Privacy Policy

Document: Privacy Policy

Provider: Hamish Hurley Coaching & Consulting | hamishhurley.com

Version: 3.0 | Effective: 1 October 2025

Compliance: GDPR, Malta Data Protection Act 2018

PRIVACY POLICY

1. WHO WE ARE

This Privacy Policy describes how Hamish Hurley (“we,” “us,” “our”) collects, uses, protects, and manages your personal information when you use our health coaching services and website.

Data Controller:

  • Name: Hamish Hurley
  • Trading Name: Hamish Hurley Coaching & Consulting
  • Location: Malta (European Union)
  • Business Structure: Sole proprietor
  • Website: hamishhurley.com

Contact for Privacy Matters:

  • Method: Contact form at https://hamishhurley.com/compliance
  • Subject Line: “Privacy Policy”
  • Response Time: Within 30 days (may extend to 60 days for complex requests)
  • Note: We do NOT display phone numbers or direct email addresses publicly to prevent spam

2. LEGAL BASIS FOR PROCESSING

Under GDPR and Malta Data Protection Act 2018, we process your personal data based on:

Contract Performance (GDPR Article 6(1)(b)):

  • Delivering health coaching services
  • Creating and managing your coaching program
  • Communicating about appointments
  • Processing payments

Legitimate Interests (GDPR Article 6(1)(f)):

  • Improving services based on feedback
  • Business administration and record-keeping
  • Fraud prevention and security

Explicit Consent (GDPR Article 6(1)(a) and Article 9(2)(a)):

  • Processing special category health data for coaching
  • Sending marketing communications
  • Using testimonials or case studies

Legal Obligation (GDPR Article 6(1)(c)):

  • Financial record-keeping for tax compliance
  • Compliance with Malta business regulations

Special Category Data – Health Information (GDPR Article 9(2)(h)):

  • Processing health data necessary for health coaching service provision
  • Based on your explicit consent and health service delivery exception

3. INFORMATION WE COLLECT

PERSONAL IDENTIFICATION INFORMATION

  • Full legal name
  • Date of birth
  • Current residence and citizenship
  • Physical mailing address
  • Email address
  • Emergency contact information
  • Payment information (bank transfer details only)

HEALTH AND LIFESTYLE INFORMATION (Special Category Data)

  • Complete health history and current health status
  • Current medical conditions and diagnoses
  • Current medications and supplements
  • Known allergies and sensitivities
  • Previous surgeries and health issues
  • Family health history
  • Mental health information (if relevant)
  • Pregnancy or nursing status
  • Eating patterns and dietary information
  • Exercise habits and physical activity
  • Sleep patterns and quality
  • Stress levels and management
  • Lifestyle factors affecting health
  • Health goals and desired outcomes
  • Progress tracking data
  • Laboratory test results (if shared)
  • Biomarker data and measurements

PROFESSIONAL AND BACKGROUND INFORMATION

  • Professional background (if relevant)
  • Athletic history (if applicable)
  • Occupation and work environment factors

COMMUNICATION RECORDS

  • Email correspondence via ProtonMail
  • Coaching session notes and discussions
  • Messages via Signal App (if used)
  • Form submissions via Hipaatizer
  • Progress updates and check-ins

TECHNICAL AND USAGE INFORMATION

Currently minimal:

  • Form submission data
  • Email engagement metrics (basic only)
  • Session scheduling information

Future potential: Website analytics, cookies (if implemented, with consent)

4. HOW WE COLLECT YOUR INFORMATION

DIRECTLY FROM YOU:

  • Initial health assessment forms via Hipaatizer
  • Coaching session discussions and video calls
  • Email correspondence via ProtonMail
  • Ongoing progress tracking and check-ins
  • Forms and questionnaires
  • Payment information for bank transfers

AUTOMATICALLY (Limited):

  • Email delivery and engagement metrics (basic)
  • Form submission confirmations
  • Website contact form data

FROM THIRD PARTIES (With Your Permission Only):

  • Healthcare providers (explicit written consent required)
  • Laboratory testing companies (if you share results)
  • Family members (if participating with your consent)

We NEVER purchase data from data brokers or third-party lists.

5. HOW WE USE YOUR INFORMATION

PRIMARY COACHING SERVICE PURPOSES

Developing Personalized Programs:

  • Creating bespoke health programs based on individual biology
  • Designing recommendations aligned with natural life rhythms
  • Tailoring coaching to specific goals and health status
  • Adjusting programs based on progress

Providing Coaching Services:

  • Conducting one-to-one video coaching sessions
  • Providing progress tracking and accountability
  • Offering email support between sessions
  • Making health-related product recommendations
  • Referring to appropriate third-party services

Communication and Coordination:

  • Scheduling and confirming coaching sessions
  • Sending program materials and resources
  • Responding to questions and concerns
  • Following up on progress

BUSINESS AND ADMINISTRATIVE PURPOSES

Record-Keeping and Legal Compliance:

  • Maintaining professional coaching records (7 years)
  • Financial record-keeping for tax compliance (5 years)
  • Documenting program details and outcomes
  • Complying with legal and regulatory obligations

Service Improvement:

  • Analyzing program effectiveness (anonymized data)
  • Improving coaching methodologies
  • Developing new services
  • Professional development

MARKETING (With Consent Only)

With Your Explicit Consent:

  • Sending educational newsletters
  • Sharing relevant health information
  • Announcing new services

You Can: Opt out anytime via contact form

TESTIMONIALS (With Separate Explicit Consent Only)

We will NEVER use your information for testimonials without:

  • Separate written consent using Testimonial Release Form
  • Specific description of how information will be used
  • Your right to review content before publication
  • Your right to withdraw consent anytime

6. DATA SHARING AND DISCLOSURE

WE DO NOT SELL, RENT, OR COMMERCIALIZE YOUR PERSONAL INFORMATION. PERIOD.

SERVICE PROVIDERS (GDPR-Compliant Processors)

ProtonMail (Proton AG, Switzerland):

  • Purpose: Secure email communication
  • Data: Email address, email content, communication records
  • Safeguards: End-to-end encryption, Swiss data protection laws, GDPR compliant
  • Location: Switzerland (EU-adequate protection)

Hipaatizer (US-based):

  • Purpose: HIPAA-compliant form collection and health data processing
  • Data: Health assessment forms, personal health information
  • Safeguards: Data Processing Agreement with Standard Contractual Clauses (EU 2021/914, Module 2: Controller to Processor), encryption, AWS us-east-1 with appropriate security measures
  • Sub-processors: Amazon Web Services (AWS) us-east-1, MongoDB Atlas US regions
  • Location: United States (protected by SCCs and supplementary measures including TLS 1.2+ encryption, AES-256 encryption at rest, MFA access controls)

Proton Drive (Proton AG, Switzerland):

  • Purpose: Encrypted file sharing for lab results and health documents
  • Data: Health documents, lab results, shared files
  • Safeguards: End-to-end encryption, password protection, Swiss data protection laws
  • Location: Switzerland (EU-adequate protection)

Signal Messenger (Signal Foundation):

  • Purpose: Encrypted messaging (when client has Signal access)
  • Data: Minimal – end-to-end encrypted messages only
  • Safeguards: End-to-end encryption, open-source security

Cloud Backup Service:

  • Purpose: Secure backup for business continuity
  • Data: Encrypted backup files containing client data
  • Safeguards: Strong encryption, data processing agreement, access controls
  • Location: May include US or other locations (protected by encryption and SCCs where applicable)

All processors are:

  • Bound by written data processing agreements
  • GDPR compliant or subject to Standard Contractual Clauses
  • Required to implement appropriate security measures
  • Prohibited from using data for their own purposes

HEALTHCARE COORDINATION (With Explicit Written Consent Only)

  • Communication with your healthcare providers ONLY when you provide specific written authorization
  • You control what information is shared and with whom

LEGAL REQUIREMENTS

  • Court orders, subpoenas, or legal process
  • Regulatory investigations or governmental requests
  • Compliance with Malta or EU legal obligations

EMERGENCY SITUATIONS (Rare)

  • Where required to protect your vital interests or safety
  • Only information necessary for emergency protection shared

WE NEVER:

  • Sell your personal data to third parties
  • Rent or lease your information
  • Share data for marketing purposes of other companies
  • Provide data to data brokers

7. INTERNATIONAL DATA TRANSFERS

DATA PROCESSING LOCATIONS

Primary Processing and Storage:

  • Malta (European Union) – Provider’s base location
  • EU-based cloud services where applicable

International Transfers May Occur:

  • Provider travels internationally and may access data from various locations
  • Hipaatizer processing in United States (AWS us-east-1)
  • Cloud backup services may be located outside EU (with adequate safeguards)
  • Email communications may transit through international servers (encrypted)

SAFEGUARDS FOR NON-EU DATA TRANSFERS

All transfers of personal data outside the European Union are protected by:

Standard Contractual Clauses (SCCs):

  • European Commission approved SCCs (EU 2021/914) implemented with Hipaatizer
  • Module 2: Controller to Processor transfer clauses
  • Legally binding contracts ensuring adequate data protection
  • Enforceable data subject rights maintained

Technical Safeguards:

  • End-to-end encryption for data in transit (TLS 1.2+)
  • Strong encryption for data at rest (AES-256)
  • Secure access controls and authentication (MFA)
  • Regular security assessments

Organizational Safeguards:

  • Data processing agreements with adequate protection provisions
  • Strict access limitations (Provider only)
  • Incident response and breach notification procedures

YOUR RIGHTS REGARDING INTERNATIONAL TRANSFERS

  • Right to obtain detailed information about transfer safeguards
  • Right to obtain copies of Standard Contractual Clauses
  • Right to object to specific transfers in certain circumstances

8. YOUR RIGHTS UNDER GDPR

COMPREHENSIVE DATA PROTECTION RIGHTS (EU/UK/EEA RESIDENTS)

Right of Access (GDPR Article 15):

  • Request confirmation of whether we process your personal data
  • Obtain copies of all personal data we hold about you
  • Receive information about processing purposes, recipients, retention periods

How: Contact form with subject “Data Access Request” | Response: 30 days | Cost: Free

Right to Rectification (GDPR Article 16):

  • Correct inaccurate personal data
  • Complete incomplete personal data
  • Update outdated information

How: Contact form with subject “Data Correction Request”

Right to Erasure / “Right to be Forgotten” (GDPR Article 17):

  • Request deletion of your personal data
  • LIMITATIONS: We MUST retain some data for legal obligations:
    • Health information: 7 years (Malta professional requirements)
    • Financial records: 5 years (tax compliance)
    • Contract performance data during retention period

How: Contact form with subject “Data Erasure Request”

Right to Restrict Processing (GDPR Article 18):

  • Restrict processing when accuracy is contested
  • Restrict when processing is unlawful but you prefer restriction over erasure
  • Data marked as restricted, stored but not processed

Right to Data Portability (GDPR Article 20):

  • Receive personal data in structured, machine-readable format
  • Request transmission to another service provider (where technically feasible)
  • Format: PDF, CSV, JSON as appropriate

Right to Object (GDPR Article 21):

  • Object to processing based on legitimate interests
  • Object to direct marketing (absolute right – we must stop immediately)

Marketing opt-out: Contact form with subject “Unsubscribe”

Right to Withdraw Consent (GDPR Article 7(3)):

  • Withdraw consent at any time
  • Easy withdrawal process (as easy as giving consent)
  • No negative consequences for withdrawal

Right to Lodge Complaint:

  • Malta Information and Data Protection Commissioner:
  • Website: dataprotection.gov.mt
  • Email: idpc.info@idpc.mt
  • Address: Level 2, Airways House, High Street, Sliema SLM 1549, Malta

9. DATA SECURITY MEASURES

TECHNICAL SECURITY

Encryption:

  • All client data stored on encrypted devices
  • Full disk encryption on all computers
  • End-to-end encryption for cloud backups
  • Encrypted email via ProtonMail
  • Encrypted file sharing via Proton Drive with password protection
  • Encrypted messaging via Signal

Access Controls:

  • Strong, unique passwords (managed via 1Password)
  • Multi-factor authentication where available
  • Access strictly limited to Provider only
  • Regular password updates
  • Automatic device locking

Network Security:

  • Secure internet connections only
  • VPN when using public networks
  • Firewall protection
  • Regular security updates
  • Malware and antivirus protection

ORGANIZATIONAL SECURITY

Data Minimization:

  • Collect only data necessary for coaching
  • Regular review and deletion of unnecessary data
  • Automatic deletion after retention periods

Business Continuity:

  • Regular encrypted backups
  • Disaster recovery procedures

Incident Response:

  • Data breach response procedures established
  • Monitoring for unauthorized access
  • Regular security assessments

DATA BREACH NOTIFICATION

In the Event of a Data Breach:

Notification to Authorities:

  • Malta Data Protection Authority notified within 72 hours of breach discovery

Notification to Affected Individuals:

  • Direct notification without undue delay if breach poses high risk
  • Clear explanation of nature of breach, consequences, and measures taken

10. DATA RETENTION PERIODS

Active Client Data: Duration of coaching relationship plus 7 years

Health Information and Coaching Records:

  • Retention: 7 years from last service date
  • Reason: Malta professional record-keeping requirements for health-related services

Financial and Payment Records:

  • Retention: 5 years from transaction date
  • Reason: Malta tax compliance and financial record-keeping obligations

Marketing and Communication Consent:

  • Retention: Until consent withdrawn
  • Action: Immediate removal from marketing lists upon withdrawal

General Correspondence:

  • Retention: Duration of relationship plus 3 years

After Retention Periods Expire:

  • Secure deletion using data destruction procedures
  • Complete removal from all systems and backups
  • Anonymization of any data used for statistics (no personal identifiers)

11. COOKIES AND TRACKING TECHNOLOGIES

CURRENT STATUS: MINIMAL TRACKING

Currently, we collect minimal technical data. No cookies or sophisticated tracking is currently implemented on the website.

FUTURE IMPLEMENTATION (Will Require Consent)

If we implement cookies or tracking in the future, we will:

  • Provide clear cookie banner with choices before setting non-essential cookies
  • Obtain consent for non-essential cookies and tracking
  • Provide cookie preference center for granular control
  • Allow easy withdrawal of consent anytime

Potential Future Cookie Categories:

  • Essential Cookies (No consent required): Session management, security, website functionality
  • Analytics Cookies (Requires consent): Understanding website usage, aggregated data only
  • Marketing Cookies (Requires explicit consent): Personalized content, measuring campaign effectiveness

12. CHILDREN’S PRIVACY

Primary Audience: Services designed primarily for adults 18+

Services for Minors (Under 18):

  • Explicit consent from parent or legal guardian required
  • Parent must review and agree to all policies
  • Parent signs Client Coaching Agreement on behalf of minor
  • Additional care and safeguards for health data of minors

Parental Rights:

  • Full access to minor’s information
  • Right to withdraw consent and terminate services anytime
  • Right to access, correct, or delete minor’s data

NO Marketing to Children: No marketing or promotional communications to children under 16

13. CHANGES TO THIS PRIVACY POLICY

How We Update:

  • Material changes communicated directly to active clients via email
  • Updated effective date clearly displayed
  • Previous versions available upon request

For Material Changes:

  • 30 days advance notice before changes take effect
  • Clear explanation of what is changing and why
  • Option to object or withdraw consent if you disagree
  • Right to terminate services if you don’t accept changes

14. COMPLAINTS AND SUPERVISORY AUTHORITY

Step 1: Contact Us Directly

  • Method: Contact form at hamishhurley.com
  • Subject Line: “Privacy Complaint” or “Data Protection Concern”
  • Response: We will investigate and respond within 30 days

Step 2: Malta Data Protection Authority

  • Website: dataprotection.gov.mt
  • Email: idpc.info@idpc.mt
  • Phone: +356 2328 7100
  • Address: Level 2, Airways House, High Street, Sliema SLM 1549, Malta

Step 3: Your Local Data Protection Authority

  • EU/EEA Residents: Right to lodge complaint with supervisory authority in your country
  • Full list: edpb.europa.eu
  • UK Residents: Information Commissioner’s Office (ICO) – ico.org.uk

15. REGULATORY COMPLIANCE

GDPR COMPLIANCE WITHOUT REGISTRATION

We comply with GDPR and Malta Data Protection Act 2018 through:

  • Internal Record-Keeping: We maintain comprehensive internal records of processing activities as required by GDPR Article 30
  • No IDPC Registration Required: As a sole proprietor health coach not conducting large-scale processing, we are not required to register with Malta’s IDPC. Registration requirements were abolished in 2018 under GDPR, which focuses on accountability through internal records rather than mandatory registration
  • Accountability Measures: We maintain documentation of our legal basis for processing, data protection impact assessments where required, and compliance procedures

PROFESSIONAL STANDARDS

  • Confidentiality maintained per international coaching standards
  • Health information handled with enhanced care
  • Professional boundaries respected
  • Continuing education in data protection practices

16. SUMMARY OF KEY POINTS

What You Need to Know:

  1. We Protect Your Privacy: Your data is encrypted, secure, and never sold
  2. You Have Control: Comprehensive GDPR rights to access, correct, delete, and control your data
  3. Minimal Data Collection: We collect only what’s necessary for coaching
  4. Secure Tools: All service providers are GDPR-compliant with strong security (ProtonMail, Hipaatizer with SCCs, Proton Drive, Signal)
  5. International Transfers: Protected by encryption, SCCs, and supplementary safeguards
  6. Your Rights: Easy to exercise via contact form
  7. Transparency: Clear information about collection, use, and protection
  8. Limited Retention: 7 years for health data, 5 years for financial, deleted after
  9. No Marketing Without Consent: Opt-in only, easy opt-out anytime
  10. Complaints Welcome: Right to complain to Malta IDPC or your local authority

17. CONTACT INFORMATION

For All Privacy-Related Matters:

  • Website: https://hamishhurley.com/compliance/
  • Method: Secure contact form only
  • Subject Lines:
    • “Privacy Policy”
  • Message Body Title:
    • “Data Rights Request” – for access, rectification, erasure, portability
    • “General Inquiry” – for general questions
    • “Data Protection Concern” – for concerns about data handling
    • “Privacy Complaint” – for formal complaints
    • “Unsubscribe” – for marketing communications

Response Timeframes:

  • Data Rights Requests: 30 days (may extend to 60 days for complex requests)
  • General Inquiries: 5-7 business days
  • Urgent Security Concerns: 24-48 hours
  • Complaints: 30 days with full investigation

Why Contact Form Only: Prevents spam, ensures secure communication, allows proper tracking of requests, maintains your privacy and security

Document Control

Version: 3.0 | Effective: 1 October 2025 | Next Review: 1 October 2026

This Privacy Policy complies with GDPR, Malta Data Protection Act 2018, and international health coaching professional standards.

END OF PRIVACY POLICY

Scroll to Top