Skip to content
Privacy

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your personal information, and how we aim to handle it responsibly and in line with applicable privacy laws.

Effective: June 2, 2026PIPEDAUAE PDPLPrivacy-First
01

Operator Identity & Scope

This Privacy Policy (“Policy”) is issued by Mama Hala Consulting Group (registered in Ontario, Canada) and Mama Hala Project Management (registered in Dubai, UAE), collectively operating under the trade name “Mama Hala Consulting” (“Operator”, “we”, “us”, or “our”). We are a professional consultation and coaching practice operated by Mama Hala. Mama Hala Consulting provides educational coaching, parenting guidance, relationship support, and family consultation; these services are supportive and non-clinical, and are not psychotherapy, clinical counselling, diagnosis, or regulated mental-health treatment. Our in-person sessions take place at shared office and business-service locations, by appointment only — these are not clinics, walk-in locations, or dedicated private offices. We maintain a presence at:

• Canada: 430 Hazeldean Rd, Ottawa, ON K2L 1E8, Canada • United Arab Emirates: HDS Business Centre, Cluster M, JLT, 34th Floor, Dubai, UAE

Contact: admin@mamahala.ca | +1 613-222-2104

This Policy applies to the mamahala.ca website (“Website”), all related products, services, and digital platforms (collectively, “Services”), including in-person consultation sessions in Canada and the UAE, online consultation sessions delivered to clients worldwide, the Mama Hala Academy, downloadable toolkits, quizzes, the AI Chat Companion, and all related communications.

This Policy is legally binding between you (“User”, “you”, or “your”) and the Operator. By accessing or using the Website and Services, you acknowledge that you have read, understood, and agree to be bound by this Policy, regardless of your geographic location. If you do not agree, you must not access or use the Website and Services.

03

Data We Collect

We collect and process personal data only where we have a lawful basis to do so and only to the extent necessary to provide our Services. You can browse the Website without revealing your identity; however, certain features require you to provide information. The categories of data we may collect include:

Identity & Contact Data — Full name, email address, phone number, country of residence, timezone, preferred language, salutation
Booking & Scheduling Data — Service selected, appointment date and time, session mode (online or in-person), session duration, client notes, preferred language for session
Payment & Billing Data — Transaction amounts, currency, payment method type, billing address (where provided). Note: We do NOT store credit card numbers or bank account details; all payment card data is processed exclusively by our PCI-DSS compliant payment processor
Sensitive Consultation Information — AI-assisted session notes, preparation tips, consultation context, service recommendations, assessment results, and any information you voluntarily share during sessions or via forms. This information is treated as sensitive personal data under applicable laws and receives heightened protection
Educational & Program Data — Academy enrollment status, course progress, module completion, quiz answers and scores, toolkit downloads, certificate records
Communications Data — Contact form messages, email correspondence, chat transcripts with our AI Companion, newsletter subscription status
Behavioral & Analytics Data — Pages visited, services browsed, event registrations, toolkit downloads, quiz participation, referral source. This data is collected in aggregate and used only for service improvement
Technical Data — IP address (used for rate limiting and abuse prevention only, not for profiling), browser type, device information, session identifiers, cookies and local storage data as described in this Policy
Internal Denial Records — When we exercise our right under our Terms of Service §11 to refuse service, we may retain an internal record of the relevant identifiers (email address, phone number, IP address) together with the reason and date, accessible only to administrators, for abuse-prevention purposes. You may request a copy of any such record relating to you under the data-rights provisions of this Policy

You may choose not to provide certain information, but this may limit your ability to use specific features of the Services.

04

Sensitive Personal & Consultation Information

As a professional consultation and coaching practice, we may collect and process sensitive personal information related to your emotional well-being, family circumstances, and personal life. This includes information you share during consultation sessions, booking forms, AI-assisted session notes, and assessment or quiz results.

We treat this information with heightened care:

• We collect and use this information only with your consent, and only to provide the consultation, coaching, and support services you have requested. • Under UAE PDPL (Article 7): Sensitive personal data requires explicit and informed consent, which we obtain before processing. • Under GDPR-aligned standards: where they apply, such data is treated as a special category and processed only with your explicit consent.

This information is never used for marketing or analytics, and is never shared with third parties for commercial purposes. Mama Hala Consulting provides educational coaching and family consultation; it is not a regulated health-care provider, and these are business records, not regulated medical, clinical, or health records.

05

How We Use Your Data

We act as both a data controller and data processor when handling Personal Information. We process your data only for specific, legitimate purposes:

Service Delivery — Managing bookings, conducting consultation sessions, providing academy courses, delivering toolkits and resources
Payment Processing — Processing payments through our secure payment processor, generating invoices and receipts, managing billing records
AI-Assisted Support — Helping prepare brief session notes and suggest suitable services from the information you provide, to support your consultation experience
Communications — Sending booking confirmations, session reminders, receipts, and responding to your inquiries
Account Management — Maintaining your account, tracking course progress, managing session history
Service Improvement — Analyzing aggregate usage patterns (not individual behavior) to improve our Website and Services
Legal & Regulatory Compliance — Meeting obligations under PIPEDA, UAE PDPL, tax law, and other applicable regulations
Safety & Security — Preventing abuse, detecting fraud, enforcing our terms, and protecting the rights and safety of users
Marketing (Consent-Based Only) — Sending newsletters and service updates only to users who have expressly opted in, in full compliance with CASL and UAE PDPL requirements

We will never sell your personal data to third parties. We do not engage in automated decision-making or profiling that produces legal effects concerning you without human oversight.

07

AI & Automated Processing

We use third-party artificial intelligence technology to enhance certain aspects of our Services. We believe in full transparency about how AI is used in our practice:

• AI Chat Companion: An AI-powered conversational assistant is available for general informational support related to our academy courses and resources. It does not provide clinical advice, diagnoses, or therapeutic interventions. • Session Preparation: AI may help prepare brief session notes and suggest a suitable service based on information you provide during booking. • Administrative Support: AI assists with invoice descriptions, email drafting, and other administrative tasks.

Important safeguards:

• AI does not make service-related decisions, provide diagnosis, psychotherapy, clinical advice, or determine the outcome of any consultation; all decisions are made by Mama Hala. • AI-generated content is reviewed and supplemented by professional judgment. • You have the right to request human review of any AI-generated assessment or recommendation. • Data processed by AI may be handled by a third-party technology provider (currently based in the United States), subject to their own terms and privacy practices. • Where AI tools are used, we aim to limit the information shared and to avoid entering unnecessary sensitive consultation information; AI-assisted administrative or service-preparation content is reviewed by Mama Hala before it is used. • AI outputs are never used to profile or make automated decisions that produce legal effects concerning you.

08

Third-Party Data Processors

We share your data only with trusted third-party service providers who are essential to the operation of our Services. Each processor is bound by contractual obligations to protect your data. We do not sell or share your data with unaffiliated third parties for their own purposes.

Our data processors and their roles:

Payment Processor (United States) — A PCI-DSS Level 1 certified payment processor handles all payment card transactions. We never store credit card numbers on our servers.
Email Delivery Service (United States) — A professional email delivery service processes transactional and marketing emails on our behalf, handling email addresses and message content.
Calendar & Video Conferencing Platform (United States) — A secure calendar and video conferencing platform manages appointment scheduling and hosts online consultation sessions. Appointment details and participant email addresses are shared.
AI Service Provider (United States) — A third-party AI service provider powers the Chat Companion, session preparation tools, and administrative support features. Processes text data submitted to AI features.
Cloud Hosting & Computing Provider (United States) — A cloud hosting platform provides website hosting, serverless computing, and edge delivery. Processes all data transmitted through the Website.
Managed Database Service (United States) — A managed database service hosts session data, analytics, lead records, and booking information.
Messaging Platform (opt-in) — If you choose to communicate with us via WhatsApp or provide a WhatsApp number, a third-party messaging platform processes your phone number and message content to deliver session-related and administrative messages.

We may also disclose personal data if required by law, court order, or government request, or if necessary in good faith to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a lawful government request in any jurisdiction where we operate.

09

Cross-Border & International Data Transfers

Because we operate in multiple jurisdictions and rely on service providers based in different countries, your personal data is transferred across international borders.

While we maintain offices in Canada and the United Arab Emirates, our Website’s hosting and database infrastructure is provided by cloud platforms that operate from the United States. As a result, personal data you submit through the Website is processed primarily on infrastructure located in the United States, and may also be processed by our other sub-processors in the United States and additional countries (as described in the Third-Party Data Processors section above).

We use reasonable safeguards to protect your information when it crosses borders, including encryption in transit and at rest, and written data-processing terms that require our service providers to protect your information and use it only on our documented instructions. We transfer only the information needed for the specific purpose, and we remain accountable for your information when it is processed on our behalf outside your country.

We keep our cross-border transfers and the safeguards above under review as our service providers and applicable laws evolve. By using our Services, you acknowledge and consent to the transfer and processing of your data as described in this section. If you have questions about the safeguards applied to a specific transfer, or concerns about transfers to a particular jurisdiction, please contact us at admin@mamahala.ca before submitting personal data.

10

Cookies & Local Storage

Our Website uses a limited number of cookies, local-storage mechanisms, and basic first-party analytics, primarily for functional purposes. We do not use third-party advertising or tracking cookies.

Cookies we set:

booking_session — Functional cookie (HttpOnly, Secure, SameSite=Lax). Maintains your session when managing bookings. Expires at end of browser session.
academy_session — Functional cookie (HttpOnly, Secure, SameSite=Lax). Maintains your session when accessing academy content. Expires at end of browser session.
mh_preview — Internal administrative cookie used only by the Operator for testing purposes. Not set for regular users.
SessionStorage keys — Used for analytics deduplication to prevent counting the same page view multiple times. Cleared when you close the browser tab. No personal data is stored.

You can manage or delete cookies through your browser settings. Disabling functional cookies may affect your ability to use certain features such as booking management and academy access. For detailed instructions on managing cookies, consult your browser’s help documentation.

11

Returning Client Recognition

When you book a session, we keep a customer record keyed by your email address so we can recognize you next time and skip the data re-entry. We treat this carefully:

Soft recognition only — typing a known email triggers a hint to send you a sign-in link, but never auto-fills any personal information without verification.
Magic-link verification — to actually pre-fill your details, you must click a one-time link we email you. This proves you are the account owner before any personal data is shown.
Explicit opt-in — we only persist your details for next time when you tick the "Remember me on this device" checkbox during booking.
Data we remember — name, phone, country, last service booked, and your preferred session mode. Nothing more.
Retention — customer records are kept for 24 months from your last booking, then automatically deleted unless legal retention rules require longer (e.g., paid invoices kept 7 years for tax purposes).
Self-serve controls — sign in to your account portal anytime to download a copy of your data (right to portability) or delete it entirely (right to erasure). See the "Your Rights" sections below.

We do not share your customer record with anyone. We do not use it for marketing. We do not sell it.

12

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are:

Consultation Records — We generally retain consultation records for 7 years from the date of the last session as an internal business record-retention policy, unless a shorter or longer period is required by applicable law or needed for legitimate business, tax, safety, dispute-resolution, or legal purposes
Financial & Transactional Records — 6 to 7 years, as required by the Canada Revenue Agency (CRA) and the UAE Federal Tax Authority (FTA)
Contact Inquiries — 2 years from the date of submission, or until you request deletion
Academy & Course Progress — Duration of your enrollment plus 2 years, or until you request deletion
Analytics Data — Rolling 12-month window for aggregate statistics; individual event records deleted after 12 months
Session Cookies — Expire at the end of your browser session
Email Communications — Retained for the duration of our business relationship plus 2 years
AI Chat Transcripts — Retained for a maximum of 30 days for quality assurance, then permanently deleted

After the applicable retention period expires, we securely delete or anonymize the data. Where we retain aggregated or anonymized data for statistical purposes, such data cannot be used to identify you.

13

Your Rights (Canada)

If you are located in Canada, you have the following rights under PIPEDA:

• Right of Access: You may request access to your personal data and receive confirmation of whether it is being processed. Under PIPEDA Principle 9, we will respond within 30 days. • Right to Correction: You may request correction of inaccurate or incomplete personal data. • Right to Withdraw Consent: You may withdraw your consent to the processing of your data at any time by contacting us. This may affect our ability to provide certain Services. • Right to Complain: You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe your privacy rights have been violated. • Record Access: You may request access to the personal information we hold about you, ask us to correct it, or ask how it has been shared.

To exercise any of these rights, contact us at admin@mamahala.ca. We will respond within 30 days of receiving your verified request. We will not charge a fee for reasonable access requests.

14

Your Rights (UAE)

If you are located in the United Arab Emirates, you have the following rights under the UAE Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021:

• Right of Access (Article 13): You may request access to your personal data that we hold. • Right to Rectification (Article 14): You may request correction of inaccurate personal data. • Right to Erasure (Article 15): You may request deletion of your personal data, subject to legal retention requirements. • Right to Restriction (Article 16): You may request that we restrict the processing of your data in certain circumstances. • Right to Data Portability (Article 17): You may request to receive your personal data in a structured, commonly used, machine-readable format. • Right to Object (Article 18): You may object to the processing of your personal data for specific purposes, including direct marketing. • Right Against Automated Decisions (Article 19): You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you. • Right to Complain: You may file a complaint with the UAE Data Office if you believe your data protection rights have been violated.

To exercise any of these rights, contact us at admin@mamahala.ca. We will respond within 30 days. There is no fee for exercising your rights.

15

Your Rights (International Clients)

If you are located outside Canada and the UAE, we apply GDPR-grade data protection rights as our global minimum standard. Regardless of your location, you have the right to:

• Access your personal data and obtain a copy • Rectify inaccurate or incomplete data • Request erasure of your data (“right to be forgotten”), subject to legal retention requirements • Restrict or object to certain types of processing • Receive your data in a portable format • Withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal • Not be subject to decisions based solely on automated processing that produce legal effects • Lodge a complaint with your local data protection authority

We commit to responding to all data subject requests within 30 days, regardless of your location. Contact us at admin@mamahala.ca to exercise any right. If your country has specific data protection legislation that grants you additional rights, we will honor those rights to the extent they are brought to our attention.

16

Data Deletion & Erasure Requests

You may request the deletion of your personal data at any time by emailing admin@mamahala.ca with the subject line “Data Deletion Request.”

To protect your privacy, we will verify your identity before acting on the request. Once your identity is confirmed, we will:

• Acknowledge receipt of your request within 5 business days. • Complete the deletion across our primary systems within 30 days. • Notify our third-party subprocessors to purge your data from their systems, in accordance with our data processing agreements. • Provide written email confirmation once the deletion is complete.

Statutory Retention Exceptions

Certain legal and regulatory obligations require us to retain specific data beyond a standard deletion request. These exceptions are strictly limited to:

• Consultation Records — Retained for a minimum of 7 years as an internal business record-retention policy. • Financial & Transactional Records — Retained for 6 to 7 years to satisfy mandatory audit and tax requirements under the Canada Revenue Agency (CRA) and the UAE Federal Tax Authority (FTA). • Legal Compliance — Any records directly relevant to an active legal hold, ongoing litigation, or an official regulatory investigation.

In the rare event that your data falls under one of these retention mandates, we will explicitly notify you of the specific legal framework requiring its preservation and the anticipated timeline. Any data retained under these exceptions is securely isolated from active databases, limited to the absolute minimum necessary, and strictly barred from any operational use or processing.

You may also use the self-serve “Delete My Account” control in your account portal at any time; the same identity-verification, timeline, and statutory exceptions described here apply.

17

Children’s Privacy

Our Services are not directed at children, and we do not knowingly collect personal data from minors without appropriate parental or guardian consent.

• Canada: We do not knowingly collect personal information from individuals under the age of 13 without verified parental consent. • UAE: Processing of personal data of individuals under 18 years of age for sensitive purposes requires the consent of a parent or legal guardian, in accordance with UAE PDPL. • Internationally: We comply with the higher of the applicable age threshold in the user’s jurisdiction.

If you are a parent or guardian and believe your child has provided personal data without your consent, please contact us at admin@mamahala.ca and we will promptly delete such data.

Where our services involve minors (e.g., parenting guidance, youth support, or family consultation), parental or guardian consent is obtained before any personal data is collected, and additional safeguards are applied to protect the minor’s information.

18

Data Breach Notification

We maintain comprehensive security measures to protect your data. In the unlikely event of a data breach involving your personal information, we will take reasonable steps to investigate, contain, and address the incident. Where required by applicable law, we will notify affected individuals and/or the relevant authorities, and we may also contact affected individuals directly where we believe there is a meaningful risk of harm

19

Information Security

We implement and maintain industry-standard administrative, technical, and physical safeguards to protect your personal data:

• Encryption in transit and at rest for personal data • Access controls and authentication for administrative access • A PCI-DSS Level 1 certified payment processor for card payments; no card numbers are stored on our servers • Rate limiting and abuse-prevention measures on forms and endpoints • Secure session cookies (HttpOnly, Secure, SameSite) • Regular dependency updates to address known vulnerabilities

While we strive to protect your data using these measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any security vulnerabilities that come to our attention.

20

Email & Communications

We send emails through a professional email delivery service. All electronic communications comply with the Canadian Anti-Spam Legislation (CASL) and applicable UAE and international anti-spam regulations.

• Transactional Emails: Booking confirmations, session reminders, payment receipts, and account notifications are sent based on your contract with us and do not require separate marketing consent. • Marketing Emails: Newsletters, service updates, and promotional content are sent only with your express opt-in consent. • Every marketing email includes a clear, one-click unsubscribe mechanism. • We honor unsubscribe requests within 10 business days (CASL requirement). • We do not purchase email lists or send unsolicited commercial messages.

If you correspond with us via email, we may retain the content of your messages, your email address, and our responses for the purpose of resolving your inquiry and maintaining a record of our communications.

22

Changes & Amendments

We reserve the right to update this Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

• We will update the “Effective Date” at the top of this page. • For material changes that significantly affect how we process your data, we will notify you via email at least 30 days before the changes take effect. • Your continued use of the Website and Services after the effective date of the revised Policy constitutes your acceptance of the changes. • If you do not agree with the revised Policy, you should discontinue use of the Services and contact us to exercise your data rights.

23

Contact & Complaints

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise any of your data rights, please contact us:

Mama Hala Consulting Attn: Privacy Inquiries 430 Hazeldean Rd, Ottawa, ON K2L 1E8, Canada Email: admin@mamahala.ca Phone: +1 613-222-2104

Regulatory Authorities:

• Canada: Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca | 1-800-282-1376 • Ontario: Information and Privacy Commissioner of Ontario — ipc.on.ca • UAE: UAE Data Office — For complaints regarding personal data processing under UAE PDPL • International: You may also contact your local data protection authority if you believe your privacy rights have been violated.

We take all privacy concerns seriously and will respond to your inquiry within 30 days.