Privacy policy.

www.bodhibydesign.com Privacy Policy

Type of website: Wellness Practice
Effective date: 29th day of July, 2024

This Privacy Policy includes important information about your personal data, and we encourage you to read it carefully.

This Privacy Policy describes the personal data we collect, how we use it, and share it along with details on how you can reach us on privacy-related issues.   In this Policy, “Bodhi By Design”, “we”, “our,” or “us” refers to Bodhi By Design, LLC, responsible for the collection, use and handling of your personal data as related in this document.

www.bodhibydesign.com (the "Site") is owned and operated by Bodhi By Design, LLC and can be contacted at:

hello@bodhibydesign.com
(571) 210-2011
________________________________________

Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:

  1. The personal data we will collect;

  2. Use of collected data;

  3. Who has access to the data collected;

  4. The rights of Site users; and

  5. The Site's cookie policy.

This Privacy Policy applies in addition to the Terms and Conditions of our Site.

GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.

Consent
By using our Site users agree that they consent to:

  1. The conditions set out in this Privacy Policy.

When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.

You can withdraw your consent by: Unsubscribing from newsletters and contacting the site admin to close user accounts.

Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.

We rely on the following legal bases to collect and process the personal data of users in the EU:

  1. Users have provided their consent to the processing of their data for one or more specific purposes; and

  2. Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the personal data necessary to perform a contract the consequences are that the user is ineligible for: 

    • Scheduling appointments and services 

    • Pre-payment of service and recurring appointments 

    • Site memberships and user accounts  

    • Communication through newsletters and contact forms.

Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.

Data Collected Automatically
This website is hosted by Squarespace. Squarespace collects personal data When you visit and use our Site, and may automatically collect and store the following information:

  1. IP address;

  2. Hardware and software details;

  3. Clicked links;

  4. Content viewed; and

  5. Content viewed before entering the site.

Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:

  1. First and last name;

  2. Email address;

  3. Phone number;

  4. Payment information;

  5. Auto fill data; 

  6. Details relating to your appointment (for example, who referred you); and

  7. Appointment Intake Information.

This data may be collected using the following methods:

  1. Booking and paying for services;

  2. Setting up a user account; 

  3. Subscribing to the newsletter or member site; and

  4. Filling out a Contact Form.

How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect automatically is used for the following purposes:

  1. Squarespace needs the data to run this website, and to protect and improve its platform and services. Squarespace analyzes the data in a depersonalized form.  You can read their privacy policy at https://www.squarespace.com/privacy.

  2. We share this information with Squarespace, our scheduling service provider, so that they can provide online booking services to us.

  3. Our payment processor(s), Stripe, will also collect payment information from you. You can read their privacy policy at https://stripe.com/privacy.  We collect personal information to improve our checkout experience and customer service.

  4. We share your contact information with Squarespace, our email marketing provider, so they can send these emails on our behalf.  Your contact information is cached on Squarespace and not stored anywhere else (Google or other external service).

  5. When you submit information to this website via webform (Contact Form), we collect the data requested in the webform in order to track and respond to your submissions. Your form submission is through  Zoho, our business email provider, for our response.  Your contact information is not stored (i.e. Zoho, Google Drive or other external storage service).

  6. This website serves font files from and renders fonts using Google Fonts and Adobe Fonts. To properly display this site to you, these third parties may receive personal information about you.

The data we collect when the user performs certain functions may be used for the following purposes:

  1. Booking an appointment;

  2. Intake and consent forms;

  3. Creating user accounts; 

  4. Processing payment, including vaulting credit card information for future use when booking recurring appointments; and

  5. Client communications, including Contact Forms and Email Campaigns.

Who We Share Personal Data With
Employees
We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties
We may share user data with the following third parties:

  1. Facebook; and

  2. Instagram.

We may share the following user data with third parties:

  1. Information about your browser, network and device;

  2. Details about the web page or content you shared or proposed to share; and

  3. Your IP address.

We may share user data with these third parties for the following purposes:

  1. Social media links clicked while using the site which enable you to share pages or other content from this site.

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Your information is not sold for third-party marketing (see below), nor does this Site use ads.

Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:

  1. If the law requires it;

  2. If it is required for any legal proceeding;

  3. To prove or protect our legal rights; and

  4. To buyers or potential buyers of this company in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved.

You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data
In order to protect your security, Squarespace website traffic is encrypted via SSL providing a secure end-to-end connection to site visitors. SSL prevents hackers from impersonating our website or stealing information that customers submit, like an email address or a credit card number. All domains connected to Squarespace are automatically protected with free SSL certificates.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

International Data Transfers
Squarespace transfers user personal data to the following countries:

  1. United States.

When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.

If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:

  1. The country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or

  2. We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.

Your Rights as a User
Under the GDPR, you have the following rights:

  1. Right to be informed;

  2. Right of access;

  3. Right to rectification;

  4. Right to erasure;

  5. Right to restrict processing;

  6. Right to data portability; and

  7. Right to object.

Children
We do not knowingly collect or use personal data from children under 18 years of age. If we learn that we have collected personal data from a child under 18 years of age, the personal data will be deleted as soon as possible. If a child under 18 years of age has provided us with personal data their parent or guardian may contact our privacy officer.

How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here:
hello@bodhiby design.com

Do Not Track Notice

Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.

How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:

  1. You can opt-out of the use of your personal data for marketing emails. You can opt-out by clicking "unsubscribe" on the bottom of any marketing email.

  2. You can close down your user account for booking recurring appointments. You can opt-out by contacting the site admin to close your account.

  3. You can continue to opt out of analytic and performance cookies unless you accept them on the cookies banner. 

Cookie Policy
A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our Site:

  1. Functional cookies
    Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits;

  2. Analytical cookies
    Analytical cookies allow Squarespace to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc;

  3. Security cookies
    Prevent fraudulent use of login credentials; and

  4. Third-Party Cookies
    Third-party cookies are created by a website other than ours. We may use third-party cookies to achieve the following purposes:

    1. Help users sign into their services from Squarespace services.

Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. Bodhi By Design, LLC is a US-based business under the privacy laws of the Commonwealth of Virginia, and with no operations outside of the United States.  Therefore, if you are an EU member, you may lodge a complaint with the supervisory authority of your country of residence.  For complaints regarding Squarespace’s privacy policies, see section 7 of their Privacy Policy.

Contact Information
If you have any questions, concerns or complaints, you can contact us at:

hello@bodhibydesign.com