Privacy policy

Last updated: September 2026

The short version. Orderly Disruption Ltd (trading as Adaptive Fitness) is the UK data controller. We collect the minimum needed to sell and deliver assessments and credentials — never your payment details. Anything beyond delivery, including marketing and anonymised group insight, is explicit opt-in and defaults to no. Your certificate and badge live at link-accessible pages — that is how third-party verification works — shared only with you and, where you consented, the buyer of your code; either can be taken down on request. Data leaves the UK only under written safeguards.

Two companion pages say this in pictures and names: How we treat your data (the journey, one page) and Who handles your data (every provider, in plain language).

1. Who we are

Orderly Disruption Ltd, a company registered in England and Wales, trading as Adaptive Fitness, operates this website and the SGEP Fitness assessment and credentialing services (together, the "Services"). For applicable data-protection law, including UK GDPR, we are the data controller. Contact for anything in this policy, including exercising your rights: info@orderlydisruption.com.

2. What we collect, and why

What we hold depends on how you interact with us. For each purpose, UK GDPR requires a lawful basis; they are stated below.

If you… We process Why, and on what basis
Browse the store Device and usage information (IP address, browser, pages viewed), via cookies and similar technologies To operate and secure the site (legitimate interests); optional cookies only with your consent via the cookie banner
Buy access codes Your name, email address and order reference, passed to us by the Merchant of Record you bought from To deliver what you bought — codes, sign-in links, order records (performance of a contract). We never receive or store your payment details; the Merchant of Record is the independent controller of your payment
Take an assessment Your name, email address, answers' outcome, score, pass/fail result, your answers to the consent questions asked inside the test, and, as on any website, the IP address you take it from To run the assessment and issue your result and certificate (performance of a contract, and our legitimate interest in administering assessments bought for you by someone else — for example your employer). Where a buyer purchased your code, the outcome is shared with that buyer only if you explicitly consent before starting; declining means the assessment cannot begin, and that is disclosed up front
Earn a credential Your name, the credential, issue and expiry dates; your choice about publication To issue and host the badge and certificate (performance of a contract). Certificates (ClassMarker) and badges (issued by us on the Open Badges standard, hosted on our own infrastructure) are hosted at link-accessible pages — anyone who has the link can view them, because that is what makes third-party verification possible. We share your links only with you and, where you consented before starting, with the buyer of your code; whether to share them further is your choice. You can ask us to have a certificate or badge taken down at any time
Join the league table or publish a profile A pseudonym you choose (your GamerTag), your passed assessments, scores and expiry dates, and how you chose to appear — by name, by pseudonym, or both With your consent only; off by default. The league table and your public profile show only what you chose to publish. Withdraw at any time from your results page and they disappear. Your employer or any buyer of your code never receives a league table
Opt in to marketing Your email address and marketing preference, with a dated record of your consent To send occasional email you asked for (consent) — via the in-assessment marketing question or the footer signup, each defaulting to no; unsubscribe in every email
Opt in to group insight Your result, contributed to anonymised aggregate statistics With your consent only. Aggregates are shown only for groups of at least ten people; below that threshold, nothing is shown to anyone. No individual breakdowns, no ranking
Apply to be an ambassador What you send in your application; if accepted, your name, community and path To assess your application (legitimate interests) and, if you are accepted, to run the programme, which includes listing your name, community and path publicly as an ambassador (performance of the ambassador terms). A name change waits for our approval before it goes live
Contact us Whatever you include in your message, and our reply To respond to you (legitimate interests)

We do not collect special-category ("sensitive") data, and our assessments are designed not to solicit it. We do not use your personal information for automated decision-making with legal or similarly significant effects.

3. Who processes your data for us

A small number of specialist companies process personal data on our instructions, each under a written data processing agreement: ClassMarker (runs the assessments), Resend (sends our transactional email), Google Workspace (our standby email sender, used only if Resend is unavailable, switched on and off by hand), and Cloudflare (hosts our delivery system, including the credentials we issue ourselves and their public verification pages). Like any email provider, Resend and Google each keep a record of what they send for us, including your address; we keep those records for 30 days. Checkout is handled by a Merchant of Record — FastSpring, Paddle, or Lemon Squeezy — which is the seller of record and the independent controller of your payment data under its own privacy policy. There is no third-party credential portal and no social sign-in: access to your results works through single-use sign-in links we email to you, so no identity provider is involved and there is no password to create.

A backup credential-verification page is hosted on GitHub, so badges can be checked even if our own site is down. It holds no personal data and sends nothing anywhere; a credential you paste into it is checked inside your own browser. GitHub receives the ordinary data of a web visit, such as your IP address, under its own privacy statement.

Who each company is, where it is, and the safeguard covering each data flow: Who handles your data.

We may also disclose personal information where you direct or consent to it; to professional advisers under confidentiality; in connection with a business transaction such as a merger; and to comply with legal obligations, enforce our terms, or protect the rights and safety of our users and others.

4. Relationship with Shopify

The store pages are hosted by Shopify, which collects and processes personal information about your access to and use of the store in order to provide it — for example, operating the storefront and checkout. Where Shopify processes personal information for its own purposes, Shopify is responsible for that processing, including responding to requests to exercise your rights over it. To learn more, see the Shopify Consumer Privacy Policy; depending on where you live, you may exercise certain rights at the Shopify Privacy Portal.

We do not sell or share your personal information for targeted advertising. Shopify's cross-merchant advertising features are switched off for this store. If that ever changes, this policy and Your Privacy Choices will change first, and an opt-out will be provided. If you visit with the Global Privacy Control signal enabled, we honour it as an opt-out preference for that browser and device in any event. Other than Global Privacy Control, we do not recognise other "Do Not Track" signals.

5. International transfers

Some of our processors hold data outside the UK. Every such transfer is covered by a recognised safeguard: the UK's adequacy regulations, the EU–US Data Privacy Framework including its UK Extension, or the EU Standard Contractual Clauses together with the UK Addendum / International Data Transfer Agreement, written into our agreements. The safeguard for each provider is listed on Who handles your data.

6. How long we keep it

Only as long as each purpose requires: order and delivery records for the statutory accounting period; assessment results and credential records for the life of the credential and a limited period after expiry, so revalidation and verification work; consent and consent-withdrawal receipts for as long as we must be able to demonstrate them; support correspondence and ambassador applications for a limited period after resolution or decision. When a retention period ends, data is deleted or anonymised. On an erasure request, we delete what law does not require us to keep — anonymised accounting figures and a dated record that you withdrew consent survive, because they must.

One further record survives an erasure request. Where we have refused someone further assessments — for abuse of the service, of our staff, or of the assessment itself — we keep a record of that refusal and the reason for it, so that the refusal holds. It is kept on the basis of our legitimate interest in preventing the same abuse recurring, reviewed at least annually, written as a record of what happened rather than an opinion of the person, and never used for any other purpose. The full retention schedule is available on request.

7. Your rights

Under UK GDPR (and equivalent laws where you live), you can ask us for access to your personal information, correction, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing rests on consent — marketing, group insight, the league table and public profile, the verification page — you can withdraw that consent at any time, without affecting the lawfulness of what happened before.

Exercise any of these by emailing info@orderlydisruption.com. One email is enough; we may need to verify your identity, we will not discriminate against you for exercising your rights, and you may act through an authorised agent with proof of authority. Where a right needs to reach a processor — for example erasing an assessment record at ClassMarker — we carry the request through the chain; verification pages for credentials we issue ourselves are removed by us directly. If we ever refuse a request, in whole or in part, we tell you that we have, and why.

Complaints. Contact us first and we will try to put it right. You are also entitled to complain to the UK Information Commissioner's Office (ico.org.uk) or, in the EEA, to your local supervisory authority (list).

8. Cookies

The store uses necessary cookies to function, and optional cookies (analytics, advertising) only with your consent, managed through the cookie banner, where you can also change your choices later. Shopify's checkout sets its own cookies as described in its privacy policy.

9. Children

The Services are not directed at children, and we do not knowingly collect personal information from anyone under the age of majority in their jurisdiction. If you believe a child has provided us personal information, contact us and we will delete it. We do not have actual knowledge that we "share" or "sell" (as defined in applicable law) personal information of individuals under 16.

10. Security

Data is encrypted in transit everywhere and at rest with our processors; sign-in links work exactly once; access codes are single-purpose; our own operator access is protected by hardware-key authentication. No security is perfect, and we will not pretend otherwise — but our incident-response procedure commits us to notifying affected people and regulators as applicable law requires if something goes wrong.

11. Changes to this policy

When our practices change, this policy changes with them — we post the revised version here, update the date above, and give any notice applicable law requires. The version history of our customer-facing data documents is kept with our internal register.

12. Contact

Orderly Disruption Ltd (t/a Adaptive Fitness), registered in England and Wales — data controller.
info@orderlydisruption.com