Privacy Policy Effective Date: July 21, 2025 (Last Updated: March 22, 2026)

At nataliemallia.com, we are committed to protecting your privacy and handling your personal information in accordance with the Personal Health Information Protection Act (PHIPA, 2004) of Ontario and the federal Personal Information Protection and Electronic Documents Act (PIPEDA). This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website [https://nataliemallia.com] and use our coaching services, including The Craving Reset.

1. Information We Collect

  • Personal Information: We collect information that you voluntarily provide, including your name, email address, phone number, and any details shared during consultations.

  • Personal Health Information (PHI): As a nutrition professional, we may collect information regarding your health history, dietary habits, and physical or mental health status to provide tailored coaching.

  • Usage Data: We collect information about your interactions with our website, such as IP address, browser type, and pages visited.

  • Cookies: We use cookies to enhance your experience. You can adjust your browser settings to refuse cookies at any time.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our coaching programs and website.

  • Manage your bookings, health assessments, and client communications.

  • Send newsletters and promotional materials related to The Craving Reset (you may opt-out at any time).

  • Improve our services based on your feedback.

  • Comply with professional and legal obligations.

3. How We Share Your Information

We do not sell or trade your personal information. We only share data in these specific cases:

  • Service Providers: With trusted third parties (e.g., MailerLite, Practice Better) who assist our business. These providers are contractually obligated to maintain confidentiality.

  • Circle of Care: We may share health information with your other healthcare providers (e.g., your GP) only with your implied or express consent to coordinate your care.

  • Legal Requirements: If required by law or in response to valid requests by public authorities (e.g., a court order).

  • Business Transfers: In the event of a merger or sale, your information may be transferred as a business asset.

4. Data Security & Residency

We implement reasonable administrative, technical, and physical safeguards to protect your information.

  • International Transfer: Your information may be stored and processed in the United States or other countries where our service providers (such as MailerLite) maintain facilities. By using our services, you consent to the transfer of information outside of Canada.

5. Your Rights and Choices

Under PHIPA and PIPEDA, you have the right to:

  • Access and receive a copy of your personal health records.

  • Correct or update inaccurate information.

  • Withdraw your consent for us to use your information (subject to legal/contractual restrictions).

  • Breach Notification: Be notified in the event of a significant privacy breach that puts your data at risk.

To exercise these rights, please contact our Privacy Officer at the email below.

6. Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect information from children.

7. Changes to This Policy

We may update this policy periodically. We will notify you of significant changes by posting the updated policy on our website.

8. Contact Us & Regulatory Filing

If you have questions or wish to make a complaint regarding our privacy practices, please contact:

Privacy Officer: Natalie Mallia Email: hello@nataliemallia.com

If we are unable to resolve your concern, you have the right to contact the Information and Privacy Commissioner of Ontario (IPC) or the Office of the Privacy Commissioner of Canada.