaching records for up to five (5) years due to our professional insurance obligations (or as otherwise required by law). After this period, or if the data is no longer needed, we securely delete or anonymise your data.

9. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any changes will be posted on this page with an updated “Effective Date.”

10. Contact Us

If you have any questions about this Privacy Policy, or would like to exercise your data protection rights, please contact adina@withflowinmind.com. We will be happy to address any concerns you might have regarding the protection of your personal data.

Cookie Policy

Effective Date: Feb 8, 2025

Summary:

  • We use cookies primarily via Squarespace Analytics to improve user experience and understand website traffic.

  • You can manage or disable cookies in your browser settings.

  • Continuing to browse our site indicates your acceptance of our cookie usage.

1. What Are Cookies?

Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that placed the cookie. They help make your experience on our website more user-friendly and personalised.

2. Types of Cookies We Use

2.1. Essential Cookies: Required for core website functionality (such as security and page navigation). The site cannot function properly without these cookies.
2.2. Analytics Cookies: Squarespace uses these to collect anonymised information about how visitors use our website (pages viewed, time spent, etc.).

3. Managing Cookies

3.1. Browser Controls: You can set your browser to refuse or delete cookies. Please note that disabling certain cookies may affect your user experience and some features of our site may not function as intended.
3.2. Cookie Banner: We display a cookie banner allowing you to opt in or out of certain cookie categories.

4. Third-Party Cookies

Our website may contain links or embedded content from third-party sites (e.g., Instagram, LinkedIn). These sites may also use cookies, for which we are not responsible. Please review the cookie policies of any third-party sites you visit.

5. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. The “Effective Date” at the top indicates when the latest changes were made.

6. Contact Us

For any questions or concerns about our Cookie Policy, please email adina@withflowinmind.com.