The Integrated Human AS
Privacy Policy & Data Protection
Effective date: Sept 23.2026
Registered name | The Integrated Human AS |
|---|---|
Organisation number | 923 773 312 |
Registered office | Stallgata 10, 5700 Voss, Norway |
Postal address | Postboks 546, 5703 Voss, Norway |
Contact | support@integrated-human.com |
Website | integrated-human.com |
This Policy is written to match The Integrated Human’s Terms & Conditions. Where a clause here mirrors a Terms clause, that’s noted in the section heading.
01 Purpose & Scope
1.1 What this covers. This Privacy Policy explains what personal data The Integrated Human AS (“TIH”, “we”, “us”) collects, why, how long we keep it, and what rights you have over it. It applies to everyone who visits integrated-human.com, registers for a TIH course, retreat, group session or digital product, or books a personal session with Siv Jøssang Shields.
1.2 Read alongside the Terms. This Policy should be read alongside TIH’s Terms & Conditions, which govern your purchase or use of a TIH service. Where the two documents describe the same processing — personal-session health information, for example — they’re written to match. If you ever find a difference between them, tell us at support@integrated-human.com and we’ll fix it.
02 Who We Are
2.1 Data controller. TIH is a trading name of The Integrated Human AS, a Norwegian private limited company, organisation number 923 773 312, registered office at Stallgata 10, 5700 Voss, Norway, postal address Postboks 546, 5703 Voss, Norway. We are the data controller for the personal data described in this Policy.
2.2 Contact. Reach us at support@integrated-human.com. For anything about your data specifically, contact our Privacy Contact — see Section 15.
03 Legal Basis We Rely On
3.1 The four bases. GDPR requires a lawful basis for every use of personal data. Through this Policy we rely on four:
- Contract — processing needed to sell you, and deliver, a course, retreat, session or product you’ve bought.
- Consent — processing you’ve actively agreed to, such as health information at personal-session intake, or a newsletter subscription.
- Legitimate interest — processing that helps us run TIH, such as basic site analytics or fraud prevention, weighed against your right to privacy.
- Legal obligation — processing we’re required to do, such as keeping financial records.
3.2 Which applies where. Each section below names which of these four applies to that activity.
04 What We Collect, By Activity
4.1 Visiting the website (legitimate interest). Google Analytics and Google Tag Manager record pages viewed, general location, device and browser type. Meta’s Facebook Pixel records visits for retargeting. None of this identifies you by name — see Section 6 for how you control it through cookies.
4.2 Contact forms and newsletter (consent). If you message us through the site, we collect your name, email and message. If you subscribe to our newsletter, we collect your name and email through Kit. You can unsubscribe at any time using the link in any newsletter email, or by writing to support@integrated-human.com.
4.3 Course, event and product registration (contract). Buying a course, retreat, group session or digital product, we collect your name, email, address and phone number, processed through our web store and shared with our payment processor — see Section 8.
4.4 Personal-session booking (contract, and consent for health information). Booking a personal session with Siv, we collect your name, email and phone number to arrange the session, and — separately, under its own consent — the health information described in Section 5. Payment is taken through our web store — see Section 8.
4.5 Personal-session recordings (consent). Some personal sessions are recorded so you can revisit the guidance between sessions — see the Personal Session Consent Form. TIH also keeps its own copy, for 1 year from the session, then deletes it. The recording is never used for marketing or training, and is not shared with anyone else, without your separate written consent.
05 Special-Category Health Data (Personal Sessions)
5.1 What’s collected. Before your first personal session, and before the free introductory call that precedes it, you’re asked to complete an intake form — currently a Google Form, or your answers sent directly by email — which may ask about your physical and mental health history. This can include special-category health data under GDPR Article 9.
5.2 Why, and your consent. We ask for this solely to assess whether a TIH practice is appropriate for you, and to let your practitioner work with you safely. Completing the intake form, or sending us this information by email, is your explicit consent to us processing it for that purpose.
5.3 Never for marketing. This information is never used for marketing.
5.4 Who can see it. It’s stored securely and accessible only to your practitioner and the TIH staff who need it to run your sessions.
5.5 How long we keep it. We keep it for 5 years from your last session, after which we delete it unless the law requires us to keep it longer. If you complete the intake form and don’t go on to book sessions, we delete it 6 months after you submit it. Separately, we keep a much more limited record for up to 20 years, for a different purpose — see Section 7.2.
5.6 Withdrawing consent. You can withdraw this consent at any time by writing to support@integrated-human.com, though doing so may limit our ability to keep working with you safely.
06 Cookies & Tracking
6.1 Non-essential cookies. Our website uses cookies for analytics (Google Analytics, Google Tag Manager) and advertising (Facebook Pixel). A cookie-consent banner lets you accept or decline these when you first visit, and you can change your choice at any time through that banner.
6.2 Essential cookies. Cookies needed to run the site — for example, to remember what’s in your cart — don’t require consent and can’t be declined.
07 Data Retention
7.1 By category. We keep personal data only as long as we need it:
Category | Retention | Basis |
|---|---|---|
Website analytics | 26 months | Legitimate interest |
Newsletter / marketing data | Until you unsubscribe, or 2 years of inactivity | Consent |
Course, event & checkout records | 5 years from purchase | Legal obligation |
Personal-session health intake | 5 years from your last session | Consent — see §5.5 |
Personal-session intake where no session is booked | 6 months from submission | Consent — see §5.5 |
Contact-form enquiries (no purchase) | 12 months | Legitimate interest |
Personal-session recordings | 1 year from the session | Consent |
Proof of Terms acceptance & risk/health self-disclosure (retreats, events, courses, personal sessions) | Up to 20 years from the retreat, event, course or session | Legitimate interest — legal-claim defence, GDPR Art. 17(3)(e) |
The 5-year period for course, event and checkout records reflects Norway’s bookkeeping law (bokføringsloven) and is confirmed by TIH’s accountant.
7.2 Proof of agreement. Separately from the records above, we keep a minimal record that you accepted our Terms & Conditions — including the assumption of risk (Terms §4, or §6.10 for personal sessions) and the health self-disclosure (Terms §1.5, or §6.4 for personal sessions) — for up to 20 years after your retreat, event, course or personal session. This reflects the outer time limit under Norwegian law for a personal-injury claim to be brought (foreldelsesloven §9), and is kept only to establish or defend such a claim if one is ever made. This record is limited to your name, the booking or order reference, the date, and which version of the Terms you accepted — not further detail.
Technical note: for this record to hold up, TIH’s checkout and booking flow needs its own clearly labelled, not-pre-ticked acceptance step for the risk and health-disclosure clauses specifically — not folded into a generic “I agree to the Terms” tickbox — with the acceptance timestamped and stored separately from data that gets routinely deleted on the shorter schedules above.
08 Who We Share Data With
8.1 Processors we use. We share personal data only with the processors below, and only for the purpose stated:
- Stripe, PayPal, Vipps, Klarna — payment processing
- Hostinger — website hosting
- Kit — email newsletter delivery
- Google Forms — personal-session intake
- Zoom — delivering personal sessions online
- WordPress, Elementor, WooCommerce — running the website and checkout
- YouTube — TIH’s own channel, for the podcast and other public video content
- Riverside — podcast and video recording
- Google Analytics, Google Tag Manager, Meta (Facebook Pixel) — site analytics and advertising
8.2 No sale of data. We never sell, rent or otherwise distribute your personal data to third parties outside this list.
09 International Transfers
9.1 Safeguards. Some of the processors listed in Section 8 are based outside the EU/EEA. Where that’s the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent safeguard recognised under GDPR, to protect your data in transit and once it arrives.
10 Data Security
10.1 Encryption. All traffic to and from our website is encrypted (HTTPS/TLS). Personal data submitted through the site’s forms is encrypted in transit.
10.2 Access control. Access to personal data is limited to TIH staff and practitioners who need it to do their work.
10.3 Breach notification. If personal data we hold is affected by an unlawful data breach, we’ll report it to the relevant people and authorities within 72 hours, in line with GDPR.
11 Your Rights Under GDPR
11.1 What you can ask for. You have the right to:
- Access the personal data we hold about you
- Correct it if it’s inaccurate or incomplete
- Ask us to delete it
- Restrict how we use it
- Receive it in a portable format
- Object to our processing it
- Withdraw consent at any time, for anything based on consent, without affecting processing already done
11.2 How to exercise these. Contact support@integrated-human.com or our Privacy Contact (Section 15) to exercise any of these rights.
12 Children & Minors
12.1 Minimum age. TIH’s services, and TIH accounts, are for people aged 18 and over.
12.2 No data from minors. We don’t knowingly collect or process personal data belonging to anyone under 18. If you believe a minor has given us data, contact us and we’ll delete it.
13 Complaints & Supervisory Authority
13.1 Talk to us first. If you’re unhappy with how we’ve handled your data, contact us first at support@integrated-human.com.
13.2 Data protection authority. You can also complain to Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no).
13.3 Consumer complaints. A complaint about a purchase, rather than your data specifically, can go to Forbrukertilsynet or Forbrukerklageutvalget — see Terms & Conditions Section 12.3. The European Commission’s Online Dispute Resolution platform closed on 20 July 2025 and is no longer available.
14 Changes to This Policy
14.1 Updates. We may update this Policy from time to time. The effective date is shown at the top of this document — please check back periodically.
15 Contact Us
Privacy Contact | Marit Tyssedal Gabrielsen — marit@integrated-human.com |
|---|---|
General enquiries | support@integrated-human.com |
Postal address | The Integrated Human AS, Stallgata 10, 5700 Voss, Norway |