Neurogenic Integration’s Privacy Policy
1.0 About This Policy
This Privacy Policy explains how Neurogenic Integration AS (“NI”, “we”, “us”) collects, uses, and processes personal data when you use our website, purchase our courses, memberships, events, or the TRE® Provider Certification Program, or otherwise interact with us. It also describes your rights and how to exercise them. If you have questions about this Policy, contact us using the details in Section 10 below.
- User privacy and data protection are human rights.
- We have a duty of care to the people within our data.
- Data is a liability, and we only collect and process it when necessary.
- We loathe spam as much as you do.
- We will never sell or rent your personal information. Certain personal data is made public in limited, clearly-flagged circumstances described in this Policy — for example, the public Certified Provider Directory (Section 3.4) and published podcast episodes (Section 3.8) — but only where you have agreed to that public use.
2.0 Applicable Law
This Policy is designed to comply with the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven), which implements the GDPR in Norway.
If you are located outside the EEA — including in the UK, United States, or Canada — your local law may give you additional rights beyond those described here. See Section 9, International Visitors, below.
2.1 Legal Basis for Processing Personal Data
Neurogenic Integration processes personal data in accordance with the GDPR and applicable Norwegian data protection law. Depending on the context, we rely on one or more of the following legal bases:
- Contractual necessity — to deliver courses, memberships, events, and the TRE® Provider Certification Program; to engage and manage facilitators, course-creators, and other contractors; and to maintain the public Certified Provider Directory for graduates who complete certification.
- Consent — for marketing communications, participation in recorded sessions where consent is the applicable basis, and any featured or identifiable promotional use of your image.
- Legitimate interests — for program administration, certification records, safety, quality assurance, the integrity of training programs, and general documentation of group events, balanced against your right to object.
- Legal obligation — to comply with accounting, tax, or other regulatory requirements.
Special category data related to health, nervous-system responses, or embodied experience is processed only with your explicit consent, and solely for purposes directly related to training, safety, and certification.
Sessions with Red Beard Somatic Therapy and third-party video courses are provided by separate, independent companies under their own privacy terms. NI is not the data controller for those services — see Section 6.3 for details.
3.0 Personal Information We Collect And Why
3.1 Site Visitation Tracking
Like most websites, this site uses Google Analytics (GA), Google Tag Manager (GTM), and Meta (Facebook) Pixel to understand how visitors find and use our web pages. These tools only load after you consent via our cookie banner; you can withdraw consent at any time by adjusting your cookie preferences or browser settings.
GA and GTM record data such as your geographical location, device, browser, and operating system, and your computer’s IP address — Google does not grant us access to the IP address itself. We consider Google and Meta to be third-party data processors (see Section 6.0).
This site is built on WordPress with WooCommerce and hosted by Hostinger. WordPress and Hostinger may collect standard technical data (browser type, referring site, date/time of requests) in the ordinary course of hosting the site.
3.2 Contact Forms & Email Newsletter
When you contact us or subscribe to our newsletter, your name, email, and any message content is processed. Newsletter subscribers’ name and email are forwarded to ConvertKit (Kit), our email marketing processor. General contact-form messages are sent to us by encrypted email (TLS) and are not stored with a third-party processor.
You can unsubscribe from the newsletter at any time via the link in any newsletter email, or request removal by contacting us.
3.3 Course, Membership & Event Checkout
When you register or purchase, your name, address, phone number, and email are stored in our WooCommerce database, hosted by Hostinger. Payments are processed by Stripe and PayPal, who receive your payment details directly — we do not store card data ourselves. If you book a 1:1 session, your name, email, and appointment details are processed by Acuity, our scheduling processor.
3.4 Certification Program & Sensitive Data
Participation in the TRE® Provider Certification Program involves educational, experiential, and evaluative components that may require processing additional personal data.
This may include special category data under Article 9 GDPR — physical or mental health, nervous system responses, stress or trauma-related experiences, and other information voluntarily shared in intake forms, personal sessions, supervised practice, or video review submissions.
This data is processed solely for education, training, evaluation, safety, certification decisions, and quality assurance. Participation in the Certification Program constitutes explicit consent to this processing.
Video review submissions are uploaded to your own unlisted YouTube channel for trainer review, or, where applicable, hosted via Vimeo. These recordings may include practice clients or other third parties; obtaining their consent before recording is your responsibility (see Certification Program Terms).
Provider Directory. On certification, your name and certification status are published in the public Certified Provider Directory, as described in the Certification Program Terms, on the basis of contractual necessity — this is part of what certification includes.
3.5 Facilitator & Contractor Data
If you facilitate workshops or provide services to NI under a facilitator or contractor agreement, we process your name, contact and payment details, and proof of professional liability insurance, for the purposes of engaging you, paying you, and meeting our own risk-management obligations.
3.6 Photography, Recording & Your Image
Our online and in-person sessions, classes, workshops, and events are routinely recorded on video and audio, and photographed, for documentation, education, and promotion by NI and our sister companies Integrated Human (integrated-human.com) and Red Beard Somatic Therapy (redbeardsomatictherapy.com). Because these are group settings, you may appear in general or wide-angle recordings or photos.
General documentation. We rely on our legitimate interest to capture and use this general footage, and you will be given clear notice that recording is taking place.
Your right to object. Tell NI or your facilitator before or during the session, and we will take reasonable steps to accommodate you and remove you from published materials on request where reasonably possible.
Featured promotional use. Where we want to feature you specifically and identifiably — a close-up, named image, or testimonial — we will ask for your separate consent, which you may decline or withdraw later.
Recordings and photographs from classes, workshops, and events are stored and processed via Riverside (recording) and Vimeo (hosting), which may involve storage outside the EEA — see Section 6.2, International Transfers.
For certification video reviews, see Section 3.4. For podcast guests, see Section 3.8.
3.7 Red Beard Somatic Therapy & Third-Party Courses
Sessions with Red Beard Somatic Therapy and video courses created by independent third-party educators are provided by separate, independent companies under their own privacy terms and their own data-controller responsibility. NI is not the data controller for those services, and this Policy does not cover how those companies handle your data — see their own privacy policies before booking or purchasing.
3.8 Podcast Guests
If you appear as a guest on the NI podcast, we record your name, likeness, voice, and any information you share during recording, using Riverside. The episode is hosted via Buzzsprout, and published on YouTube, Spotify, and TikTok, and syndicated automatically from Buzzsprout to other podcast directories and players (including Apple Podcasts, Amazon Music, iHeartRadio, and similar services), which pull the episode from our RSS feed and are not separately provided your personal data by us.
This processing is based on your consent, given before recording. Published episodes are retained indefinitely unless you request removal, though removal from third-party distribution platforms and directories may not always be technically possible once published, or may take time to propagate.
4.0 How We Store Your Personal Information
Course, membership, and checkout data is stored in our WooCommerce database (built on WordPress), hosted by Hostinger. Other data is held by the third-party processors named in Section 6.0, each for the purpose described in Section 3.0.
4.1 Data Retention
We keep personal data only as long as necessary for the purpose it was collected for:
- Course, membership, and event data — for the duration of your relationship with NI, plus up to 5 years afterward for accounting and tax records (bokføringsloven), unless you request earlier deletion and no legal obligation requires retention.
- Certification records (certificates, assessments, video review feedback, ethical/certification decisions) — retained indefinitely, to allow verification of certification status on request.
- Facilitator and contractor records — for the duration of the engagement, plus up to 5 years for accounting records.
- Newsletter subscribers — until you unsubscribe or request removal.
- Podcast guest recordings — retained once published unless removal is requested; see Section 3.8.
- Site analytics data — per Google’s and Meta’s standard retention windows (see their respective privacy policies).
Where a retention period above is not fixed, we apply the general test: as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce our agreements.
Participants may request access to or deletion of their personal data in accordance with applicable law. Please note that deletion of certain certification-related records may impact our ability to verify certification status.
5.0 About This Website’s Server
This website is hosted by Hostinger. All traffic between this website and your browser is encrypted and delivered over HTTPS.
6.0 Our Third-Party Data Processors
We use the following third parties to process personal data on our behalf. All are engaged under appropriate data protection safeguards, including Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework certification.
Processor | Purpose | Privacy Policy |
|---|---|---|
Google (Analytics, Tag Manager) | Site analytics | policies.google.com/privacy |
Meta (Facebook Pixel) | Retargeting / advertising | facebook.com/privacy/policy |
ConvertKit (Kit) | Email marketing, newsletter | kit.com/privacy |
Hostinger | Website hosting | hostinger.com/privacy-policy |
WooCommerce (Automattic) | E-commerce platform | automattic.com/privacy |
Stripe | Payment processing | stripe.com/privacy |
PayPal | Payment processing | paypal.com/us/legalhub/privacy-full |
Acuity Scheduling | 1:1 session booking | acuityscheduling.com/privacy |
Vimeo | Video hosting | vimeo.com/privacy |
YouTube (Google) | Unlisted video hosting for certification video reviews; podcast publishing | policies.google.com/privacy |
Riverside | Recording (classes, events, podcast) | riverside.fm/privacy |
Buzzsprout | Podcast hosting and RSS distribution | buzzsprout.com/privacy |
Spotify | Podcast publishing | spotify.com/privacy |
TikTok | Podcast/clip publishing | tiktok.com/legal/privacy-policy |
6.2 International Data Transfers
Several of our processors are located in the United States. Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses approved by the European Commission and, where the receiving company is certified, the EU-US Data Privacy Framework, as the legal basis for the transfer. You can request a copy of the relevant safeguard from us at any time.
6.3 Separate Data Controllers
Red Beard Somatic Therapy and third-party video course creators are separate, independent data controllers for the services they provide through our platform. This Policy does not cover their data handling — see Section 3.7.
7.0 Data Breaches
We will report any unlawful data breach of this website’s database or the database(s) of any of our third-party data processors to any and all relevant persons and authorities within 72 hours of the breach, where it is apparent that personal data stored in an identifiable manner has been compromised.
8.0 Your Rights & Changing Your Information
Upon request, we will tell you whether we hold any of your personal information, and provide a copy of it. If you would like to correct, update, or delete information we hold about you, contact us using the details in Section 10 below. Deletion may not be possible where it would impact our ability to provide the Services to you, or where we have a legal obligation to retain the data (see Section 4.1). We will respond to requests within a reasonable timeframe.
9.0 International Visitors
NI’s customers are located across nearly every continent. This Policy is written to meet EEA/Norwegian standards, which are among the most protective in the world. If you are located outside the EEA — including in the United States or Canada — nothing in this Policy limits any additional rights available to you under your own local law (for example, California or Quebec privacy law). Where those local rights go further than this Policy, your local rights apply.
10.0 Complaints & Supervisory Authority
If you have a concern about how we handle your personal data, contact us first at siv@neurogenic-integration.com — we aim to respond within 5 business days. If you’re not satisfied with our response, you have the right to lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority), or with the data protection authority in your own EEA country of residence. If you have a related contractual complaint rather than a data protection one, you can also contact Forbrukerrådet (the Norwegian Consumer Council).
11.0 Data Controller
The data controller of this website and the services described in this Policy is:
Neurogenic Integration AS
Organisation number: 933 271 471
Stallgata 10, 5700 Voss, Norway
Postal address: Postboks 546, 5703 Voss, Norway
12.0 Data Protection Contact
Siv Jøssang Shields
Email: siv@neurogenic-integration.com
13.0 Changes To This Privacy Policy
This Privacy Policy may change from time to time in line with legislation, industry developments, or changes to our processors or services. We recommend checking this page occasionally for updates.
14.0 Related Documents
Our Terms & Conditions and Event Waiver can be found on our website.