Privacy policy

Last updated: July 14, 2026

The short version. Orderly Disruption Ltd (trading as Adaptive Fitness) is the UK data controller. We collect the minimum needed to sell and deliver assessments and credentials — never your payment details. Anything beyond delivery, including marketing and anonymised group insight, is explicit opt-in and defaults to no. Your certificate and badge live at link-accessible pages — that is how third-party verification works — shared only with you and, where you consented, the buyer of your code; either can be taken down on request. Data leaves the UK only under written safeguards.

Two companion pages say this in pictures and names: How we treat your data (the journey, one page) and Who handles your data (every provider, in plain language).

1. Who we are

Orderly Disruption Ltd, a company registered in England and Wales, trading as Adaptive Fitness, operates this website and the SGEP Fitness assessment and credentialing services (together, the "Services"). For applicable data-protection law, including UK GDPR, we are the data controller. Contact for anything in this policy, including exercising your rights: info@orderlydisruption.com.

2. What we collect, and why

What we hold depends on how you interact with us. For each purpose, UK GDPR requires a lawful basis; they are stated below.

If you… We process Why, and on what basis
Browse the store Device and usage information (IP address, browser, pages viewed), via cookies and similar technologies To operate and secure the site (legitimate interests); optional cookies only with your consent via the cookie banner
Buy access codes Your name, email address and order reference, passed to us by the Merchant of Record you bought from To deliver what you bought — codes, sign-in links, order records (performance of a contract). We never receive or store your payment details; the Merchant of Record is the independent controller of your payment
Take an assessment Your name, email address, answers' outcome, score, pass/fail result, and your answers to the consent questions asked inside the test To run the assessment and issue your result and certificate (performance of a contract, and our legitimate interest in administering assessments bought for you by someone else — for example your employer). Where a buyer purchased your code, the outcome is shared with that buyer only if you explicitly consent before starting; declining means the assessment cannot begin, and that is disclosed up front
Earn a credential Your name, the credential, issue and expiry dates; your choice about publication To issue and host the badge and certificate (performance of a contract). Certificates (ClassMarker) and badges (Sertifier) are hosted at link-accessible pages — anyone who has the link can view them, because that is what makes third-party verification possible. We share your links only with you and, where you consented before starting, with the buyer of your code; whether to share them further is your choice. You can ask us to have a certificate or badge taken down at any time
Opt in to marketing Your email address and marketing preference, with a dated record of your consent To send occasional email you asked for (consent) — via the in-assessment marketing question or the footer signup, each defaulting to no; unsubscribe in every email
Opt in to group insight Your result, contributed to anonymised aggregate statistics With your consent only. Aggregates are shown only for groups of at least ten people; below that threshold, nothing is shown to anyone. No individual breakdowns, no ranking
Contact us Whatever you include in your message, and our reply To respond to you (legitimate interests)

We do not collect special-category ("sensitive") data, and our assessments are designed not to solicit it. We do not use your personal information for automated decision-making with legal or similarly significant effects.

3. Who processes your data for us

A small number of specialist companies process personal data on our instructions, each under a written data processing agreement: ClassMarker (runs the assessments), Sertifier (issues and hosts credentials, with recipient data hosted in the EU), Resend (sends our transactional email), and Cloudflare (hosts our delivery system). Checkout is handled by a Merchant of Record — FastSpring, Paddle, or Lemon Squeezy — which is the seller of record and the independent controller of your payment data under its own privacy policy. If you sign in to the credential portal with a social or enterprise account (Google, Apple, LinkedIn, Microsoft), that identity provider processes your basic sign-in details under its own policy; we never receive your password.

Who each company is, where it is, and the safeguard covering each data flow: Who handles your data.

We may also disclose personal information where you direct or consent to it; to professional advisers under confidentiality; in connection with a business transaction such as a merger; and to comply with legal obligations, enforce our terms, or protect the rights and safety of our users and others.

4. Relationship with Shopify

The store pages are hosted by Shopify, which collects and processes personal information about your access to and use of the store in order to provide it — for example, operating the storefront and checkout. Where Shopify processes personal information for its own purposes, Shopify is responsible for that processing, including responding to requests to exercise your rights over it. To learn more, see the Shopify Consumer Privacy Policy; depending on where you live, you may exercise certain rights at the Shopify Privacy Portal.

We do not sell or share your personal information for targeted advertising. Shopify's cross-merchant advertising features are switched off for this store. If that ever changes, this policy and Your Privacy Choices will change first, and an opt-out will be provided. If you visit with the Global Privacy Control signal enabled, we honour it as an opt-out preference for that browser and device in any event. Other than Global Privacy Control, we do not recognise other "Do Not Track" signals.

5. International transfers

Some of our processors hold data outside the UK. Every such transfer is covered by a recognised safeguard: the UK's adequacy regulations, the EU–US Data Privacy Framework including its UK Extension, or the EU Standard Contractual Clauses together with the UK Addendum / International Data Transfer Agreement, written into our agreements. The safeguard for each provider is listed on Who handles your data.

6. How long we keep it

Only as long as each purpose requires: order and delivery records for the statutory accounting period; assessment results and credential records for the life of the credential and a limited period after expiry, so revalidation and verification work; consent and consent-withdrawal receipts for as long as we must be able to demonstrate them; support correspondence for a limited period after resolution. When a retention period ends, data is deleted or anonymised. On an erasure request, we delete what law does not require us to keep — anonymised accounting figures and a dated record that you withdrew consent survive, because they must. The full retention schedule is available on request.

7. Your rights

Under UK GDPR (and equivalent laws where you live), you can ask us for access to your personal information, correction, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing rests on consent — marketing, group insight, the verification page — you can withdraw that consent at any time, without affecting the lawfulness of what happened before.

Exercise any of these by emailing info@orderlydisruption.com. One email is enough; we may need to verify your identity, we will not discriminate against you for exercising your rights, and you may act through an authorised agent with proof of authority. Where a right needs to reach a processor — for example erasing an assessment record at ClassMarker, or removing a verification page at Sertifier — we carry the request through the chain.

Complaints. Contact us first and we will try to put it right. You are also entitled to complain to the UK Information Commissioner's Office (ico.org.uk) or, in the EEA, to your local supervisory authority (list).

8. Cookies

The store uses necessary cookies to function, and optional cookies (analytics, advertising) only with your consent, managed through the cookie banner, where you can also change your choices later. Shopify's checkout sets its own cookies as described in its privacy policy.

9. Children

The Services are not directed at children, and we do not knowingly collect personal information from anyone under the age of majority in their jurisdiction. If you believe a child has provided us personal information, contact us and we will delete it. We do not have actual knowledge that we "share" or "sell" (as defined in applicable law) personal information of individuals under 16.

10. Security

Data is encrypted in transit everywhere and at rest with our processors; sign-in links work exactly once; access codes are single-purpose; our own operator access is protected by hardware-key authentication. No security is perfect, and we will not pretend otherwise — but our incident-response procedure commits us to notifying affected people and regulators as applicable law requires if something goes wrong.

11. Changes to this policy

When our practices change, this policy changes with them — we post the revised version here, update the date above, and give any notice applicable law requires. The version history of our customer-facing data documents is kept with our internal register.

12. Contact

Orderly Disruption Ltd (t/a Adaptive Fitness), registered in England and Wales — data controller.
info@orderlydisruption.com