This Privacy Policy describes how Divine Design LLC ("Divine Design," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, discloses, and safeguards personal information in connection with our technology-licensing, consulting, health & wellness coaching, and product services, and our websites (the "Services"). By using the Services, you agree to this Policy.
1. Our Role: Controller vs. Service Provider
We act as a controller/business for information about our consulting and coaching clients, product customers, prospects, and website visitors. Where our licensed technology processes data on a Licensee's behalf, the Licensee is the controller and we act as a service provider/processor, handling that data only per our agreement and the Licensee's instructions. If you are an end customer of a Licensee, please review that Licensee's privacy notice.
2. Information We Collect
Information you provide
- Identifiers and account data — name, business name, email, phone, mailing/shipping address, and any login credentials.
- Commercial and billing data — engagement, subscription, order, and transaction records; EIN/tax identifiers; and billing details processed by our payment providers (we do not store full card numbers).
- Health & wellness information you choose to share — for Coaching Services, information you voluntarily provide about your goals, lifestyle, diet, and general wellness. This is used only to deliver coaching and is treated as sensitive (see Section 4). Coaching Services are educational and are not medical care.
- Communications and content — messages, support requests, and materials you submit.
Information collected automatically
- Internet/device activity — IP address, browser/device type, pages viewed, actions, timestamps.
- Approximate location — general location inferred from IP.
- Cookies and similar technologies — see Section 10.
3. Statutory Categories, Sources, Purposes, and Disclosures
The table maps the categories of personal information we handle (using California Consumer Privacy Act categories, as amended) to sources, purposes, and disclosures. We do not sell personal information for money, and we do not "share" it for cross-context behavioral advertising as defined under U.S. state privacy laws. We do not sell or share mobile opt-in information or SMS consent for third-party marketing; reply STOP to opt out of texts at any time.
| Category | Examples | Sources | Purpose | Sold / Shared |
|---|---|---|---|---|
| Identifiers | Name, email, phone, address, IP, account ID | You; your devices; providers | Provide and support the Services; fulfill orders | No |
| Commercial information | Engagement, order, and billing records | You; payment providers | Process payments and manage engagements/orders | No |
| Internet/electronic activity | Usage, pages, actions, device/browser data | Automatically | Operate, measure, secure, improve | No |
| Geolocation (approximate) | General location from IP | Automatically | Security, fraud prevention, localization | No |
| Sensitive personal information | Login credentials; health/wellness info you share for coaching | You | Authentication; delivering Coaching Services only | No |
| Inferences (limited) | Preferences derived to personalize/improve | Derived | Service improvement and personalization | No |
4. Sensitive Personal Information
Sensitive personal information we may handle includes credentials for accounts you hold with us, authorization tokens for Connected Accounts, any health or wellness information you voluntarily share for Coaching Services, and sensitive content that may appear within a Connected Account you authorize us to process (Section 15). We do not collect or store passwords for Connected Accounts; access is by authorization token issued through the provider's OAuth flow, stored securely and revocable by you at any time. We use sensitive information only to authenticate your account, to deliver the coaching you request, and to provide the Connected Account features you have enabled. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for purposes beyond those permitted by law. You may request that we limit our use of sensitive personal information (Section 11). We handle this information with the safeguards described in Section 13.
5. Sub-processors and Service Providers
We engage vetted service providers and sub-processors under contracts requiring them to protect information and use it only to provide services to us. These include: cloud hosting and infrastructure; our technology and communications providers; payment processing (PowerPay Direct and its licensed processing partners for coaching and product payments; and bank/ACH for license and consulting fees); order fulfillment and shipping; and analytics. A named sub-processor list is available to clients under a data-processing agreement on request. The specific underlying processors and gateways are kept confidential.
6. Payment Processing
Coaching and Product payments are processed through PowerPay Direct and its licensed payment-processing partners and gateways. License and consulting fees are generally invoiced and paid by bank transfer/ACH. All payment providers operate under their own terms, privacy policies, and PCI-DSS obligations. Card details are entered directly into the processor's or gateway's secure systems; we receive only limited transaction information and do not receive or store complete card numbers.
7. How We Use Information
- Provide, personalize, and support licensing, consulting, coaching, and Product services.
- Process payments, orders, and engagements.
- Communicate about your account, orders, coaching, and support.
- Improve and develop our Services, and secure them against fraud and abuse.
- Comply with legal obligations and enforce our agreements.
8. Automated Processing and Personalization
Our Services include personalization and AI-assisted features that use automated processing to tailor content and recommendations. We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Coaching guidance is delivered by or under the direction of a human. You may contact us with questions about our automated processing.
9. How Long We Keep Information
We retain personal information for as long as needed to provide the Services and for legitimate business and legal purposes, then delete or de-identify it. Retention criteria include the duration of your engagement or account, tax/accounting/legal requirements, dispute resolution, and routine backup cycles. Coaching-related information is retained only as long as reasonably necessary to provide and document the coaching, unless you request earlier deletion.
10. Cookies, Tracking, and Opt-Out Signals
We and our providers use cookies, pixels, and similar technologies to operate, secure, measure, and improve the Services. You can control cookies through your browser and any controls we offer. We honor the Global Privacy Control (GPC) and similar opt-out preference signals where required. If we later introduce advertising cookies or pixels whose use results in a "sale" or "sharing" under applicable law, we will update this Policy and provide a clear opt-out.
11. Your U.S. State Privacy Rights
Residents of U.S. states with comprehensive privacy laws — including California, Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — may have rights to: access/know; correct; delete; portability; opt out of sale, sharing/targeted advertising, and certain profiling (we do not sell or share); and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.
How to exercise. Submit a request to support@d3designs.net. We will verify your identity before responding within the timeframe required by law. You may use an authorized agent, subject to verification, and may appeal a declined request by replying to our decision. If your data was provided by a Licensee, please direct your request to that Licensee.
12. Data Location
We are based in and process personal information in the United States, and the Services are intended for U.S. users. If you access the Services from outside the United States, you understand your information will be processed in the United States.
13. Security
We use administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity, including encryption in transit, access controls, and least-privilege practices. Health-related and other sensitive information is held with additional safeguards, including encryption in transit and at rest, access limited to personnel who need it for the service you requested, separate storage from general business records, and contractual confidentiality obligations on any service provider that handles it. Whether particular information is regulated under HIPAA depends on the role in which it is received; where we act as a business associate of a covered entity, that work is governed by the applicable business associate agreement rather than by this Policy. If we become aware of a security breach affecting your personal information, we will notify you and any affected parties as required by law and without undue delay. No system is completely secure, and we cannot guarantee absolute security.
14. Children's Privacy
The Services are intended for users 18 or older. We do not knowingly collect personal information from children. If you believe a child provided us information, contact us and we will delete it.
15. Connected Accounts and Google API Services
Some Services work with accounts you already control — such as email, calendar, file storage, or CRM systems ("Connected Accounts"). You authorize each connection, and we access only the permission scopes you grant. You may revoke access at any time through the provider's security settings or by contacting us.
What we access. Depending on the Services you request: [list the actual scopes in plain language — for example: read message metadata and content in the mailbox you connect; read calendar events; read files you designate]. We do not access accounts or scopes you have not authorized.
What we do with it. We use Connected Account data only to provide and improve the specific features you asked for — for example organizing, summarizing, extracting tasks or themes, and producing reports and dashboards for you.
Google API Services — Limited Use. Divine Design's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, with respect to data obtained through Google APIs:
- We use it only to provide or improve the user-facing features you have connected it for, and we do not use it for unrelated purposes.
- We do not sell it, and we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit prior consent.
- We do not use it for advertising of any kind, including serving, targeting, personalizing, or measuring advertising.
- We do not use it to determine creditworthiness or for lending purposes, and we do not use it in any credit, lending, insurance, employment, or housing decision.
- We do not allow humans to read it, except in these limited cases: with your affirmative consent for specific messages; where necessary for security purposes such as investigating abuse or resolving a security incident; to comply with applicable law; or where the data has been aggregated and anonymized so that it can no longer be associated with you, and then only for internal operations. Aggregation or de-identification does not release derived information from the other restrictions in this Section.
- We do not use it to train generalized artificial intelligence or machine learning models, and we do not permit any provider to do so. We process this data only through provider arrangements we have verified prohibit training on it. Where no compliant arrangement is available for a given provider or feature, we do not send this data to that provider.
These commitments apply to information derived from Google API data as well as to the data itself.
16. AI Processing and Derived Insights
Where you have asked for AI-assisted features, content from your Connected Accounts and materials you provide may be processed by third-party model providers under contract with us to produce summaries, extracted tasks, themes, classifications, and reports ("derived insights").
- Derived insights are treated with the same restrictions as the source data they came from. Insights derived from Google API data carry the Limited Use commitments in Section 15.
- We do not use your content or derived insights to train general-purpose models, and we process them only through provider arrangements we have verified prohibit training. Where no compliant arrangement exists for a feature, we do not enable that feature for Connected Account data.
- Model providers act as our service providers for this processing and are listed with our other sub-processors in Section 5.
- AI output can be inaccurate. It is provided for your review and does not replace your own judgment.
17. Separation Between Services
Divine Design offers distinct services, and data does not move between them.
- Your connected workspace. The accounts you authorize form a single connected workspace for the features you have enabled. Within that workspace, and only to deliver features you requested, information from one authorized account may be combined with another — for example, relating calendar events to messages, or building a dashboard that draws on both. You control which accounts and features are included, and you can remove any of them at any time.
- Outside that workspace, no reuse. Connected Account information and insights derived from it are not used for any other purpose, product, or Divine Design offering, and are not made available to any affiliated business.
- Financing and lending are walled off absolutely. Connected Account information and derived insights are never used for, combined with, or made available to any financing, funding, lending, or merchant-services offering, and are never used to evaluate eligibility, creditworthiness, or terms for any such offering. This restriction cannot be waived by agreement, including by you.
- Information you separately and knowingly provide to another service is governed by the disclosures made in that service, and is not combined back into your connected workspace.
18. Retention and Deletion of Connected Account Data
Different categories of data have different lifecycles. The table states what we do on each trigger.
| Category | On disconnect or request | On engagement end |
|---|---|---|
| Authorization tokens | Revoked and deleted immediately | Revoked and deleted immediately |
| Raw content and attachments retrieved from a Connected Account | Deleted within [30] days | Deleted within [30] days |
| Derived insights — summaries, themes, extracted tasks | Deleted within [30] days unless embedded in a deliverable you have asked us to keep | Same |
| Deliverables you commissioned — reports, dashboards, exports | Retained per your written instruction; available for export for [30] days after termination, then deleted unless you instruct otherwise | Same |
| Operational logs — access and error records containing limited metadata | Retained up to [90] days for security and troubleshooting, then deleted | Same |
| Backups | Expire on their own cycle, within [35] days; not restored to active use after a deletion request | Same |
| Business records — contracts, invoices, tax records | Retained under Section 9 and used for no other purpose | Same |
De-identification is not a release. Where we retain aggregated or anonymized information, the restrictions in Section 15 continue to apply to anything derived from Google API data.
To request deletion, contact us using Section 19. We will confirm in writing when deletion is complete. These timelines are consistent with the export and data-handling provisions of the Terms and Conditions; if the two ever conflict as to Connected Account data, this Policy controls.
19. Contact Us
Divine Design LLC
Attn: Privacy
Wyoming, USA
Email: support@d3designs.net
20. Changes to This Policy
We may update this Policy from time to time. We will revise the "Effective date" above and, for material changes, provide additional notice. Continued use after changes take effect constitutes acceptance.
21. Governing Law
This Policy is governed by the laws of the State of Wyoming, without regard to conflict-of-laws principles, except where a mandatory privacy law of your jurisdiction applies.
