Client CodesBack to sign in

Privacy policy

Effective date: 7 October 2026 · Version 1.1 · Green Jelly Marketing Ltd · Company No. 08258774

This policy explains what personal data we collect when you use Client Codes, why we collect it, who we share it with, and the rights you have over it. It is written in plain English and forms part of our Terms and Conditions.

1. Who we are

Client Codes is operated by Green Jelly Marketing Ltd, trading as The Human Design Business, a company registered in England and Wales. Client Codes is part of The Human Design Business®.

Full company details:

Green Jelly Marketing Ltd
Trading as: The Human Design Business
Company number: 08258774
Registered address: 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ
VAT number: GB155399771

For the purposes of UK GDPR and the Data Protection Act 2018, Green Jelly Marketing Ltd is the data controller in respect of the personal data of leaders who hold a Client Codes account. In respect of the personal data of your clients that you enter into the platform, you (the leader) are the data controller and Green Jelly Marketing Ltd is the data processor. See section 4 for how this split works.

Contact: me@sharithompson.co.uk.

2. What data we collect

2.1 Leader account data

When you create a Client Codes account we collect your name, email address, password (stored as a one-way hash), the plan you are on, and basic account metadata such as when you signed up and when you last logged in. If you set up white label branding we also store your brand name and, if you upload one, your logo.

2.2 Leader birth data

During onboarding you enter your own date of birth, time of birth and place of birth so we can generate your Attraction Code chart. This is stored against your account so we can display and regenerate your chart.

2.3 Client data entered by leaders

When you add a client to your workspace you enter their first name and their birth date, time and place. We use this to generate their Human Design chart and the guides you create for them. We only ever receive this data because you have chosen to enter it. Your clients do not have accounts, do not log in, and do not interact with the platform directly.

2.4 Guide, review and Attraction Code content

We store the AI-generated guides, content reviews and Attraction Code reports produced within your workspace, along with any private notes you add against a client record.

2.5 Payment data

Card payments are processed by Stripe, with manual invoicing available during beta by arrangement. We do not see or store your full card number. Stripe returns a customer identifier and non-sensitive metadata (plan, status, billing period) which we store against your account.

2.6 Technical data

Our infrastructure providers automatically log basic technical information such as IP address, browser type and request timestamps for security, abuse prevention and diagnostic purposes. This is not used to profile you or build a marketing picture of you.

3. Why we collect it and our legal basis

We only process personal data where we have a lawful basis under UK GDPR to do so.

  • Leader account data and leader birth data: performance of a contract with you (Article 6(1)(b)). We need this data to give you access to the platform and to generate your Attraction Code.
  • Client data entered by leaders: processing on your documented instructions as your processor (Article 28), on the lawful basis you have established with your client as controller.
  • Payment data: performance of the subscription contract with you (Article 6(1)(b)) and compliance with our legal accounting obligations (Article 6(1)(c)).
  • Technical logs and security data: our legitimate interests in keeping the platform secure and available (Article 6(1)(f)).
  • Service emails (e.g. password reset, billing notices): performance of the contract with you (Article 6(1)(b)).

4. Controller and processor roles for client data

The people you work with professionally never sign up to Client Codes. You decide whether to enter their information, what to enter, and how long to keep it. Under UK GDPR that makes you the data controller in relation to your clients' personal data and makes Green Jelly Marketing Ltd the data processor.

In practical terms:

  • You are responsible for obtaining your client's consent (or another lawful basis) before entering their birth details. Client Codes enforces a consent checkbox at the add-client step as a prompt, but the underlying legal responsibility sits with you.
  • We process client data only on your instructions and only to provide the platform features you have chosen to use (chart generation, guides, reviews).
  • We do not use your clients' data for our own purposes, do not sell it, and do not use it to train AI models.
  • If you receive a data subject request (access, correction, deletion) from one of your clients, you handle it as their controller. We will support you where we can, for example by helping you delete a client record.

5. Who we share data with

We use a small number of trusted third parties to run Client Codes. Each is used only for the purpose described.

  • Bodygraph Chart API: receives the birth date, time and place you enter (your own or your client's) in order to return the corresponding Human Design chart. Operated under its own terms and privacy policy.
  • Anthropic (Claude): receives chart-derived data and any content you submit for review, in order to generate the guides, reviews and Attraction Code reports shown in your workspace. Anthropic processes this data as a data processor and does not use it to train its models under our current API terms.
  • Supabase: our secure cloud database and authentication provider. Stores your account, chart data, guides, reviews and notes.
  • Stripe: processes card payments, with manual invoicing available during beta by arrangement. Card details are entered directly into Stripe and never touch our servers.
  • Email delivery provider: used to send account-related emails such as password resets, billing notices and important service updates.
  • ActiveCampaign, LLC (US): our customer email list. Receives the first name and email address of paying customers only, never any client data, for product updates and offers. You can unsubscribe at any time.
  • Meta Platforms Ireland Ltd (with Meta Platforms, Inc. in the US): advertising measurement via the Meta pixel on our public pages. Loaded only after a visitor accepts non-essential cookies. It does not receive any chart, client or workspace data.
  • Vimeo: hosts training videos inside the signed-in app. The player runs in privacy mode and does not set tracking cookies.

We do not sell your data, we do not share your account or client data with advertisers, and we do not disclose it to any other third party except where legally required (for example, in response to a valid court order).

6. How long we keep data and what happens when you delete your account

We keep your account data and workspace data for as long as your Client Codes account is active. You can delete a client record at any time from within the platform, which removes that client's chart, guides and reviews.

When you delete your account, we permanently delete your profile, your Attraction Code chart, all of your client records and all associated charts, guides, reviews and notes. Deletion cascades through the database automatically and completes within 30 days across our infrastructure and backups.

We may retain a minimal record (for example, an invoice or a suspension note) where we are required to do so by law, for tax and accounting purposes, or to defend a legal claim. Such records do not include your clients' personal data.

7. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you
  • ask us to correct data that is inaccurate or incomplete
  • ask us to delete your data (subject to any legal retention obligations)
  • object to or restrict certain processing
  • receive a copy of your data in a portable format
  • withdraw any consent you have given at any time
  • complain to the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been handled unlawfully

To exercise any of these rights over your own leader account data, email me@sharithompson.co.uk. We will respond within one month.

Because we are a processor for your clients' data, requests from your clients should be directed to you as their controller in the first instance. If your client contacts us directly, we will refer them to you unless you have asked us to do otherwise or we are legally required to respond.

8. Our privacy commitment on admin access

Green Jelly Marketing Ltd operates an administrative interface for the purpose of running the platform, resolving technical issues and supporting users. As a matter of deliberate design and policy, the platform administrator does not have access to the content of individual client records: including chart data, guide content, review content or notes.

The admin interface shows only operational status (for example whether a chart or guide has been generated) and not the underlying data. This means that even the platform owner cannot read your clients' Human Design information, the guides generated for them, or the content of any reviews or notes within your workspace. This is a trust commitment, not just a technical detail, and it is mirrored in Section 5.3 of our Terms and Conditions.

9. Cookies and tracking

Essential storage: we use strictly necessary cookies or local storage to keep you signed in, to remember your interface preferences and to remember your cookie choice. These do not need consent.

Marketing: on our public pages we use the Meta pixel (Meta Platforms Ireland Ltd) to measure how our adverts perform. It only loads after you choose "Accept all" or turn marketing on in "Manage preferences". It may record the pages you visit, your browser details and your IP address, and Meta may use this to measure and improve ad delivery. If you reject it, nothing is loaded or set.

We record your choice, the date you made it and the version of the notice you saw. You can change or withdraw your choice at any time using the "Cookie settings" link in the footer. Training videos are hosted by Vimeo and play in privacy mode, so the player does not set tracking cookies.

10. International transfers

Some of our processors are based outside the UK. Specifically, Anthropic and Stripe are US-headquartered, and the Bodygraph Chart API may process requests outside the UK. Where personal data is transferred outside the UK, we rely on appropriate safeguards under UK GDPR, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or adequacy decisions where these apply. ActiveCampaign receives customer names and email addresses in the US under the UK International Data Transfer Addendum within its data processing terms [CONFIRM]. Meta Platforms receives pixel data in the US only where you have accepted non-essential cookies; the safeguard relied on is the UK Extension to the EU-US Data Privacy Framework, under which Meta Platforms, Inc. is certified [CONFIRM].

Our database (Supabase) is configured to store data in a region within the UK or EU where available.

10a. The CASH Audit

The CASH Audit at /cash-audit is a free calculator. It does not ask for your name or email address. The figures and answers you enter stay in your browser while you use it, are not sent to our servers or any third party, are not stored, and are cleared when you close the page or choose "Start again". Because nothing is collected, there is nothing for us to retain or delete. If you have accepted non-essential cookies, the Meta pixel may record that you visited the page, but not your answers.

11. Security

We take reasonable and proportionate technical and organisational measures to protect the data held in Client Codes. This includes encrypted connections (HTTPS), password hashing, row-level access controls on our database so that leaders can only access their own workspace data, and restricted administrator access as described in section 8. No online service can be guaranteed 100% secure, but we design and operate Client Codes with your clients' privacy in mind.

12. Changes to this policy

We may update this policy from time to time. If we make material changes we will notify you by email to the address registered to your account and by displaying a notice within the platform. The current version is always available at theclientcodes.com/privacy.

13. Contact

For any privacy question, data request, or complaint, contact:

Email: me@sharithompson.co.uk
Company: Green Jelly Marketing Ltd
Trading as: The Human Design Business
Company number: 08258774
Registered address: 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ
VAT number: GB155399771