Tapping Oasis Privacy Policy

                                                                

                                                  Effective date: 31 March 2020

 

We respect your right to privacy. Please read this privacy policy carefully because it explains in detail how we collect, use and disclose your personal data, and what choices you have with respect to your personal data.


 

1. GENERAL INFORMATION

2. TYPES AND PURPOSES OF PERSONAL DATA

3. NON-PERSONAL DATA

4. MARKETING COMMUNICATION

5. HOW LONG DO WE KEEP YOUR DATA?

6. HOW DO WE SHARE AND DISCLOSE DATA?

7. INTERNATIONAL TRANSFERS OF PERSONAL DATA

8. PROTECTION OF PERSONAL DATA

9. YOUR RIGHTS REGARDING PERSONAL DATA

10. TERM, TERMINATION, AND AMENDMENTS

11. CONTACT US

 

1. GENERAL INFORMATION

In this section, we provide you with general information about the entity that is responsible for your personal data, this privacy policy, and Tapping Oasis.

 

1.1 About the Privacy Policy. This Tapping Oasis Privacy Policy (the “Privacy Policy”) governs the processing of personal data collected from individual users (the “user”, “you” and “your”) through the website http://www.tappingoasis.com and the related services (collectively, “Tapping Oasis”). This Privacy Policy does not apply to any third-party applications or software that integrate with Tapping Oasis or any other third-party products, services or businesses.

1.2 Data controller. The company that is responsible for the processing of your personal data through Tapping Oasis is ‘Tapping Oasis’ having a business address at Carrer d´Arago 643, 7 – 9, 08026 Barcelona, Spain (“we”, “us”, and “our”). We act as a data controller with regard to your personal data collected through Tapping Oasis.

1.3 What is Tapping Oasis? Tapping Oasis features information about EFT tapping services (i.e., a combination of ancient Chinese acupressure and modern psychology) provided by a certified EFT practitioner Nicole Herrle and allows booking online EFT tapping sessions.

1.4 Your consent to the Privacy Policy. Before you submit any personal data through Tapping Oasis, you are encouraged to read this Privacy Policy that is always available on Tapping Oasis. In some cases, we may seek to obtain your consent for the processing of your personal data. For example, we may seek your prior consent in the following instances:

    • If we intend to collect other types of personal data that are not mentioned in this Privacy Policy;

    • If we intend to use your personal data for purposes that are not indicated in this Privacy Policy;

    • If we would like to disclose or transfer your personal data to third parties that are not specified in this Privacy Policy; or

    • If we significantly amend this Privacy Policy.

1.5 Children. Tapping Oasis should not be accessed and used by persons under the age of 18. Therefore, we do not knowingly collect personal data of persons under the age of 18.

1.6 Cookies. To ensure the best possible user experience, we use cookies on Tapping Oasis. For detailed information about our cookies, please refer to our cookie policy available at https://www.tappingoasis.com/cookie-policy.

 

2. TYPES AND PURPOSES OF PERSONAL DATA

We collect only a minimal amount of personal data that is necessary for ensuring your proper use of Tapping Oasis. We use your personal data for specified and limited purposes. In this section, we explain what personal data we collect from you, for what purposes we use that data, and on what lawful bases we rely when processing personal data.

 

2.1 Types of personal data. We comply with data minimisation principles. Thus, we collect only a minimal amount of personal data that is necessary for your use of Tapping Oasis. The list of the types of personal data that we collect from you is provided in section 2.3 below.

2.2 Purposes of personal data. We process your personal data only for specified and legitimate purposes explicitly mentioned in this Privacy Policy. In short, we will use personal data only for the purposes of enabling you to use Tapping Oasis, booking your appointments, providing the requested services, maintaining and improving Tapping Oasis, conducting research about our business activities, and replying to your enquiries. We will not use your personal data for any purposes that are different from the purposes for which your personal data was provided.

2.3 Overview of types and purposes of your personal data. The list below provides a detailed description of the types of personal data that we collect, the purposes for which we use it, and the legal bases on which we rely when processing your personal data.

    • When you register a user account, we collect your (i) first name, (ii) last name, (iii) email address and (iv) password. If you choose to login by using your Facebook or Google account, we will have access to the personal data that you allow Facebook or Google to share with us (e.g., your full name, email address, and profile photo). We use such data only for registering and maintaining your user account and providing you with the requested services (e.g., schedule an appointment and send you updates regarding your appointments). The legal basis on which we rely is ‘performing a contract with you’.

    • When you update your user account, we collect your (i) first name, (ii) last name, (iii) email address, and (iv) phone number. We use such data only for updating your user account, contacting you, if necessary, and maintaining our business records. The legal bases on which we rely are ‘performing a contract with you’, ‘pursuing our legitimate business interests’ (i.e., to administer our business), and ‘your consent’ (for optional personal data).

    • When you book an appointment, we collect your (i) first name, (ii) last name, (iii) billing address, (iv) phone number (optional) and (v) birth date (optional). We use such data to schedule your appointment and provide you with the requested services. The legal bases on which we rely are ‘performing a contract with you’ and ‘your consent’ (for optional personal data).

    • When you contact us by email, we collect your (i) name, (ii) email address, and (iii) any information that you decide to provide in your message. We use such data to respond to your enquiries and provide you with the requested information. The legal bases on which we rely are ‘pursuing our legitimate business interests’ (i.e., to grow and promote our business) and ‘your consent’ (for optional personal data).

    • When you make a payment, we collect your PayPal information (if you choose to pay through PayPal) or, if you choose to pay by a credit card, your (i) credit card number, (ii) credit card expiration date, (iii) CVV code, (iv) cardholder’s name, (v) email address, and (vi) PayPal details. Such data is used only for processing your payments and maintaining our accountancy records. Please note that all payments are processed by our third-party payment processors and we will not have access to all of your payment information. The legal bases on which we rely are ‘performing a contract with you’, ’pursuing our legitimate business interests’ (i.e., to administer our business), and ‘complying with our legal obligations’.

    • When you browse Tapping Oasis, we collect your IP address and cookie-related data. We will use your IP address for analytics purposes. We will not be able to identify you in any manner. The legal basis on which we rely is ‘pursuing our legitimate business interests’ (i.e., to analyse and improve our business activities) and ‘your consent’ (for cookie-related data).

2.4 Additional data. From time to time, we may receive certain additional data if you participate in a focus group, contest, activity or event, request support, interact with our social media accounts, submit your feedback and reviews or otherwise communicate with us. Please note that the provision of such data is optional and you may choose what personal data you would like to share with us. We kindly request you to exercise your due diligence when making your personal data publicly available. We will use such personal data to reply to you, provide you with the requested services, or for pursuing our legitimate business interests (i.e., to analyse and improve our business).

2.5 Sensitive data. When you use Tapping Oasis, we do not collect special categories of personal data (“sensitive data”) from you, such as your health information, opinion about your religious and political beliefs, racial origins, membership of a professional or trade association, or information about your sexual orientation, unless you decide to provide such sensitive data, at your own sole discretion, during the individual sessions. Please note that the provision of sensitive data is optional and you may choose what sensitive data you would like to share during your sessions. Your sensitive data will be kept in strict confidentiality and used only for the sole purpose of providing you with the requested services. The legal bases on which we rely are ‘your consent’ and ‘performing a contract with you’.

2.6 Failure to provide personal data. If you fail to provide us with the personal data when requested, we may not be able to perform the requested operation and you may not be able to use the full functionality of Tapping Oasis, receive the services provided through Tapping Oasis, or get our response.

2.7 Privacy of communication. When you use Tapping Oasis for facilitating your individual EFT tapping sessions, you communicate directly with us. We put reasonable efforts to ensure that any communication data transmitted through Tapping Oasis remains confidential and properly protected. Moreover, we do not intentionally and directly access, manage, correct, delete, share, or disclose your communication, unless it is strictly necessary for provision of EFT tapping sessions, enforcement of our terms and conditions, or we are requested by law enforcement agencies to do so.

 

3. NON-PERSONAL DATA

When you use Tapping Oasis, we collect some technical data about your device and visits. In this section, we inform you what non-personal data we collect from you and for what purposes we use that data.

 

3.1 What non-personal data do we collect? When you use Tapping Oasis, we automatically collect certain technical non-personal data about your use of Tapping Oasis for analytics purposes. Please note that de-identified personal data is also considered to be non-personal data. Although such non-personal data allows us to analyse your use of Tapping Oasis, it does not allow us to identify you. The non-personal data collected by us includes the following information:

  • The type of device that you use;

  • Operating system that you use;

  • The browser that you use;

  • Your log files;

  • URL address clicked from Tapping Oasis;

  • Your country; and

  • Your other online behaviour data.

3.2 Your feedback. If you contact us, we may keep records of any questions, complaints, recommendations, or compliments made by you and the response, if any. Where possible, we will de-identify your personal data.

3.3 How do we use non-personal data? We will use non-personal data for the following purposes:

    • To analyse what kind of users visit and use Tapping Oasis;

    • To examine the relevance, popularity, and engagement rate of the content available on Tapping Oasis;

    • To investigate and help prevent security issues and abuse;

    • To develop and provide additional features to Tapping Oasis; and

    • To personalise Tapping Oasis for your specific needs.

3.4 Aggregated and de-identified data. In case your non-personal data is combined with certain elements of your personal data in a way that allows us to identify you, we will handle such aggregated data as personal data. If your personal data is aggregated or de-identified in a way that it can no longer be associated with an identified or identifiable natural person, it will not be considered personal data and we may use it for any business purpose.

 

4. MARKETING COMMUNICATION

From time to time, you may receive promotional messages from us. In this section, we explain when you may receive notices from us and what you can do to decline our commercial communication.

 

4.1 Marketing messages. To keep you updated about the latest developments related to Tapping Oasis, our new services, additional features of Tapping Oasis, and special offers, we may send you marketing messages, such as newsletters, promotions, and advertisements. You will receive such marketing messages or be contacted by us for marketing purposes only if:
 

    • We receive your express (“opt-in”) consent to receive marketing messages (please note that your voluntary subscription to our newsletters substitutes such consent); or

    • We decide to send you marketing messages about our new services that are closely related to the services already used by you.

4.2 Opting-out. You can opt-out from receiving marketing messages at any time free of charge by clicking on the “unsubscribe” link contained in any of the marketing messages sent to you or by contacting us directly.

4.3 Informational notices and service updates. From time to time (if we have your email address), we may send you important informational notices, such as service-related, technical or administrative emails, information about your bookings and payments, your privacy and security, and other administrative matters. Please note that we will send such notices on an “if-needed” basis and they do not fall within the scope of direct marketing communication that requires your prior consent.

 

5. HOW LONG DO WE KEEP YOUR DATA?

We store your personal data only if it is necessary for its specific and limited purposes. In this section, we specify the time period for which we keep your personal and non-personal data in our systems.

 

5.1 Retention of personal data. We will store your personal data in our systems only until such personal data is required for the purposes described in this Privacy Policy or you request us to delete your personal data, whichever comes first. After your personal data is no longer necessary for its purposes and there is no other legal basis for storing it, we will immediately securely delete your personal data from our systems.

5.2 Retention of non-personal data. We may retain non-personal data pertaining to you for as long as necessary for the purposes described in this Privacy Policy. This may include keeping non-personal data after you have deactivated your user account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.

5.3 Retention as required by law. Please note that, in some cases, we may be obliged by law to store your personal data for certain period of time (e.g., for accountancy purposes). In such cases, we will store your personal data for the time period stipulated by the applicable law and delete the personal data as soon as the required retention period expires.

 

6. HOW DO WE SHARE AND DISCLOSE DATA?

We may need to cooperate with external service providers and share some personal data with them. In this section, you can find information about third parties that have access to your personal data and the instances when we make data transfers.

 

6.1 Do we disclose your personal data? If necessary, we will disclose your personal data to the service providers with whom we cooperate (our data processors). For example, we may share your personal and non-personal data with entities that provide certain technical support services to us, such as business analytics, advertising, and email distribution services, or if you explicitly request us to disclose the personal data. We do not sell your personal data to third parties.

6.2 When do we disclose your personal data? The disclosure of your personal data is limited to the situations when such data is required for the following purposes:

    • Ensuring the proper operation of Tapping Oasis;

    • Ensuring the delivery of the services requested by you;

    • Providing you with the requested information;

    • Pursuing our legitimate business interests;

    • Enforcing our rights, preventing fraud, and security purposes;

    • Carrying out our contractual obligations;

    • Law enforcement purposes; or

    • If you provide your prior consent to such a disclosure.

6.3 With what data processors do we share your personal data? We will share your personal data only with the data processors that agree to ensure an adequate level of protection of personal data that is consistent with this Privacy Policy and the applicable data protection laws. The data processors that will have access to your personal data are:

6.4 Sharing of non-personal data. Your non-personal data may be disclosed to third parties for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving Tapping Oasis, responding to lawful requests from public authorities or developing new products and services.

6.5 Legal requests. If requested by a public authority, we will disclose information about the users of Tapping Oasis to the extent necessary for pursuing a public interest objective, such as national security or law enforcement.

6.6 Successors. In case our business is sold partly or fully, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in line with this Privacy Policy.

 

7. INTERNATIONAL TRANSFERS OF PERSONAL DATA

Your personal data may be transferred outside the country where you reside. In this section, we explain when we transfer personal data abroad and what safeguards we implement to ensure that your personal is properly protected.

 

Some of our data processors listed in section 6 of this Privacy Policy are located outside the country in which you reside. For example, if you reside in the European Economic Area (EEA), we may need to transfer your personal data to jurisdictions outside the EEA. In case it is necessary to make such a transfer, we will make sure that the jurisdiction in which the recipient third party is located guarantees an adequate level of protection for your personal data (e.g., the recipient is a Privacy-Shield certified entity) or we conclude an agreement with the respective third party that ensures such protection (e.g., a data processing agreement based pre-approved standard contractual clauses).

 

8. PROTECTION OF PERSONAL DATA

We put our best efforts to keep your personal data safe and secure. In this section, we inform you about our technical measures that help us to protect your personal data.

 

8.1 Our security measures. We implement organisational and technical information security measures to protect your personal data from loss, misuse, unauthorised access, and disclosure. The security measures taken by us include secured networks, SSL protocol, encryption, strong passwords, limited access to your personal data by our staff, and anonymisation of personal data (when possible). In order to ensure the security of your personal data, we kindly ask you to use Tapping Oasis through a secure network only.

8.2 Handling security breaches. Although we put our best efforts to protect your personal data, given the nature of communications and information processing technology and the Internet, we cannot be liable for any unlawful destruction, loss, use, copying, modification, leakage, and falsification of your personal data caused by circumstances that are beyond our reasonable control. In case a serious breach occurs, we will take reasonable measures to mitigate the breach, as required by the applicable law. Our liability for any security breach will be limited to the highest extent permitted by the applicable law.

 

9. YOUR RIGHTS REGARDING PERSONAL DATA

You have the right to control how we process your personal data. Below, we list the rights that you can exercise with regard to your personal data and explain how you can exercise those rights.

 

9.1 What rights do you have? Subject to any exemptions provided by law, you may ask us to:

    • Get a copy of your personal data that we store;

    • Get a list of purposes for which your personal data is processed;

    • Rectify inaccurate personal data;

    • Move your personal data to another processor;

    • Delete your personal data from our systems;

    • Object and restrict processing of your personal data;

    • Withdraw your consent, if you have provided one; or

    • Process your complaint regarding your personal data.

9.2 How to exercise your rights? Please contact us by email at nicole@tappingoasis.com and explain in detail your request. In order to verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information, so that we would be able to identify you in our system. We will answer your request within a reasonable time frame but no later than 2 weeks.

9.3 How to launch a complaint? If you would like to launch a complaint about the way in which we handle your personal data, we kindly ask you to contact us first and express your concerns. After you contact us, we will investigate your complaint and provide you with our response as soon as possible. If you are not satisfied with the outcome of your complaint, you have the right to lodge a complaint with your local data protection authority.

 

10. TERM, TERMINATION, AND AMENDMENTS

This Privacy Policy may be changed or terminated at any time. In this section, we explain for how long this document is valid and how you will be informed about any changes.

 

10.1 Term and termination. This Privacy Policy enters into force on the effective date indicated at the top of the Privacy Policy and remains valid until terminated or updated by us.

10.2 Amendments. The Privacy Policy may be changed from time to time to address the changes in laws, regulations, and industry standards. The amended version of the Privacy Policy will be posted on this page and, if we have your email address, we will send you a notice about all the changes implemented by us. We encourage you to review our Privacy Policy to stay informed. For significant material changes in the Privacy Policy or, where required by the applicable law, we may seek your consent. If you disagree with the changes to the Privacy Policy, you should cease using Tapping Oasis.

 

11. CONTACT US

You can contact us at any time to receive further clarifications. Our contact details are specified below.

 

Please feel free to contact us if you have any questions about the Privacy Policy, our privacy and security practices, or would like to exercise your rights listed in section 9 of the Privacy Policy. You may contact us by using the following contact details:

Email: nicole@tappingoasis.com

Postal address for communication: Tapping Oasis, Nicole Herrle, Carrer d´Aragó 643, 7 – 9, 08026 Barcelona, Spain

Phone number: + 34 673036723

 

***