Privacy Policy
1. Who We Are
This Privacy Policy explains how personal data is collected, used, disclosed and protected when you visit iHemera.com (the "Website"), contact us, apply to work with us, or engage our services (together, the "Services"). iHemera is a digital brand of Mega Commercial Enterprises Limited, an Irish-registered company, incorporated under Company Number 726999, with its registered office at 77 Camden Street Lower, Dublin, D02 XE80, Ireland ("iHemera", "we", "us", "our").
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR") and the Irish Data Protection Acts 1988 to 2018, Mega Commercial Enterprises Limited is the data controller of the personal data described in this Policy.
Contact for all privacy matters: [email protected] · T: +353 87 148 3870 · 77 Camden Street Lower, Dublin, D02 XE80, Ireland.
2. Scope of This Policy
This Policy applies to personal data we process in connection with the Website and the Services, wherever in the world you are located. It does not apply to the practices of third parties that we do not control, including physicians, clinics, laboratories or other providers with whom you may choose to engage directly; those parties are independent controllers of the data you provide to them, and their own privacy policies apply.
3. The Personal Data We Collect
3.1 Data you provide to us
- Contact and enquiry data: your name, email address, country, telephone number where provided, and the content of any message, enquiry or correspondence you send us.
- Application data: the information you submit when requesting an invitation, including your goals, current health and lifestyle practices described in your own words, and any other information you choose to include.
- Engagement and intake data: if you become a client, the information you provide through our structured intake processes and during the engagement, which may include information about your lifestyle, routines, supplements, testing history, exercise, sleep, nutrition, spending, goals, constraints and preferences, and any documents or results you choose to share with us.
- Billing data: your billing name and address, and records of payments made. Payment card details are processed by our payment processor and are not received or stored by us.
- Consent records: records of the consents and acknowledgments you give.
3.2 Special category (health-related) data
The nature of our Services means that information you volunteer may include data concerning health within the meaning of Article 9 GDPR (for example, information about your sleep, fitness, supplement use, test results, or medical context you choose to disclose). We process such data only with your explicit consent, which we ask for separately and clearly before or at the point of collection, and only for the purpose of assessing your application and delivering the Services you have engaged. You may decline to provide any such information; where it is necessary for a particular Service, we will tell you, and the consequence of not providing it is only that the relevant part of the Service may not be able to be delivered. You may withdraw your consent at any time as described in Section 10.
3.3 Data collected automatically
- Technical data: IP address, browser type and version, device type, operating system, time zone, and referring pages, collected through server logs and, where you consent, cookies and similar technologies as described in our Cookie Policy.
- Usage data: information about how you navigate and use the Website, where analytics are enabled with your consent.
3.4 Data from third parties
We may receive limited personal data about you from a third party where a service is purchased as a gift for you (your name and contact details from the purchaser), or where a professional writes to us about a shared client with that client's authority. We do not purchase personal data from data brokers, and we do not collect personal data about you from social media platforms.
3.5 Information you provide about other people
Some parts of our intake ask about matters that necessarily involve other people — most commonly family health history, where patterns across relatives bear on the strategy we prepare for you. Information of this kind is personal data about those individuals, and where it concerns health it is special category data within the meaning of Article 9 GDPR.
We ask you to share such information only in general terms. Please do not give us the name, contact details or other identifying particulars of a relative or any other person; describing someone by their relationship to you — “a parent”, “a sibling” — is sufficient for our purposes. By providing information about another person, you confirm that you are entitled to share it with us.
We use this information solely to prepare and deliver the Services you have engaged. We do not create a separate record for the individual concerned, we do not attempt to identify or contact them, and we do not use their information for any other purpose. In these circumstances we rely on Article 14(5)(b) GDPR, which relieves a controller of the obligation to notify individuals where doing so would involve disproportionate effort; we keep that reliance under review. If you tell us that a person whose information you have shared objects to our holding it, we will delete it.
4. Purposes and Legal Bases for Processing
We process personal data only where a lawful basis applies. The purposes and corresponding legal bases are:
- Responding to enquiries and applications — legal basis: our legitimate interests in operating and administering an advisory practice, and, at your request, taking steps prior to entering into a contract (Article 6(1)(b) and 6(1)(f) GDPR); for any health-related information you volunteer, your explicit consent (Article 9(2)(a) GDPR).
- Delivering the Services under an engagement — legal basis: performance of a contract (Article 6(1)(b) GDPR); for health-related data, your explicit consent (Article 9(2)(a) GDPR).
- Billing, accounting and tax compliance — legal basis: performance of a contract and compliance with legal obligations to which we are subject (Article 6(1)(b) and 6(1)(c) GDPR).
- Maintaining records of our advice and engagements — legal basis: our legitimate interests in record-keeping, quality assurance and the establishment, exercise or defence of legal claims (Article 6(1)(f) and, where relevant, Article 9(2)(f) GDPR).
- Website operation, security and fraud prevention — legal basis: our legitimate interests in maintaining a secure, functioning Website (Article 6(1)(f) GDPR).
- Analytics and non-essential cookies — legal basis: your consent (Article 6(1)(a) GDPR and Regulation 5 of the Irish ePrivacy Regulations), which you may withdraw at any time.
- Complying with law and responding to lawful requests — legal basis: compliance with legal obligations (Article 6(1)(c) GDPR).
We do not use your personal data for third-party marketing, we do not sell or rent personal data to anyone, and we do not send marketing communications to enquirers. Where we ever propose to send you communications beyond responding to you and administering your engagement, we will ask for your consent first and you may withdraw it at any time.
5. Automated Decision-Making and Profiling
We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Analytical tools, including artificial-intelligence research tools, may be used to assist our work; all advice, verdicts and recommendations are reviewed and determined by human judgment before being provided to you.
6. Disclosure of Personal Data
We treat your personal data as confidential. We disclose it only as follows:
- Service providers (processors): carefully selected providers who process personal data on our behalf and under our instructions, including website hosting, email and secure document storage, form and scheduling tools, payment processing, accounting software, and analytical and AI-assisted research tools used in the preparation of our work. All such providers are bound by contractual obligations of confidentiality and data protection consistent with Article 28 GDPR, and we take steps to avoid including directly identifying client information in AI-assisted analysis wherever the work permits.
- Professional advisers: our legal, accounting, insurance and similar advisers, under duties of confidentiality, where reasonably necessary.
- Third parties at your direction: for example, a provider, clinic or physician to whom you ask us to make an introduction or provide context; such disclosures are made only with your recorded consent and limited to what is necessary.
- Legal and regulatory: where disclosure is required by law, court order, or a competent authority, or is necessary for the establishment, exercise or defence of legal claims, or to protect the vital interests of any person.
- Business transfers: in connection with any reorganisation, transfer or sale of our business or assets, in which case personal data may be transferred to the successor subject to this Policy or an equivalent standard of protection.
Confidentiality walls. Where Services involve more than one individual (for example couples or household engagements, gifted engagements, or company-funded engagements), we maintain strict confidentiality between the individuals concerned: information provided by one person is not disclosed to another — including a spouse, gift purchaser or employer — without that person's explicit consent.
7. International Transfers
We are established in Ireland and serve clients worldwide. Some of our service providers may process personal data outside the European Economic Area. Where personal data is transferred outside the EEA, we ensure an adequate level of protection by transferring only: (a) to countries the European Commission has found to provide adequate protection; (b) under the European Commission's Standard Contractual Clauses, supplemented where necessary by additional safeguards; or (c) under another valid transfer mechanism recognised by the GDPR. You may request further information about the safeguards applied by contacting [email protected].
8. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction, including encrypted storage and transmission, access controls and authentication, device security, restricted access on a need-to-know basis, confidentiality obligations on any person working with us, and structured document-management and retention practices. No method of transmission or storage is completely secure; if we become aware of a personal data breach affecting your rights and freedoms, we will notify you and the supervisory authority as required by law.
9. Data Retention
- Enquiries and unsuccessful or inactive applications: retained for up to twenty-four (24) months from our last interaction, then deleted, unless you ask us to delete them sooner or to keep your application open.
- Client engagement records (intake information, working files, deliverables, correspondence of record): retained for six (6) years from the end of the engagement, reflecting professional record-keeping practice and limitation periods for legal claims in Ireland, then securely destroyed.
- Billing, accounting and tax records: retained for the periods required by Irish tax and company law (generally six (6) years).
- Consent records: retained for as long as the consent remains relevant and thereafter as evidence of compliance.
- Anonymised information from which you can no longer be identified (for example, anonymised research notes in our internal knowledge base) is not personal data and may be retained indefinitely.
10. Your Rights
Subject to the conditions and exemptions set out in data protection law, you have the right to:
- Access the personal data we hold about you and receive a copy of it;
- Rectification of inaccurate or incomplete personal data;
- Erasure of your personal data in the circumstances set out in Article 17 GDPR;
- Restriction of processing in the circumstances set out in Article 18 GDPR;
- Data portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
- Object to processing based on our legitimate interests, on grounds relating to your particular situation;
- Withdraw consent at any time where processing is based on consent (including explicit consent to health-related data), without affecting the lawfulness of processing carried out before withdrawal. Withdrawal may mean that some or all of the Services can no longer be provided to you, and we will tell you if that is the case.
To exercise any right, contact [email protected]. We may need to verify your identity before acting on a request. We will respond within one month, extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it. Exercising your rights is free of charge, save that we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive.
Right to complain. You have the right to lodge a complaint with a supervisory authority, in particular the Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (www.dataprotection.ie), or with the supervisory authority of the EU member state of your habitual residence or place of work. We would, however, welcome the opportunity to address your concerns first at [email protected].
11. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy, which forms part of this Policy. Non-essential cookies are used only with your consent, which you may give, refuse or withdraw through the cookie controls on the Website.
12. Children
The Website and the Services are directed at adults and are not intended for, or offered to, anyone under the age of eighteen (18). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact [email protected] and we will delete it.
13. Third-Party Links
The Website may contain links to third-party websites, including providers, clinics, publications and resources referenced in our published material. We are not responsible for the privacy practices or content of those websites, and this Policy does not apply to them. We encourage you to review the privacy policy of every website you visit.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies or legal obligations. The date at the top of this page shows when it was last revised. Material changes affecting current clients will be notified directly. Your continued use of the Website or the Services after an updated Policy takes effect constitutes acknowledgment of the updated Policy; where a change requires consent under applicable law, we will seek it.
15. Contact
iHemera is a brand of Mega Commercial Enterprises Limited
77 Camden Street Lower, Dublin, D02 XE80, Ireland
Company Number 726999 · Republic of Ireland
[email protected] · T: +353 87 148 3870