Trusted Data Stewardship

Privacy Policy — BrightNowSoul

BrightNowSoul operates training and advisory programs focused on conscious evolution for business owners. This privacy policy explains the categories of personal data we collect, the reasons we process that data, third parties we may share data with, and the rights available to individuals. We take a professional, risk-aware approach to handling personal information and apply organizational and technical controls aligned with international privacy best practices. The policy is intended for participants, prospective clients, suppliers, and website visitors and reflects our obligations under applicable laws and our operational needs.

  • 17-01-2026
  • BrightNowSoul
Privacy Policy — BrightNowSoul

We collect personal data necessary to deliver our courses and services, to manage registrations and payments, to respond to enquiries, and to improve program delivery. We limit collection to what is relevant and provide clear notices at the point of collection.

01

Definitions

The following definitions clarify terms used in this policy to make the statements that follow precise and actionable.

Personal data: any information that identifies or can reasonably be used to identify an individual, such as name, email address, phone number, business affiliation, or billing details.
Processing: any operation performed on personal data including collection, storage, use, disclosure, modification and deletion.
User: an individual who visits our website, registers for a course, purchases a service, or otherwise interacts with BrightNowSoul.
Service: BrightNowSoul education programs, coaching, events, digital resources, and related customer support delivered by BrightNowSoul.
Cookies: small text files placed on a device by a website to enable functionality, store preferences, and collect analytics data to improve user experience.
02

Data Collection

We collect personal data necessary to deliver our courses and services, to manage registrations and payments, to respond to enquiries, and to improve program delivery. We limit collection to what is relevant and provide clear notices at the point of collection.

03

Information You Provide

We collect personal data that you provide directly when you register, purchase, inquire, or communicate with us.

  • Full name and preferred name used for course administration and certificates.
  • Contact details: email address and telephone number for confirmations, updates and support.
  • Billing and payment information necessary to process transactions and comply with business recordkeeping requirements.
  • Business information such as company name, role, industry and Business ID when relevant to program delivery or invoicing (Business ID: 8313347586525).
  • Responses to questionnaires, assessments and feedback supplied as part of program activities.
  • Communications you send to us, including messages, requests and preferences for marketing contact.
04

Information Collected Automatically

In addition to data you provide, we automatically collect technical and usage information when you interact with our website and digital services.

  • Device and browser information such as device type, operating system, and browser version.
  • IP address, approximate geolocation derived from IP, and time stamps of visits to support security and localization.
  • Usage data including pages accessed, session duration, navigation paths and feature usage to improve the service.
  • Referral source and campaign identifiers when you arrive via a marketing link.
  • Cookies and similar identifiers used to remember preferences and measure engagement.
  • Error logs and diagnostic data collected for troubleshooting and platform stability.
05

Third-Party Services

We work with carefully selected third-party service providers to deliver platform functionality, payment processing, communications and analytics. Contracts require appropriate data protection obligations.

  • Payment processors and business service providers to handle transactions and invoicing.
  • Email and messaging platforms for course notifications, confirmations and optional newsletters.
  • Hosting, infrastructure and analytics providers to operate the website and measure performance.
06

How We Use Data

We process personal data for clearly defined operational and legal purposes relevant to delivering services to business owners and managing our relationship with participants.

  • To register, administer and deliver course content and related services.
  • To process payments, issue receipts and comply with applicable tax and accounting obligations.
  • To communicate about schedules, course updates, customer support requests and program logistics.
  • To personalize educational materials and make reasonable accessibility accommodations.
  • To send marketing communications where you have opted in and to manage your marketing preferences.
  • To detect and prevent fraud, abuse and other unauthorized activity that could affect service integrity.
  • To conduct research and analysis using aggregated or pseudonymized data to improve course design and outcomes.
  • To comply with legal obligations and to respond to lawful requests from regulators and law enforcement.
07

Legal Bases for Processing

Where applicable law requires, we rely on appropriate legal bases for processing personal data, such as consent, contract performance, legal obligations and legitimate interests.

  • Consent: where you have given clear and specific consent for marketing or optional services.
  • Performance of a contract: processing necessary to provide courses, coaching and other services you request.
  • Legal obligations: processing to meet statutory or regulatory requirements, including tax and accounting rules.
  • Legitimate interests: for security, fraud prevention, service improvements and internal business administration, balanced against individual rights.
08

Cookies and Similar Technologies

Cookies and similar technologies help BrightNowSoul maintain secure access, remember preferences and measure how services are used. You can manage cookie preferences at any time.

We use session cookies, persistent cookies, first-party cookies and, in some cases, third-party cookies provided by analytics and advertising partners.

Cookie categories include strictly necessary cookies for site operation, functional cookies for preferences, analytics cookies for usage measurement, and marketing cookies for promotional content.

You can manage or disable cookies via your browser settings and by using any available cookie preference center on our site. Disabling cookies may affect functionality and user experience.

View our Cookie Policy

09

Data Sharing and Disclosure

We disclose personal data only as needed to fulfill the purposes above, and subject to contractual safeguards where required.

  • Service providers who perform services on our behalf (payment processors, hosting, analytics, email delivery).
  • Professional advisors, auditors and legal advisors when necessary to obtain advice or comply with legal obligations.
  • Event partners, venues and facilitators when you participate in in-person or hybrid programs.
  • Authorities or other third parties when disclosure is required by law, court order or to protect safety and legal rights.
  • Successor entities in the event of a merger, acquisition or sale of assets, with notice to affected individuals where appropriate.
  • Aggregated or anonymized data that does not identify individuals, used for research and reporting.
10

International Transfers

BrightNowSoul is based in Thailand and may transfer personal data to service providers or affiliates located in other countries to deliver the services. Transfers are made only where appropriate safeguards are in place or as permitted by law.

We use contractual protections such as data processing agreements and, where applicable, standard contractual clauses, encryption and access restrictions to protect data transferred across borders.

11

Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy, and to satisfy legal, regulatory or accounting requirements.

Account and registration data is retained for the duration of the relationship and thereafter for a period consistent with contractual and legal obligations; transactional records may be retained for tax and business recordkeeping (for example, up to seven years where required by local law).

Communications and support correspondence are retained for as long as necessary to resolve issues, manage service delivery, and comply with legal obligations.

Technical logs and diagnostic data are retained for a limited period to support security monitoring and incident response, typically a rolling period aligned with operational needs.

When personal data is no longer required, we will securely delete or anonymize it. Copies may persist in backups for a limited time as part of standard disaster recovery processes.

12

Security Measures

We apply organizational, administrative and technical safeguards proportionate to the sensitivity of the data, including encryption, access controls and continuous monitoring. Security measures are reviewed periodically and updated to address evolving risks.

  • Encryption in transit (TLS) and at rest for sensitive records where appropriate.
  • Role-based access controls, multi-factor authentication for administrative access and least-privilege principles.
  • Regular security assessments, staff training on data protection and incident response procedures.
13

Your Rights

Subject to applicable law, individuals may exercise certain rights in relation to their personal data. Requests will be handled in a timely, secure and proportionate manner.

  • Right to access: request a copy of personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion of personal data where there is no overriding legal reason to retain it.
  • Right to restriction: request limitation of processing in certain circumstances.
  • Right to data portability: request transfer of data in a structured, commonly used format where applicable.
  • Right to object: object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: if processing is based on consent, you may withdraw it without affecting processing prior to withdrawal.
  • To exercise rights, contact us using the details below. We may request identity verification and will provide information about next steps and expected timelines.
14

GDPR Residents' Rights

GDPR Residents' Rights — applicability and support

If you are located in the EU/EEA, certain protections under the General Data Protection Regulation (GDPR) may apply. We will honor GDPR rights for affected individuals and respond to requests consistent with statutory timelines.

  • If you are an EU/EEA resident, you may exercise rights of access, rectification, erasure, restriction, portability and objection as provided by GDPR.
  • We maintain records of processing activities and implement appropriate safeguards for transfers involving personal data originating in the EU/EEA.
  • If you believe we have not addressed a GDPR request properly, you may file a complaint with a competent supervisory authority in your member state.
  • To initiate GDPR-related requests, please contact our data protection contact using the details below.

If you are a resident of the European Economic Area (EEA) and wish to submit a privacy complaint related to BrightNowSoul.best, please contact our Data Protection Officer at the address or email provided below. We will contribute complaints promptly, document findings and communicate outcomes in line with applicable law. For detailed information on data transfers, processing activities and legal bases, consult the Privacy Policy sections below or request a copy via the contact channel.

15

How to Exercise Your Privacy Rights

BrightNowSoul recognizes rights available under applicable data protection laws, including the right to access, rectify or request deletion of personal data, the right to obtain portability where applicable, and the right to object to or restrict processing. To initiate a request, provide a clear description of the information or action you seek and any identity verification documents required to protect your privacy. We aim to respond to verifiable requests in accordance with statutory timelines.

[email protected]

We will acknowledge receipt of verifiable privacy rights requests within 14 calendar days. Where additional verification or complexity requires more time, we will notify you with an expected completion timeframe not to exceed 60 calendar days unless local law permits longer processing.

16

Marketing Communications

BrightNowSoul may send newsletters, course updates, event invitations and product information to individuals who opt in. Marketing content is based on preferences you set when subscribing and on the services you use. Communications will comply with applicable telecommunications and electronic marketing laws in Thailand and other jurisdictions where we operate.

You may opt out of marketing communications at any time by using the unsubscribe link included in every email or by updating your communication preferences in your account. If you opt out, you may still receive transactional messages related to your courses or account activity.

17

Children and Minors

BrightNowSoul does not knowingly market services to or knowingly collect personal data from children under 16. If we become aware that data has been collected from a person under applicable age without appropriate consent, we will take steps to delete such data promptly. Parents or guardians who believe their child’s information has been provided should contact us using the details below.

18

Links to Third-Party Sites

Our website and course materials may include links to third-party websites, payment processors and content providers. Those sites have separate privacy practices and privacy policies that BrightNowSoul does not control. We advise you to review third-party policies before providing personal information.

Links to Third-Party Sites

We disclose personal data only as needed to fulfill the purposes above, and subject to contractual safeguards where required.

Cookies and Similar Technologies

View our Cookie Policy

19

Changes to This Privacy Statement

We may update this privacy information to reflect regulatory or operational changes. Material changes will be posted on BrightNowSoul.best with an updated effective date. Non-material clarifications may be made without prior notice; significant revisions will be communicated to registered users via email where required.