Integrated Privacy Policy (Including GDPR Compliance)
Privacy Policy for www.DrEnidMartinez.com
Effective Date: December 1, 2025
Dr. Enid F. Martinez | The Heart Helix LLC (“we,” “us,” or “our”) values your privacy and is committed to safeguarding your personal information. This Privacy Policy describes the types of information we may collect from you, how we use and protect that information, and the rights you have regarding your data.
This Policy applies to all users of our website, www.DrEnidMartinez.com (the “Site”), as well as to any related services, communications, or features offered through the Site.
By accessing or using this Site, you consent to the practices described in this Policy. If you do not agree with the terms of this Policy, you must immediately discontinue use of the Site.
For users located in the European Union (EU) or European Economic Area (EEA), this Policy also outlines your rights under the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).
We encourage you to read this Privacy Policy carefully and contact us with any questions regarding how your personal data is handled.
1. Information We Collect
Nature of Services and Sensitive Information
The services provided by Dr. Enid F. Martinez | The Heart Helix LLC are intended solely for personal, spiritual, and holistic well-being and do not constitute medical diagnosis, treatment, or therapy. Any references to energy medicine, intuitive guidance, or wellness sessions are for informational and self-development purposes only.
During sessions, clients may voluntarily share information that could relate to their emotional, physical, or spiritual state. Such information is considered “special category data” under Article 9 of the GDPR and is processed only with the client’s explicit, informed consent, kept confidential, and handled in accordance with data-minimization and purpose-limitation principles.
Clients should not provide medical records or details of clinical diagnoses unless directly relevant to the requested service. Where such data is shared, it will be securely stored and deleted once it is no longer necessary for the stated purpose.
Children’s Privacy
Our services and website are intended for individuals aged 16 and above. We do not knowingly collect, use, or disclose personal information from children under the age of 16.
If we become aware that we have inadvertently received personal data from a minor without verifiable parental consent, we will promptly delete such information in accordance with applicable law, including Article 8 of the GDPR and the U.S. Children’s Online Privacy Protection Act (COPPA).
Parents or guardians who believe that their child has provided personal data to us may contact [email protected] to request its deletion or to provide the necessary consent where legally permissible.
When you access or use our Site, we may collect the following categories of information:
1. Technical and Usage Data
i. IP addresses, browser type, operating system, device identifiers, and browsing patterns.
ii. Log data such as pages visited, time spent on the Site, referral links, and general demographic information (non-identifiable).
iii. This data is primarily collected through cookies and similar technologies (see our Cookie Policy).
2. Personal Identification Data (Voluntarily Provided)
i. Name, email address, phone number, and other contact information you provide through online forms, bookings, or direct communication.
ii. Professional or business details if you choose to share them in inquiries.
3. Transaction and Payment Data
i. Payment details provided when booking services or making purchases.
ii. Payments are processed securely via trusted third-party providers (e.g., PayPal, Stripe, or other processors).
iii. We do not store full credit card numbers or sensitive financial information on our servers.
4. Communications Data
i. Records of inquiries, service requests, feedback, or correspondence you send us directly (via email, forms, or other channels).
ii. Session notes or intake details provided voluntarily during client interactions, where applicable.
5. Special Category Data (if applicable under GDPR)
i. While we do not require sensitive personal data, clients may voluntarily disclose health-related or wellness-related information in the context of services.
ii. Such data is processed with your explicit consent and handled confidentially.
2. Use of Cookies
Our Site uses cookies and similar tracking technologies to improve user experience, analyze traffic, and customize content. Cookies are small text files placed on your device when you visit a website.
1. Types of Cookies We Use
i. Strictly Necessary Cookies: Essential for core functions of the Site, such as navigation and security. These cannot be disabled.
ii. Performance & Analytics Cookies: Collect anonymous information about how visitors use our Site (e.g., pages visited, time spent, errors encountered) to help us improve functionality.
iii. Functional Cookies: Remember your preferences (such as language settings) to provide a more personalized experience.
iv. Marketing/Advertising Cookies: Track browsing behavior to deliver relevant ads or promotions. These are used only if explicitly enabled and consented to.
2. How We Use Cookies
i. To operate and maintain the Site effectively.
ii. To monitor traffic and user interactions to improve performance.
iii. To provide customization (e.g., language or display settings).
iv. To comply with legal obligations, including GDPR consent requirements.
3. Consent for Cookies (GDPR Compliance)
i. If any provision of this Agreement is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid portion shall be interpreted as closely as possible to reflect the original intent of the parties.
ii. You will have the option to:
- Accept all cookies (including analytics and marketing);
- Reject all non-essential cookies; or
- Customize preferences by category (e.g., performance, functionality, marketing).
iii. Your consent will be recorded and securely stored to demonstrate compliance. You may withdraw or modify your consent at any time by selecting “Cookie Settings” in the website footer or via your browser settings.
iv. The Heart Helix LLC maintains a detailed Cookie Register documenting the type, purpose, provider, and retention period of each cookie, which is available upon request to satisfy the accountability principle under Article 30 GDPR.
4. Managing Cookies
i. You can disable cookies in your browser settings; however, please note that some parts of the Site may not function properly if cookies are disabled.
ii. You can also clear existing cookies from your device at any time.
5. Third-Party Cookies
i. We may use third-party service providers (e.g., Google Analytics) that place cookies on your device to perform analytics or deliver advertising.
ii. These providers may collect information about your online activities across websites over time.
iii. We encourage you to review their privacy and cookie policies for additional details.
3. How We Use Information
We process personal data in accordance with applicable laws, including the GDPR where relevant. Information collected may be used for the following purposes:
1. Service Delivery
i. To respond to inquiries, provide intuitive consulting, energy medicine, or related services.
ii. To process bookings, payments, and confirmations.
2. Business Operations
i. To improve website performance, design, and content.
ii. To analyze user behavior and trends to enhance client experience.
3. Marketing & Communications
i. To send newsletters, promotions, event invitations, or service updates (only with your consent, where required by law).
ii. You may opt out of such communications at any time by following the unsubscribe link or contacting us directly.
4. Legal and Regulatory Compliance
i. To comply with tax, accounting, recordkeeping, and regulatory obligations.
ii. To enforce our Terms & Conditions or other contractual rights.
5. Security and Fraud Prevention
i. To protect the Site, users, and business operations from fraud, misuse, or unauthorized access.
Legal Bases for Processing (GDPR):
- Consent: For marketing emails, newsletters, or processing of sensitive information you voluntarily provide.
- Contractual Necessity: To fulfill bookings and provide services requested by you.
- Legal Obligations: To meet compliance and reporting requirements.
- Legitimate Interests: To improve services, ensure security, and manage client relationships.
4. Data Sharing
We respect your privacy and maintain strict controls over how your data is shared.
1. No Sale of Data
We do not sell, rent, lease, or trade your personal information to third parties for marketing purposes.
2. Limited Disclosure
We may disclose limited personal information only when necessary:
i. To comply with a valid legal obligation (e.g., subpoenas, court orders, government requests).
ii. To protect the safety, rights, or property of Dr. Enid F. Martinez, clients, or the public.
iii. To service providers, contractors, or business partners who assist in operations (e.g., payment processors, IT support) under strict confidentiality obligations.
3. Third-Party Processors and Data Processing Agreements
We engage certain third-party service providers to perform functions such as payment processing, website hosting, data storage, analytics, and customer-support tools. Each provider acts as a Data Processor within the meaning of Article 4(8) and Article 28 of the GDPR.
All processors are appointed under written Data Processing Agreements (DPAs) that:
- Require them to process personal data only on our documented instructions;
- Obligate confidentiality and restrict sub-processing without prior authorization;
- Mandate appropriate technical and organizational security measures consistent with Article 32 GDPR; and
- Require prompt notice and cooperation in the event of a suspected or confirmed data breach.
We conduct periodic reviews to ensure all processors maintain adequate safeguards and compliance with applicable privacy laws, including the U.S. FTC Act, GDPR, and UK Data Protection Act 2018 where relevant.
4. International Transfers (GDPR Requirement)
If personal data is transferred outside the EU/EEA, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or explicit user consent.
5. Data Security
We take the security of your personal information seriously and implement a variety of technical, administrative, and organizational safeguards designed to protect your data from unauthorized access, misuse, alteration, or loss.
1. Safeguards in Place
i. Secure Storage Systems: Personal data is stored on secure servers and protected by firewalls, intrusion detection, and monitoring systems.
ii. Limited Staff Access: Access to personal data is restricted to authorized personnel who require it to perform their duties, and all staff are bound by confidentiality obligations.
iii. Encryption: Where applicable, sensitive information is encrypted in transit (e.g., via SSL/TLS protocols) and at rest to prevent unauthorized access.
iv. Regular Monitoring: Security systems are reviewed and updated periodically to address emerging threats.
2. Third-Party Security
i. When using trusted third-party service providers (e.g., payment processors, hosting services, IT vendors), we require them to maintain appropriate data security standards consistent with applicable laws.
3. Client Responsibility
i. While we implement strong measures, users are responsible for safeguarding their own devices, login credentials, and internet connections to help protect against unauthorized access.
4. Limitations
i. Despite our efforts, no method of data transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of information transmitted to or from the Site.
ii. In the unlikely event of a data breach involving your personal information, we will comply with all applicable data breach notification laws, including GDPR requirements to notify regulators and affected individuals when necessary.
6. GDPR Compliance for EU/EEA Clients
If you are located in the European Union (EU) or the European Economic Area (EEA), you are entitled to certain rights under the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). These rights include:
1. Right of Access
You have the right to request confirmation as to whether your personal data is being processed and, if so, to obtain a copy of that data along with additional details about its use.
2. Right of Rectification
You may request correction of any inaccurate or incomplete personal data we hold about you.
3. Right of Erasure (“Right to Be Forgotten”)
You may request that we delete your personal data where:
i. The data is no longer necessary for the purposes for which it was collected,
ii. You withdraw consent (where processing was based on consent),
iii. You successfully object to the processing,
iv. Processing was unlawful, or
v. Erasure is required by law.
4. Right to Restriction of Processing
You may request that we limit the processing of your data in certain circumstances, such as while verifying accuracy or pending resolution of an objection.
5. Right to Data Portability
You may request to receive your personal data in a structured, commonly used, and machine-readable format and transfer it to another controller, where processing is based on consent or contract.
6. Right to Object
You may object at any time to the processing of your data based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will stop such processing immediately.
7. Right to Withdraw Consent
Where processing relies on your consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
Exercising Your Rights:
To exercise these rights, please contact us at: [email protected] We will review and respond to valid requests within 30 days, or longer if permitted by law. Verification of identity may be required before fulfilling a request.
U.S. Privacy Law Compliance (CCPA, CPRA, and Related Laws)
For clients and visitors located in the United States, The Heart Helix LLC complies with applicable U.S. federal and state privacy regulations, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and similar state laws to the extent they apply.
We do not sell, rent, or share personal information for monetary or cross-context behavioral advertising purposes. If at any time this changes, you will be notified and provided with an opportunity to opt out in accordance with Cal. Civ. Code §1798.120.
You have the right to request access to, correction of, or deletion of personal information collected about you, and to limit or opt out of certain uses or disclosures. Requests may be submitted by emailing us at [email protected]. We will verify and respond to such requests as required by applicable law.
The Heart Helix LLC is not a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act (HIPAA) and does not provide medical diagnosis or treatment services. Any wellness or energy-healing information you share is handled confidentially under this Privacy Policy, not as protected health information under HIPAA.
Additional rights under other U.S. state laws will be respected to the extent they apply, and we will continue to monitor emerging privacy regulations to maintain compliance across all jurisdictions.
7. Legal Basis for Processing
We process personal data only when there is a lawful basis under GDPR and other applicable laws. The bases we rely on include:
- Consent: Where you voluntarily provide data (e.g., subscribing to newsletters, sharing wellness information in intake forms, or consenting to cookies for analytics/marketing).
- Contractual Necessity: Where processing is required to perform a contract with you, such as booking and delivering services.
- Legal Obligations: Where we are required to comply with applicable laws, regulations, tax, or recordkeeping requirements.
- Legitimate Interests: Where processing is reasonably necessary for our business operations, including service improvement, site security, fraud prevention, or communications, provided such interests do not override your rights and freedoms.
Where processing is based on consent, you have the right to withdraw consent at any time.
8. Data Transfers Outside the EU
Because we are based in the United States, your personal data may be transferred and processed outside the European Union (EU) or European Economic Area (EEA). Whenever such transfers occur, we ensure that your personal data is afforded a level of protection consistent with GDPR requirements.
We implement one or more of the following safeguards:
Adequacy Decisions
Transfers may be made to countries that the European Commission has determined provide an adequate level of data protection.
Standard Contractual Clauses (SCCs)
Where adequacy decisions are not available, we use Standard Contractual Clauses approved by the European Commission, which contractually require recipients of personal data outside the EU/EEA to protect your data in compliance with EU standards.
Explicit Consent
In limited circumstances, we may transfer data outside the EU/EEA only with your explicit and informed consent, which you may withdraw at any time.
Other Lawful Grounds
Transfers may also occur where necessary to perform a contract with you or to establish, exercise, or defend legal claims.
By using our services, you acknowledge that your personal data may be processed in jurisdictions that may not provide the same level of protection as your home country.
9. Retention and Legal Basis for Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, accounting, and regulatory obligations, consistent with Article 5(1)(e) of the GDPR and applicable U.S. laws.
- Retention periods are determined by:
- The nature and sensitivity of the personal data;
- The purposes for which it was collected;
- Applicable statutory limitation periods; and
- Legal or contractual obligations requiring longer retention.
Examples of Retention Periods and Legal Bases:
i. Client service records: Retained for up to seven (7) years from the date of last service to meet contractual and legitimate-interest obligations and professional accountability standards.
ii. Financial and tax records: Retained for seven (7) years in accordance with U.S. Internal Revenue Code §6001 and equivalent state tax-retention requirements.
iii. Communications and consent records: Retained for the duration of the consent period plus six (6) years to demonstrate compliance under GDPR Article 7(1).
iv. Sensitive data disclosed during sessions: Retained only with explicit consent and deleted immediately upon withdrawal or after one (1) year of inactivity.
When retention is no longer justified, data will be securely deleted, anonymized, or irreversibly pseudonymized using industry-standard destruction methods.
ocumentation of retention and deletion actions is maintained to meet accountability requirements under Article 30 of the GDPR.
10. Policy Changes
1. Right to Revise
We may revise, amend, or update this Privacy Policy from time to time in response to legal, regulatory, or operational requirements, as well as to reflect changes in our services or practices.
2. Method of Notification
i. Updates will be posted on this Site with a revised “Effective Date” at the top of the Policy.
For material changes (such as those affecting your rights or how we process your data), we may also notify you directly by email or other reasonable means, where feasible.
3. User Responsibility
ii. Your continued access to or use of the Site following publication of updates constitutes your acknowledgment and acceptance of the revised Privacy Policy. We encourage you to review this Policy periodically to remain informed.
11. Complaints
1. Internal Resolution
If you have any questions, concerns, or complaints about how your personal data is collected or processed, we encourage you to first contact us at:
Email: [email protected]
Address: North Bergen, New Jersey, USA
We will make good-faith efforts to resolve the issue promptly and in compliance with applicable data protection laws.
2. GDPR Rights
If you are located in the European Union (EU) or European Economic Area (EEA) and believe that your GDPR rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA).
A list of EU/EEA supervisory authorities is available at:
https://edpb.europa.eu/about-edpb/about-edpb/members_en
3. Other Jurisdictions
If you are located outside the EU/EEA, you may have the right to file a complaint with your relevant data protection authority or regulator in your jurisdiction.
12. Data Controller, Representative, and Contact Information
The controller responsible for your personal data within the meaning of Article 4(7) of the EU General Data Protection Regulation (GDPR) and other applicable data-protection laws is:
Data Controller:
Dr. Enid F. Martinez | The Heart Helix LLC
North Bergen, New Jersey, USA
Email: [email protected]
The Heart Helix LLC is a U.S.-based entity providing intuitive spiritual consulting and energy-medicine services to clients worldwide.
EU/EEA Representative (pursuant to Article 27 GDPR)
The Heart Helix LLC has not yet appointed an EU/EEA Representative. This section will be updated once a representative is designated. For now, all GDPR-related inquiries should be directed to [email protected]
This representative serves as the point of contact for supervisory authorities and EU/EEA clients regarding data-protection issues.
You may contact either the Data Controller or the EU Representative to exercise your rights under Articles 15–22 GDPR, or to raise a privacy concern. We will respond within the timeframes required by law (typically within 30 days).
If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. A list of EU/EEA authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en
13. Governing Law and Jurisdiction
This Privacy Policy, and any dispute or claim arising from or relating to it, shall be governed by and construed in accordance with the laws of the State of New Jersey, United States of America, without regard to its conflict-of-law principles.
Individuals located in the European Union or European Economic Area retain all rights afforded under the General Data Protection Regulation (Regulation (EU) 2016/679) and other mandatory local data-protection laws, which shall prevail where they provide greater protection.
By using this Site, you agree that any dispute relating to this Privacy Policy shall fall under the exclusive jurisdiction of the competent courts of the State of New Jersey, except where mandatory consumer-protection or data-protection law requires otherwise.

