Data Protection & Privacy Policy

(Updated May 2026 — ICO Registration No. [Pending ZA number] . This policy is drafted in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and guidance from the Information Commissioner’s Office (ICO).)


1. Introduction

DeSphere.xyz provides digital guides, audio resources, gentle 7-night kits, and private bespoke support for emotional clarity, body-led reset, daily rhythm, and non-clinical wellbeing support.

This Data Protection & Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website, subscribe to updates, purchase digital products, use The Night Shelf, apply for Private Services, complete intake forms, or contact us.

DeSphere.xyz is not a medical service, therapy provider, legal service, crisis support service, or diagnostic service. Please do not submit emergency, medical, legal, or crisis information through this website.

This Policy explains:

  • What data we collect and why.
  • How we store, secure, and process data.
  • The legal basis for using your data.
  • Your rights under the UK GDPR and Data Protection Act 2018.
  • Our company’s limitations of liability and user responsibilities.

DeSphere.xyz is operated as a digital wellbeing and body-led support platform. For the purposes of this policy, “DeSphere.xyz,” “we,” “us,” or “our” refers to the operator of this website and related digital services.

Where applicable, we act as the data controller for personal information collected through our website, forms, email subscriptions, purchases, and private service applications.


3. Scope of This Policy

This Policy applies to: all users of our services, including but not limited to customers, clients, partners, vendors, and any other individuals or organizations that interact with our company. It is essential that everyone who engages with us understands the rules and guidelines outlined in this Policy, as it governs our relationship and establishes the expectations for conduct, privacy, and data protection. By utilizing our services, all parties agree to abide by the principles set forth herein, which are designed to ensure transparency, accountability, and mutual respect among all stakeholders involved.

  • All users of DeSphere.xyz, BadWith, and related services.
  • Employees, contractors, and third-party service providers acting under our authority.
  • Any personal data processed digitally or manually, including through AI-assisted or automated systems.

4. Definitions

  • “Personal Data” – any information relating to an identifiable individual (e.g., name, email, IP address).
  • “Processing” – any operation performed on personal data, whether automated or manual.
  • “Data Controller” – the person or entity determining the purposes and means of processing.
  • “Data Processor” – any third party processing data on behalf of the controller (e.g., Stripe, Google).
  • “Special Categories Data” – sensitive data such as health, ethnicity, religious belief, or sexual orientation.

5. Data We Collect

We may collect the following types of information:

Account, contact, and communication data
Name, email address, country or region, contact details, messages submitted through forms, and correspondence with us.

Purchase and transaction data
Product purchased, order details, payment status, refund or support requests, and transaction-related information processed through third-party platforms such as Gumroad, Stripe, PayPal, or other payment providers where applicable.

Private service and intake data
Information you choose to provide when applying for or using Private Services, including written reflections, relationship concerns, emotional experiences, body-related observations, lifestyle patterns, goals, preferences, or other information relevant to the service.

Website and usage data
Device information, browser type, pages visited, referral links, approximate location, cookie data, analytics data, and interaction with website content where such tools are enabled.

Email and marketing data
Subscription status, email preferences, campaign engagement, and unsubscribe activity.

Sensitive Reflection Information

Some DeSphere.xyz forms, guides, or private services may invite you to share personal reflections, emotional experiences, relationship concerns, body-related observations, sleep or rhythm patterns, or lifestyle information. You should only share information that you are comfortable providing.

DeSphere.xyz does not require you to submit medical records, psychiatric records, legal documents, emergency information, or highly sensitive personal data unless clearly requested for a specific service and appropriate to that service.

If you are experiencing a medical, mental health, legal, or safety emergency, please contact a qualified professional or emergency service in your location.


6. Lawful Bases for Processing

We process personal data only when legally justified under one or more of the following bases: these include obtaining explicit consent from the individual, fulfilling a contractual obligation, complying with legal requirements, taking steps to protect vital interests, performing tasks carried out in the public interest, or serving legitimate interests pursued by our organization or a third party, provided that such interests do not override the fundamental rights and freedoms of the data subject.

  • Consent – you have given clear permission (e.g., signing up, ticking opt-in boxes).
  • Contract – processing is necessary to provide services or subscriptions.
  • Legal Obligation – we must comply with UK/EU laws, accounting, or regulatory duties.
  • Legitimate Interest – to improve products, security, or user support (balanced against your privacy rights).

7. Purpose of Data Use

Your personal data is used for the following purposes: to enhance and personalize your experience with our services, ensuring that the content and features you encounter are relevant to your interests and needs. Additionally, we utilize this data to improve our offerings continually, conducting analysis to understand user behavior and preferences, which enables us to provide more tailored solutions. Your information also helps us communicate effectively with you, allowing us to send updates, newsletters, and promotional materials that might interest you. Furthermore, it serves essential operational functions, including maintaining the security and integrity of our platform while complying with legal obligations and regulations.

Purpose of Data Use

We may use your information to:

  • deliver digital products, guides, audio resources, 7-night kits, and private services
  • process purchases, payments, refunds, and access to digital products
  • review Private Services applications and intake forms
  • prepare custom or bespoke materials where applicable
  • respond to questions, support requests, and customer service messages
  • send email updates if you subscribe
  • improve website content, products, and user experience
  • maintain website security and prevent misuse
  • comply with legal, tax, accounting, or regulatory obligations
  • manage consent, cookies, and communication preferences

8. Third-Party Processors

We may securely share limited data with trusted vendors under strict contracts:

CategoryPurposeExamples
Website hosting / platform toolsHosting and operating the websiteWordPress / hosting provider
Payment processorsProcessing purchases and paymentsStripe, Gumroad, PayPal where applicable
Digital product platformsDelivering guides, downloads, and digital productsGumroad or similar tools
Email toolsSending updates and managing subscriptionsEmail service provider where applicable
Form toolsCollecting applications, inquiries, or intake formsWebsite forms, Tally, Google Forms, or similar tools
Analytics toolsUnderstanding website traffic and page performanceAnalytics tools where enabled
Media platformsHosting or linking free audio/video contentYouTube or similar platforms

All processors comply with UK GDPR and sign Data Processing Agreements (DPA) with LDS ARTS LTD to ensure data protection standards. These agreements define each party’s responsibilities, promoting transparency and accountability. By following these guidelines, we assure clients that data handling is secure and compliant, reducing risks of breaches, and demonstrating our commitment to privacy rights and stakeholder trust.

We only share personal information with third-party service providers where necessary to operate the website, process payments, deliver products, provide support, or comply with legal obligations.


9. Data Storage and Security

We employ:

  • SSL/TLS encryption for all data transmission.
  • Encrypted databases with restricted access.
  • Regular security audits & backups.
  • Strict employee access control (role-based).

Despite best efforts, no system is invulnerable, as cyber threats continue to evolve and become more sophisticated over time. Therefore, it is crucial for users to remain vigilant and proactive in protecting their sensitive information. Users are responsible for safeguarding their login credentials and devices, which means choosing strong, unique passwords and enabling two-factor authentication whenever possible. Additionally, keeping software and security systems up to date can help mitigate potential vulnerabilities and protect against unauthorized access. Awareness of potential phishing attempts and other malicious tactics is equally important to ensure a safer online experience.


10. International Data Transfers

Where data is transferred outside the UK, we ensure that we adhere to stringent data protection regulations and guidelines to safeguard personal information. This includes conducting thorough risk assessments to understand the implications of such transfers and implementing robust security measures to protect data integrity. We also ensure that appropriate contractual agreements are in place with third parties to uphold the same level of data security as mandated by UK laws. Furthermore, we regularly review and update our practices to comply with evolving legal standards and maintain transparency with our users regarding how their data is handled and protected.

  • Transfers are to countries recognised by the UK government as providing adequate protection; or
  • Approved safeguards such as Standard Contractual Clauses (SCCs) are in place.

11. Data Retention

Data is retained only as long as necessary for: the purpose of fulfilling specific business objectives, ensuring compliance with legal obligations, and maintaining the integrity of our systems. This practice allows us to manage our resources efficiently while also protecting the privacy of our users. To further enhance our commitment to data security, we regularly review and assess the data we hold and take appropriate actions to delete or anonymize information that is no longer required. By balancing these needs, we strive to uphold a responsible and ethical approach to data management, prioritizing user trust and transparency throughout our operations.

  • Service delivery and support.
  • Legal and tax obligations.
  • Resolving disputes and enforcing agreements.

Once no longer required, data is anonymised or securely deleted following ICO standards to ensure compliance with data protection regulations. This process involves a thorough examination of the data to determine whether it can be effectively anonymised without losing its utility, or if it needs to be permanently and securely deleted from our systems. We take great care in handling all data responsibly, implementing robust procedures that prevent any unauthorized access or misuse during the transition to anonymisation or deletion. By adhering to these standards, we uphold the trust our users place in us and demonstrate our commitment to safeguarding personal information.


12. Users’ Rights Under UK GDPR

You have the right to: access information about your personal data, seek clarification on how it is being used, and demand corrections if you find any inaccuracies. Furthermore, you have the right to request the deletion of your data when it is no longer necessary for the purposes for which it was collected. It’s important to understand these rights fully, as they empower you to take control of your personal information and ensure that it is handled with the proper respect and care.

  • Request a copy of your data (Right of Access).
  • Correct inaccurate data (Right to Rectification).
  • Request deletion (Right to Erasure).
  • Restrict or object to processing (Right to Object).
  • Receive data in a portable format (Right to Portability).

To exercise these rights, contact: ldsarts@desphere.xyz

We respond within 30 days as required by law, ensuring that every inquiry is addressed thoroughly and with the utmost care. This timeframe allows us to review all necessary information and provide a comprehensive answer that meets the legal obligations while also satisfying the needs of our clients. Our commitment to timely responses reflects our dedication to transparency and accountability in all our communications.


13. Data Breach Response

In the event of a personal data breach, it is crucial to promptly identify the extent of the breach and assess the potential risks involved. Organizations must take immediate action to mitigate any damage that may result from the exposure of sensitive information. This involves notifying affected individuals and relevant authorities, as failure to do so could lead to greater consequences. Furthermore, it’s essential to conduct a thorough investigation to understand the root cause of the breach, implement corrective measures to prevent future incidents, and ensure that robust data protection protocols are established to safeguard personal information moving forward.

  1. We will investigate immediately.
  2. Report to the ICO within 72 hours where required.
  3. Notify affected users if there’s a high risk to their data.
  4. Record the incident in our internal Breach Log for audit purposes.

14. AI & Automated Decision-Making

Some features of DeSphere.xyz/BadWith use AI-based content generation, which allows us to produce high-quality and engaging content quickly and efficiently.
We ensure that our users receive tailored experiences by leveraging advanced algorithms that analyze data and personal preferences, resulting in relevant recommendations and insightful information. This innovative approach not only optimizes the creative process but also enhances user satisfaction, creating a seamless interaction between technology and creativity.

  • No sensitive data is used to train or influence AI models.
  • Automated outputs are not used to make legal or financial decisions about individuals.
  • Users always retain the right to request review or deletion of AI-interacted data.

AI-Assisted Tools and Automated Decision-Making

Some DeSphere.xyz content, digital materials, prompts, reflections, or private service outputs may be created, organized, drafted, or supported with the assistance of AI or automated tools.

Where personal information is used for a private or custom service, we aim to limit use to what is necessary to deliver that service. We do not use personal reflections submitted through private service forms for public content without permission.

DeSphere.xyz does not use automated decision-making to approve, reject, or determine access to essential services in a way that produces legal or similarly significant effects.

AI-assisted content is not therapy, medical treatment, legal advice, diagnosis, or emergency support.


15. Children’s Data

Our services are not directed to children under 13. In order to maintain a safe and secure environment, we emphasize that users under 18 should only use the platform under parental or guardian consent. We understand the importance of protecting privacy and wellbeing for younger users, and thus, we do not knowingly collect or store children’s personal data without verifiable consent. To ensure compliance with legal regulations, our platform incorporates robust measures to verify the age of users and the necessary consents obtained from guardians. We encourage parents to be actively involved in their children’s online activities and to monitor their use of our services.

DeSphere.xyz is intended for adults aged 18 and over. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, please contact us so we can take appropriate steps to delete it.


16. Cookies & Tracking Technologies

We may use cookies and similar technologies to operate the website, understand website traffic, support forms, improve user experience, and connect users to third-party platforms such as Gumroad, Stripe, YouTube, or email tools.

For more information, please see our Cookie Policy.


17. Liability & Disclaimer (Protecting the Company)

While we take reasonable steps to protect personal information, no website, online platform, email system, or digital transmission method can be guaranteed to be completely secure. You use the website and submit information at your own discretion.


We comply with a comprehensive range of regulations and standards that are designed to ensure our operations align with industry best practices and ethical guidelines. This commitment reflects our dedication to transparency, accountability, and excellence in all our endeavors. By adhering to these rigorous criteria, we not only uphold the trust of our clients and stakeholders but also contribute positively to the environment and society at large. Additionally, our team is continuously monitoring updates and changes in relevant laws to guarantee that our compliance efforts remain robust and effective, thereby fostering a culture of integrity and responsibility within our organization.

  • UK GDPR (2018)
  • EU GDPR (for EU users)
  • Privacy and Electronic Communications Regulations (PECR)
  • ICO Guidance on Data Protection Fees

19. Contact Details

Email: ldsarts@desphere.xyz
Website: https://desphere.xyz
Contact Page: https://desphere.xyz/contact-us/


20. Policy Review and Version Control

This Policy will be reviewed annually or sooner if significant legal or operational changes occur, ensuring that our practices remain compliant and relevant in an ever-evolving environment. This proactive approach allows us to address any emerging challenges and adapt to new regulations or industry standards effectively.


Last updated: 06 May 2026
Next review: October 2026. By maintaining this schedule, we remain dedicated to fostering best practices and ensuring continuous improvement within our organization.


21. Limitation of Liability

To the extent permitted by law, DeSphere.xyz is not responsible for indirect, incidental, or consequential damages arising from use of the website, digital products, or services. This does not limit any rights you may have under applicable data protection or consumer protection law.

© 2025 LDS ARTS LTD. All rights reserved.
Registered with the Information Commissioner’s Office (ICO), United Kingdom.
Unauthorized reproduction or misuse of this policy is prohibited.