PRIVACY POLICY

AHA (Awareness Healing Appreciation) Coaching

Effective date: 30 May 2026

At AHA Coaching, your privacy matters deeply to me. As the sole trader responsible for your data, I am committed to handling it with care, transparency, and respect. This Privacy Policy explains how I collect, use, and protect your personal information in line with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

1. Who Controls Your Personal Data?

The data controller, the person responsible for deciding how your personal data is used, is:

Name: Magdalena Rozdzialik (Sole Trader)

Trading as AHA (Awareness, Healing, Appreciation) Coaching

Address: 160 Rosewood, Ballincollig, Co. Cork, Ireland

Email: info@aharecallhealing.eu

Website: www.aharecallhealing.eu

This controller is referred to throughout this policy as "we", "us", or "the Controller".

For details on how social media platforms process your data independently, see Section 8.

2. Why Do We Process Your Personal Data?

2.1 General Principles

We only collect and process data that is necessary for the purpose for which it was gathered. Personal data means any information that can identify you directly or indirectly. The scope of data we process may vary depending on the type of service provided.

2.2 Legal Bases for Processing

Your personal data is processed only where at least one of the following legal bases under Article 6 GDPR applies:

  • Consent (Art. 6(1)(a)): you have given your consent for one or more specific purposes

  • Contract (Art. 6(1)(b)): processing is necessary to perform a contract with you, or to take steps at your request before entering into one

  • Legal obligation (Art. 6(1)(c)): processing is necessary to fulfil a legal obligation placed on us

  • Legitimate interests (Art. 6(1)(f)): processing is necessary for our legitimate interests, except where overridden by your fundamental rights and freedoms. Where we rely on this basis, we have assessed that our interests are not overridden by your rights.

For special category data (such as health information), we rely on your explicit consent under Article 9(2)(a) GDPR.

2.3 Specific Purposes and Legal Bases:

  • Booking and delivering 1:1 consultations (Art. 6(1)(b))

    When you book a consultation, you provide the information necessary to arrange and deliver that service: your name, email address, and scheduling details. Sessions are conducted via Zoom or Google Meet. We take written notes during or after sessions, stored both digitally and in physical form, used solely to support your consultations and progress.

    WhatsApp (Meta Platforms) may be used for brief administrative queries only, not for conducting sessions or sharing consultation notes. When WhatsApp is used, Meta processes certain technical data, including your phone number and message metadata, under their own privacy policy.

  • Processing sensitive personal data shared during consultations (Art. 9(2)(a))

    You may share sensitive personal information during consultations, including details relating to your physical or mental health, emotional wellbeing, or personal circumstances. This is classified as special category data under GDPR and is processed only on the basis of your explicit consent, obtained before your first session via a signed intake form or consent checkbox. You may withdraw consent at any time, though this may affect our ability to continue providing services. This data is stored securely, accessed only by the Controller, and retained only as long as necessary.

  • Appointment scheduling via Jotform and Calendly (Art. 6(1)(b))

    When you book a session or complete an intake form, you provide personal data necessary to arrange your appointment and prepare for your session. This includes your name, email address, preferred date and time, and any information you include in intake forms. This data is processed by Jotform (Jotform Inc., USA) and Calendly (Calendly LLC, USA) on our behalf solely for the purpose of managing bookings, intake, and sending appointment confirmations and reminders. Data transfers outside the EEA are governed by Standard Contractual Clauses. See Section 9 for further details.

  • Handling your enquiries and correspondence (Art. 6(1)(f))

    When you contact us by email or any other available means, you naturally share personal data contained in your message. Processing this data to respond to your enquiry is in our legitimate interest.

  • Processing orders for digital products (Art. 6(1)(b), Art. 6(1)(f))

    When you purchase a digital product such as a workbook, ebook, workshop, or course, you provide data necessary to process your order, including your name, email address, and payment information. Your IP address may also be recorded by the order processing system. Order details are stored in our records and passed to our accounting documentation for tax compliance purposes.

  • User account on our course platform (Art. 6(1)(b))

    Where you purchase an online course, an account may be created for you on our course platform using the data you provided at the time of purchase. Upon deletion of your account, your data is archived for the purpose of establishing, pursuing, or defending any claims related to the account service.

  • Newsletter (Art. 6(1)(a), Art. 6(1)(f))

    If you subscribe to our newsletter, you provide the data necessary to receive it. Our mailing system may also record your IP address, approximate location, email client, and interactions with our emails such as opens and link clicks. This is used to deliver the newsletter and optimise our communications, which is our legitimate interest. You may unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us directly.

  • Blog comments (Art. 6(1)(f))

    When you leave a comment, you provide the data necessary for its publication. Our system may also record your IP address. Your comment and any publicly visible profile information will appear on the site. You may edit or delete your comment at any time. We rely on our legitimate interest in operating an interactive website.

  • Social media (Art. 6(1)(f))

    If you follow our profiles or interact with our content on Facebook, Instagram, or YouTube, we may see personal data publicly available on your profile. We process this data only within the relevant platform, solely for the purpose of managing our social media presence, which is our legitimate interest. If you contact us via private message, your data is processed to respond to you.

  • Competitions (Art. 6(1)(b), Art. 6(1)(f))

    From time to time we may run competitions. If you participate, we will process your name, email address, and any other details necessary to administer the competition. The specific data collected will be outlined in the terms and conditions of each competition.

  • Tax and accounting obligations (Art. 6(1)(c))

    In connection with the performance of contracts, we fulfil various tax and accounting obligations, including issuing invoices and maintaining accounting records. For this purpose, we process data including your name, address, and other details required by Irish tax law. Providing this data is a legal requirement.

  • Website analytics via Google Analytics 4 (Art. 6(1)(a))

    When you visit our website, Google Analytics 4 may collect certain technical data, including your anonymised IP address, browser type, device information, pages visited, and time spent on the site. This is used solely to help us understand how our website is used and to improve its content. This processing takes place only where you have given consent via our cookie banner. You may withdraw consent at any time by adjusting your cookie preferences. No analytics data is collected from visitors who decline analytics cookies.

  • Fulfilling data protection obligations (Art. 6(1)(c), Art. 6(1)(f))

    As a data controller, we are required to fulfil obligations under GDPR and the Irish Data Protection Act 2018. We may process your personal data where necessary to fulfil these obligations, for example when responding to a request relating to your data rights. We also rely on our legitimate interest in maintaining records to demonstrate accountability and legal compliance.

You can withdraw consent as described in Section 10. If we decide to process your personal data for a purpose other than that for which it was originally collected, we will inform you and request your consent where required by law.

3. How Can You Contact Us?

As a sole trader, we are not required to appoint a Data Protection Officer under GDPR and have chosen not to do so. We nonetheless take our data protection responsibilities seriously, particularly regarding the sensitive personal information that may be shared during consultations.

For any questions or concerns relating to your personal data or privacy, please contact us at:

Email: info@aharecallhealing.eu

In relation to our social media profiles, you may also contact the relevant platform directly. Their contact details and privacy policies can be found on their respective websites.

4. What Personal Data Do We Hold?

The following categories of data may be held about you, depending on your interaction with us:

4.1 General Data

  • Identity Data: your name and title

  • Contact Data: email address, phone number, and postal address

  • Financial Data: payment details processed securely via third-party payment providers; name and address to which we issue a sales document

  • Transaction Data: details of services purchased, digital products ordered, or payments made

  • Technical Data: IP address, browser type, device information, and usage data collected when you visit our website

  • Profile Data: account details where applicable, purchases and orders, preferences, feedback, and areas of interest

  • Usage Data: information about how you use our website and services

  • Marketing and Communications Data: your preferences regarding marketing communications

  • Consultation Notes: written notes taken during or after your 1:1 sessions, stored both digitally and in physical form, used solely to support the delivery of your consultations

  • Intake Form Data: information you provide through Jotform prior to your sessions, including health history and personal circumstances relevant to your coaching

  • Correspondence Data: information contained in emails, messages, or any other communications you send to us

  • Social Media Data: information publicly visible on your social media profiles when you interact with our accounts

  • Anonymous Data: data that cannot be used to identify you, such as aggregated website statistics

4.2 Children and Young People

  • Our services are available to clients aged 16 and over. Clients aged 16 or 17 are considered minors under Irish law. Before any sessions can take place with a client in this age group, written consent from at least one parent or legal guardian is required. Parental or guardian consent is also required for any processing of their personal data, in accordance with GDPR Article 8 and the Irish Data Protection Act 2018.

  • We do not knowingly provide services to anyone under the age of 16 and do not intentionally collect personal data from children under 16. If we become aware that personal data has been collected from a child under 16 without appropriate parental consent, we will delete that data promptly.

  • Adult clients may voluntarily share limited information relating to their children or other family members during consultations where relevant. Any such information is treated confidentially and processed only where necessary in connection with the delivery of our services.

4.3 Special Category and Sensitive Data

Where necessary for the provision of coaching and wellbeing services, we may process special category data, including health and wellbeing information shared during consultations or in related communications. Such data are:

  • Collected only when strictly necessary for the delivery of your sessions

  • Collected through a signed intake form or affirmative consent checkbox prior to the first consultation

  • Handled with the utmost confidentiality

  • Processed on the basis of your explicit consent under Article 9(2)(a) GDPR

  • Accessible only to the Controller

4.4 We do not collect

  • Information relating to race or ethnicity, religious or philosophical beliefs, sexual orientation, political opinions, trade union membership, biometric data, or criminal convictions or offences.

5. How Did We Obtain Your Personal Data?
  • Direct Interactions – In most cases you provide your personal data to us directly when making a booking, purchasing a product, completing an intake form, filling in a contact form, attending a consultation, subscribing to our newsletter, or communicating with us.

  • Automated Technologies – Some information may be collected automatically through cookies, server logs, and analytics tools when you visit our website. See Section 11 for details.

  • Third Parties – In some cases we may receive your personal data from third parties, including payment providers, booking and intake systems, and analytics services, as well as from publicly available sources where lawful

6. How Do We Keep Your Data Safe?

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access. These measures include:

  • Access controls and confidentiality obligations for anyone who handles your data

  • Secure and encrypted storage systems

  • Physical notes taken during sessions are stored in a locked cabinet accessible only to the Controller; once transferred to digital format, physical copies are destroyed

  • HTTPS encryption to protect data transmitted between your browser and our website

  • Regular backups and security updates

  • Breach detection and response procedures

No method of transmission over the internet or electronic storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Irish Data Protection Commission without undue delay and, where required, we will notify you directly.

7. How Long Do We Keep Your Data?

We process your personal data only for as long as necessary for the purpose for which it was collected. The end of processing for one purpose does not necessarily result in deletion, as the same data may be processed for another purpose with its own retention period. Complete deletion occurs when we have fulfilled all purposes or in other circumstances required by GDPR.

The following retention periods apply:

Where data is no longer required for its original purpose, it may be anonymised and retained for statistical or research purposes rather than deleted. You can withdraw consent as described in Section 10.

8. Who Has Access to Your Personal Data?

We do not share your personal data with third parties except where necessary to deliver our services, fulfil our legal obligations, and comply with applicable law. All third parties are required to respect the security and confidentiality of your data at all times.

We share your data only with the following groups:

8.1 Data Processors

External service providers engaged by us to carry out specific tasks on our behalf. All processors are bound by a data processing agreement and are required to process your data only in accordance with our instructions and in full compliance with GDPR.

8.2 Regulatory and Legal Recipients

Regulatory authorities, law enforcement bodies, or other organisations to whom we are legally required to disclose your data.

8.3 Professional Advisors

Where necessary, a solicitor or legal advisor bound by professional confidentiality may access your data. This would only occur where legal assistance requires it.

We currently operate as a sole trader and work alone. Should we engage any contractors or collaborators in the future, they will only be granted access to your personal data where strictly necessary to carry out their duties and will be bound by appropriate confidentiality and data protection obligations.

8.4 Our Third-Party Service Providers:

  • Website, appointment scheduling, email, course platform, and invoicing: Systeme.io (Systeme.io SAS, France). As a French company operating within the EU, Systeme.io is subject to GDPR.

  • Intake forms: Jotform (Jotform Inc., USA). We use Jotform to collect intake and consent information prior to sessions. Data transfers outside the EEA are governed by Standard Contractual Clauses. See Section 9.

  • Payment processing: We use the following providers and do not store card details ourselves:

    Stripe (Stripe Payments Europe Limited, Ireland)

    PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg)

    Revolut (Revolut Bank UAB, Lithuania) - used for direct bank transfers. When you make a payment via bank transfer, Revolut processes your name and transaction details in accordance with their own privacy policy. We do not store your bank account details.

  • Appointment scheduling: Calendly (Calendly LLC, USA). Used solely for managing bookings and sending confirmations and reminders. Data transfers outside the EEA are governed by Standard Contractual Clauses. See Section 9.

  • Video consultations: Zoom (Zoom Video Communications, USA) and Google Meet (Google LLC, USA). WhatsApp (Meta Platforms, USA) may also be used optionally for brief administrative calls. All three involve data transfers outside the EEA governed by Standard Contractual Clauses. See Section 9.

  • Document and note storage: Google Drive (Google LLC, USA). Used to store digital consultation notes and documents. Data transfers outside the EEA are governed by Standard Contractual Clauses. See Section 9.

  • Website analytics: Google Analytics 4 (Google LLC, USA). Used to analyse website traffic and improve our services. Processing takes place only where you have given consent via our cookie banner. Data transfers outside the EEA are governed by Standard Contractual Clauses. See Section 9.

  • Irish Revenue and tax authorities: your personal data may be shared with the Irish Revenue Commissioners where necessary to fulfil our tax and accounting obligations.

  • Law enforcement and public authorities: Where required by law, your personal data may be disclosed to bodies such as An Garda Síochána, courts, or other public authorities entitled to access personal data under Irish or EU law.

  • Social media platforms (Facebook, Instagram, and YouTube): when you interact with our profiles or contact us via social media, those platforms may process your personal data independently as separate controllers. Processing by these platforms is governed by their own privacy policies.

9. Do We Transfer Data Outside the EEA?

Some of the third-party services we use involve the transfer of your personal data to countries outside the European Economic Area (EEA), specifically to the United States of America. In each case, appropriate safeguards are in place to ensure your data receives a level of protection equivalent to that required under GDPR. We minimise the scope of data transferred outside the EEA to what is strictly necessary.

The legal transfer mechanisms we rely on are:

  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • EU–US Data Privacy Framework (DPF), where applicable

The services involving international data transfers are as follows:

Clients are encouraged not to share sensitive health or personal information through WhatsApp messages. For more information about the safeguards applied by each provider, please refer to their respective privacy policies.

10. What Are Your Rights?

Under GDPR and the Irish Data Protection Act 2018, you have the following rights in relation to your personal data:

  • Right to information (Art. 12–13) You have the right to be informed about how your personal data is collected and used. This Privacy Policy fulfils that obligation.

  • Right of access (Art. 15) You have the right to obtain confirmation of whether we process your personal data and to receive a copy, along with information about how and why it is being processed.

  • Right to rectification (Art. 16) You have the right to request that we correct any inaccurate personal data and have incomplete data completed.

  • Right to erasure (Art. 17) You have the right to request that we delete your personal data, for example, where it is no longer necessary for the purpose it was collected, where you have withdrawn your consent, or where we have been processing your data unlawfully.

  • Right to restriction of processing (Art. 18) You have the right to request that we restrict the processing of your personal data to storage only, for example, where you believe the data we hold is inaccurate.

  • Right to data portability (Art. 20) Where processing is based on your consent or a contract, you have the right to receive the personal data you have provided in a structured, commonly used, and machine-readable format.

  • Right to object (Art. 21(1)) You have the right to object to processing where we rely on legitimate interests as our legal basis. We will stop processing your data unless we can demonstrate compelling legitimate grounds that override your rights.

  • Right to object to direct marketing (Art. 21(2)–(3)) You have an unconditional right to object to processing for direct marketing purposes at any time, without justification. Once we receive your objection, we will immediately stop processing your data for marketing purposes.

  • Right to withdraw consent Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Please note that these rights are not absolute and may not apply in all circumstances. The detailed rules governing these rights are set out in Articles 15 to 21 of the GDPR.

To exercise any of the above rights, please contact us at info@aharecallhealing.eu. We will respond within one month. In complex cases we may extend this by a further two months, in which case we will notify you within the first month and explain the reason for the delay.

Right to complain – Regardless of any other consideration, you always have the right to lodge a complaint with the Irish Data Protection Commission (DPC) if you believe your personal data has been processed unlawfully: DPC Website: www.dataprotection.ie

11. Cookie Policy

11.1 What Cookies Are

Cookies are small text files stored on your device when you visit our website. They help the website work properly and allow us to understand how people use it. Some cookies are removed when you close your browser (session cookies). Others stay on your device for longer so the website can remember your settings (persistent cookies).

11.2 Why We Use Cookies

We use cookies for three main reasons: to make the website function correctly (newsletter forms, shopping basket, etc.); to measure how the website is used (analytics); and to improve our content and services. We do not use cookies to sell your personal data.

Under Irish law (SI 336 of 2011), we are required to obtain your consent before placing any non-essential cookies on your device.

11.3 Types of Cookies We Use

  • Strictly necessary cookies: required for the website to work, including page navigation, forms, and basic functionality. These cannot be disabled.

  • Analytics cookies: help us understand how visitors use the website (pages visited, time on site, etc.). We use Google Analytics 4 for this purpose. These are only set where you have given consent.

  • Marketing cookies: we do not currently use marketing or advertising cookies.

11.4 Cookie List

We recommend auditing your live site periodically to verify that the cookie list remains complete and up to date.

11.5 Your Choices

When you first visit our website, you can choose which cookies you allow (except strictly necessary cookies, which are always active). You can change or withdraw your consent at any time through your browser settings or the cookie settings on our website.

11.6 More Information

If you would like to learn more about cookies in general, you can visit www.aboutcookies.org.

12. Do We Show You Targeted Advertising?

We do not use targeted advertising cookies, behavioural advertising, or retargeting technologies on our website. We do not display personalised ads based on your browsing behaviour, and we do not use advertising tracking tools such as the Meta Pixel or Google Ads remarketing.

Our marketing activity is limited to direct communication with people who have chosen to receive it, such as email newsletters and service updates.

If we introduce online advertising in the future, this Privacy Policy will be updated accordingly before any such advertising begins, and we will obtain appropriate consent through our cookie settings.

13. Do We Make Automated Decisions About You?

We do not make any decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you.

We do use basic automated tools as part of running our business. For example, our platform (Systeme.io) may automatically tag or segment you based on actions you take, such as purchasing a product, opening an email, or signing up for a specific service. This helps us send you more relevant communications.

This type of processing does not assess your character, predict your behaviour in any significant way, or affect your access to our services. It is purely organisational and used only to improve your experience.

14. How Can You Manage Your Privacy?
  • Email Communications

    Every marketing email we send includes an unsubscribe link. You can opt out at any time by clicking that link or by contacting us at info@aharecallhealing.eu. Unsubscribing from marketing does not affect communications related to a service you have purchased (e.g. confirmation emails, course access).

  • Cookies and Website Tracking

    You can manage or withdraw your cookie consent at any time using the cookie settings on our website. You can also control cookies through your browser settings — most browsers allow you to block or delete cookies. Please note that disabling certain cookies may affect how our website functions.

  • Your Data Rights

    Under Irish and EU data protection law, you have the right to access, correct, delete, or restrict the processing of your personal data, as well as the right to object to certain types of processing. See Section 10 for a full explanation of your rights and how to exercise them.

15. Anything Else You Should Know?

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to read their privacy policies before providing any personal data.

We do not sell your personal data to third parties under any circumstances.

If you have any concerns about how we handle your personal data, please contact us in the first instance at info@aharecallhealing.eu. We will do our best to resolve any issue promptly and fairly.

16. How Do We Update This Policy?

We may update this Privacy Policy from time to time. If we make any significant changes, we will notify you by email. To the extent permitted by applicable law, your continued use of our services following such notification constitutes your acceptance of the updated policy.

We encourage you to review this policy periodically. Previous versions are also available for your reference on our website.

17. Final Provisions

This Privacy Policy is governed by and construed in accordance with the laws of Ireland and the General Data Protection Regulation (GDPR).

This policy is reviewed on an ongoing basis to ensure it remains accurate and up to date.

Current version adopted: 30 May 2026

Last reviewed: June 2026