Privacy Policy
This Privacy Policy describes how Strainttforceix collects, uses, stores, and protects your personal information when you visit our website or use our services.
Last updated:
1. Introduction and Data Controller
Strainttforceix, located at 675 Ponce De Leon Ave NE, Atlanta, GA 30308, USA, operates the website strainttforceix.world and provides non-medical educational lifestyle workshops. We are the data controller responsible for your personal data collected through this website and our related services.
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) where applicable, and other relevant data protection legislation. This policy applies to all visitors, users, and customers who interact with our website and services.
By using our website or submitting your personal information through our contact forms, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please refrain from using our website or providing your personal data.
2. Personal Data We Collect
We collect personal data that you voluntarily provide to us, as well as certain information automatically collected when you visit our website. The categories of personal data we may collect include:
2.1 Information You Provide Directly
- Full name when you submit our contact form or register for a workshop
- Email address for communication and registration purposes
- Phone number if you choose to provide it during registration or contact
- Message content and inquiry details submitted through our contact form
- Workshop preferences, session dates, and attendance format selections
- Payment information processed through third-party payment processors (we do not store full credit card details on our servers)
- Consent records including timestamps for GDPR compliance documentation
2.2 Information Collected Automatically
- IP address and approximate geographic location derived from IP
- Browser type, version, and operating system information
- Device type and screen resolution
- Pages visited, time spent on pages, and navigation paths
- Referring website or source that directed you to our site
- Cookie identifiers and similar tracking technologies as described in our Cookie Policy
- Date and time of visits and interactions with our website
3. Purpose and Legal Basis for Processing
We process your personal data only for specified, explicit, and legitimate purposes. The legal bases for our processing activities under GDPR include:
3.1 Contractual Necessity
Processing necessary to fulfill our contractual obligations when you register for workshops, purchase educational products, or engage our consulting services. This includes managing your registration, providing session materials, and processing payments.
3.2 Legitimate Interests
Processing necessary for our legitimate business interests, including improving our website and services, analyzing usage patterns, preventing fraud, ensuring network security, and responding to inquiries. We balance these interests against your rights and freedoms.
3.3 Consent
Processing based on your explicit consent, such as sending marketing communications, using non-essential cookies, or processing data for purposes not covered by other legal bases. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
3.4 Legal Obligation
Processing necessary to comply with applicable laws, regulations, court orders, or governmental requests, including tax reporting, accounting requirements, and responding to lawful data subject requests.
4. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
- Responding to your inquiries submitted through our contact form within two business days
- Processing workshop registrations and managing your participation in our programs
- Sending confirmation emails, session reminders, and pre-workshop materials
- Processing payments and issuing receipts for purchased services and products
- Providing customer support and addressing questions about our workshops
- Improving our website functionality, content, and user experience through analytics
- Detecting and preventing fraudulent activity, abuse, and security incidents
- Complying with legal obligations and enforcing our Terms of Use
- Sending promotional communications about workshops and programs when you have opted in
- Maintaining records required for business operations and regulatory compliance
5. Data Sharing and Third-Party Processors
We do not sell your personal data to third parties. We may share your information with trusted service providers who assist us in operating our website and delivering our services, subject to strict data processing agreements:
- Payment processors for secure transaction handling
- Email service providers for transactional and marketing communications
- Website hosting and cloud infrastructure providers
- Analytics service providers for website usage analysis
- Customer relationship management tools for inquiry management
All third-party processors are contractually obligated to process your data only on our instructions, implement appropriate security measures, and comply with applicable data protection laws. We may also disclose personal data when required by law, to protect our legal rights, or in connection with a business transfer such as a merger or acquisition.
6. International Data Transfers
Strainttforceix is based in the United States. If you access our website from the European Economic Area or other regions with data protection laws, your personal data may be transferred to and processed in the United States. We ensure appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission and adequacy decisions where applicable.
7. Data Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law:
- Contact form submissions: retained for 24 months from the date of submission, then securely deleted
- Workshop registration records: retained for 5 years for accounting and legal compliance purposes
- Payment and transaction records: retained for 7 years as required by tax and financial regulations
- Marketing consent records: retained for the duration of consent plus 3 years for compliance documentation
- Website analytics data: retained in aggregated form for 26 months, then anonymized or deleted
- Cookie data: retention periods vary by cookie type as detailed in our Cookie Policy
When personal data is no longer needed, we securely delete or anonymize it using industry-standard methods to prevent unauthorized recovery.
8. Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security practices include:
- HTTPS encryption for all data transmitted between your browser and our servers
- Secure server infrastructure with regular security updates and patches
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security assessments and vulnerability monitoring
- Encrypted storage for sensitive data at rest
- Incident response procedures for detecting and addressing data breaches
- Staff training on data protection practices and privacy obligations
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but commit to notifying affected individuals and relevant authorities of any data breach as required by applicable law.
9. Your Rights Under GDPR and Applicable Laws
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data in certain circumstances
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is consent-based
- Right to Lodge a Complaint: File a complaint with your local data protection authority
To exercise any of these rights, contact us using the details provided in Section 12. We will respond to your request within 30 days, or inform you if an extension is needed. We may need to verify your identity before processing your request.
10. Children's Privacy
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. Parents or guardians who believe their child has provided personal data to us should contact us immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via email or a prominent notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your data.
12. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Strainttforceix
675 Ponce De Leon Ave NE, Atlanta, GA 30308, USA
Email: assist@strainttforceix.world
Phone: +1 404-900-7900
For data protection inquiries specifically, please include "Privacy Request" in your subject line. We aim to respond to all privacy-related communications within 30 days.