Data Processing Agreement
Effective date: 7 October 2026 · Version 1.1 · Green Jelly Marketing Ltd · Company No. 08258774
This Data Processing Agreement ("DPA") governs the processing by Green Jelly Marketing Ltd of personal data about your clients that you enter into Client Codes. It forms part of, and is incorporated into, the Client Codes Terms and Conditions available at theclientcodes.com/terms. By using Client Codes to process client personal data you agree to this DPA in the form then in force.
1. Parties and definitions
The parties to this DPA are:
- Processor: Green Jelly Marketing Ltd, a company registered in England and Wales (Company No. 08258774), operator of Client Codes.
- Controller: you, the leader, consultant, facilitator or programme lead who holds a Client Codes account and enters personal data about your clients into the platform.
In this DPA the following terms have the meanings set out below. Other capitalised terms have the meaning given to them in the Terms and Conditions.
- Client personal data: the first name, date of birth, time of birth and place of birth that you enter into Client Codes about a client, together with any chart data, guide, review, Attraction Code content or notes derived from or attached to that record.
- Data subject: an individual whose client personal data you enter into the platform.
- UK GDPR: the retained EU Regulation 2016/679 as incorporated into UK law, read together with the Data Protection Act 2018.
- Sub-processor: a third party engaged by the processor to process client personal data on the controller's behalf.
- Standard Contractual Clauses: the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses combined with the UK Addendum, as applicable.
2. Subject matter and duration
The subject matter of the processing is the generation, storage and delivery of Human Design chart data, guides, content reviews and Attraction Code outputs about your clients, on your instruction.
This DPA applies for as long as your Client Codes account is active and client personal data is processed on the platform, plus any retention period agreed under section 5.6 following termination of your account or of the Terms and Conditions.
3. Nature and purpose of processing
The processor will process client personal data only to provide the Client Codes platform. Specifically the processor will:
- receive client personal data from the controller when the controller enters it into the platform
- transmit birth data to the Bodygraph Chart API to generate the client's Human Design chart
- transmit chart-derived data (and any review content the controller uploads) to Anthropic to generate guides, reviews and Attraction Code outputs
- store the resulting chart data, guides, reviews and notes in a cloud database provided by Supabase
- make that data available to the controller within the controller's own workspace, and remove it when the controller deletes it
The processor will not use client personal data for its own purposes, will not sell it, and will not use it to train artificial intelligence models.
4. Categories of data subject and data
4.1 Data subjects
Your clients, that is, the individuals you work with professionally and whose birth details you enter into the platform. Data subjects do not hold Client Codes accounts and do not interact with the platform directly.
4.2 Categories of personal data
- first name
- date of birth
- time of birth (or a "time unknown" flag)
- place of birth
- derived Human Design chart data (type, authority, profile, defined centres, gates, channels, incarnation cross and related chart outputs)
- AI-generated guides, reviews and Attraction Code content associated with the client record
- any private notes the controller records against the client record
- any content the controller uploads for review through the content review flow
Client personal data does not include special category data under Article 9 UK GDPR unless the controller chooses to enter such data (for example, by including health information in a review upload or in notes). The controller is responsible for the lawfulness of any special category processing it initiates.
5. Processor obligations
5.1 Processing on documented instructions
The processor will process client personal data only on the controller's documented instructions. The controller's use of the platform (creating client records, generating charts, generating guides, running content reviews, deleting records) constitutes the controller's documented instructions. Any further processing requires the controller's specific written instruction. The processor will inform the controller if, in its opinion, an instruction infringes UK GDPR.
5.2 Confidentiality and admin access
The processor ensures that anyone authorised to process client personal data on its behalf is bound by an appropriate duty of confidentiality.
As a contractual commitment (and not only as a product feature), the platform administrator does not have access to the content of individual client records: including chart data, guide content, review content or notes. The administrative interface exposes only operational status such as whether a chart or guide has been generated. This restriction is the same one described in the Terms and Conditions section 5.3 and the Privacy Policy section 8, and it applies to Green Jelly Marketing Ltd staff and to any contractors acting on its behalf.
5.3 Security
The processor will implement appropriate technical and organisational measures to protect client personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current measures include:
- encrypted connections (HTTPS/TLS) for all data in transit between the controller, the platform, and sub-processors
- password hashing for controller account credentials
- row-level security policies on the Supabase database so that each controller can only access their own workspace data, and a database-level trigger that enforces plan-based client limits before any client record can be created
- restricted platform administrator access as described in section 5.2, with no admin visibility into client record content
- reliance on Supabase's own security posture for the underlying database (access controls, logging, encryption at rest, backups)
- use of vetted third-party APIs (Bodygraph, Anthropic) accessed over encrypted connections
5.4 Assistance with data subject requests
Because your clients do not hold Client Codes accounts and do not have a direct relationship with the processor, requests from a data subject (access, rectification, erasure, restriction, portability, objection) should be handled by the controller as the party responsible for that data. If a data subject contacts the processor directly, the processor will refer them to the controller.
Taking into account the nature of the processing, the processor will provide reasonable technical assistance to help the controller respond to a valid data subject request, for example by helping locate, export or delete a specific client record.
5.5 Personal data breach notification
The processor will notify the controller without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting client personal data. The notification will include the information required to allow the controller to meet its own notification obligations to the Information Commissioner's Office and (where required) to data subjects.
5.6 Return or deletion at end of processing
On termination of the controller's account, or on the controller's earlier written request, the processor will delete or return all client personal data at the controller's choice, subject to any legal retention requirement. In the absence of a specific instruction, the processor will delete client personal data in accordance with the retention windows set out in the Terms and Conditions section 4.9 and the Privacy Policy.
5.7 Records and audits
The processor will make available to the controller, on reasonable request, the information necessary to demonstrate compliance with this DPA and with Article 28 UK GDPR. Given the scale of the platform, audits will normally be satisfied by written responses to reasonable questionnaires and by the processor's published security and privacy documentation. On-site audits may be requested on at least 30 days written notice, no more than once in any 12 month period (except following a personal data breach), at the controller's cost, and subject to reasonable confidentiality and security requirements.
6. Sub-processors
The controller authorises the processor to engage the following sub-processors to process client personal data on the controller's behalf as at the effective date of this DPA:
- Bodygraph Chart API: generation of Human Design charts from birth data
- Anthropic (Claude): generation of guides, reviews and Attraction Code content from chart-derived data
- Supabase: cloud database and authentication provider that stores workspace data
- Stripe: processes card payments for Training Only, subscription and Lifetime fees, with manual invoicing available during beta by arrangement. Stripe does not process client personal data as defined in this DPA, and is listed for completeness only
The processor will give the controller at least 30 days written notice before adding or replacing a sub-processor that processes client personal data. During that notice period the controller may object on reasonable data protection grounds. If a reasonable objection cannot be resolved, the controller may terminate the affected part of the service in accordance with the Terms and Conditions.
The processor remains fully liable to the controller for the performance of its sub-processors' obligations relating to client personal data.
7. International transfers
Some sub-processors are established, or operate infrastructure, outside the UK. Where client personal data is transferred outside the UK, the processor relies on appropriate safeguards under UK GDPR, including (as applicable) the UK International Data Transfer Agreement, the EU Standard Contractual Clauses combined with the UK Addendum, or an adequacy decision.
Publisher note: the specific processing regions for Bodygraph, Anthropic and Supabase have not been confirmed at the time of drafting. This section will be updated with the specific regions and safeguards for each sub-processor before this DPA is offered to leaders. Do not rely on this section as a confirmation of hosting location until it has been finalised.
8. Liability
The liability of each party under this DPA is subject to, and forms part of, the overall liability regime set out in the Terms and Conditions section 10 (Limitation of liability). Nothing in this DPA creates a separate cap on liability or extends the processor's liability beyond what is already agreed in the Terms and Conditions.
9. Term and termination
This DPA takes effect when the controller first uses Client Codes to process client personal data and remains in effect for as long as the controller has an active account and such processing continues. It terminates automatically on termination of the Terms and Conditions between the controller and the processor. Sections that by their nature should survive termination (in particular sections 5.5, 5.6, 5.7 and 8) will do so.
10. Governing law and jurisdiction
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.
11. Contact
Questions or requests under this DPA should be sent to:
Email: me@sharithompson.co.uk
Company: Green Jelly Marketing Ltd
Trading as: The Human Design Business
Company number: 08258774
Registered address: 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ
VAT number: GB155399771