Privacy Policy

Version Dated: 20 December 2023

About Us

Nid Ra t/a Nid’s Nidra is a sole proprietorship (“We/Us/Nid”) whose registered office is Unit 2, 8 Eustace Street, Manly, NSW, 2095, Australia operates the websites www.nidsnidra.com,and provide the Services (as defined below). 

Services” means all and parts of the following:

  • Embody the wellbeing live events both in person and online worldwide, workshops, community, membership, online courses, and recordings;

  • Business provide educational information, documentation, videos and live training sessions of foundational business, marketing and legal concepts for entrepreneurs; and 

  • Aroma the candles and essential oils with meditation, affirmations and ritual guidance.

We are committed to providing quality Services to you and this Privacy Policy outlines our ongoing obligations to you in respect of how we manage your Personal Data. 

We are the controller of any personal information gathered by your use of our websites and Services. Our website is a general audience website, intended for users of all ages. Where we use third parties to process your data, these parties are known as processors of your personal data.  We have a contract with these third parties for the provision of these services.

A data ‘controller’ means the individual or organisation which, alone or jointly with others, determines the purposes and means of the processing of personal data.

A data ‘processor’ means the individual or organisation which processes personal data on behalf of the controller.

The Purpose of this Policy

In the course of providing you with our services we will collect and process information that is commonly known as Personal Data. This includes when you may share personal data in contact with us via our website, online forms, email, social media accounts, the telephone, when writing to us directly, in person, or where we provide you with paper based forms for completion or we complete a form with you.

Your personal data is protected by law and we want you to know your individual rights, which include your right to know what data is held about you, how this data is processed and how you can place restrictions on the use of your data.

We provide this Policy to help you understand:

  • what kind of information we collect in connection with our services, 

  • the purposes for which we use the information, 

  • how we may share this information, and 

  • what we do to retain and safeguard your Personal Data.

The laws applied to this Policy:

We have also identified that we have clients across many countries and seek to provide a high standard to care and protect your personal data and privacy. Australia is identified as the named territory where the processing of personal data takes place. 

We adopted and aim to comply with the following laws Privacy Act 1988 (Cth, Australia) and the Australian Privacy Principles (APPs); the Personal Data Protection and Electronic Documents Act, SC 2000, c5 (federal, Canada);  the Personal Data Protection Act (Alberta, Canada);  the Personal Data Protection Act (British Columbia, Canada); all applicable United States federal and state privacy laws, including, but not limited to, the California Online Privacy Protection Act (CalOPPA), Early Learning Personal Data Protection Act (ELPIPA); the General Data Protection Regulations (EU) or (“GDPR”); the Data Protection Act 2018 (UK); Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais) (Law No. 13,709/2018) ("LGPD"), any other applicable privacy legislation (collectively the “Data Acts”).

The Data Acts govern the way that we collect, use, disclose, store, secure and dispose of your Personal Data.

What is ‘Personal Data’?

Personal Data is information or an opinion that identifies a natural person. Examples include an individual’s name, age, address, date of birth, gender and contact details.

Sensitive Data is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

We are legally required to comply with specific data processing requirements for Personal Data.

What data do we collect about you?

All Nid Ra sub-brands will collect and process the following categories of data: 

  • Personal Data such as an individual’s name, address, and contact details, and email address.

  • We do not knowingly accept information or attendance of anyone under the age of 18 years old.

Embody as a provider of wellbeing services, will additionally collect the following categories of data: 

  • Personal data such as date of birth, location of birth, full name, gender, and contact details, and email address.

  • Special categories of personal data such as health and details on historic injuries or illnesses (physical and physiological), audio, video and audio-visual, photographs, beliefs, and aspects of your health that may affect your participation or our provision of services to you. 

Business as an education provider may additionally collect the following categories of data: 

  • Special categories of personal data including: as spiritual, social, religious, beliefs, associations or memberships, and aspects of your social interactions that may affect your participation or our provision of services to you. 

Third Parties

Where reasonable and practicable to do so, we will collect your Personal Data only from you. However, in some circumstances we may be provided with information by third parties. We may use third party suppliers for management of specific services e.g. payment processing, and they may store some of your Personal Data to provide such service to you. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party or that you can access your account to check this information directly yourself.

Links to Other Websites

Our services may include links to third party websites. When you click on this link you have left our website and services. We do not have control over what cookies or beacons or other technology these sites may use to track activity into their website, and do not have control over what data they may collect or their privacy policy. Use of their websites and clicking on those links is at your sole risk. We are not responsible for the protection and privacy of any information that you provide whilst visiting such sites and these sites are not governed by this Privacy Policy. We suggest that you read their privacy statement before using the website. 

We do not provide any personally identifiable customer information to these sites.

Why do we collect your Personal Data?

Personal Data is collected in many ways including interviews, online calls, text message, online chat, correspondence, by telephone, by email, via our website, webinars, events, promotions, campaigns, from our websites, from media and publications, from other publicly available sources, from cookies and from third parties, including but not limited to social media platforms such as Facebook, Instagram, YouTube, and LinkedIn. We don’t guarantee website links or policy of authorised third parties. 

Our primary purpose to collect and process this Personal Data is to provide our services to you and to personalise your experience with us. We may also use your Personal Data for secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use or disclosure. You may unsubscribe from our mailing/marketing lists at any time by contacting us in writing or email as below. 

When we collect Personal Data we will, where appropriate and where possible, explain to you why we are collecting the information and how we plan to use it. By providing this personal data to us you are consenting our use in the manner set out in this Policy.  If you object to the collection, sharing and use of your personal data we may be unable to provide you with our services. 

Sensitive Data will be used by us only:

  • For the primary purpose for which it was obtained,

  • For a secondary purpose that is directly related to the primary purpose,

  • With your consent; or where required or authorised by law.

We do not sell or pass your personal information onto third parties.

Data Management

We use third party software to securely store your data to perform specific functions to support our services (“third party suppliers”). Third party suppliers have access to personal information needed to perform their functions, but may not use it for other purposes. Further, they must process the personal information as permitted by the UK’s implementation of the General Data Protection Regulation 2017 (EU Data Protection Directive 2016/680 ). Their privacy policy is linked within as to how they handle data as part of the service we use. With all of the third party suppliers you can ask us to review your stored data to ensure that it is accurate and best serves you.  

Client Notes

We take and keep notes about our appointments, documents and notes are stored as digital records only and saved in Google Drive. They provide TLS standard encryption to protect your Personal Data and a two-step authentication process. We may keep your records on remote digital devices that are encrypted and password protected. Storage of these files is necessary as a legal requirement by our insurer BMS.  

Bookings

We use Arketa to manage our client bookings and Nid’s App content where you can save favourites . This software requires you to complete the following information for your account: name, contact email and telephone number. You may update the details in Arketa at any time by logging into the account or emailing us. You may be asked questions about your health and birth history depending upon the services that you are engaging. 

Payment Online

If you pay using an online transaction such as credit card we use Stripe and Paypal. These third-party payment facilitators are PCI DSS v 3.2.1 compliant to ensure your financial data is secure and we can never access your full payment details. Arketa stores card information only if you choose and if you make in-app purchases your card details are managed by your mobile phone app software provider (commonly Apple or Google). We do not have access to this information. 

Communications

We use email, SMS texts, Arketa app, and WhatsApp, Signal and Telegram to communicate with you. Emails directly with you are stored in our account with Google unless part of the Service Provision (see below). Any telephone or online calls may be recorded with your permission and stored in your clients records as a digital file. We have followed Google’s security check-list for security on all our files, communications and calendars. 

We provide a ‘manage your emails’ option in all of our Mailchimp marketing emails. You can select your preferences for what to receive and not within each email or at https://www.nidsnidra.com/opt-out 

WhatsApp is a secure end-to-end encrypted service. If you prefer not to communicate using this or SMS texts you may request Telegram app or not to communicate via messenger services. You choose to download Nid’s app and your profile settings in your Arketa account. You can request not to receive by any of these means at any time. 

Service Provision

Embody clients online and Business sessions including group online sessions and webinars are hosted via Zoom. You do not need an account for this, but it will require you to register a name when logging in. 

Your service emails for booking reminders and App notifications are managed in Arketa this includes your free subscription to Nid’s free content, courses, bookings and memberships. If you ‘unsubscribe’ from these emails you cannot receive any service notifications or reminders for your purchases and bookings. Please check your junk folders if you do not receive these and add nid@ nidsnidra.com to your contacts. 

Website

Our website is hosted by Squarespace. While using our website, we may ask you to provide us with certain personally identifiable information that might be collected through our website provider Squarespace. This includes the collection of your unique online electronic identifier; this is commonly known as an IP address, browser type, browser version, the pages of our website that you visit, the time and date of your visit, the time spent on those pages and other statistics. Squarespace uses cookies to provide the website and ensure the necessary function of our services. To learn more about the cookies on our website, please read our Cookie Policy here. 

If you contact us via our website, you may provide us with personal data when completing online health or contact forms. This form is hosted by Squarespace

We use Google Analytics GA4 to give us an idea of where our website traffic data comes from and how people use our website. We link this use to Google Ads which allows us to understand those interested in our services and how we can design adverts that will interest that audience and encourage them to purchase our services. We also use Google Signals that tracks your use across devices and platforms to better target your interests if you have a Google account. Google Analytics may have cookies used to track traffic to and around our website. Google GA4 anonymises your IP address for privacy compliance. See above for how to change your settings in Google. 

You can opt out of seeing personalised ads here. Details on Google Analytics can be found here

Marketing

We may promote our services to you using the information you provide to us, including email, App notifications, WhatsApp or text. If you wish to receive promotional offers please opt in by completing the form on our website, on social media to Nid Ra or by emailing nid@ nidsnidra.com to request to be added.  You can turn off app notifications within your smart phone settings. 

If you opt in to receive our regular monthly email plus occasional extra emails with new launches and announcements to share with you. The content will include: 

  • Embody with wellbeing tips, service updates and offerings, you can choose between monthly or weekly. There are also modality specific emails, e.g. retreat, breathwork or geographically focused emails.

  • Business a ‘work’ related blog and YouTube video. 

Our emails are sent from Mailchimp which stores information that you submit in your forms. You can unsubscribe from this at any time from within one of these emails or contacting us at nid @nidsnidra.com. If you unsubscribe you will not receive service related emails for memberships, communities and online courses. We suggest that you use the ‘manage my email preferences’ option in each email or at https://www.nidsnidra.com/opt-out 

The blog post emails are sent weekly from Mailchimp. You can change your preference to receive these at any time. 

If you follow us on any social media platforms, your privacy settings in your social media account control what you share with others. Please be aware that our settings are to ‘Public’ where you leave reviews, comments and we will tag you where appropriate. Where appropriate, on our retreats and during our services we may take photographs and/ or videos of you and may be used on social media and marketing of our services. Please contact us at any time should you wish to change or amend any posts on social media by us.  

Quotes for Services

If you contact us for a quote or request details on the services we provide, we consider ourselves as having a legitimate business interest to provide you with further information about our products and services. You may request that we stop this at any time with the contact details below.  

Nid’s Nidra Business Development

We will also use your personal data to manage your account, perform statistical analysis on the data we collect, for business forecasting purposes and to develop new and market existing products and services. 

Data Retention/ Disclosure of Information

We may release personal data where we believe that it is appropriate in a number of circumstances, including the following:

  • Third parties where you consent to the use or disclosure;

  • Where required or authorised by law;

  • To enforce or apply our agreements with you;

  • To protect the rights, property or safety of us, our clients or others; and

  • With your consent following specific notice or request from us. 

This includes fraud protection, but not selling, sharing or otherwise disclosing personally identifiable information from clients for commercial purposes in a way that is contrary to this Privacy Policy.

Security of Personal Data

Your Personal Data is stored in a manner that reasonably protects it from misuse and loss and from unauthorized access, modification or disclosure.

When your Personal Data is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify your Personal Data. However, most of the Personal Data is or will be stored in client files which will be kept by us for the Duration Period. 

Duration Period

If you have received Services with us we will store your data for seven (7) years from your last appointment with us (“Duration Period”), as required by our insurers (BMS) for any potential claims.

You may have access to this information stored, but this falls under the circumstances where your Right to Request Erasure may be denied. Please see the ICO guidance on this exception: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/ 

Your Rights

You have legal rights about your personal data. You grant use of your data under the contract and terms herein through your active conduct and use of our services. At any time you have the right to know what personal data relates to you that is held by us, for what purpose, how it is collected and used, with whom it is shared, where it is located, to object to its processing, to have the data corrected if inaccurate, to take copies of the data and to place restrictions on its processing. You can also request the deletion of their personal data.

You may request the following at any time about your data held by us with regards to the services that we provide:

  • The right to be informed about the personal data being processed;

  • The right to rectification of your personal data

  • The right to erasure of your personal data

  • The right to restrict processing of your personal data

  • The right to data portability (to receive an electronic copy of your personal data)

  • The right to object to the processing of your personal data

  • The right to access your personal data

In accordance with the General Data Protection Regulations (“GDPR”), you may request a copy of all data that we store about you at no cost at nid@ nidsnidra.com. In order to protect your Personal Data we may require identification from you before releasing the requested information. Repeated, unfounded or excessive requests may be challenged by us. 

There are some limited circumstances that may limit the information that we can provide to you in a request, for example, public interest, law enforcement, legal and or health related matters. 

Please also bear in mind that we rely on third parties for some of your information in the flow of data. It may take us the full calendar month permitted to provide a full response to your request.  

If you require further information on your Individual Rights or you wish to exercise your Individual Rights, please contact nid @nidsnidra.com

Maintaining the Quality of Your Personal Data

It is important to us that your Personal Data is up to date. We will take reasonable steps to make sure that your Personal Data is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.

International Data Transfers

Our services are available internationally. We control and manage Personal Data in Australia. We may transfer data outside of Australia to our suppliers to provide the service to you.

If you are European, we transfer your data outside the European Economic Area to fulfil our services to you as we are based in Australia. We do so in accordance with this Privacy Policy. 

Where we require consent, your rights and what you are consenting to will be clearly communicated to you. Where you provide consent, you can withdraw this at any time by contacting our Data Privacy Representative at nid@ nidsnidra.com

Such parties are not permitted to use your personal data for any other purpose than for what has been agreed with us. These parties are also required to safeguard your personal data through the use of appropriate technical and organisational data security measures and are prohibited from disclosing or sharing your data with other third parties without our prior authorisation, or unless as required by law. Please contact our data privacy representative for further information on the measures undertaken to safeguard your data.

Data Privacy Representative 

To ensure data privacy and protection has appropriate focus within our organisation we have a Data Privacy Officer who is the sole trader of Nid’s Nidra. 

The Data Privacy Officer is Nid Ra, who may be contacted at: nid@ nidsnidra.com

Policy Updates

We reserve the right to update and amend this Privacy Policy at any time, effective upon posting an updated version on the Website. We will publish such updates on our website and may email notifications to you. Continued use of the Website after any such changes shall constitute your consent to such changes. 

Enquiries and Complaints 

If you have any queries or complaints about our Privacy Policy please contact us at:

Nid Ra

nid@ nidsnidra.com

If you are dissatisfied with how our Data Privacy Officer handles your matter. You have the right to complain to the Office of Australia’s Information Commissioner (OAIC). The OAIC may be contacted via its website which is https://www.oaic.gov.au/ , by live chat or by calling their helpline on +61 1300 363 992.

Version: 20 December 2023

Privacy Policy Query

Please let us know any questions that you have about how we care for your personal information. 

nid@ nidsnidra.com

If you want to use parts or all of this Policy please purchase it from Nid. Contact her for the purchase link.