Privacy Policy

Siri Kalla Integrative Healthcare

Last updated: [February 1, 2026]

Siri Kalla Integrative Healthcare (organisation number 920 226 531) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the General Data Protection Regulation (GDPR), the Norwegian Personal Data Act, and applicable EU data protection laws.

1. Data Controller and Contact Information

Data controller:

Siri Kalla Integrative Healthcare

Organisation number: 920 226 531

Contact email: [email protected]

If you have questions about this Privacy Policy or wish to exercise your data protection rights, you may contact us using the email address above.

2. What Personal Data We Collect and Why

We only collect personal data that is necessary for clearly defined purposes. Depending on how you interact with us, we may collect the following:

a. Contact details

When you sign up for a webinar, newsletter, free resource, or submit a lead form (including Meta Instant Lead Forms), we may collect:

Name

Email address

Phone number (if provided)

Purpose:

To deliver the requested content, confirm registrations, provide relevant follow-up information, and communicate with you regarding your enquiry.

b. Webinar, event, and programme registrations

When you register for webinars, courses, or other educational events, we collect the information required to manage your registration.

Purpose:

To confirm your participation, send access links or materials, provide reminders, and follow up where relevant.

c. Marketing and newsletters

If you explicitly opt in to receive newsletters or marketing communications, we collect your email address and, where applicable, your name.

Purpose:

To send you the communications you have consented to.

You may unsubscribe at any time using the unsubscribe link in our emails or by contacting us directly.

d. Questionnaires and health-related information (special category data)

In some cases, we may offer optional questionnaires that include health- or fertility-related information.

Important:

Submission of health data is always voluntary

Such data is collected only with your explicit consent

Health data is used solely for the stated purpose (for example, preparation for a consultation or personalised guidance)

Health data is never used for advertising, profiling, or shared with third parties for marketing purposes.

e. Website usage and cookies

When you visit our website, we may collect limited technical data using cookies and similar technologies, only after you give consent. This may include:

Pages visited

Time and date of visit

Browser and device type

IP address (processed in accordance with GDPR)

Purpose:

To analyse website usage, improve user experience, and measure the effectiveness of our content and marketing.

f. Support and direct communication

If you contact us via email or other communication channels, we process the personal data you provide in order to respond to your enquiry.

We encourage you not to share unnecessary sensitive data through public or unsecured channels.

Providing personal data is voluntary. However, if you choose not to provide certain information (such as an email address), we may be unable to deliver the requested service.

3. Legal Basis for Processing

We process personal data only when we have a lawful basis under GDPR, including:

Consent:

For newsletters, marketing communications, marketing cookies, Meta Pixel tracking, and processing of health data.

Performance of a contract or requested service:

For webinar registrations, event participation, and delivery of requested information.

Legal obligation:

Where we are required to retain data under applicable laws (for example, accounting regulations).

Legitimate interest:

For limited analytics and service improvement, where our interests do not override your rights and freedoms.

You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

4. Consent Management

We use clear and active consent mechanisms, including:

Explicit opt-in checkboxes for newsletters and marketing

Cookie consent banners before any non-essential cookies or tracking are activated

Explicit consent before submitting health-related information

You may withdraw consent at any time by:

Clicking the unsubscribe link in our emails

Adjusting your cookie preferences

Contacting us at [email protected]

5. Processing of Health Data (Special Category Data)

Where health or fertility-related data is collected:

It is processed only with explicit consent

It is used strictly for the stated purpose

It is stored securely with restricted access

It is never shared with advertising platforms or used for marketing

It is deleted or anonymised when no longer required

You are never required to provide health data in order to access general content or marketing materials.

6. Data Processors and Third-Party Services

We use trusted service providers that act as data processors under GDPR. These processors handle data only according to our instructions and are subject to data processing agreements (DPAs).

Main processor

GoHighLevel (CRM and communication platform)

Used for:

Storing contact information

Managing email communications

Handling lead and form submissions

GoHighLevel processes data solely on our behalf and does not use it for its own purposes.

International transfers:

GoHighLevel may store data on servers located outside the EU/EEA, including the United States. Safeguards include:

EU Standard Contractual Clauses (SCCs)

Participation in the EU–US Data Privacy Framework

Additional service providers (for hosting, analytics, or support) are also bound by DPAs and GDPR-compliant safeguards.

7. Meta (Facebook and Instagram) Advertising and Analytics

We use Meta technologies, including:

Meta Pixel

Meta Instant Lead Forms

Conversions API (CAPI)

What data may be collected

When you consent to marketing cookies or submit a Meta lead form, Meta may collect:

Page visits, form submissions, and interactions

Device and browser information

IP address

A Meta identifier if you are logged into Facebook or Instagram

Purpose

Measuring advertising performance

Understanding audience engagement

Delivering relevant ads on Meta platforms

Legal relationship

For the initial collection of data via Meta Pixel and Instant Forms, Siri Kalla Integrative Healthcare and Meta Platforms Ireland Ltd. act as joint controllers.

We have accepted Meta’s Joint Controller Addendum. Meta is responsible for subsequent processing of data within its platforms.

Meta’s Privacy Policy:

https://www.facebook.com/privacy/policy

Important:

We do not send health-related or sensitive data to Meta.

8. Your Rights Under GDPR

You have the right to:

Access your personal data

Correct inaccurate data

Request deletion (“right to be forgotten”)

Restrict processing

Data portability

Object to processing, including direct marketing

Withdraw consent at any time

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):

https://www.datatilsynet.no

Requests may be sent to [email protected]. We respond within 30 days.

9. Data Retention

We retain personal data only as long as necessary:

Newsletter subscribers: Until you unsubscribe

Webinar and event participants: Typically up to 6–12 months unless further consent is given

Client or consultation data: Retained as required for service delivery and legal obligations

Health data: Retained only for the duration necessary for the stated purpose

Data is securely deleted or anonymised when no longer required.

10. Data Security

We apply appropriate technical and organisational measures, including:

Encrypted connections (HTTPS)

Access controls and authentication

Secure platforms and vendors

Regular security monitoring

Incident response procedures, including GDPR breach reporting where required

11. Transfers Outside the EU/EEA

Where international transfers occur, we ensure protection through:

Standard Contractual Clauses

EU–US Data Privacy Framework participation

Encryption and strict access controls

12. Changes to This Policy

We may update this Privacy Policy to reflect legal or operational changes. The latest version will always be available on our website. Material changes will be clearly communicated.