Privacy

Privacy notice

How The Hypno Academy handles the information you choose to share through this website. Version 2026-08-16.

What we collect

We only store information you voluntarily type into a form on this website: your name, email address and — if you choose to provide them — phone number, country, city, your message, the certifications you are interested in, your preferred format and timing, and your answers in the course finder or your conversation with Thea, our Academy Guide.

When you submit a form we also store limited context about that submission: the page you submitted from, the referring page and any campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) present in the address.

We do not use fingerprinting, hidden identity inference or visitor tracking, and we do not attempt to identify you if you do not submit a form.

Why we use it

To answer your enquiry and give you the guidance you asked for. This operational follow-up happens whether or not you accept marketing.

If — and only if — you tick the separate marketing box, to send you occasional emails about programmes, dates and learning resources. Marketing consent is never pre-ticked and never bundled into the service you requested.

Consent record

We store the exact wording you were shown, the language it was shown in, the policy version (2026-08-16) and the timestamp, so your choice is provable and auditable. You can withdraw marketing consent at any time and we will act on it.

Abuse prevention

To protect the forms against automated abuse we keep a short-lived, hashed record derived from the submitting connection for a maximum of 24 hours. It is never added to your enquiry record and never exported.

Retention

Enquiries are kept for up to 24 months from your last contact with us, after which they are deleted or anonymised. Abuse-prevention records are deleted within 24 hours. Consent records are kept for as long as needed to document your choice.

Language and location detection

When you first visit the site, we choose a default language by reading (1) your browser's own language preference, (2) whether you are on the .dk domain, and (3) a country code supplied by the server edge network (geo-IP). The geo-IP check is used only to decide whether to default to Danish.

We do not store your IP address, exact location, or any other personal data from this check. The country code is used only for the immediate language choice and is not linked to your enquiry, form submissions, or your conversation with Thea.

You can always override the automatic choice with the language switcher in the header or by adding ?lang=en or ?lang=da to the address. Our legal basis for this automated language decision is legitimate interest (GDPR Article 6(1)(f)), because showing the site in the right language is a necessary part of providing the service.

Thea conversations

Thea is our digital Academy Guide. The messages you and Thea exchange are stored together with the language of the conversation and, if you choose to give it, the email address you submit when asking to be connected with THA Team Staff.

We store these conversations for two purposes only: to follow up on questions that need a person, and to review and improve the quality and accuracy of Thea's answers.

Conversations are not readable in the browser and are not exposed through any public interface. They are accessible only to authorised Academy staff through an authenticated, allowlisted internal console, and to our hosting, database and AI model providers acting on our instructions.

Please do not share sensitive health information with Thea. If you would like a conversation deleted, or a copy of what is stored, write to registration@thehypnoacademy.com and we will act on your request.

Atlas questions in the portals

Atlas is the AI Learning Guide inside the Student and Trainer portals. When you ask Atlas a question, we store the question text, the language, the portal role it was asked from, the outcome, and the titles of the internal knowledge records used in the answer.

We do not store your name, email address or user id in this log. Your question is linked only to a one-way technical hash, so we can spot abuse patterns without identifying you.

This log is used only to check that Atlas answers accurately and to see where our knowledge needs improving. It is accessible only to authorised Academy staff through an authenticated, allowlisted internal console. Atlas cannot see your enrolments, grades or course progress.

Please do not share sensitive health information with Atlas. Write to registration@thehypnoacademy.com if you have questions about this log.

Internal handling of your enquiry

When Thea hands your conversation over to a person, we create an internal case for the Academy team. The case holds a short excerpt of the conversation, the language, the time, and the contact details you already gave us with consent — nothing more.

Academy staff may add internal notes, an owner, a priority and a due date, and may generate a reply draft from our verified knowledge. Drafts are internal suggestions only; a person reviews and sends every answer.

Internal cases are private. They are not readable from the website, and only signed-in, approved Academy staff can reach them through an authenticated internal workspace. We keep resolved cases for up to 24 months for service and quality purposes, then delete them.

Write to registration@thehypnoacademy.com to ask what we hold about your enquiry or to have it deleted.

Student and trainer accounts

If you sign in to the Student or Trainer portal, we store your email address, the sign-in record created by our authentication provider, and any profile details you choose to add yourself: your name, country and phone number, plus your preferred language.

We also store the roles and access the Academy has granted you (student, trainer or team staff), your access requests and their outcome, and — when relevant — the programme or cohort you are connected to and your certification status. This is used only to give you the right access and to run the Academy's teaching administration.

Portal records cannot be read from the browser. They are accessible only to authorised Academy staff through an authenticated, allowlisted internal console, and to our hosting and database providers acting on our instructions. Write to registration@thehypnoacademy.com to correct or delete your portal profile.

Processors

The website and its database are operated on our behalf by our hosting and database providers, and Thea, our Academy Guide, uses an AI model provider to generate her answers. They process data only on our instructions and only to deliver these functions.

Payment, enrolment and course access are handled separately on the Academy's FreshLearn platform. No payment or card details are collected on this website.

Your rights

You can request access to, correction of, or deletion of your information, object to processing, ask for a copy of your data, or withdraw marketing consent. Write to registration@thehypnoacademy.com or use the contact page and we will respond personally.

Who is responsible

The controller for the processing described here is The Hypno Academy LLC, 187 E Warm Springs Rd, STE B306, Las Vegas, NV 89119, USA. Write to registration@thehypnoacademy.com or call +1 (725) 525-9966 with any question about your data.

This notice covers this website and the Academy's handling of your information. Enrolment and course delivery take place on our learning platform, described below.

Enrolment, course access and certification

When you enrol, a member account is created on our learning platform at thehypnoacademy.freshlearn.com, operated for us by FreshLearn. That account holds your name, email address, the programmes you are enrolled in, your progress through lessons, assessment submissions and the certificates issued to you.

We use these records to deliver the training you bought, to verify who has completed which programme, to issue and re-issue certificates, and to keep the evidence a certifying body may ask us for. The legal basis is performance of our contract with you and, for keeping certification records after a programme ends, our legitimate interest in being able to verify a credential we issued.

Enrolment and certification records are kept for as long as the credential can reasonably need to be verified, and at least for the period required by applicable accounting and accreditation rules.

Payments

Payments are processed by the learning platform's payment providers, currently Stripe and PayPal. You enter your card or account details directly with them.

The Academy does not receive or store your full card number or card security code. What we see is payment metadata: the amount, currency, date, payment status, instalment schedule where a payment plan applies, the last digits and brand of the card, and the name and email used for the purchase.

We use this to fulfil the purchase, manage payment plans and refunds, and meet our bookkeeping and tax obligations. The legal basis is performance of the contract and compliance with a legal obligation. Financial records are kept for the retention period required by applicable accounting law.

Student, Trainer and Staff portals

If you have access to a private portal on this website, we store your account email, the roles granted to you, the date access was requested and approved, and — for trainers — the classes you register, the participants you submit for certification and the support requests you send us.

Participant details submitted by a trainer are used only to run the class and issue certificates. Portal activity is logged for security and audit purposes: who changed a status or a note, and when.

The legal basis is performance of our contract with students and trainers and our legitimate interest in a secure, auditable administration. These records are kept for the life of the relationship and for the period needed to document certification.

Who processes data for us

We use a small number of service providers who process personal data on our instructions under a data processing agreement:

  • Supabase — database, authentication and storage for this website and its portals.
  • Lovable — application hosting and the edge network that serves the site.
  • FreshLearn — the learning platform: member accounts, enrolment, course delivery and certificates.
  • Stripe and PayPal — payment processing (they act as independent controllers for their own compliance duties).
  • OpenAI — the language model behind Thea and Atlas, processing the message text sent in a conversation.
  • Our email and support providers — sending confirmations, answers and, where you consented, newsletters.

International transfers

The Academy is established in the United States and several of our providers process data in the United States. If you are in the EU, EEA or the UK, your information will therefore be transferred outside your region.

For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) in our agreements with providers, supplemented by the technical measures those providers apply, such as encryption in transit and at rest and access control. You can ask us for information about the safeguards that apply to a specific provider.

Your rights and how to complain

Where the GDPR or UK GDPR applies to you, you have the right of access to your data, rectification, erasure, restriction of processing, objection to processing based on legitimate interest, and data portability. You can withdraw consent — including marketing consent — at any time, and withdrawing does not affect the lawfulness of processing before you withdrew.

Write to registration@thehypnoacademy.com and we will respond, normally within one month. We may need to confirm your identity before acting on a request about someone's personal data.

If you believe we have handled your data incorrectly, you may complain to your national data protection authority. In Denmark that is Datatilsynet (datatilsynet.dk); in the UK, the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve it with you first.

Security

Data is transmitted over encrypted connections and stored in access-controlled systems. Enquiry, portal and conversation records are never exposed to the browser of a site visitor; they are readable only through authenticated internal consoles limited to specific, allowlisted staff accounts, with administrative actions logged.

Cookies

This website uses only strictly necessary cookies and browser storage — your language choice, your sign-in session in the private portals, and short-lived technical state. We do not use analytics or advertising cookies. The cookie policy explains each item in detail.

Policy version 2026-08-16