DIFY

LEGAL

Privacy Policy

Last updated: 10 September 2026

DIFY respects your privacy and is committed to protecting the personal information you provide when using this website.

This Privacy Policy explains what personal information DIFY collects, why it is collected, how it may be used, who it may be shared with and the rights available to you.

1. Who we are

This website is operated by DIFY, a self development brand offering the DIFY Passport, one to one foundation sessions and in person events. References to “we”, “us” and “our” mean DIFY.

You can contact us about privacy matters through the contact details published on our Contact page.

2. Information we collect

Depending on how you interact with DIFY, we may collect your name, email address, purchase and order details, booking details, delivery address for your welcome booklet, messages you send us and technical information such as device type, browser and pages visited.

When you join the Events waitlist, we collect your name and email address.

When you purchase the DIFY Passport, we collect the information needed to process the order and give you access to the Passport.

When you book a foundation session, the information needed to arrange the booking is processed through our booking provider.

3. How we use your information

We use personal information to process purchases, provide access to the DIFY Passport, send access and booking information, manage coaching sessions, post your welcome booklet, manage the Events waitlist, respond to enquiries, keep the website secure, understand website usage where you have consented, and meet our legal obligations.

4. Legal bases

Where UK GDPR applies, we rely on: performance of a contract, to deliver the products and sessions you have purchased; consent, for marketing emails and non essential cookies; legitimate interests, to secure and improve the website and respond to enquiries; and legal obligation, for tax and accounting records.

5. Payment information

Payments are handled by our payment provider. Card details are entered directly with that provider and DIFY does not store complete payment card numbers.

6. Booking information

Foundation sessions are scheduled through Calendly. When you book, Calendly processes your name, email address and chosen time slot on our behalf so we can hold the session.

7. Email communications

If you join the Events waitlist or opt in to updates, your name and email address are added to the DIFY mailing list. You can unsubscribe at any time using the link in any marketing email. Transactional emails, such as your Passport access details, are sent regardless of marketing preferences because they are needed to deliver your order.

8. Cookies and analytics

The website uses necessary cookies to function and, with your consent, analytics cookies to understand how the site is used. Analytics do not load for UK and EU visitors until consent is given. Full details are in our Cookies Policy.

9. Sharing information

We share personal information only with the service providers needed to run DIFY: our website host, payment provider, booking provider, email platform, analytics provider and delivery partners. Each acts on our instructions. We may also disclose information where required by law. DIFY does not sell personal information.

10. Data retention

We keep order and transaction records for six years to meet accounting and tax requirements. Mailing list data is kept until you unsubscribe. Enquiry emails are kept for up to two years. Analytics data is retained for up to fourteen months.

11. UK GDPR rights

If UK or EU data protection law applies to you, you may request access to your personal information, ask for inaccurate information to be corrected, request deletion in certain circumstances, request restriction of processing, object to certain processing and request portability. You may withdraw consent at any time where processing is based on consent, and you may complain to the Information Commissioner’s Office.

12. United States privacy rights

Depending on where you live, you may have rights under applicable United States privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act. These may include rights of access, correction and deletion, and rights relating to the sale or sharing of personal information. DIFY does not sell or share personal information for cross context behavioural advertising.

13. Security

We use reasonable technical and organisational measures, including encrypted connections and access controls, to protect personal information against unauthorised access, loss, misuse or alteration. No internet transmission can be guaranteed to be completely secure.

14. International transfers

Some of our providers process information outside the United Kingdom. Where this happens we rely on appropriate safeguards, such as UK approved standard contractual clauses or an adequacy decision.

15. Children

This website and the DIFY Passport are intended for adults aged 18 and over and are not directed at children.

16. Changes to this policy

We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last revised.

17. Contact

For any privacy question, or to exercise your rights, please contact us using the details on our Contact page.