Neurogenic Integration’s Privacy Policy
1.0 About This Policy
This Privacy Policy explains how Neurogenic Integration AS (“NI”, “we”, “us”) collects, uses, and processes personal data when you use our website, purchase our courses, memberships, events, or the TRE™ Provider Certification Program, or otherwise interact with us. It also describes your rights and how to exercise them. If you have questions about this Policy, contact us using the details in Section 10 below.
- User privacy and data protection are human rights.
- We have a duty of care to the people within our data.
- Data is a liability, and we only collect and process it when necessary.
- We loathe spam as much as you do.
- We will never sell or rent your personal information. Certain personal data is made public in limited, clearly-flagged circumstances described in this Policy — for example, the public Certified Provider Directory (Section 3.4) and published podcast episodes (Section 3.8) — but only where you have agreed to that public use.
2.0 Applicable Law
This Policy is designed to comply with the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven), which implements the GDPR in Norway.
If you are located outside the EEA — including in the UK, United States, or Canada — your local law may give you additional rights beyond those described here. See Section 9, International Visitors, below.
2.1 Legal Basis for Processing Personal Data
Neurogenic Integration processes personal data in accordance with the GDPR and applicable Norwegian data protection law. Depending on the context, we rely on one or more of the following legal bases:
- Contractual necessity — to deliver courses, memberships, events, and the TRE™ Provider Certification Program; to engage and manage facilitators, course-creators, and other contractors; and to maintain the public Certified Provider Directory for graduates who complete certification.
- Consent — for marketing communications, participation in recorded sessions where consent is the applicable basis, and any featured or identifiable promotional use of your image.
- Legitimate interests — for program administration, certification records, safety, quality assurance, the integrity of training programs, and general documentation of group events, balanced against your right to object.
- Legal obligation — to comply with accounting, tax, or other regulatory requirements.
Special category data related to health, nervous-system responses, or embodied experience is processed only with your explicit consent, and solely for purposes directly related to training, safety, and certification.
Third-party video courses are provided by separate, independent companies under their own privacy terms. NI is not the data controller for those services — see Section 6.3 for details.
3.0 Personal Information We Collect And Why
3.1 Site Visitation Tracking
Like most websites, this site uses Google Analytics (GA), Google Tag Manager (GTM), and Meta (Facebook) Pixel to understand how visitors find and use our web pages. These tools only load after you consent via our cookie banner; you can withdraw consent at any time by adjusting your cookie preferences or browser settings.
GA and GTM record data such as your geographical location, device, browser, and operating system, and your computer’s IP address — Google does not grant us access to the IP address itself. We consider Google and Meta to be third-party data processors (see Section 6.0).
This site is built on WordPress with WooCommerce and hosted by Hostinger. WordPress and Hostinger may collect standard technical data (browser type, referring site, date/time of requests) in the ordinary course of hosting the site.
3.2 Contact Forms & Email Newsletter
When you contact us or subscribe to our newsletter, your name, email, and any message content is processed. Newsletter subscribers’ name and email are forwarded to ConvertKit (Kit), our email marketing processor. General contact-form messages are sent to us by encrypted email (TLS) and are not stored with a third-party processor.
You can unsubscribe from the newsletter at any time via the link in any newsletter email, or request removal by contacting us.
3.3 Course, Membership & Event Checkout
When you register or purchase, your name, address, phone number, and email are stored in our WooCommerce database, hosted by Hostinger. Payments are processed by Stripe and PayPal, who receive your payment details directly — we do not store card data ourselves. Certification programme personal sessions and video review sessions are scheduled via Acuity, our scheduling processor — see Section 3.4.
3.4 Certification Program & Sensitive Data
Participation in the TRE™ Provider Certification Program involves educational, experiential, and evaluative components that may require processing additional personal data.
This may include special category data under Article 9 GDPR — physical or mental health, nervous system responses, stress or trauma-related experiences, and other information voluntarily shared in intake forms, personal sessions, supervised practice, or video review submissions.
This data is processed solely for education, training, evaluation, safety, certification decisions, and quality assurance. Participation in the Certification Program constitutes explicit consent to this processing.
Session delivery by independent contractors. Personal sessions and video review sessions are delivered by independent contractors engaged by NI, not by NI employees. These contractors process your data as processors acting on NI’s instructions, under a signed data-processing agreement that requires them to: access your information only through NI-designated systems (Acuity for scheduling); keep it confidential; apply appropriate security measures; not store or retain it beyond what’s needed to deliver the session; and notify NI within 24 hours of any suspected data breach. Where a contractor’s session involves special category data — for example, health or nervous-system information you share — they are contractually bound to handle it with the same care described above.
Video review submissions. Video review submissions are uploaded to your own unlisted YouTube channel for trainer review, or, where applicable, hosted via Vimeo. You share the video link directly with your reviewer for this purpose; NI does not download, store, or retain a copy of the recording at any point — access is limited to viewing via the link you provide. These recordings may include practice clients or other third parties; obtaining their consent before recording is your responsibility (see Certification Program Terms).
Provider Directory. On certification (or, for audit graduates, on completing the audit and signing the separate Directory Listing Agreement), the following is published in the public Certified Provider Directory on the basis of contractual necessity — this is part of what a listing includes: your name, the organisation and year you were certified by, your NI audit-completion year (where applicable), your TRE™ trainer title and year (if you hold one), qualifications and degrees, other certifications and licences, your biography, photograph, and contact details and links, as you supply them. This is described further in the Provider Directory Listing Agreement.
3.5 Facilitator & Contractor Data
If you facilitate workshops or provide services to NI under a facilitator or contractor agreement, we process your name, contact and payment details, and proof of professional liability insurance, for the purposes of engaging you, paying you, and meeting our own risk-management obligations.
3.6 Photography, Recording & Your Image
Our online classes and workshops are delivered and recorded via Zoom, and the recordings are stored in Vimeo for our member library. Our in-person sessions, classes, and events are also routinely recorded on video and audio, and photographed, for documentation, education, and promotion by NI and our sister companies Integrated Human (integrated-human.com) and Red Beard Somatic Therapy (redbeardsomatictherapy.com). Because these are group settings, you may appear in general or wide-angle recordings or photos.
General documentation. We rely on our legitimate interest to capture and use this general footage, and you will be given clear notice that recording is taking place.
Your right to object. Tell NI or your facilitator before or during the session, and we will take reasonable steps to accommodate you and remove you from published materials on request where reasonably possible.
Featured promotional use. Where we want to feature you specifically and identifiably — a close-up, named image, or testimonial — we will ask for your separate consent, which you may decline or withdraw later.
Podcast episodes and NI’s own pre-recorded lesson content are produced using Riverside and hosted on Vimeo. For certification video reviews, see Section 3.4. For podcast guests, see Section 3.8. For in-person events, see Section 3.10, In-Person Events.
3.7 Third-Party Video Courses
Video courses created by independent third-party educators are provided by separate, independent companies under their own privacy terms and their own data-controller responsibility. NI is not the data controller for those services, and this Policy does not cover how those companies handle your data — see their own privacy policies before purchasing.
3.8 Podcast Guests
If you appear as a guest on the NI podcast, we record your name, likeness, voice, and any information you share during recording, using Riverside. The episode is hosted via Buzzsprout and Vimeo, and published on YouTube, Spotify, and TikTok, and syndicated automatically from Buzzsprout to other podcast directories and players (including Apple Podcasts, Amazon Music, iHeartRadio, and similar services), which pull the episode from our RSS feed and are not separately provided your personal data by us.
This processing is based on your consent, given before recording. Published episodes are retained indefinitely unless you request removal, though removal from third-party distribution platforms and directories may not always be technically possible once published, or may take time to propagate.
3.9 Programme Audit Applicants
If you apply for the self-paced Programme on an audit basis, we collect a copy of your existing TRE™ Provider certificate, together with the name of your certifying organisation and the year you were certified, to assess your eligibility. NI may disclose this certification information directly to your certifying organisation to confirm it is valid and has not been withdrawn or revoked. This is processed on the basis of contractual necessity, to process your application.
3.10 In-Person Events — Health Self-Certification & Emergency Contacts
If you attend an in-person retreat, workshop, class, or course, the Event Waiver you sign asks you to confirm certain health information — for example, whether you have a history of conditions such as epilepsy, psychiatric conditions, or recent surgery — so that you can assess for yourself whether you should obtain medical clearance before taking part. This is special category health data under Article 9 GDPR, processed only with your explicit consent, given by signing the Waiver, and used solely for your own safety self-assessment — NI does not review, assess, or act on this information beyond holding your signed confirmation on file.
The Waiver also asks for an emergency contact’s name and phone number. This is personal data about a third party that you provide to us; we hold it solely in case of a medical emergency during the event, and do not use it for any other purpose. Please make sure your emergency contact is aware you have shared their details with us for this reason.
4.0 How We Store Your Personal Information
Course, membership, and checkout data is stored in our WooCommerce database (built on WordPress), hosted by Hostinger. Other data is held by the third-party processors named in Section 6.0, each for the purpose described in Section 3.0.
4.1 Data Retention
We keep personal data only as long as necessary for the purpose it was collected for, or for as long as needed to establish, exercise, or defend legal claims (GDPR Article 17(3)(e)), including where special category data is involved (Article 9(2)(f)). Retention periods are tiered according to the nature of the record:
Tier 1 — Financial and bookkeeping records (5 years). Invoices, payment records, and accounting documentation are retained for 5 years after the end of the financial year they relate to, as required under Norwegian bookkeeping law (bokføringsloven).
Tier 2 — Contracts and related records (10 years after the relationship ends). Course, membership, and certification agreements, facilitator and contractor agreements, Programme Audit applications, and refund records are retained for 10 years after the relationship ends, reflecting the general limitation period for contractual claims under Norwegian law (foreldelsesloven § 10 no. 4).
Tier 3 — Waivers, health data, and incident records (up to 20 years). Event Waivers, health self-certifications, informed-consent records, personal-session and certification-related health data (see Section 3.4), and incident records are retained for up to 20 years after the activity they relate to, reflecting the long-stop limitation period for personal-injury claims under Norwegian law (foreldelsesloven § 9).
Certification records (certificates, assessments, video review feedback, ethical/certification decisions) are retained indefinitely, to allow verification of certification status on request.
Newsletter subscribers’ data is retained until you unsubscribe or request removal. Podcast guest recordings are retained once published unless removal is requested; see Section 3.8. Site analytics data is retained per Google’s and Meta’s standard retention windows.
Where a retention period above does not apply to a particular record, we apply the general test: as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce our agreements.
Participants may request access to or deletion of their personal data in accordance with applicable law. Please note that deletion of a record before the period above has elapsed may impact our ability to defend against a claim, verify certification status, or meet our own legal obligations.
5.0 About This Website’s Server
This website is hosted by Hostinger. All traffic between this website and your browser is encrypted and delivered over HTTPS.
6.0 Our Third-Party Data Processors
We use the following third parties to process personal data on our behalf. All are engaged under appropriate data protection safeguards, including Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework certification.
|
Processor |
Purpose |
Privacy Policy |
|---|---|---|
|
Google (Analytics, Tag Manager) |
Site analytics |
policies.google.com/privacy |
|
Meta (Facebook Pixel) |
Retargeting / advertising |
facebook.com/privacy/policy |
|
ConvertKit (Kit) |
Email marketing, newsletter |
kit.com/privacy |
|
Hostinger |
Website hosting |
hostinger.com/privacy-policy |
|
WooCommerce (Automattic) |
E-commerce platform |
automattic.com/privacy |
|
Stripe |
Payment processing |
stripe.com/privacy |
|
PayPal |
Payment processing |
paypal.com/us/legalhub/privacy-full |
|
Acuity Scheduling |
Scheduling for certification personal sessions and video review sessions |
acuityscheduling.com/privacy |
|
Zoom |
Live class/workshop delivery and recording |
zoom.us/privacy |
|
Vimeo |
Video hosting (member library, podcast) |
vimeo.com/privacy |
|
YouTube (Google) |
Unlisted video hosting for certification video reviews; podcast publishing |
policies.google.com/privacy |
|
Riverside |
Recording (podcast, NI’s own lesson content) |
riverside.fm/privacy |
|
Buzzsprout |
Podcast hosting and RSS distribution |
buzzsprout.com/privacy |
|
Spotify |
Podcast publishing |
spotify.com/privacy |
|
TikTok |
Podcast/clip publishing |
tiktok.com/legal/privacy-policy |
6.2 International Data Transfers
Several of our processors are located in the United States. Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses approved by the European Commission and, where the receiving company is certified, the EU-US Data Privacy Framework, as the legal basis for the transfer. You can request a copy of the relevant safeguard from us at any time.
6.3 Separate Data Controllers
Third-party video course creators are separate, independent data controllers for the services they provide through our platform. This Policy does not cover their data handling — see Section 3.7.
7.0 Data Breaches
We will report any unlawful data breach of this website’s database or the database(s) of any of our third-party data processors to any and all relevant persons and authorities within 72 hours of the breach, where it is apparent that personal data stored in an identifiable manner has been compromised.
8.0 Your Rights & Changing Your Information
Upon request, we will tell you whether we hold any of your personal information, and provide a copy of it. If you would like to correct, update, or delete information we hold about you, contact us using the details in Section 10 below. Deletion may not be possible where it would impact our ability to provide the Services to you, or where we have a legal obligation to retain the data (see Section 4.1). We will respond to requests within a reasonable timeframe.
9.0 International Visitors
NI’s customers are located across nearly every continent. This Policy is written to meet EEA/Norwegian standards, which are among the most protective in the world. If you are located outside the EEA — including in the United States or Canada — nothing in this Policy limits any additional rights available to you under your own local law (for example, California or Quebec privacy law). Where those local rights go further than this Policy, your local rights apply.
10.0 Complaints & Supervisory Authority
If you have a concern about how we handle your personal data, contact us first at siv@neurogenic-integration.com — we aim to respond within 5 business days. If you’re not satisfied with our response, you have the right to lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority), or with the data protection authority in your own EEA country of residence. If you have a related contractual complaint rather than a data protection one, you can also contact Forbrukerrådet (the Norwegian Consumer Council).
11.0 Data Controller
The data controller of this website and the services described in this Policy is:
Neurogenic Integration AS
Organisation number: 933 271 471
Stallgata 10, 5700 Voss, Norway
Postal address: Postboks 546, 5703 Voss, Norway
12.0 Data Protection Contact
Siv Jøssang Shields
Email: siv@neurogenic-integration.com
13.0 Changes To This Privacy Policy
This Privacy Policy may change from time to time in line with legislation, industry developments, or changes to our processors or services. We recommend checking this page occasionally for updates.
14.0 Related Documents
Our Terms & Conditions and Event Waiver can be found on our website.