Privacy Notice
Effective Date: 2nd May 2023
Mitra Sessions, a sole proprietor, (“Mitra,” “we”, “us” and “our”) is committed to respecting the privacy and security of personal information. This Privacy Notice (the “Notice”) explains how we collect, use and disclose personal information as well as the choices you have associated with that information. For the purposes of this Privacy Notice, Mitra is the data controller of the personal information collected and/or received.
By accessing and/or using the Services (as defined below), you signify that you have received and read this Notice. We may update this Notice from time to time as described in the Changes to this Notice Section below.
1. SCOPE
This Notice applies to all personal information that Mitra collects or receives, uses, or shares when you:
Throughout this Notice, we refer to all of the above together as Mitra’s “Services.”
2. PERSONAL INFORMATION WE COLLECT AND HOW WE COLLECT IT
As used in this Notice, “personal information” means any information about or relating to an individual natural person that directly or indirectly identifies that person.
This Notice also describes practices in relation to information that we collect or receive that does not identify you. While this information is not personal information for purposes of this Notice, we will treat it as personal information to the extent we link it to personal information about you.
We collect the following personal information in connection with the Services:
a. Information That You Provide to Us Directly
We collect personal information that you provide to us directly when you access or use the Services. The information we collect depends on the type of Services you access or use and may include the following:
b. Information Collected Indirectly
We automatically collect information about any computer or device you use to access the Services and your activity when you use the Services. Depending on your activity, the information we collect may include:
c. Information Received From Third Parties
We receive information from the following types of third parties:
d. Sensitive Personal Information
In some cases, the information you choose to provide to us may include sensitive information, such as sensitive health information, including past or present medical conditions. You may also choose to provide sensitive information related to your racial or ethnic background, your gender identity (such as LGBT+), or your religion, to the extent that it may impact your session and you would like to make us aware of the information. In some cases, we may ask for or collect this information related to offerings we provide that are designed uniquely to support individuals of particular racial, gender identity, or other unique sensitive personal attributes. The amount and type of sensitive information you choose to provide is up to you and is voluntary. As required under applicable law, we will obtain your consent prior to collecting such sensitive personal information.
e. Choosing Not to Provide Personal Information
You may choose not to provide information directly to us or to not use the Services. However, some personal information is necessary so that we can provide you with the Services you have requested. Failure or refusal to provide this information may prevent us from providing you with access to our Services.
3. LEGAL BASES FOR PROCESSING
We rely on the following legal bases for collecting, using, sharing, and otherwise processing personal information:
4. HOW WE USE INFORMATION
We collect, use, process, combine, retain and store personal information that we collect or receive for the following purposes:
5. AUTOMATED DECISION MAKING AND PROFILING
We do not use personal information for automated decision making or profiling.
6. HOW WE SHARE INFORMATION
We transmit, share, grant access, make available and provide personal information to or with the following types of third parties:
Please note that when you attend a group class or other group offering online, other class participants and any other joint instructors or assistants will be able to view your image, video and name based on how you use the videoconferencing software. We ask that all participants be respectful of one-another’s privacy and not share identifying personal information without first obtaining consent.We do not sell personal information that we collect or receive.
7. HOW WE PROTECT INFORMATION
We have implemented what we believe to be commercially reasonable and appropriate technical and organizational security measures to help protect the personal information that we collect. However, the transmission of information via the Internet is not completely secure, and we cannot and do not guarantee that personal information will be completely protected.
By using our Services, you understand and assume the risks associated with your activities on the Internet. If you have reason to believe that your information is no longer secure, please let us know by contacting us using the information provided in the “Contact Us” section of this Notice below.
8. DATA RETENTION
We keep personal information for as long as necessary for our business purposes, or as otherwise required to operate the Services, comply with your requests, or comply with applicable law.
In some instances, we may choose to anonymize personal information instead of deleting it. We may do this for statistical use, for example.
9. INFORMATION FROM MINORS
We require the consent of a parent or guardian for minors under the age of 16 to access or use the Services. We make reasonable efforts to ensure that we do not target or collect personal information directly from minors under the age of 16 without prior parental consent. If you are a parent or guardian of a child under the age of 16, and believe that your child may have provided us with personal information without your consent, please contact us at [email protected], and we will delete that information as required by applicable law.
10. THIRD-PARTY WEBSITES
The Services may provide links to third-party websites and online services. For example, you may be prompted to create an account directly with our scheduling services provider when you book an appointment or register for a class. Such links are provided to you only as a convenience and are not paid advertisements or endorsed by us. By clicking on these links, the operators of the third-party websites may collect your personal information. We do not review and are not responsible for the content or data collection practices of third parties, and your use of third-party websites is subject to their respective terms of use and privacy policies. Please review the privacy policies and terms and conditions of those third party websites or services before providing personal information to them. We encourage you to read the privacy policies of each and every website that you visit.
11. PAYMENT PROCESSING
We do not directly collect your payment information and do not store your payment information. We use third party, PCI-compliant payment processors that collect the payment information on our behalf to complete the transactions.
12. YOUR CHOICES
As described below, we provide you with the ability to access and update personal information and to limit our use of personal information for marketing and advertising purposes.
a. Accessing and Updating Personal Information
If you would like to access or update your personal information, you may send your request to us at [email protected]. We will review your request and respond in accordance with applicable law. We may require you to provide additional information to identify yourself. We do not promise that we will be able to satisfy your request. Not all personal information is maintained in a format that you can access or change. For example, the personal information may already have been relied or acted upon, or disclosed to third parties, and we generally do not take steps (or have the ability to take steps) to undo prior reliance or actions. We also may not accommodate a request to change information if we believe the change would violate any law or legal requirement, cause the information to be incorrect, or if doing so would be burdensome in our discretion. In any case where we provide access or updates, we perform this service free of charge, except if doing so would require a disproportionate effort.
b. Newsletter and Marketing Email Opt-Out
We may send you marketing or newsletter emails from time to time. If you do not wish to receive them, you can opt-out following the unsubscribe instructions in the emails or by contacting us . We will work to honor your request within 10 business days or as required under applicable law. If you opt-out, we will still send you transactional emails for service purposes, such as responses to your requests, payment confirmations, or scheduling confirmations.
c. Cookies and Online Advertising Opt-Out
As described above in this Notice, we collect and may permit third parties to collect information using cookies and other technologies. Please see our Cookie Notice for ways to exercise your choices around cookies and other technologies.
13. EUROPEAN PRIVACY RIGHTS
If the GDPR applies to you because you are located in the European Economic Area, you have certain rights in relation to your personal information.
Explanation of Individual Rights
How to Submit a Request
These rights are subject to certain rules around when you can exercise them. If are located in the European Economic Area and wish to exercise any of the rights set out above, please contact us at [email protected]. You will not have to pay a fee to access your personal information (or to exercise any of the other rights) unless your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
We will respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated as required by law.
In addition, if you no longer wish to receive our marketing/promotional information, we remind you that you may withdraw your consent to direct marketing at any time directly from the unsubscribe link included in each electronic marketing message we send to you. If you do so, we will promptly update our databases and will take all reasonable steps to meet your request at the earliest possible opportunity, but we may continue to contact you to the extent necessary for the purposes of providing the Services as requested and/or ordered by you.If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact us.
14. INTERNATIONAL DATA TRANSFERS
The personal information that we collect or receive may be sent to and stored on servers located outside of the country where you are located, including in the United States. Such storage is necessary in order to process the information. The third-party service providers we use may be situated outside of your home country or regional area and have staff operating outside of your country or regional area. The data protection laws of the United States or other countries may not be as comprehensive or equivalent to those in your country of residence.The European Union’s General Data Protection Regulation (“GDPR”) allows for transfer of personal information from the European Union to a third country in certain situations. We rely on legally-provided mechanisms to lawfully transfer personal information across borders. For example, we may enter into the EU Standard Contractual Clauses adopted by the EU Commission. More information about the Standard Contractual Clauses is available here.
15. ADVERTISING AND TRACKING
We use personal information to send you marketing communications about our products and Services and/or the products and services of our partners or others that we think may interest you. You may choose to opt-out at any time as described in the “Your Choices” section of this Notice. From time to time, we or our authorized third-party service providers or agents may use cookies or other tracking technologies for our advertising purposes. Please see our Cookie Notice for more information about cookies and tracking technologies we use for advertising.
16. DO-NOT-TRACK PREFERENCES
The Services do not monitor for or behave differently if your computer or browser transmits a “do-not-track” or similar message to us or the Services.
17. CALIFORNIA PRIVACY RIGHTS
We do not share personal information with third parties for their own marketing purposes. If you have questions or would like to learn more about how we share personal information with third parties and for what purposes, please send us an email at [email protected].
18. CHANGES TO THIS NOTICE
We may amend this Notice from time to time. When we do so, we will update the “Effective Date” noted at the top of this page. Whenever we make any material changes to this Notice, we will provide you with notice before the modifications are effective, such as by posting a notice on our Site or sending a message to the most recent email address that we have on file for you. We encourage you to review this Notice regularly for any changes. Your continued use of the Services after the posting of an updated Privacy Notice and/or any such update notice will be subject to the terms of the then-current Privacy Notice.
19. CONTACT US
If you have questions about this Notice or our privacy practices, please contact us at [email protected].