Identity of the Controller
Dharma Funder ("Dharma Funder," "we," "us," or "our") is the business name of Rebecca Funder, sole proprietor, operating the website dharmafunder.com and related digital properties from Santa Cruz, California, United States. Dharma Funder is a sole executive advisory practice providing structural diagnostic and intervention services to senior leaders and founders.
This Privacy Policy describes how we collect, use, store, and protect personal information when you visit our website, use our diagnostic tools, subscribe to our Substack publication, or engage our advisory services. This policy applies to all users, including residents of the European Union ("EU"), European Economic Area ("EEA"), and United Kingdom ("UK").
Section 2Categories of Information Collected
2.1 Diagnostic Tools (Decision Access Diagnostic and The Decision Access Map)
- First name and email address, collected via pre-assessment email gate before the diagnostic begins
- Assessment responses consisting of multiple-choice selections indicating decision-making patterns under pressure
- Diagnostic result classification (Full Access, Constrained Access, or Pattern Override)
- Timestamp of submission
2.2 Substack Publication
- Email address, collected at subscription
- Open and click-through engagement data, collected and processed by Substack
2.3 Advisory Engagements
- Full name, email address, and phone number
- Professional role and organizational context, provided during intake
- Communication records exchanged in the course of advisory engagements
- Payment information, processed and stored exclusively by Stripe. We do not access, store, or retain card numbers, bank account details, or other financial credentials.
2.4 Speaking Engagements and Events
- Name and email address of attendees who voluntarily provide contact information at live events, workshops, or speaking engagements
- Diagnostic tool submissions completed at or following an event
2.5 Website Usage
- Pages visited, time on site, device type, and browser information, collected via standard analytics
- Cookies and similar tracking technologies as described in Section 8
Purposes and Lawful Basis for Processing
We process personal information for the following purposes. For each purpose, the applicable lawful basis under both California law and the EU General Data Protection Regulation ("GDPR") is stated.
- Delivering diagnostic results and follow-up resources. Lawful basis: consent (provided at email gate submission) and performance of pre-contractual steps (Art. 6(1)(b) GDPR).
- Processing payments for advisory services. Lawful basis: performance of a contract (Art. 6(1)(b) GDPR).
- Sending email communications to opted-in subscribers. Lawful basis: consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time by unsubscribing.
- Fulfilling advisory engagements. Lawful basis: performance of a contract (Art. 6(1)(b) GDPR).
- Improving our tools, content, and service delivery. Lawful basis: legitimate interest (Art. 6(1)(f) GDPR). The legitimate interest is improving the quality and relevance of our advisory services and diagnostic tools.
- Complying with applicable legal obligations. Lawful basis: legal obligation (Art. 6(1)(c) GDPR).
Third-Party Processors
We share personal information with the following third-party service providers ("sub-processors"), each of which processes data under its own privacy policy and applicable data processing terms:
- Stripe (payment processing). Stripe handles all payment transactions. We do not receive or store card details. Stripe is certified under the EU-US Data Privacy Framework.
- GoHighLevel ("GHL") (CRM, email automation, website hosting, funnel infrastructure). Contact information and diagnostic results are stored in GHL for the purpose of email follow-up sequences and client management.
- Substack (email publication and subscriber management).
- Google Analytics (website usage analytics). Anonymized usage data is collected to understand site performance.
We do not sell, rent, or trade personal information to third parties for marketing purposes.
Section 5Data Retention
- Diagnostic tool submissions: retained in GHL for 24 months from date of submission. If the individual becomes an active advisory client, retention extends for the duration of the engagement plus 12 months.
- Substack subscriber data: retained for as long as the subscription remains active. Data is removed upon unsubscription per Substack's data handling procedures.
- Advisory engagement records: retained for 7 years from the conclusion of the engagement, consistent with California record-keeping requirements for professional services.
- Payment records: retained by Stripe in accordance with Stripe's data retention policy and applicable financial regulations.
- Event contact information: retained for 24 months from the date of the event, unless the individual opts into ongoing communications.
- Website analytics: retained per Google Analytics default settings, which is 14 months for user-level data.
Your Rights (All Users)
- Request access to the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data, subject to applicable legal retention requirements
- Unsubscribe from email communications at any time using the unsubscribe link in any email
- Opt out of analytics tracking via your browser settings or a Do Not Track signal
To exercise any of these rights, contact us at the address listed in Section 14. We will respond to verified requests within 30 days.
Section 7Additional Rights for EU, EEA, and UK Residents (GDPR)
If you are a resident of the European Union, European Economic Area, or United Kingdom, you have the following additional rights under the General Data Protection Regulation ("GDPR") and the UK General Data Protection Regulation ("UK GDPR"):
- Right of Access (Art. 15). You may request confirmation of whether we process your personal data and, if so, obtain a copy of that data along with information about the purposes of processing, the categories of data, and the recipients.
- Right to Rectification (Art. 16). You may request correction of inaccurate personal data or completion of incomplete data.
- Right to Erasure (Art. 17). You may request deletion of your personal data where the data is no longer necessary for the purposes for which it was collected, you withdraw consent, or the data has been unlawfully processed. This right is subject to legal exceptions, including retention required by applicable law.
- Right to Restriction of Processing (Art. 18). You may request restriction of processing in certain circumstances, including while the accuracy of your data is contested or while we assess whether our legitimate interests override your rights.
- Right to Data Portability (Art. 20). You may request that we provide your personal data in a structured, commonly used, machine-readable format and transmit it to another controller, where processing is based on consent or contract performance and carried out by automated means.
- Right to Object (Art. 21). You may object to processing based on our legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right to Withdraw Consent. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
- Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state or UK territory where you reside, where you work, or where the alleged infringement took place.
To exercise any GDPR right, contact us at the address listed in Section 14. We will respond within 30 days. If we require an extension (up to an additional 60 days for complex requests), we will notify you within the initial 30-day period with an explanation of the reason for the delay.
Section 8Cookies and Tracking
Our website uses cookies and similar technologies to maintain session functionality and analyze usage patterns. You can control cookies through your browser settings. Disabling cookies may limit certain functionality of our diagnostic tools.
We do not use cookies for advertising, retargeting, or cross-site tracking.
Section 9International Data Transfers
Dharma Funder is based in the United States. If you are located in the EU, EEA, or UK, your personal data will be transferred to and processed in the United States.
We rely on the following mechanisms to ensure adequate protection for international transfers of personal data:
- EU-US Data Privacy Framework. Where our sub-processors (including Stripe and Google) are certified under the EU-US Data Privacy Framework, transfers rely on that certification as the adequacy mechanism.
- Standard Contractual Clauses. For transfers to sub-processors not covered by the Data Privacy Framework, we rely on the European Commission's Standard Contractual Clauses (2021 SCCs) for EU transfers and the UK International Data Transfer Agreement ("UK IDTA") or UK Addendum for UK transfers.
You may request a copy of the applicable transfer mechanism by contacting us at the address listed in Section 14.
Section 10Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by Art. 34 GDPR.
Section 11Security Measures
We implement reasonable administrative, technical, and physical safeguards to protect personal information. Payment processing is handled exclusively by Stripe using industry-standard encryption (PCI DSS Level 1). Diagnostic tools use HTTPS for data transmission. Access to CRM and publication accounts is restricted to authorized personnel.
No method of transmission or storage is completely secure. We cannot guarantee absolute security of personal information.
Section 12California Residents: CCPA and CPRA
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"):
- Right to Know. You may request disclosure of the categories and specific pieces of personal information we have collected, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete. You may request deletion of personal information we have collected, subject to legal exceptions.
- Right to Correct. You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of these rights.
To submit a verifiable consumer request, contact us at the address listed in Section 14. We will verify your identity before processing any request and respond within 45 days.
Section 13Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Material changes will be communicated via email to active subscribers and clients.
Section 14Contact
For questions about this Privacy Policy, to exercise your data rights, or to submit a GDPR or CCPA request, contact:
Dharma Funder
Santa Cruz, California, United States
Email: [email protected]
Dharma Funder does not have a Data Protection Officer, as this is not required for a sole advisory practice under Art. 37 GDPR. All data protection inquiries are handled directly by the controller at the email address above.