Last updated: August 12, 2026
This policy explains how SUITS - the Scientific, Universal, Individual, Transformative System of Wellness - collects, uses and protects your personal data. It sits alongside our Cookies Policy, which covers what we store on your device.
A wellness assessment asks personal questions. Your answers can say something about your health, your money, your relationships and your beliefs, so we have built SUITS to collect as little as it needs, to keep what it collects to itself, and to give you a straightforward way to take it back.
SUITSofLIFE is the data controller for the personal data described here. That means we decide why and how it is processed, and we are answerable for it under the General Data Protection Regulation and equivalent laws. Where a provider we rely on decides these things for itself - our payment processor, for example - it acts as an independent controller for that part, under its own privacy notice.
Every piece of personal data we hold falls into one of the four groups below, together with the reason we process it and the legal basis that permits us to.
Created when you sign in for the first time. We never see or store your password - authentication is handled entirely by our identity provider.
| Data | Where it comes from | Why we process it | Legal basis |
|---|---|---|---|
| Email address, name, profile picture and the identifier issued by your login provider | Auth0, when you sign in or sign up | To create your profile, recognise you on later visits, attach your assessments to you and contact you about your account. | Performance of a contract |
| Account role (standard user or administrator) | Assigned by SUITS | To decide which parts of the platform you may reach, such as the administration area. | Legitimate interests - securing the platform |
The heart of the service, and the most personal information we hold. Your answers can reveal a great deal about your health, finances, relationships and beliefs, and we treat them accordingly.
| Data | Where it comes from | Why we process it | Legal basis |
|---|---|---|---|
| Your answers to foundation and deep-dive questions across the eight wellness domains | You, as you complete an assessment | To calculate your domain, category and archetype scores and to keep your progress so you can return to an unfinished assessment. | Your explicit consent |
| Calculated scores, card token summaries, insights, blind spots and recommendations | Derived by SUITS from your answers | To produce your results view and your final report. | Your explicit consent |
| Aggregated, de-identified score distributions | Derived from all users' results | To show you how your results compare with those of other people, and to improve our scoring model. Comparison figures are aggregates - no other user can be identified from them, and no one sees your individual answers. | Legitimate interests - improving the service |
Collected only when you unlock a paid deep-dive assessment. Card details go directly to our payment processor and never reach our servers.
| Data | Where it comes from | Why we process it | Legal basis |
|---|---|---|---|
| Card number, expiry date and security code | You, entered on Stripe's checkout page | To take payment. SUITS never receives, sees or stores these details. | Performance of a contract |
| Payment reference, amount, currency, status and the assessment purchased | Stripe, once a payment completes | To unlock what you bought, reconcile payments, handle refunds and meet our accounting and tax obligations. | Performance of a contract and legal obligation |
Generated automatically as you use the platform. We keep it deliberately minimal and use it to run the service safely, not to profile you.
| Data | Where it comes from | Why we process it | Legal basis |
|---|---|---|---|
| Server logs containing IP address, timestamp, requested endpoint and browser user agent | Generated when your browser contacts our servers | To keep the service available, diagnose faults and detect abuse. | Legitimate interests - security and reliability |
| Administrative audit events recording actions taken in the administration area | Generated when an administrator acts on an account | To maintain an accountable record of changes made to accounts and questions. | Legitimate interests - accountability |
Some of the questions in the Hearts and Spades suits touch on your physical health, your emotional state and your spiritual or philosophical outlook. Under the GDPR this is a special category of personal data, and it may only be processed with your explicit consent. You give that consent when you choose to begin an assessment, and you may withdraw it at any time by deleting your answers or your account. We never use this information to make automated decisions with legal or similarly significant effects about you.
We do not sell your personal data, we do not rent it, and we do not share it with advertisers. It is disclosed only to the providers that make the service work, each bound to process it only on our instructions or under its own regulatory duties.
| Provider | Role | What they receive |
|---|---|---|
| Auth0 (Okta, Inc.) | Identity provider | Your email address, name and login activity. Auth0 authenticates you and issues the tokens that keep you signed in. |
| Stripe, Inc. | Payment processor | Your card details, billing information and the amount charged. Stripe acts as an independent controller for fraud prevention and its own regulatory duties. |
| Our hosting provider | Infrastructure | All data stored by the platform, held in encrypted form on servers we control. The provider has no right to access or use it. |
We may also disclose data where the law requires it - in response to a valid court order, for example - or where it is necessary to establish or defend a legal claim. If SUITS is ever sold or merged, your data may transfer with the business, and we will tell you before that happens.
Your assessment data is stored on servers we control. Our identity and payment providers operate globally and may process data outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses or another safeguard recognised under Chapter V of the GDPR.
Access to the platform requires a valid, signed token issued by our identity provider, and every request is checked against it. Administrative functions are restricted to a small number of accounts and every action taken through them is recorded. Traffic is encrypted in transit, database credentials and API keys are held as environment secrets rather than in our code, and access to production data is limited to those who need it to operate the service. No system is perfectly secure, but if a breach ever put your rights at risk we will notify you and the relevant supervisory authority as the law requires.
Whatever your location, we extend the following rights to everyone who uses SUITS. Exercising them is free and we will respond within one month.
SUITS is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
We review this policy whenever we change what we collect, why we collect it or who we share it with. Material changes will be reflected in the "last updated" date at the top of this page, and where the law requires it we will ask for your consent before the change takes effect.