Updated December 12, 2019
For the purposes of the European Union’s General Data Protection Regulation 2016/679 or GDPR, 3W Wellness Inc. is the data controller
The information that we collect, described herein, may be stored and processed in the United States. It also may be stored and processed in countries in which we or our agents maintain facilities. By using the Site and Service, you consent to any such transfer of information outside of your country, even if data protection laws may be different in the other locations, as compared to the country where you reside. The Site makes no representation or warranty on any duty to permanently store information you may provide. By using the Site or Service and providing us with information, you waive any claims that may arise under your own or any other local or national laws, rules or regulations or international treaties.
This includes, but is not limited to, websites accessible from links found on the Site that contain pictures or information about merchandise (including but not limited to Third Wave of psychedelic-related merchandise such as clothing) or other material displayed on the Site, which can be further viewed or ordered from that other, third party website.
Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Website) and the details about the path followed within the Website with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
Cookies are small pieces of data stored on a User’s device.
Data Processors (or Service Providers):
Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
Data Subject is any living individual who is the subject of Personal Data.
The User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
The means by which the Personal Data of the User is collected and processed.
Information Collection And Use
We collect several different types of information for various purposes to provide and improve our Service to you.
Types of Data Collected:
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”).
Personally-identifiable information may include but is not limited to: Email address, Name, Address, State, Province, ZIP/Postal code, City, Cookies, and Usage Data.
We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt-out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.
You always have the option to not provide information by choosing not to use the Site, or by not using the Site feature for which information is being collected.
The Site may collect different types of information from you. This includes certain aspects of Personally Identifiable Information (“PII”). The PII that we collect with your consent may include your name, date of birth, email address, mailing address, phone number and any other information (including registration information) that you provide to us that is linked to your identity. We only collect PII that is relevant to the services that we provide and the maintenance of the Site, e.g., registering as a Member, subscribing to services, signing up for newsletters, responses to survey questions, inquiries made through our Site/phone/mail/email.
We also may collect information that relates to your Site or Service usage, such as date/time/extent of your usage of the Site and Service, your location, your usage preferences, your purchasing patterns, your interactions with other users, the Site pages you visit (and for how long), the mobile platform/service provider you use, your browser, your operating system, your IP address, and other unique device identifiers (“Other Information”).
We may compile this information, and related data, and conduct an analysis of it (using consultants or third-parties as appropriate) to make improvements to our Site or to follow up on abandoned purchases. We may also provide this information to third parties, including advertisers.
Tracking & Cookies Data
We also may collect information through “cookies” or similar technologies. “Cookies” are alphanumeric identifiers inserted and stored by your web browser, on your hard drive or via mobile IDs. Third Wave (and, potentially, third-party advertisers or other partners) may set and access cookies—including those stored on your computer or mobile device—to track and store preferential information about you, for purposes such as (i) recognizing when you return to the Site and use any Service, (ii) ensuring the Site and Service is tailored to specific needs or preferences, and (iii) personalizing content to ensure you enjoy your visit. Cookies can also be used to control the display of ads, track your Site usage patterns, record registration and personalization information, and track the various Site items that you view.
Cookie technology can facilitate the gathering of anonymous information about users on an aggregate level. Such aggregated information may be used within Third Wave and is only shared with third party advertisers on an aggregated and non-personally identifiable basis. It is possible that Internet browsers might allow users to adjust settings to prevent cookies from being downloaded to their computers. Check with the provider(s) of your particular browser(s) to find out whether and to what extent this is true for various browsers, and if so, how to make the adjustments you seek. Before you do, however, note that deleting cookies or directing your browser to refuse them may limit your ability to use certain portions of our Site that require cookies to function. We will provide you with access to PII you provide us for as long as we maintain that information in a readily accessible format. We will also work with you to correct any errors in your PII. If you wish to access or correct any PII that you have submitted through our Website or to have us completely remove your PII from our systems, please send an e-mail with your specific request to [email protected].
Examples of Cookies we use: session cookies (we use these cookies to operate our Service) and preference cookies (we use these cookies to remember your preferences and various settings).
We collect information from third-party social networking sites, including information that social networking sites provide to us if you use your credentials at such social networking sites to opt-in for some of our Services (such as your name and email address to pre-populate our sign-up form). The information you allow us to access varies by social networking site and depends on the level of privacy settings you have in place at the social networking site. You can control and find out more about these privacy settings at the applicable social networking site. We are not responsible for the privacy policies or practices of third party social networking sites.
Mode and place of processing the Data:
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. Data processing is carried out using computers and/or IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
The legal basis of data processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Note: In some jurisdictions, the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
The Data is processed at the Owner’s operating offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Use of Data
The Data concerning the User may be used for one or more of the following purposes:
- To provide and maintain our Services
- To notify you about changes to our Services
- To allow you to participate in interactive features of our Service when you choose to do so
- To provide customer support
- To gather analysis or valuable information so that we can improve our Services
- To monitor the usage of our Services
- To detect, prevent and address technical issues
- To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information
If you register for the Site or any Service, you may receive newsletters, notices and/or special offers via email or text message, unless you have requested otherwise at the time of registration or as set forth below. You may unsubscribe at any time by following the instructions contained at the very end of every such email or text message or elsewhere as directed by Third Wave. If a third party vendor provides such newsletters, you may unsubscribe in accordance with the instructions provided by such third party.
If you are having problems unsubscribing please contact us at [email protected] (forwarding the email, text or newsletter and including in the Subject line the words “Unsubscribe”), and we will use reasonable efforts to remove you within seven (7) business days. Please note that Third Wave will not process any unsubscribe requests submitted as direct replies to any newsletter.
Retention of Data
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation, upon order of a competent authority, or as otherwise required by law.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after the expiration of the retention period.
Transfer Of Data
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
As noted above, we may share your PII, or non-PII-related information, with unrelated third parties (e.g., advertisers, sponsors or other vendors). We may engage a third-party service provider to handle billing for such products or Services on our behalf. Further, we may use third parties to outsource one or more aspects of our business, in which case, we would have to disclose to such third parties the PII necessary for such third parties to provide such services.
Disclosure Of Data
If Third Wave is acquired by or merged with a third-party entity, or sells all or substantially all of its assets, we reserve the right to transfer or assign the information and content we have received and collected from our users as part of such merger, acquisition, sale, or other change of control. In the unlikely event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors’ rights generally, we may not be able to control how your PII is treated, transferred, or used.
Disclosure for Law Enforcement. Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Security Of Data
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
The Site takes security measures intended to protect confidential information and keep it free from alteration. However, the Internet is not a secure environment and the nature of security risks evolves; the technical and organizational industry standards relating to the management of those risks also evolve. While we strive to keep our technology secure and may upgrade as we deem appropriate, based on new tools that may become available in the future, the security of any information collected, stored or used by us cannot be guaranteed.
If you ever discover inaccuracies in our data or in your PII, or if you become aware of your information or PII being made available online without authorization, we urge you to notify us immediately. In the unlikely event an unauthorized third party compromises the Site’s security measures, the Site will not be responsible for any damages directly or indirectly caused by an unauthorized third party’s ability to view, use or disseminate such information. You hereby acknowledge that Third Wave shall not be responsible or liable for any dissemination of your information that results from your disclosure of such information to any third party.
Legal Basis for Processing Personal Data Under General Data Protection Regulation (GDPR)
The Owner may process your Personal Data because:
- We need to perform a contract with you
- You have given us permission to do so
- The processing is in our legitimate interests and it’s not overridden by your rights
- For payment processing purposes
- To comply with the law
Your Data Protection Rights Under General Data Protection Regulation (GDPR)
Where the European Union’s General Data Protection Regulation 2016/679, or GDPR, applies, in certain circumstances and subject to data processing agreements, you have rights in relation to the personal information we hold about you. We set out below an outline of those rights and how to exercise those rights. Please note that we will require you to verify your identity before responding to any requests to exercise your rights by providing details only known to the account holder. To exercise any of your rights, please send an email to [email protected]. Please note that for each of the rights below we may have valid legal reasons to refuse your request and, in such instances, we will let you know if that is the case.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
- The right to access, update or to delete the information we have on you.
- The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right to object. You have the right to object to our processing of your Personal Data.
- The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format.
- The right to withdraw consent. You also have the right to withdraw your consent at any time where the Owner relied on your consent to process your personal information.
Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Platform services and hosting
These services have the purpose of hosting and running key components of this website, therefore allowing the provision of this website from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
We may use Google to remarket to Website Visitors. For example, if you previously visited our website and expressed interest in a product, we may serve you advertisements containing a discount when you visit Google or other websites in the Google Audience Network.
- Note that third-party vendors, including Google, may show our ads on their websites based on information gathered during your visit.
We use Facebook Custom Audiences to deliver advertisements to Website Visitors on Facebook based on email addresses that you have shared with us, providing you have granted us permission to do so. You may learn more about Facebook Custom Audiences by visiting the Facebook help center.
We also may use information associated with Visitor social media accounts, such as demographic and other information about an individual’s title, industry or organization, to improve our marketing efforts.
We may use the information we have collected from you to enable us to display advertisements. As an example, we may purchase advertisements which are presented selectively to users who have expressed an interest in participating in live workshops.
Data Processing Solutions
Typeform is a survey service. Sometimes, we direct our visitors/clients to surveys. This way we collect personal data to improve our services, understand the needs of our clients regarding our services and for marketing purposes.
Personal Data collected by Typeform: None
Personal Data collected by us with Typeform: Full name, email, various Data regarding education, financial status, geographical location.
WooCommerce is a WordPress eCommerce plugin. WooCommerce is made by Automattic, the corporate arm of WordPress. Personal data collected are necessary for the purchase process.
Zapier is an API service that connects various Websites that we work with (WordPress, WooCommerce, Process Street, Acuity Scheduling, Google Sheets). With Zapier, we process data between these Websites (full name and email).
Personal Data collected with Zapier: None.
AffiliateWP is a WordPress plugin that tracks and processes user data for the purpose of monitoring referral sources and allocating affiliate commissions.
User Database Management
This type of service allows the Owner to build user profiles by starting from an email address, a personal name, or other information that the User provides to this website, as well as to track User activities through analytics features. This Personal Data may also be matched with publicly available information about the User (such as social networking profiles) and used to build private profiles that the Owner can display and use for improving this website.
Some of these services may also enable the sending of timed messages to the User, such as emails based on specific actions performed on this website.
ActiveCampaign (ActiveCampaign, Inc.)
ActiveCampaign is a User database management service provided by ActiveCampaign, Inc.
AirTable (Formagrid, Inc.)
Airtable is a cloud collaboration service.
We may use third-party Service Providers to monitor and analyze the use of our Service.
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this website, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
Personal Data collected: Cookies and Usage Data.
We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing (e.g. payment processors).
The payment processors we work with are:
PayPal or Braintree
Traffic optimization and distribution
This type of service allows this website to distribute their content using servers located across different countries and to optimize their performance.
Which personal data is processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this website and the User’s browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information User are transferred.
Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc.
The way Cloudflare is integrated means that it filters all the traffic through this website, i.e., communication between this website and the User’s browser, while also allowing analytical data from this website to be collected.
Amazon Web Services (AWS)
Amazon Web Services (AWS) is a secure cloud services platform, offering computing power, database storage, content delivery, and other functionality to help businesses scale and grow. Explore how millions of customers are currently leveraging AWS cloud products and solutions to build sophisticated Websites with increased flexibility, scalability and reliability.
This type of service analyzes the traffic of this website, potentially containing Users’ Personal Data, with the purpose of filtering it from parts of traffic, messages, and content that are recognized as SPAM.
Akismet (Automattic Inc.)
Akismet is a SPAM protection service provided by Automattic Inc.
Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of this website and interact with them.
This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Google Fonts (Google Inc.)
Google Fonts is a typeface visualization service provided by Google Inc. that allows this website to incorporate the content of this kind on its pages.
YouTube video widget (Google Inc.)
YouTube is a video content visualization service provided by Google Inc. that allows this website to incorporate the content of this kind on its pages.
Personal Data collected: Cookies and Usage Data.
Additional information about Data collection and processing
The User’s Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Website or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User’s Personal Data
System logs and maintenance
For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (System logs) use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
How “Do Not Track” requests are handled
This Website does not support “Do Not Track” requests. To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.
Links To Other Sites
As noted in the Legal Disclaimer, the Site is intended for mature audiences. People under the age of 21 should not be using the Site. Relatedly, the privacy of children is of the utmost importance—again, children should not be accessing or using the Site, but the privacy of children nevertheless remains of utmost importance—and we are committed to complying with the Children’s Online Privacy Protection Act (COPPA). This Website does not knowingly collect, use, or disclose PII from children under the age of 13. If we ever discover that we have inadvertently collected PII from children under the age of 13, we will delete it as soon as possible. If you are a parent or legal guardian and believe that we have collected PII from your child under the age of 13, please email us at [email protected], and we will take steps to delete this PII as soon as possible.