Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your personal information, and how we aim to handle it responsibly and in line with applicable privacy laws.
Table of Contents
Operator Identity & Scope
This Privacy Policy (“Policy”) is issued by Mama Hala Consulting Group (registered in Ontario, Canada) and Mama Hala Project Management (registered in Dubai, UAE), collectively operating under the trade name “Mama Hala Consulting” (“Operator”, “we”, “us”, or “our”). We are a professional consultation and coaching practice operated by Mama Hala. Mama Hala Consulting provides educational coaching, parenting guidance, relationship support, and family consultation; these services are supportive and non-clinical, and are not psychotherapy, clinical counselling, diagnosis, or regulated mental-health treatment. Our in-person sessions take place at shared office and business-service locations, by appointment only — these are not clinics, walk-in locations, or dedicated private offices. We maintain a presence at:
• Canada: 430 Hazeldean Rd, Ottawa, ON K2L 1E8, Canada • United Arab Emirates: HDS Business Centre, Cluster M, JLT, 34th Floor, Dubai, UAE
Contact: admin@mamahala.ca | +1 613-222-2104
This Policy applies to the mamahala.ca website (“Website”), all related products, services, and digital platforms (collectively, “Services”), including in-person consultation sessions in Canada and the UAE, online consultation sessions delivered to clients worldwide, the Mama Hala Academy, downloadable toolkits, quizzes, the AI Chat Companion, and all related communications.
This Policy is legally binding between you (“User”, “you”, or “your”) and the Operator. By accessing or using the Website and Services, you acknowledge that you have read, understood, and agree to be bound by this Policy, regardless of your geographic location. If you do not agree, you must not access or use the Website and Services.
Legal Frameworks & Compliance Standards
Mama Hala Consulting Group (Canada) and Mama Hala Project Management (UAE) are registered and operate in both Canada and the United Arab Emirates, and provide online services to clients globally under the trade name “Mama Hala Consulting.” We aim to handle your personal information responsibly and in accordance with applicable privacy and data protection laws, including:
Where these frameworks differ, we aim to follow the approach that best protects your personal information. Nothing in this Policy is intended to limit any rights you may have under applicable law.
Data We Collect
We collect and process personal data only where we have a lawful basis to do so and only to the extent necessary to provide our Services. You can browse the Website without revealing your identity; however, certain features require you to provide information. The categories of data we may collect include:
You may choose not to provide certain information, but this may limit your ability to use specific features of the Services.
Sensitive Personal & Consultation Information
As a professional consultation and coaching practice, we may collect and process sensitive personal information related to your emotional well-being, family circumstances, and personal life. This includes information you share during consultation sessions, booking forms, AI-assisted session notes, and assessment or quiz results.
We treat this information with heightened care:
• We collect and use this information only with your consent, and only to provide the consultation, coaching, and support services you have requested. • Under UAE PDPL (Article 7): Sensitive personal data requires explicit and informed consent, which we obtain before processing. • Under GDPR-aligned standards: where they apply, such data is treated as a special category and processed only with your explicit consent.
This information is never used for marketing or analytics, and is never shared with third parties for commercial purposes. Mama Hala Consulting provides educational coaching and family consultation; it is not a regulated health-care provider, and these are business records, not regulated medical, clinical, or health records.
How We Use Your Data
We act as both a data controller and data processor when handling Personal Information. We process your data only for specific, legitimate purposes:
We will never sell your personal data to third parties. We do not engage in automated decision-making or profiling that produces legal effects concerning you without human oversight.
Legal Basis for Processing
We process your personal data only where we have a lawful basis to do so. The legal bases we rely on depend on the applicable law and the nature of the processing:
• Consent: Where you have given clear, informed, and voluntary consent to the processing of your data for specific purposes. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. • Contract Performance: Where processing is necessary to perform our obligations under a contract with you (e.g., delivering consultation sessions you have booked and paid for). • Legal Obligation: Where processing is necessary to comply with a legal obligation (e.g., tax reporting, responding to lawful government requests, and business or tax record-retention requirements). • Legitimate Interest: Where processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms (e.g., improving our services, ensuring security). • Vital Interests: In exceptional circumstances, where processing is necessary to protect someone’s life or physical safety.
For sensitive information (including personal and family matters), we rely exclusively on your explicit consent, obtained before processing begins.
AI & Automated Processing
We use third-party artificial intelligence technology to enhance certain aspects of our Services. We believe in full transparency about how AI is used in our practice:
• AI Chat Companion: An AI-powered conversational assistant is available for general informational support related to our academy courses and resources. It does not provide clinical advice, diagnoses, or therapeutic interventions. • Session Preparation: AI may help prepare brief session notes and suggest a suitable service based on information you provide during booking. • Administrative Support: AI assists with invoice descriptions, email drafting, and other administrative tasks.
Important safeguards:
• AI does not make service-related decisions, provide diagnosis, psychotherapy, clinical advice, or determine the outcome of any consultation; all decisions are made by Mama Hala. • AI-generated content is reviewed and supplemented by professional judgment. • You have the right to request human review of any AI-generated assessment or recommendation. • Data processed by AI may be handled by a third-party technology provider (currently based in the United States), subject to their own terms and privacy practices. • Where AI tools are used, we aim to limit the information shared and to avoid entering unnecessary sensitive consultation information; AI-assisted administrative or service-preparation content is reviewed by Mama Hala before it is used. • AI outputs are never used to profile or make automated decisions that produce legal effects concerning you.
Third-Party Data Processors
We share your data only with trusted third-party service providers who are essential to the operation of our Services. Each processor is bound by contractual obligations to protect your data. We do not sell or share your data with unaffiliated third parties for their own purposes.
Our data processors and their roles:
We may also disclose personal data if required by law, court order, or government request, or if necessary in good faith to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a lawful government request in any jurisdiction where we operate.
Cross-Border & International Data Transfers
Because we operate in multiple jurisdictions and rely on service providers based in different countries, your personal data is transferred across international borders.
While we maintain offices in Canada and the United Arab Emirates, our Website’s hosting and database infrastructure is provided by cloud platforms that operate from the United States. As a result, personal data you submit through the Website is processed primarily on infrastructure located in the United States, and may also be processed by our other sub-processors in the United States and additional countries (as described in the Third-Party Data Processors section above).
We use reasonable safeguards to protect your information when it crosses borders, including encryption in transit and at rest, and written data-processing terms that require our service providers to protect your information and use it only on our documented instructions. We transfer only the information needed for the specific purpose, and we remain accountable for your information when it is processed on our behalf outside your country.
We keep our cross-border transfers and the safeguards above under review as our service providers and applicable laws evolve. By using our Services, you acknowledge and consent to the transfer and processing of your data as described in this section. If you have questions about the safeguards applied to a specific transfer, or concerns about transfers to a particular jurisdiction, please contact us at admin@mamahala.ca before submitting personal data.
Returning Client Recognition
When you book a session, we keep a customer record keyed by your email address so we can recognize you next time and skip the data re-entry. We treat this carefully:
We do not share your customer record with anyone. We do not use it for marketing. We do not sell it.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are:
After the applicable retention period expires, we securely delete or anonymize the data. Where we retain aggregated or anonymized data for statistical purposes, such data cannot be used to identify you.
Your Rights (Canada)
If you are located in Canada, you have the following rights under PIPEDA:
• Right of Access: You may request access to your personal data and receive confirmation of whether it is being processed. Under PIPEDA Principle 9, we will respond within 30 days. • Right to Correction: You may request correction of inaccurate or incomplete personal data. • Right to Withdraw Consent: You may withdraw your consent to the processing of your data at any time by contacting us. This may affect our ability to provide certain Services. • Right to Complain: You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe your privacy rights have been violated. • Record Access: You may request access to the personal information we hold about you, ask us to correct it, or ask how it has been shared.
To exercise any of these rights, contact us at admin@mamahala.ca. We will respond within 30 days of receiving your verified request. We will not charge a fee for reasonable access requests.
Your Rights (UAE)
If you are located in the United Arab Emirates, you have the following rights under the UAE Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021:
• Right of Access (Article 13): You may request access to your personal data that we hold. • Right to Rectification (Article 14): You may request correction of inaccurate personal data. • Right to Erasure (Article 15): You may request deletion of your personal data, subject to legal retention requirements. • Right to Restriction (Article 16): You may request that we restrict the processing of your data in certain circumstances. • Right to Data Portability (Article 17): You may request to receive your personal data in a structured, commonly used, machine-readable format. • Right to Object (Article 18): You may object to the processing of your personal data for specific purposes, including direct marketing. • Right Against Automated Decisions (Article 19): You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you. • Right to Complain: You may file a complaint with the UAE Data Office if you believe your data protection rights have been violated.
To exercise any of these rights, contact us at admin@mamahala.ca. We will respond within 30 days. There is no fee for exercising your rights.
Your Rights (International Clients)
If you are located outside Canada and the UAE, we apply GDPR-grade data protection rights as our global minimum standard. Regardless of your location, you have the right to:
• Access your personal data and obtain a copy • Rectify inaccurate or incomplete data • Request erasure of your data (“right to be forgotten”), subject to legal retention requirements • Restrict or object to certain types of processing • Receive your data in a portable format • Withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal • Not be subject to decisions based solely on automated processing that produce legal effects • Lodge a complaint with your local data protection authority
We commit to responding to all data subject requests within 30 days, regardless of your location. Contact us at admin@mamahala.ca to exercise any right. If your country has specific data protection legislation that grants you additional rights, we will honor those rights to the extent they are brought to our attention.
Data Deletion & Erasure Requests
You may request the deletion of your personal data at any time by emailing admin@mamahala.ca with the subject line “Data Deletion Request.”
To protect your privacy, we will verify your identity before acting on the request. Once your identity is confirmed, we will:
• Acknowledge receipt of your request within 5 business days. • Complete the deletion across our primary systems within 30 days. • Notify our third-party subprocessors to purge your data from their systems, in accordance with our data processing agreements. • Provide written email confirmation once the deletion is complete.
Statutory Retention Exceptions
Certain legal and regulatory obligations require us to retain specific data beyond a standard deletion request. These exceptions are strictly limited to:
• Consultation Records — Retained for a minimum of 7 years as an internal business record-retention policy. • Financial & Transactional Records — Retained for 6 to 7 years to satisfy mandatory audit and tax requirements under the Canada Revenue Agency (CRA) and the UAE Federal Tax Authority (FTA). • Legal Compliance — Any records directly relevant to an active legal hold, ongoing litigation, or an official regulatory investigation.
In the rare event that your data falls under one of these retention mandates, we will explicitly notify you of the specific legal framework requiring its preservation and the anticipated timeline. Any data retained under these exceptions is securely isolated from active databases, limited to the absolute minimum necessary, and strictly barred from any operational use or processing.
You may also use the self-serve “Delete My Account” control in your account portal at any time; the same identity-verification, timeline, and statutory exceptions described here apply.
Children’s Privacy
Our Services are not directed at children, and we do not knowingly collect personal data from minors without appropriate parental or guardian consent.
• Canada: We do not knowingly collect personal information from individuals under the age of 13 without verified parental consent. • UAE: Processing of personal data of individuals under 18 years of age for sensitive purposes requires the consent of a parent or legal guardian, in accordance with UAE PDPL. • Internationally: We comply with the higher of the applicable age threshold in the user’s jurisdiction.
If you are a parent or guardian and believe your child has provided personal data without your consent, please contact us at admin@mamahala.ca and we will promptly delete such data.
Where our services involve minors (e.g., parenting guidance, youth support, or family consultation), parental or guardian consent is obtained before any personal data is collected, and additional safeguards are applied to protect the minor’s information.
Data Breach Notification
We maintain comprehensive security measures to protect your data. In the unlikely event of a data breach involving your personal information, we will take reasonable steps to investigate, contain, and address the incident. Where required by applicable law, we will notify affected individuals and/or the relevant authorities, and we may also contact affected individuals directly where we believe there is a meaningful risk of harm
Information Security
We implement and maintain industry-standard administrative, technical, and physical safeguards to protect your personal data:
• Encryption in transit and at rest for personal data • Access controls and authentication for administrative access • A PCI-DSS Level 1 certified payment processor for card payments; no card numbers are stored on our servers • Rate limiting and abuse-prevention measures on forms and endpoints • Secure session cookies (HttpOnly, Secure, SameSite) • Regular dependency updates to address known vulnerabilities
While we strive to protect your data using these measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any security vulnerabilities that come to our attention.
Email & Communications
We send emails through a professional email delivery service. All electronic communications comply with the Canadian Anti-Spam Legislation (CASL) and applicable UAE and international anti-spam regulations.
• Transactional Emails: Booking confirmations, session reminders, payment receipts, and account notifications are sent based on your contract with us and do not require separate marketing consent. • Marketing Emails: Newsletters, service updates, and promotional content are sent only with your express opt-in consent. • Every marketing email includes a clear, one-click unsubscribe mechanism. • We honor unsubscribe requests within 10 business days (CASL requirement). • We do not purchase email lists or send unsolicited commercial messages.
If you correspond with us via email, we may retain the content of your messages, your email address, and our responses for the purpose of resolving your inquiry and maintaining a record of our communications.
Links to Third-Party Resources
Our Website may contain links to external websites, resources, or services not owned or controlled by us. We are not responsible for the privacy practices, content, or data collection of any third-party websites. We encourage you to review the privacy policy of every external site you visit.
Our linking to a third-party website does not constitute endorsement of that site’s privacy practices or content.
Changes & Amendments
We reserve the right to update this Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
• We will update the “Effective Date” at the top of this page. • For material changes that significantly affect how we process your data, we will notify you via email at least 30 days before the changes take effect. • Your continued use of the Website and Services after the effective date of the revised Policy constitutes your acceptance of the changes. • If you do not agree with the revised Policy, you should discontinue use of the Services and contact us to exercise your data rights.
Contact & Complaints
If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise any of your data rights, please contact us:
Mama Hala Consulting Attn: Privacy Inquiries 430 Hazeldean Rd, Ottawa, ON K2L 1E8, Canada Email: admin@mamahala.ca Phone: +1 613-222-2104
Regulatory Authorities:
• Canada: Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca | 1-800-282-1376 • Ontario: Information and Privacy Commissioner of Ontario — ipc.on.ca • UAE: UAE Data Office — For complaints regarding personal data processing under UAE PDPL • International: You may also contact your local data protection authority if you believe your privacy rights have been violated.
We take all privacy concerns seriously and will respond to your inquiry within 30 days.
