Privacy Policy

Privacy Policy

GDPR notice for the website, Kajabi platform, coaching, and Soul Cartography application

Effective: 22 July 2026  |  Version 1.0

 

This Policy explains how Diana Hansen collects, uses, shares, stores, and protects personal data. It must be read together with the Cookie Policy and any short-form notice shown when information is collected.

 

1. Data controller

Business

Diana Hansen

CVR

44324229

Email

[email protected]

Website

https://www.diana-hansen.com/

Country of establishment

Denmark

 

Diana Hansen is a Danish sole proprietorship and is the controller for the processing described in this Policy, except where a third party independently determines its own purposes and means of processing.

2. Services covered

  • https://www.diana-hansen.com/
  • Kajabi-hosted courses, memberships, subscriptions, checkouts, email communications, and community functions;
  • The custom House & Soul Cartography application and its reports, timelines, charts, and AI-assisted features;
  • One-to-one and group coaching, mentorship, Zoom or other online sessions, workshops, events, and support communications.

3. Personal data we collect

  • Identity and contact data: name, email, telephone, address, country, username, and account identifiers.
  • Birth and calculation data: birth date, birth time, birthplace, time zone, derived coordinates, name information, and chart-calculation inputs.
  • Account and Kajabi data: login, offers purchased, course progress, membership level, community profile, posts, comments, reactions, attendance, and access history.
  • Transaction data: purchase, subscription, payment status, invoices, VAT, refunds, and limited payment details supplied by the processor.
  • Coaching data: booking, session attendance, correspondence, goals, agreed actions, proportionate notes, and recordings where separately agreed.
  • Reflective content: questionnaire responses, personal narratives, goals, relationships, professional circumstances, aspirations, and journal-style entries.
  • House & Soul Cartography and AI data: prompts, uploaded inputs, generated interpretations, calculations, model outputs, feedback, and technical logs.
  • Technical data: IP address, device, browser, operating system, timestamps, security events, referring pages, cookies, and usage events.
  • Marketing data: newsletter subscription, consent, preferences, campaign engagement, and suppression records.
  • Event and media data: attendance, accessibility or dietary requests, photographs, voice, video, and testimonial material where applicable.

4. Sensitive data

The Services do not generally require medical records or other special-category data. You may voluntarily disclose information concerning health, disability, mental health, religion or philosophical beliefs, sexuality, or emotional experiences in coaching, community, or reflective responses. Please provide only what is necessary. Where we intentionally process special-category information, we identify both an Article 6 lawful basis and an applicable Article 9 condition, such as explicit consent where appropriate.

Do not send medical records, psychiatric records, government identity documents, full financial account information, passwords, criminal records, or highly sensitive third-party information through general email, community posts, or AI prompts unless we specifically request it through an appropriate secure process.

5. How we collect data

  • Directly from you when you register, purchase, submit a form, request a report, join Kajabi, communicate, attend coaching, or use the app.
  • Automatically through necessary logs, cookies, consented analytics, security tools, and similar technologies.
  • From Kajabi, payment providers, scheduling tools, video providers, email providers, hosting providers, AI providers, and other vendors supporting the Services.
  • From another person when they lawfully request a relationship, family, or third-party analysis and have an appropriate lawful basis or authority.

6. Purposes and lawful bases

Purpose

Examples

Likely GDPR basis

Sensitive data condition

Provide Services

Accounts, Kajabi access, reports, coaching, support

Contract / pre-contract steps

Explicit consent or another Article 9 condition if applicable

Payments and records

Billing, invoices, VAT, refunds, fraud

Contract; legal obligation; legitimate interests

Usually not applicable

Community operation

Profiles, posts, moderation, safety

Contract; legitimate interests

Depends on what members submit

Security

Authentication, logs, misuse prevention

Legitimate interests; legal obligation

Usually not applicable

Marketing

Newsletters, offers, campaigns

Consent or another permitted direct-marketing basis

Not ordinarily applicable

Analytics

Usage, errors, product improvement

Consent where tracking requires it; limited legitimate interests where lawful

Avoid sensitive content

AI-assisted delivery

Prompts, reports, summaries, personalization

Contract

Additional Article 9 condition where sensitive data is intentionally processed

Testimonials

Public image, quote, story

Consent / separate permission

Explicit consent where sensitive information appears

Claims and compliance

Disputes, legal requests, evidence

Legal obligation; legitimate interests; legal claims

Legal-claims condition where applicable

 

7. Kajabi

Kajabi hosts courses, memberships, subscriptions, checkouts, email functions, and community features. When Kajabi processes personal data on Diana Hansen’s instructions, it acts as a processor under its contractual data-protection terms. Kajabi may also act independently for certain platform-security, payment, or legal purposes described in its own notices. Your Kajabi account activity, purchase, progress, community participation, and subscription status may be available to Diana Hansen’s authorized team for service delivery, support, moderation, billing administration, and compliance.

8. House & Soul Cartography application and AI

The custom application processes birth inputs, questionnaire responses, calculations, saved reports, timelines, account information, and interactions needed to provide the app. AI may assist with synthesis, drafting, summarization, translation, search, or support. The Service description should identify whether outputs are automated, AI-assisted, practitioner reviewed, or personally reviewed.

We do not intend to use House & Soul Cartography data to diagnose medical or psychiatric conditions or to make solely automated decisions producing legal or similarly significant effects. We do not use Customer Content to train a proprietary general-purpose model unless we separately explain that use, establish a lawful basis, satisfy any special-category requirements, and provide legally required choices or consent.

9. Coaching and confidentiality

Coaching information is used to schedule and deliver the agreed relationship, maintain proportionate notes, communicate, and manage payment and legal records. Coaching confidentiality is contractual and privacy-based; it is not represented as equivalent to attorney-client or clinical privilege. Disclosures may occur with your permission, where required by law, to protect life or safety, for legal claims, or to approved vendors and advisers under appropriate obligations.

10. Recipients and vendors

  • Kajabi for courses, community, subscriptions, checkout, email, and related platform functions;
  • Payment processors integrated with Kajabi or separately approved;
  • Website, cloud, database, authentication, and custom app hosting providers;
  • Zoom or other approved video and scheduling providers;
  • Email, CRM, customer-support, analytics, consent-management, and security vendors;
  • AI providers used for approved House & Soul Cartography or operational functions;
  • Accountants, attorneys, insurers, and authorities where lawful.

A current vendor register should be maintained internally. Where a vendor is a processor, an Article 28 data-processing agreement is required. Vendor access is limited to what is necessary for the defined purpose.

11. International transfers

Some providers may process information outside Denmark or the EEA. Transfers are made using an applicable adequacy decision, Standard Contractual Clauses, or another recognized safeguard, together with supplementary measures where required. The actual transfer mechanism depends on the selected Kajabi, cloud, payment, AI, email, and support vendors.

12. Retention

We retain data only as long as necessary for service delivery, statutory accounting and tax obligations, contractual records, consent evidence, security, complaints, and legal claims. The following are target periods and must be confirmed against production systems and Danish counsel:

Category

Target retention rule

Kajabi account and membership data

Active relationship plus up to 24 months, unless a longer legal or claims need applies

Invoices and accounting records

Required Danish accounting and tax period

House & Soul Cartography raw inputs

Active access plus up to 24 months, unless the user deletes earlier or a different product term applies

Final reports

During stated access period and up to 24 months after closure unless retained by user or legally required

AI prompts and intermediate outputs

Shortest configured period reasonably necessary; not indefinite

Coaching notes

Up to 24 months after coaching ends, unless a dispute or legal obligation justifies longer

Support communications

Up to 36 months after resolution

Marketing consent and suppression

Consent evidence for the relevant claims period; minimal suppression while necessary to honor opt-out

Security logs

Typically 30-180 days depending on risk

Community content

Until deleted, account closure, or the applicable Kajabi community retention setting; moderation evidence may be retained longer

 

13. Security

We use risk-appropriate safeguards such as role-based access, password hashing, multifactor authentication where available, encryption in transit, vendor review, logging, backups, confidentiality duties, data minimization, and incident response. No system is entirely risk-free. You are responsible for securing your credentials.

14. Personal-data breaches

We assess suspected breaches promptly. Where a breach is likely to present risk, we notify the competent authority without undue delay and, where feasible, within 72 hours after awareness. Where high risk is likely, affected individuals may also be notified without undue delay.

15. Your GDPR rights

  • Access your personal data and information about processing;
  • Correct inaccurate or incomplete data;
  • Request deletion where legal conditions are met;
  • Request restriction in specified circumstances;
  • Receive eligible data in a structured, commonly used, machine-readable format;
  • Object to legitimate-interest processing and to direct marketing at any time;
  • Withdraw consent without affecting prior lawful processing;
  • Receive safeguards for applicable solely automated significant decisions;
  • Complain to the Danish Data Protection Agency or another competent authority.

Send requests to [email protected]. We may request proportionate identity verification. We ordinarily respond within one month, subject to lawful extension for complex or numerous requests. Rights are not absolute; limited records may be retained for law, accounting, security, suppression, or legal claims.

16. Children and third-party reports

Standard Services are intended for adults. Child or family offerings require a separately reviewed lawful basis, authority, child-appropriate notice, and safeguarding process. Adults must not use interpretive information to impose a fixed identity, diagnosis, predetermined future, or restrictive path upon a child. A person submitting another individual’s data represents that they have an appropriate lawful basis or authority.

17. Cookies and marketing

Necessary cookies support security and service operation. Optional analytics, preference, embedded-media, and marketing technologies are used only after required consent. Marketing may be sent where legally permitted. You may unsubscribe at any time; limited suppression data may remain to honor your choice.

18. Changes

We may update this Policy to reflect legal, vendor, product, security, or operational changes. Material changes will receive additional notice or consent where required. The revision date will be displayed.

19. Complaints and contact

Contact [email protected] first. You also have the right to lodge a complaint with Datatilsynet, the Danish Data Protection Agency.

Business

Diana Hansen

CVR

44324229

Email

[email protected]

Website

https://www.diana-hansen.com/

Country of establishment

Denmark




Close

50% Complete

Two Step

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.