Privacy Policy | Dharma Funder
Dharma Funder

Privacy Policy

Effective: 2026-07-19
Section 1

Identity of the Controller

Dharma Funder ("Dharma Funder," "we," "us," or "our") is the business name of Rebecca Funder, sole proprietor, operating the website dharmafunder.com and related digital properties from Santa Cruz, California, United States. Dharma Funder is a sole executive advisory practice providing structural diagnostic and intervention services to senior leaders and founders.

This Privacy Policy describes how we collect, use, store, and protect personal information when you visit our website, use our diagnostic tools, subscribe to our Substack publication, or engage our advisory services. This policy applies to all users, including residents of the European Union ("EU"), European Economic Area ("EEA"), and United Kingdom ("UK").

Section 2

Categories of Information Collected

2.1 Diagnostic Tools (Decision Access Diagnostic and The Decision Access Map)

2.2 Substack Publication

2.3 Advisory Engagements

2.4 Speaking Engagements and Events

2.5 Website Usage

Section 3

Purposes and Lawful Basis for Processing

We process personal information for the following purposes. For each purpose, the applicable lawful basis under both California law and the EU General Data Protection Regulation ("GDPR") is stated.

Section 4

Third-Party Processors

We share personal information with the following third-party service providers ("sub-processors"), each of which processes data under its own privacy policy and applicable data processing terms:

We do not sell, rent, or trade personal information to third parties for marketing purposes.

Section 5

Data Retention

Section 6

Your Rights (All Users)

To exercise any of these rights, contact us at the address listed in Section 14. We will respond to verified requests within 30 days.

Section 7

Additional Rights for EU, EEA, and UK Residents (GDPR)

If you are a resident of the European Union, European Economic Area, or United Kingdom, you have the following additional rights under the General Data Protection Regulation ("GDPR") and the UK General Data Protection Regulation ("UK GDPR"):

To exercise any GDPR right, contact us at the address listed in Section 14. We will respond within 30 days. If we require an extension (up to an additional 60 days for complex requests), we will notify you within the initial 30-day period with an explanation of the reason for the delay.

Section 8

Cookies and Tracking

Our website uses cookies and similar technologies to maintain session functionality and analyze usage patterns. You can control cookies through your browser settings. Disabling cookies may limit certain functionality of our diagnostic tools.

We do not use cookies for advertising, retargeting, or cross-site tracking.

Section 9

International Data Transfers

Dharma Funder is based in the United States. If you are located in the EU, EEA, or UK, your personal data will be transferred to and processed in the United States.

We rely on the following mechanisms to ensure adequate protection for international transfers of personal data:

You may request a copy of the applicable transfer mechanism by contacting us at the address listed in Section 14.

Section 10

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by Art. 34 GDPR.

Section 11

Security Measures

We implement reasonable administrative, technical, and physical safeguards to protect personal information. Payment processing is handled exclusively by Stripe using industry-standard encryption (PCI DSS Level 1). Diagnostic tools use HTTPS for data transmission. Access to CRM and publication accounts is restricted to authorized personnel.

No method of transmission or storage is completely secure. We cannot guarantee absolute security of personal information.

Section 12

California Residents: CCPA and CPRA

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"):

To submit a verifiable consumer request, contact us at the address listed in Section 14. We will verify your identity before processing any request and respond within 45 days.

Section 13

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Material changes will be communicated via email to active subscribers and clients.

Section 14

Contact

For questions about this Privacy Policy, to exercise your data rights, or to submit a GDPR or CCPA request, contact:

Dharma Funder
Santa Cruz, California, United States
Email: [email protected]

Dharma Funder does not have a Data Protection Officer, as this is not required for a sole advisory practice under Art. 37 GDPR. All data protection inquiries are handled directly by the controller at the email address above.

This Privacy Policy is prepared for business use and regulatory compliance. It is not legal advice and does not substitute for review by licensed counsel in the applicable jurisdiction. Review by a California-licensed attorney and, for GDPR compliance, an EU/UK-qualified data protection practitioner, is recommended before publication.