Keara Nash, trading as Keara Nash Coaching, respects your privacy and is committed to handling personal data lawfully, fairly and transparently. This Privacy Policy explains what information is collected, why it is used, how it is protected and the rights available to you under the General Data Protection Regulation (GDPR) and applicable Irish data-protection law.
1. Who is responsible for your information
The data controller is Keara Nash, a sole trader trading as Keara Nash Coaching and based in the Republic of Ireland. Questions, requests or complaints about personal data may be sent to [email protected].
2. Who this policy applies to
This policy applies to prospective, current and former clients, customers, subscribers, event attendees and other people who interact with Keara Nash Coaching through landing pages, booking and payment pages, forms, email, social media, Zoom, the Connected Campaigns client portal or community, digital products, coaching, HeartHealing™ and related services.
3. Personal data that may be collected
· Identity and contact details, including your name, email address, telephone number, billing details and social-media handle.
· Booking, purchase and transaction information, including the service selected, payment status and invoice records. Full card details are normally handled by the payment provider and are not stored by Keara Nash Coaching.
· Communications, forms, applications, survey answers, testimonials, support requests and notes relating to the services provided.
· Account and participation information, including member-area access, attendance, programme progress and engagement with emails or digital resources.
· Technical information collected by the platforms used, such as IP address, device/browser information, login data, cookies and similar technologies.
· Special-category or sensitive information that you choose to disclose in connection with coaching or HeartHealing™, which may include information about physical or mental health, relationships, traumatic experiences or other personal circumstances.
Please share only information that is relevant to the service. Services are intended for adults aged 18 or over unless expressly agreed otherwise in writing.
4. How and why personal data is used
· To respond to enquiries, assess suitability, administer bookings and deliver purchased services or content.
· To manage client accounts, access, payments, invoices, support, rescheduling and programme communications.
· To keep appropriate confidential session or progress notes and provide personalised follow-up resources.
· To send requested lead magnets, service messages and, where permitted, marketing communications.
· To operate, secure and improve the business, platforms, offers and client experience.
· To meet tax, accounting, legal, safeguarding, insurance and dispute-resolution obligations.
5. Lawful bases
Depending on the purpose, personal data is processed because it is necessary to take steps at your request or perform a contract; because there is a legal obligation; because there is a legitimate business interest that does not override your rights; or because you have given consent. Marketing consent may be withdrawn at any time.
Where special-category data is processed, it will ordinarily be because you have given explicit consent by choosing to disclose it for the service. You may withdraw that consent, but this may mean a service cannot safely or properly continue. Information may also be processed where necessary to establish, exercise or defend legal claims or where another lawful exception applies.
6. Marketing
Marketing emails are sent only where there is a lawful basis to do so. Every marketing email will provide a way to unsubscribe. Unsubscribing from marketing does not prevent necessary service emails about a booking, purchase, payment, account or programme. You may also opt out by emailing [email protected].
7. Cookies and tracking
Landing pages, forms, booking systems, payment pages and member areas may use cookies or similar technologies to function, remember preferences, measure performance and support marketing. Where consent is legally required for non-essential cookies, consent should be requested through the relevant page or platform. Browser settings may also be used to control cookies, although disabling essential cookies may affect functionality.
8. Who personal data may be shared with
Personal data is shared only where reasonably necessary. Recipients may include providers of customer relationship management and email services, website or funnel hosting, booking systems, Zoom/video services, payment processing, accounting, cloud storage, form and survey services, community/member-area services, IT support, professional advisers, insurers and public authorities where legally required.
Service providers are expected to handle data only for the agreed purpose and with appropriate safeguards. Personal data is not sold.
9. International transfers
Some technology providers may store or process information outside Ireland or the European Economic Area. Where this occurs, reasonable steps will be taken to rely on a lawful transfer mechanism, such as an adequacy decision, approved contractual protections or another mechanism permitted by data-protection law.
10. Retention
Personal data is kept only for as long as it is reasonably required for the purpose collected and to meet legal, accounting, insurance or dispute-related obligations. As a working guide:
· Financial, invoice and transaction records may be retained for at least the period required by Irish tax and accounting law, commonly six years after the relevant accounting period.
· Client agreements, core service records and relevant communications may be retained for up to six years after the service ends where reasonably required for legal or insurance purposes.
· Sensitive intake information and detailed working notes should be reviewed regularly and securely deleted or anonymised when no longer necessary.
· Marketing information is kept until consent is withdrawn, an objection is made or the information is no longer useful, subject to keeping a minimal suppression record so an opt-out is respected.
11. Security and confidentiality
Reasonable organisational and technical measures are used to protect personal data, including access controls, passwords, secure platforms, limited access and appropriate deletion. No internet or electronic storage system can be guaranteed completely secure. Clients are responsible for using a private setting and secure device where confidentiality is important, particularly for online sessions.
12. Recording sessions and testimonials
Private sessions will not be recorded without prior notice and consent. Group sessions may be recorded for replay access where this is stated in advance. Participants should avoid sharing information they do not want included in a recording. A testimonial, image, name, case study or identifiable client result will not be published without permission. Consent may be withdrawn for future use, although material already lawfully published or distributed may not always be capable of full recall.
13. Your data-protection rights
Subject to legal conditions and exemptions, you may request access to your personal data; correction; deletion; restriction; portability; or objection to certain processing. You may withdraw consent at any time and may object to direct marketing. Identity may need to be verified before a request is completed. Requests should be sent to [email protected] and will normally be answered within one month.
You also have the right to complain to the Data Protection Commission in Ireland. Its current contact details and complaint process are available at www.dataprotection.ie.
14. Changes to this Privacy Policy
This policy may be updated when the business, services, providers or legal requirements change. The current version should display its effective date. Material changes will be communicated where appropriate.