Pranic Healers Convention Privacy Policy - Pranic Healing
2096
wp-singular,page-template-default,page,page-id-2096,wp-theme-bridge,theme-bridge,bridge-core-3.0.8,qi-blocks-1.5.3,qodef-gutenberg--no-touch,woocommerce-no-js,qodef-qi--no-touch,qi-addons-for-elementor-1.11.1,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode-title-hidden,qode_grid_1300,footer_responsive_adv,columns-3,qode-theme-ver-29.5,qode-theme-bridge,qode_header_in_grid,wpb-js-composer js-comp-ver-6.10.0,vc_responsive,elementor-default,elementor-kit-138

DATA PROTECTION AND PRIVACY POLICY
For MCKS Course and events Participants and Confidentiality Agreements

1. Purpose of this Privacy Policy
This Data Protection and Privacy Policy explains how Institute for Inner Studies Limited (“IIS Limited”) and, where applicable, Institute for Inner Studies, Inc., Philippines (“IIS Philippines”), collect, use, store, disclose, and otherwise process personal data relating to MCKS course participants and persons who complete the applicable Confidentiality, Intellectual Property and Conditions of Participation Agreement.
This Privacy Policy is intended to provide information concerning the processing of personal data in accordance with applicable data protection laws, including, where applicable, the General Data Protection Regulation (GDPR) and the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules and regulations, and applicable National Privacy Commission issuances.

2. Data Controllers
For personal data collected and processed by IIS Limited in connection with its own activities, IIS Limited acts as the relevant personal data controller/data controller to the extent provided under applicable law.
Where IIS Philippines independently determines the purposes and means of processing personal data received or collected in the Philippines, IIS Philippines may act as a separate personal information controller/data controller for such processing.
Where a party processes personal data solely on behalf of another party, the parties shall implement the appropriate contractual and organizational arrangements required under applicable data protection laws.

3. Personal Data We May Process
Depending on the nature of the course, agreement, or administrative transaction, we may process:

    • full name;
    • residential or mailing address;
    • email address;
    • telephone/mobile number;
    • date of birth;
    • course enrollment information;
    • course attendance and completion records;
    • instructor and/or course organizer information;
    • communications concerning courses and student administration;
    • records of prior MCKS courses attended or completed; and
    • information contained in forms, correspondence, or documents voluntarily submitted by the participant.
      We seek to collect only personal data that is adequate, relevant, necessary, and proportionate to the purposes for which it is processed.

    4. Purposes of Processing
    Personal data may be processed for the following purposes:
    a. administering and documenting MCKS course registrations;
    b. maintaining student and course records;
    c. verifying course participation, attendance, and completion;
    d. maintaining a history of courses attended or completed;
    e. communicating with students concerning course administration;
    f. administering the Confidentiality, Intellectual Property and Conditions of Participation Agreement;
    g. protecting the intellectual property, confidential materials, teachings, and proprietary interests of IIS and the relevant rights holders;
    h. complying with applicable legal, regulatory, accounting, and recordkeeping obligations;
    i. responding to legitimate requests concerning student records; and
    j. maintaining the security and integrity of our systems, records, and course administration processes.
    Personal data shall not be processed for purposes that are incompatible with the purposes disclosed in this Privacy Policy unless otherwise permitted by applicable law or appropriate notice and consent is obtained where required.

    5. Legal Bases for Processing
    Depending on the particular processing activity and applicable law, IIS may rely upon one or more lawful bases, including:
    a. the data subject’s consent;
    b. the necessity of processing for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract;
    c. compliance with a legal obligation;
    d. protection of vital interests; or
    e. legitimate interests, where permitted by applicable law and where such interests are not overridden by the rights and freedoms of the data subject.
    Where processing is specifically based on consent, the consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

    6. Transmission to IIS Philippines
    Where necessary for legitimate student and course administration purposes, personal data may be transmitted by IIS Limited to Institute for Inner Studies, Inc., Philippines.
    The information transmitted may include the participant’s name, address, email address, telephone/mobile number, date of birth, and relevant MCKS course history.
    The purposes of such transmission include maintaining student records, verifying course participation, administering current and future course registrations, maintaining course history, and facilitating legitimate course-related communications.

    7. Disclosure to Third Parties
    Personal data may be disclosed only where reasonably necessary for the purposes described in this Privacy Policy or where permitted or required by applicable law.
    Depending on the circumstances, recipients may include:

      • affiliated or related IIS entities;
      • authorized instructors and course organizers;
      • information technology and hosting service providers;
      • administrative and professional service providers;
      • legal, accounting, or professional advisers;
      • governmental or regulatory authorities where legally required; and
      • Other persons or entities where disclosure is necessary to establish, exercise, or defend legal rights.
        Where required by applicable law, appropriate contractual and technical safeguards shall be implemented in connection with such disclosures.
        Personal data shall not be sold or disclosed to unrelated third parties for their independent marketing purposes without the appropriate legal basis and, where required, the participant’s consent.

      8. International Transfers
      Where personal data is transferred between jurisdictions, IIS shall take reasonable and appropriate measures to ensure that the transfer is conducted in accordance with applicable data protection laws.
      Where the GDPR applies, transfers of personal data outside the European Economic Area shall be made using an applicable lawful transfer mechanism and appropriate safeguards as required under applicable GDPR provisions.
      Where required, appropriate contractual safeguards, including applicable standard contractual arrangements, shall be implemented.

      9. Data Security
      IIS and its authorized service providers shall implement reasonable and appropriate organizational, physical, and technical measures designed to protect personal data against:

        • unauthorized access;
        • unauthorized disclosure;
        • accidental or unlawful destruction;
        • accidental loss;
        • alteration;
        • misuse; and
        • Other unauthorized or unlawful processing.
          Access to personal data shall be limited to persons who require such access for legitimate and authorized purposes.

        10. Retention of Personal Data
        Personal data shall be retained only for as long as reasonably necessary to fulfill the purposes for which it was collected, to administer student and course records, to comply with applicable legal and regulatory obligations, or to establish, exercise, or defend legal claims.
        Where specific retention periods are prescribed by applicable law or internal records-management requirements, the applicable retention period shall be observed.
        When personal data is no longer required, it shall be securely deleted, destroyed, anonymized, or otherwise disposed of in accordance with applicable law and IIS’s records-retention procedures.

        11. Data Subject Rights
        Subject to applicable law and any applicable limitations or exceptions, data subjects may have the right to:
        a. obtain information concerning the processing of their personal data;
        b. request access to their personal data;
        c. request correction or rectification of inaccurate or incomplete information;
        d. request deletion or erasure where legally applicable;
        e. object to certain processing;
        f. request restriction of processing where applicable;
        g. withdraw consent where consent is the legal basis for processing;
        h. obtain or request portability of personal data where applicable; and
        i. lodge a complaint with the competent data protection authority.

        12. Philippine Data Privacy Rights
        For processing subject to Philippine law, data subjects may exercise the rights granted under Republic Act No. 10173 and applicable regulations and issuances of the National Privacy Commission, subject to applicable legal limitations.
        The Philippine Data Privacy Act requires processing to adhere to the principles of transparency, legitimate purpose, and proportionality and recognizes, among others, rights relating to information, access, correction, objection, and complaint.

        13. Questions, Requests and Complaints
        For questions concerning the collection, use, storage, disclosure, or processing of personal data, or to exercise applicable data subject rights, please contact:
        Email: info@globalpranichealing.com
        Written requests should identify the data subject and reasonably describe the information or action being requested.
        Where appropriate, IIS may request additional information to verify the identity of the requesting individual before processing a data subject request.

        14. Changes to this Privacy Policy
        IIS may amend this Privacy Policy from time to time to reflect changes in applicable laws, regulatory requirements, processing activities, systems, or organizational practices.
        Where required by applicable law, material changes affecting the processing of personal data shall be communicated to affected data subjects and any additional consent required by law shall be obtained.

        15. Acknowledgment
        By signing the applicable consent or course participation documentation, the participant acknowledges that he or she has been provided with and has had the opportunity to read and understand this Data Protection and Privacy Policy.