HOLOS COLLECTIVE, S.R.L. PRIVACY POLICY
Last modified: January 27, 2022
HOLOS Collective, S.R.L, a Costa Rican corporation together with its representatives, consultants, employees, officers, and directors (collectively “Holos Global” “we,” “us,” or “our”) operates the websites located at https://www.holos.global/ and other related sites (collectively, the “Site”) offering a space and events for individuals, through our mission to nurture wellbeing by living in harmony within self, community and nature (together with the Site, the “Services”).
Holos Global respects and protects the privacy of the users that use our Services. We maintain strict policies to ensure the privacy of those who use our Services (“End Users,” “you,” or “your”) or those who may just visit our Site without otherwise using our Services (“Visitors”). This policy (“Privacy Policy”) describes the types of information we may collect from you and our practices for collecting, using, maintaining, protecting, and disclosing such information. This Privacy Policy also includes a description of certain rights that you may have over information that we may collect from you.
By using the Services, you agree to this Privacy Policy. If you do not agree with our policies and practices, your choice is to not use our Services.
Summary of Data Collection, Disclosure and Sale
Here is short summary of data the categories of data we have collected, disclosed, and sold over the last twelve months. We do not sell data. The rest of this Privacy Policy provides more in-depth information on our privacy practices.
Identifiers, such as contact details, such as real name, alias, address, telephone number, unique personal identifiers, online identifiers, IP address, email address, and account name.
Do we collect? Yes
Will we disclose this data as part of our business? Yes
Will we sell this data? No
Categories of PI described in the California Consumer Privacy Act, GDPR or otherwise (including name, email, phone number, mailing address, birthday, SSN, driver’s license number, bank account number, health information)
Do we collect? Yes
Will we disclose this data as part of our business? Yes
Will we sell this data? No
Commercial information: (Transaction information, purchase history, financial details, and payment information)
Do we collect? No
Will we disclose this data as part of our business? No
Will we sell this data? No
Geolocation data: (device location)
Do we collect? No
Will we disclose this data as part of our business? No
Will we sell this data? No
Internet or other electronic network activity information: (Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements)
Do we collect? Yes
Will we disclose this data as part of our business? Yes
Will we sell this data? No
Inferences drawn from other personal information to create a profile about a consumer: (for example, an individual’s preferences and characteristics)
Do we collect? Yes
Will we disclose this data as part of our business? Yes
Will we sell this data? No
Biometric information
Do we collect? No
Characteristics of protected classifications under California or United States federal law
Do we collect? Yes
Audio, visual or similar information
Do we collect? Yes
Professional or employment related information
Do we collect? No
Non-public education information (per the Family Educational Rights and Privacy Act)
Do we collect? No
INFORMATION THAT HOLOS GLOBAL COLLECTS
Types of Information Collected
Personal Data
“Personal Data” is information by which you may be personally identified. Holos Global may collect the following Personal Data from you:
Name;
Email;
Mailing Address;
Phone Number;
Date of Birth;
Citizenship;
Health background or health status (including but not limited to experiences with plant medicines, what medications you are currently taking, what mental health conditions you have or have experienced in the past, whether or not you are pregnant or breastfeeding, your dietary preferences, and more) (optional based on the Services) and
Profile photo (optional).
Your bank account information, payment information, social security number, or driver’s license number may be collected by third-party vendors, including our payment processes. Such identifying information is not collected or stored by Holos Global.
Your data may be processed, collected, shared or stored by third-party vendors, including our website service provider, Easol Trading Limited, our booking service provider Retreat Guru, our third party payment processor SquareSpace, or other service providers we use to conduct business. Our Site service provider’s Privacy Policy is linked here for your convenience. Such processing, collection, sharing or storing of data by such third parties is not processed, collected, shared or stored by Holos Global.
Non-Personal Data
Non-personal data includes any data that cannot be used on its own to identify, trace, or identify a person. We may collect your device information, including GPS data and IP address.
When non-Personal Data you give to us is combined with Personal Data we collect about you, it will be treated as Personal Data and we will only use it in accordance with this Privacy Policy.
How we collect information
We collect information when you provide it do us directly through an interaction with us; for example
When you apply or register for the service;
When you fill out intake forms;
When you fill out feedback forms;
When you contact us through our Site;
When you contact us for service requests.
Why we collect and how we use your information. (Legal Basis)
We collect and use your Personal Data when we have a legitimate purpose to do so, including the following reasons:
to verify your eligibility to use the Services;
when it is necessary for the general functioning of the Services, including to contact you;
when it is necessary in connection with any contract you have entered into with us or to take steps prior to entering into a contract with us;
when we have obtained your or a third party’s prior consent;
when we have a legitimate interest in processing your information for the purpose of providing or improving our Services;
when have a legitimate interest in using the information for the purpose of contacting you, subject to compliance with Applicable Law; or
when we have a legitimate interest in using the information for the purpose of detecting, and protecting against, breaches of our policies and applicable laws.
We may use aggregated (anonymized) information about our End Users, and information that does not identify any individual, without restriction.
Information Collected from Third Parties
Information from our service providers: We may receive information about you from third-party service providers that we engage for marketing our products and services.
Information from social media sites and other publicly available sources: When you choose to login or sync your account through a third-party account, or interact or engage with us on social media sites, or other social platforms, through posts, comments, questions, instant messaging, and other interactions, we may collect such publicly accessible information, including profile information, to allow us to connect with you, improve our products, or better understand user reactions and issues. Once collected, this information may remain with us even if you delete it from the social media sites. We may also add and update information about you, from other publicly available sources.
Accessing and Controlling Your Information
If you would like to prevent us from collecting your information completely, you should cease use of our Services. You can also control certain data via these other methods:
Correction capabilities: You have the ability access and correct any inaccuracies in your personally identifiable information by contacting us at bookings@holos.global.
Opt-out of non-essential electronic communications: You may opt out of receiving newsletters and other non-essential messages by using the ‘unsubscribe' function included in all such messages or by contacting us directly at bookings@holos.global. However, you will continue to receive notices and essential transactional emails.
Optional information: You can always choose not to fill in non-mandatory fields when you submit any form linked to our services.
Under the United States California Consumer Privacy Act, the Virginia Consumer Data Protection Act, and Nevada’s privacy laws regarding notice of information collected, residents of these states have statutory data rights. We provide the same control and rights over your data no matter where you choose to live in the United States. As a user of Holos Global, you have the following control over your data:
Right to access: You have the right to access (and obtain a copy of, if required) the categories of personal information that we hold about you, including the information's source, purpose and period of processing, and the persons to whom the information is shared.
Right to rectification: You have the right to update the information we hold about you or to rectify any inaccuracies. Based on the purpose for which we use your information, you can instruct us to add supplemental information about you in our database.
Right to erasure: You have the right to request that we delete your personal information in certain circumstances, such as when it is no longer necessary for the purpose for which it was originally collected.
Right to restriction of processing: You may also have the right to request to restrict the use of your information in certain circumstances, such as when you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Right to data portability: You have the right to transfer your information to a third party in a structured, commonly used and machine-readable format, in circumstances where the information is processed with your consent or by automated means.
Right to object: You have the right to object to the use of your information in certain circumstances, such as the use of your personal information for direct marketing
If you are a resident of the European Economic Area (EEA), you may have certain rights under the European Union’s General Data Protection Regulation (GDPR). The information collected from you by us must be explained as follows in order for GDPR compliance. Please email us if you have any questions or want to exercise your rights in accordance with this Privacy Policy under these applicable laws.
Holos Global’s legal basis for the processing your data includes the necessity to contract with you and perform our Services.
Holos Global's legitimate interests in collecting such data include legitimate interests of our business, including but not limited to performing Services for you and other End Users, collecting necessary information in order to safely and accurately perform such Services, fraud prevention, information security, direct marketing, and legal compliance.
Holos Global does not collect categories of personal data from sources other than yourself.
Holos Global may transfer personal data outside of the jurisdiction, such as in Costa Rica, where we conduct our Services, such data is transferred using Google Drive technologies.
Holos Global stores this information for as long as necessary to conduct Services. We will delete any data that has not been used for a period of five (5) years or longer.
Holos Global does not use automated decision-making, such as profiling, during your application process.
If you are a citizen where which GDPR applies, you have the right to object to or restrict data processing, the right to erasure also known as the right to be forgotten, and the right to data portability.
At any time, you have the right to withdraw your consent for us to use, store, or collect your data and file a complaint with your local supervisory authority.
Exercise Your Data Rights
We acknowledge your right to request access, amendment, or deletion of your data. We also recognize that you have the right to prohibit sale of your data, but we do not sell data.
You can exercise the rights described above, by sending an email or mail to the addresses listed in the Questions and Comments section below. Only you, or an agent authorized to make a request on your behalf, may make a request related to your personal information.
We cannot respond to your request if, (i) we cannot verify your identity; or (ii) your request lacks sufficient details to help us handle the request. We will make best efforts to respond to your request withing forty five (45) days of its receipt. If we cannot respond in forty five (45) days, we will inform you, in writing, the reason for the delay and will respond to your request within 90 days. Any information we provide will only cover the twelve (12)-month period preceding the request's receipt.
We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. We are not obligated to provide responses to your data requests more than twice in a twelve (12)-month period.
Automated Data Collection Methods
Cookies A cookie is a small file placed on the hard drive of your computer. Cookies may be used to help our third party website host manage and report on your interaction with the Site.
Log Files We use means through the Services to collect IP addresses, location data, and access times.
How Long Do We Store Personal Data?
We will only retain your Personal Data for as long as is necessary to fulfil the purposes for which it is collected. This length of time may vary according to the nature of your relationship with us. Personal Data will be purged after five (5) years of nonuse of an account.
Users under the age of 16
Our Services are not intended for anyone under 18, particularly children under 16 years of age, and we do not knowingly collect Personal Data from children under 18. Participation in our Services is limited to individuals of 18 years old or older (or the age of majority in your jurisdiction). If you are under 18, do not use or register on the Services, use any of the interactive submission features on our Site, or provide any information about yourself to us. If we learn we have collected or received Personal Data from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at the email address listed below.
Do Not Track Settings
We do not track our Users over time and across third party websites to provide targeted advertising and do not specifically respond to Do Not Track (“DNT”) signals.
WHO WE SHARE DATA WITH
We may use aggregated (anonymized) information about our End Users and Visitors, and information that does not identify any individual, without restriction.
We do not sell or otherwise disclose Personal Data specific personal or transactional information to anyone except as described below.
Affiliates and Subsidiaries
We may, for our legitimate interests, share your information with entities under common ownership or control with us who will process your information in a manner consistent with this Privacy Policy and subject to appropriate safeguards. Such parent companies, affiliates, or subsidiaries may be located in Costa Rica, the United Kingdom, or the United States
Successors in Interest
We may, for our legitimate interests, share your information with a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, in which Personal Data about our End Users is among the assets transferred. You will be notified of any such change by a prominent notice displayed on our Services or by e-mail. Any successor in interest to this Privacy Policy will be bound to the Privacy Policy at the time of transfer.
Law enforcement and other governmental agencies
We may share your information when we believe in good faith that such sharing is reasonably necessary to investigate, prevent, or take action regarding possible illegal activities or to comply with legal process. This may involve the sharing of your information with law enforcement, government agencies, courts, and other organizations.
Service Providers
We may, for our legitimate interests, share certain information with contractors, service providers, third party authenticators, and other third parties we use to support our business and who are bound by contractual obligations to keep Personal Data confidential and use it only for the purposes for which we disclose it to them. Some of the functions that our service providers provide are as follows:
Host server infrastructure and storage;
Business analytics services;
User and identity verification management;
Payment processing;
Site log analytics service for activity, performance, and troubleshooting;
Marketing, sales, and service management;
Conducting our Services; and
Email management services.
We may use and disclose your personal data that you have voluntarily provided to us, including your health information, to third parties who contract with us to conduct our Services. We hereby acknowledge that any such disclosure shall be in compliance with all applicable data privacy laws, including medical privacy or health information laws to the extent such laws are applicable, in any given disclosure (“Applicable Law(s)”) and further acknowledge compliance with any such policies of covered third party entities we may work with.
THIRD-PARTY SERVICES AND WEBSITES
Holos Global is not responsible for the privacy policies or other practices employed by websites linked to, or from, our Site nor the information or content contained therein, and we encourage you to read the privacy statements of any linked third party. This includes sharing information via social media websites.
DATA STORAGE AND HOW HOLOS GLOBAL PROTECTS YOUR INFORMATION
Holos Global stores basic End User data on our servers including name, email, phone number, address, and username. Payments are not always required by End Users. If an End User makes a purchase and a payment is required, then payment information is processed and stored by our partners or service providers. Personal Data about End Users and Visitors is stored within the United States. The Services are only intended to be used inside the United States and we do not seek users from outside the United States. If you are using the Services from the EEA or other regions with laws governing data collection and use, please note that you are agreeing to the transfer of your Personal Data to the United States. The United States may have laws which are different, and potentially not as protective, as the laws of your own country. By providing your Personal Data, you consent to any transfer and processing in accordance with this Privacy Policy. For the avoidance of doubt, our Site and Services are not intended for any users outside of the United States.
Holos Global employs physical, electronic, and managerial control procedures to safeguard and help prevent unauthorized access to your information. We choose these safeguards based on the sensitivity of the information that we collect, process and store and the current state of technology. Our outsourced service providers who support our operations are also vetted to ensure that they too have the appropriate organizational and technical measures in place to protect your information.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee the security of your information transmitted to the Services. Any transmission of information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Services. In the event that there is breach in the information that we hold; we shall notify of such breach via email or via notice on the Services.
CHANGES TO THE PRIVACY POLICY
It is our policy to post any changes we make to our Privacy Policy on this page of the Site. If we make material changes to how we treat our End Users’ or Visitors’ Personal Data, we will notify you by email to the primary email address specified in your account or through a prominent notice on the Site. Such changes will be effective when posted. The date the Privacy Policy was last revised is identified at the top of the page. Your continued use of our Services following the posting of any modification to this Privacy Policy shall constitute your acceptance of the amendments to this Privacy Policy. You can choose to delete the Site and discontinue use of the Service if you do not accept any modified version of this Privacy Policy.
QUESTIONS AND COMMENTS
If you have any questions or comments about this Privacy Policy, or if you would like to file a request about the data we hold or file a deletion request, please contact Customer Support at bookings@holos.global