This Privacy Policy describes how Wristnystrength ("we," "us," or "our"), operating at https://wristnystrength.world, collects, uses, discloses, and protects personal data when you visit our website or use our non-clinical nutrition coaching and educational services. We do not collect health records for medical treatment purposes through this website. We are committed to transparency and compliance with the General Data Protection Regulation (GDPR) where it applies, relevant United States privacy laws including state consumer privacy laws where applicable, and industry best practices for data protection.
1. Data controller
The data controller responsible for your personal data is:
Wristnystrength
1801 Race St, Cincinnati, OH 45202, USA
Phone: +1 513-665-4839
Email: assist@wristnystrength.world
Website: https://wristnystrength.world
For privacy-related inquiries, including exercising your rights, contact us using the details above. We will respond within the timeframes required by applicable law, generally within 30 days for GDPR requests.
2. Scope of this policy
This policy applies to personal data processed through our website, contact forms, coaching engagements, educational product purchases, email correspondence, and cookie technologies described in our Cookie Policy. It does not apply to third-party websites linked from our pages, which maintain their own privacy practices.
3. Categories of personal data we collect
3.1 Data you provide directly
- Identity and contact data: name, email address, phone number if supplied, and mailing address when relevant for in-person services.
- Communication content: messages submitted through our contact form or email, including topics you wish to discuss regarding nutrition education.
- Consent records: timestamps and scope of GDPR or marketing consents you provide.
- Coaching-related information: dietary preferences, schedules, and goals you choose to share during sessions. We do not require medical diagnoses to receive general coaching.
- Payment-related data: billing name and transaction references when you purchase programs. Card details are processed by payment providers; we do not store full card numbers on our servers.
3.2 Data collected automatically
- Technical data: IP address, browser type, device type, operating system, and referring URL.
- Usage data: pages viewed, time on page, and interaction events when analytics cookies are accepted.
- Cookie identifiers as described in our Cookie Policy.
4. Purposes and legal bases for processing
We process personal data only for specified, explicit purposes:
- Service delivery: To respond to inquiries, schedule consultations, and provide nutrition coaching and educational materials you request. Legal basis: contract performance and pre-contractual steps (GDPR Art. 6(1)(b)).
- Communication: To send administrative messages about bookings, policy updates, or support. Legal basis: legitimate interests in operating our business (Art. 6(1)(f)) or consent where required.
- Marketing: To send information about programs and resources where you have opted in. Legal basis: consent (Art. 6(1)(a)). You may withdraw consent at any time.
- Analytics: To understand website usage and improve content, only with cookie consent. Legal basis: consent (Art. 6(1)(a)).
- Legal compliance: To meet tax, accounting, and regulatory obligations. Legal basis: legal obligation (Art. 6(1)(c)).
- Security: To detect abuse, prevent fraud, and protect our systems. Legal basis: legitimate interests (Art. 6(1)(f)).
5. Data retention periods
We retain personal data only as long as necessary for the purposes outlined above:
- Contact form submissions: up to 24 months after last interaction, unless a coaching relationship continues.
- Active client coaching records: duration of engagement plus 36 months for reference and dispute resolution.
- Marketing consents and email lists: until you unsubscribe or withdraw consent, plus a minimal suppression record to honor opt-out.
- Analytics logs: up to 14 months when analytics cookies are enabled.
- Financial and tax records: as required by Ohio and federal law, typically seven years.
- Server security logs: up to 90 days unless needed for incident investigation.
When retention periods expire, we delete or anonymize data in a secure manner.
6. Sharing and international transfers
We do not sell your personal data. We may share data with:
- Service providers bound by data processing agreements (hosting, email delivery, payment processing, analytics if consented).
- Professional advisers where legally required (accountants, legal counsel under confidentiality).
- Authorities when compelled by valid legal process.
Some providers may process data in the United States or other countries. Where GDPR applies, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for transfers outside the European Economic Area.
7. Security measures
We implement technical and organizational measures appropriate to the risk, including:
- HTTPS encryption for website traffic.
- Access controls limiting employee access to personal data on a need-to-know basis.
- Secure storage of credentials and periodic review of vendor security practices.
- Procedures for reporting and responding to suspected data breaches in line with GDPR notification requirements where applicable.
No method of transmission over the Internet is completely secure. We encourage you to use strong passwords for any client portals and to contact us promptly if you suspect unauthorized access.
8. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion where no overriding legal basis requires retention.
- Restriction: Request limited processing in certain circumstances.
- Portability: Receive data you provided in a structured, machine-readable format where processing is based on consent or contract and carried out by automated means.
- Objection: Object to processing based on legitimate interests or to direct marketing at any time.
- Withdraw consent: Where processing relies on consent, withdrawal does not affect prior lawful processing.
- Complaint: Lodge a complaint with your local supervisory authority. EU residents may contact their national data protection authority.
To exercise rights, email assist@wristnystrength.world with sufficient detail to verify your identity. We may request additional information to prevent unauthorized disclosure.
9. Children
Our services are directed at adults. We do not knowingly collect personal data from children under 16 without parental consent. If you believe we have collected such data, contact us for prompt deletion.
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects without human involvement.
11. California privacy notice
California residents may have additional rights under the CCPA/CPRA, including knowing categories of data collected, requesting deletion, and opting out of sale or sharing. We do not sell personal information as defined by California law. Submit requests using the contact details in Section 1.
12. Changes to this policy
We may update this Privacy Policy to reflect legal or operational changes. The "Last updated" date at the top will change accordingly. Material changes will be communicated through the website or email where appropriate.
13. Related documents
Please also review our Cookie Policy, Terms of Use, and Refund Policy for additional information about your use of wristnystrength.world.