Document: Privacy Policy
Provider: Hamish Hurley Coaching & Consulting | hamishhurley.com
Version: 3.0 | Effective: 1 October 2025
Compliance: GDPR, Malta Data Protection Act 2018
PRIVACY POLICY
1. WHO WE ARE
This Privacy Policy describes how Hamish Hurley (“we,” “us,” “our”) collects, uses, protects, and manages your personal information when you use our health coaching services and website.
Data Controller:
- Name: Hamish Hurley
- Trading Name: Hamish Hurley Coaching & Consulting
- Location: Malta (European Union)
- Business Structure: Sole proprietor
- Website: hamishhurley.com
Contact for Privacy Matters:
- Method: Contact form at https://hamishhurley.com/compliance
- Subject Line: “Privacy Policy”
- Response Time: Within 30 days (may extend to 60 days for complex requests)
- Note: We do NOT display phone numbers or direct email addresses publicly to prevent spam
2. LEGAL BASIS FOR PROCESSING
Under GDPR and Malta Data Protection Act 2018, we process your personal data based on:
Contract Performance (GDPR Article 6(1)(b)):
- Delivering health coaching services
- Creating and managing your coaching program
- Communicating about appointments
- Processing payments
Legitimate Interests (GDPR Article 6(1)(f)):
- Improving services based on feedback
- Business administration and record-keeping
- Fraud prevention and security
Explicit Consent (GDPR Article 6(1)(a) and Article 9(2)(a)):
- Processing special category health data for coaching
- Sending marketing communications
- Using testimonials or case studies
Legal Obligation (GDPR Article 6(1)(c)):
- Financial record-keeping for tax compliance
- Compliance with Malta business regulations
Special Category Data – Health Information (GDPR Article 9(2)(h)):
- Processing health data necessary for health coaching service provision
- Based on your explicit consent and health service delivery exception
3. INFORMATION WE COLLECT
PERSONAL IDENTIFICATION INFORMATION
- Full legal name
- Date of birth
- Current residence and citizenship
- Physical mailing address
- Email address
- Emergency contact information
- Payment information (bank transfer details only)
HEALTH AND LIFESTYLE INFORMATION (Special Category Data)
- Complete health history and current health status
- Current medical conditions and diagnoses
- Current medications and supplements
- Known allergies and sensitivities
- Previous surgeries and health issues
- Family health history
- Mental health information (if relevant)
- Pregnancy or nursing status
- Eating patterns and dietary information
- Exercise habits and physical activity
- Sleep patterns and quality
- Stress levels and management
- Lifestyle factors affecting health
- Health goals and desired outcomes
- Progress tracking data
- Laboratory test results (if shared)
- Biomarker data and measurements
PROFESSIONAL AND BACKGROUND INFORMATION
- Professional background (if relevant)
- Athletic history (if applicable)
- Occupation and work environment factors
COMMUNICATION RECORDS
- Email correspondence via ProtonMail
- Coaching session notes and discussions
- Messages via Signal App (if used)
- Form submissions via Hipaatizer
- Progress updates and check-ins
TECHNICAL AND USAGE INFORMATION
Currently minimal:
- Form submission data
- Email engagement metrics (basic only)
- Session scheduling information
Future potential: Website analytics, cookies (if implemented, with consent)
4. HOW WE COLLECT YOUR INFORMATION
DIRECTLY FROM YOU:
- Initial health assessment forms via Hipaatizer
- Coaching session discussions and video calls
- Email correspondence via ProtonMail
- Ongoing progress tracking and check-ins
- Forms and questionnaires
- Payment information for bank transfers
AUTOMATICALLY (Limited):
- Email delivery and engagement metrics (basic)
- Form submission confirmations
- Website contact form data
FROM THIRD PARTIES (With Your Permission Only):
- Healthcare providers (explicit written consent required)
- Laboratory testing companies (if you share results)
- Family members (if participating with your consent)
We NEVER purchase data from data brokers or third-party lists.
5. HOW WE USE YOUR INFORMATION
PRIMARY COACHING SERVICE PURPOSES
Developing Personalized Programs:
- Creating bespoke health programs based on individual biology
- Designing recommendations aligned with natural life rhythms
- Tailoring coaching to specific goals and health status
- Adjusting programs based on progress
Providing Coaching Services:
- Conducting one-to-one video coaching sessions
- Providing progress tracking and accountability
- Offering email support between sessions
- Making health-related product recommendations
- Referring to appropriate third-party services
Communication and Coordination:
- Scheduling and confirming coaching sessions
- Sending program materials and resources
- Responding to questions and concerns
- Following up on progress
BUSINESS AND ADMINISTRATIVE PURPOSES
Record-Keeping and Legal Compliance:
- Maintaining professional coaching records (7 years)
- Financial record-keeping for tax compliance (5 years)
- Documenting program details and outcomes
- Complying with legal and regulatory obligations
Service Improvement:
- Analyzing program effectiveness (anonymized data)
- Improving coaching methodologies
- Developing new services
- Professional development
MARKETING (With Consent Only)
With Your Explicit Consent:
- Sending educational newsletters
- Sharing relevant health information
- Announcing new services
You Can: Opt out anytime via contact form
TESTIMONIALS (With Separate Explicit Consent Only)
We will NEVER use your information for testimonials without:
- Separate written consent using Testimonial Release Form
- Specific description of how information will be used
- Your right to review content before publication
- Your right to withdraw consent anytime
6. DATA SHARING AND DISCLOSURE
WE DO NOT SELL, RENT, OR COMMERCIALIZE YOUR PERSONAL INFORMATION. PERIOD.
SERVICE PROVIDERS (GDPR-Compliant Processors)
ProtonMail (Proton AG, Switzerland):
- Purpose: Secure email communication
- Data: Email address, email content, communication records
- Safeguards: End-to-end encryption, Swiss data protection laws, GDPR compliant
- Location: Switzerland (EU-adequate protection)
Hipaatizer (US-based):
- Purpose: HIPAA-compliant form collection and health data processing
- Data: Health assessment forms, personal health information
- Safeguards: Data Processing Agreement with Standard Contractual Clauses (EU 2021/914, Module 2: Controller to Processor), encryption, AWS us-east-1 with appropriate security measures
- Sub-processors: Amazon Web Services (AWS) us-east-1, MongoDB Atlas US regions
- Location: United States (protected by SCCs and supplementary measures including TLS 1.2+ encryption, AES-256 encryption at rest, MFA access controls)
Proton Drive (Proton AG, Switzerland):
- Purpose: Encrypted file sharing for lab results and health documents
- Data: Health documents, lab results, shared files
- Safeguards: End-to-end encryption, password protection, Swiss data protection laws
- Location: Switzerland (EU-adequate protection)
Signal Messenger (Signal Foundation):
- Purpose: Encrypted messaging (when client has Signal access)
- Data: Minimal – end-to-end encrypted messages only
- Safeguards: End-to-end encryption, open-source security
Cloud Backup Service:
- Purpose: Secure backup for business continuity
- Data: Encrypted backup files containing client data
- Safeguards: Strong encryption, data processing agreement, access controls
- Location: May include US or other locations (protected by encryption and SCCs where applicable)
All processors are:
- Bound by written data processing agreements
- GDPR compliant or subject to Standard Contractual Clauses
- Required to implement appropriate security measures
- Prohibited from using data for their own purposes
HEALTHCARE COORDINATION (With Explicit Written Consent Only)
- Communication with your healthcare providers ONLY when you provide specific written authorization
- You control what information is shared and with whom
LEGAL REQUIREMENTS
- Court orders, subpoenas, or legal process
- Regulatory investigations or governmental requests
- Compliance with Malta or EU legal obligations
EMERGENCY SITUATIONS (Rare)
- Where required to protect your vital interests or safety
- Only information necessary for emergency protection shared
WE NEVER:
- Sell your personal data to third parties
- Rent or lease your information
- Share data for marketing purposes of other companies
- Provide data to data brokers
7. INTERNATIONAL DATA TRANSFERS
DATA PROCESSING LOCATIONS
Primary Processing and Storage:
- Malta (European Union) – Provider’s base location
- EU-based cloud services where applicable
International Transfers May Occur:
- Provider travels internationally and may access data from various locations
- Hipaatizer processing in United States (AWS us-east-1)
- Cloud backup services may be located outside EU (with adequate safeguards)
- Email communications may transit through international servers (encrypted)
SAFEGUARDS FOR NON-EU DATA TRANSFERS
All transfers of personal data outside the European Union are protected by:
Standard Contractual Clauses (SCCs):
- European Commission approved SCCs (EU 2021/914) implemented with Hipaatizer
- Module 2: Controller to Processor transfer clauses
- Legally binding contracts ensuring adequate data protection
- Enforceable data subject rights maintained
Technical Safeguards:
- End-to-end encryption for data in transit (TLS 1.2+)
- Strong encryption for data at rest (AES-256)
- Secure access controls and authentication (MFA)
- Regular security assessments
Organizational Safeguards:
- Data processing agreements with adequate protection provisions
- Strict access limitations (Provider only)
- Incident response and breach notification procedures
YOUR RIGHTS REGARDING INTERNATIONAL TRANSFERS
- Right to obtain detailed information about transfer safeguards
- Right to obtain copies of Standard Contractual Clauses
- Right to object to specific transfers in certain circumstances
8. YOUR RIGHTS UNDER GDPR
COMPREHENSIVE DATA PROTECTION RIGHTS (EU/UK/EEA RESIDENTS)
Right of Access (GDPR Article 15):
- Request confirmation of whether we process your personal data
- Obtain copies of all personal data we hold about you
- Receive information about processing purposes, recipients, retention periods
How: Contact form with subject “Data Access Request” | Response: 30 days | Cost: Free
Right to Rectification (GDPR Article 16):
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information
How: Contact form with subject “Data Correction Request”
Right to Erasure / “Right to be Forgotten” (GDPR Article 17):
- Request deletion of your personal data
- LIMITATIONS: We MUST retain some data for legal obligations:
- Health information: 7 years (Malta professional requirements)
- Financial records: 5 years (tax compliance)
- Contract performance data during retention period
How: Contact form with subject “Data Erasure Request”
Right to Restrict Processing (GDPR Article 18):
- Restrict processing when accuracy is contested
- Restrict when processing is unlawful but you prefer restriction over erasure
- Data marked as restricted, stored but not processed
Right to Data Portability (GDPR Article 20):
- Receive personal data in structured, machine-readable format
- Request transmission to another service provider (where technically feasible)
- Format: PDF, CSV, JSON as appropriate
Right to Object (GDPR Article 21):
- Object to processing based on legitimate interests
- Object to direct marketing (absolute right – we must stop immediately)
Marketing opt-out: Contact form with subject “Unsubscribe”
Right to Withdraw Consent (GDPR Article 7(3)):
- Withdraw consent at any time
- Easy withdrawal process (as easy as giving consent)
- No negative consequences for withdrawal
Right to Lodge Complaint:
- Malta Information and Data Protection Commissioner:
- Website: dataprotection.gov.mt
- Email: idpc.info@idpc.mt
- Address: Level 2, Airways House, High Street, Sliema SLM 1549, Malta
9. DATA SECURITY MEASURES
TECHNICAL SECURITY
Encryption:
- All client data stored on encrypted devices
- Full disk encryption on all computers
- End-to-end encryption for cloud backups
- Encrypted email via ProtonMail
- Encrypted file sharing via Proton Drive with password protection
- Encrypted messaging via Signal
Access Controls:
- Strong, unique passwords (managed via 1Password)
- Multi-factor authentication where available
- Access strictly limited to Provider only
- Regular password updates
- Automatic device locking
Network Security:
- Secure internet connections only
- VPN when using public networks
- Firewall protection
- Regular security updates
- Malware and antivirus protection
ORGANIZATIONAL SECURITY
Data Minimization:
- Collect only data necessary for coaching
- Regular review and deletion of unnecessary data
- Automatic deletion after retention periods
Business Continuity:
- Regular encrypted backups
- Disaster recovery procedures
Incident Response:
- Data breach response procedures established
- Monitoring for unauthorized access
- Regular security assessments
DATA BREACH NOTIFICATION
In the Event of a Data Breach:
Notification to Authorities:
- Malta Data Protection Authority notified within 72 hours of breach discovery
Notification to Affected Individuals:
- Direct notification without undue delay if breach poses high risk
- Clear explanation of nature of breach, consequences, and measures taken
10. DATA RETENTION PERIODS
Active Client Data: Duration of coaching relationship plus 7 years
Health Information and Coaching Records:
- Retention: 7 years from last service date
- Reason: Malta professional record-keeping requirements for health-related services
Financial and Payment Records:
- Retention: 5 years from transaction date
- Reason: Malta tax compliance and financial record-keeping obligations
Marketing and Communication Consent:
- Retention: Until consent withdrawn
- Action: Immediate removal from marketing lists upon withdrawal
General Correspondence:
- Retention: Duration of relationship plus 3 years
After Retention Periods Expire:
- Secure deletion using data destruction procedures
- Complete removal from all systems and backups
- Anonymization of any data used for statistics (no personal identifiers)
11. COOKIES AND TRACKING TECHNOLOGIES
CURRENT STATUS: MINIMAL TRACKING
Currently, we collect minimal technical data. No cookies or sophisticated tracking is currently implemented on the website.
FUTURE IMPLEMENTATION (Will Require Consent)
If we implement cookies or tracking in the future, we will:
- Provide clear cookie banner with choices before setting non-essential cookies
- Obtain consent for non-essential cookies and tracking
- Provide cookie preference center for granular control
- Allow easy withdrawal of consent anytime
Potential Future Cookie Categories:
- Essential Cookies (No consent required): Session management, security, website functionality
- Analytics Cookies (Requires consent): Understanding website usage, aggregated data only
- Marketing Cookies (Requires explicit consent): Personalized content, measuring campaign effectiveness
12. CHILDREN’S PRIVACY
Primary Audience: Services designed primarily for adults 18+
Services for Minors (Under 18):
- Explicit consent from parent or legal guardian required
- Parent must review and agree to all policies
- Parent signs Client Coaching Agreement on behalf of minor
- Additional care and safeguards for health data of minors
Parental Rights:
- Full access to minor’s information
- Right to withdraw consent and terminate services anytime
- Right to access, correct, or delete minor’s data
NO Marketing to Children: No marketing or promotional communications to children under 16
13. CHANGES TO THIS PRIVACY POLICY
How We Update:
- Material changes communicated directly to active clients via email
- Updated effective date clearly displayed
- Previous versions available upon request
For Material Changes:
- 30 days advance notice before changes take effect
- Clear explanation of what is changing and why
- Option to object or withdraw consent if you disagree
- Right to terminate services if you don’t accept changes
14. COMPLAINTS AND SUPERVISORY AUTHORITY
Step 1: Contact Us Directly
- Method: Contact form at hamishhurley.com
- Subject Line: “Privacy Complaint” or “Data Protection Concern”
- Response: We will investigate and respond within 30 days
Step 2: Malta Data Protection Authority
- Website: dataprotection.gov.mt
- Email: idpc.info@idpc.mt
- Phone: +356 2328 7100
- Address: Level 2, Airways House, High Street, Sliema SLM 1549, Malta
Step 3: Your Local Data Protection Authority
- EU/EEA Residents: Right to lodge complaint with supervisory authority in your country
- Full list: edpb.europa.eu
- UK Residents: Information Commissioner’s Office (ICO) – ico.org.uk
15. REGULATORY COMPLIANCE
GDPR COMPLIANCE WITHOUT REGISTRATION
We comply with GDPR and Malta Data Protection Act 2018 through:
- Internal Record-Keeping: We maintain comprehensive internal records of processing activities as required by GDPR Article 30
- No IDPC Registration Required: As a sole proprietor health coach not conducting large-scale processing, we are not required to register with Malta’s IDPC. Registration requirements were abolished in 2018 under GDPR, which focuses on accountability through internal records rather than mandatory registration
- Accountability Measures: We maintain documentation of our legal basis for processing, data protection impact assessments where required, and compliance procedures
PROFESSIONAL STANDARDS
- Confidentiality maintained per international coaching standards
- Health information handled with enhanced care
- Professional boundaries respected
- Continuing education in data protection practices
16. SUMMARY OF KEY POINTS
What You Need to Know:
- We Protect Your Privacy: Your data is encrypted, secure, and never sold
- You Have Control: Comprehensive GDPR rights to access, correct, delete, and control your data
- Minimal Data Collection: We collect only what’s necessary for coaching
- Secure Tools: All service providers are GDPR-compliant with strong security (ProtonMail, Hipaatizer with SCCs, Proton Drive, Signal)
- International Transfers: Protected by encryption, SCCs, and supplementary safeguards
- Your Rights: Easy to exercise via contact form
- Transparency: Clear information about collection, use, and protection
- Limited Retention: 7 years for health data, 5 years for financial, deleted after
- No Marketing Without Consent: Opt-in only, easy opt-out anytime
- Complaints Welcome: Right to complain to Malta IDPC or your local authority
17. CONTACT INFORMATION
For All Privacy-Related Matters:
- Website: https://hamishhurley.com/compliance/
- Method: Secure contact form only
- Subject Lines:
- “Privacy Policy”
- Message Body Title:
- “Data Rights Request” – for access, rectification, erasure, portability
- “General Inquiry” – for general questions
- “Data Protection Concern” – for concerns about data handling
- “Privacy Complaint” – for formal complaints
- “Unsubscribe” – for marketing communications
Response Timeframes:
- Data Rights Requests: 30 days (may extend to 60 days for complex requests)
- General Inquiries: 5-7 business days
- Urgent Security Concerns: 24-48 hours
- Complaints: 30 days with full investigation
Why Contact Form Only: Prevents spam, ensures secure communication, allows proper tracking of requests, maintains your privacy and security
Document Control
Version: 3.0 | Effective: 1 October 2025 | Next Review: 1 October 2026
This Privacy Policy complies with GDPR, Malta Data Protection Act 2018, and international health coaching professional standards.
END OF PRIVACY POLICY