Privacy Policy
- Who we are
- Which sites this covers
- What we collect
- Why we use it, and our legal basis
- Assessment data
- Cookies and tracking
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights
- How to exercise your rights
- Sale and sharing of personal data
- Children
- Automated decisions
- Changes to this policy
- Contact and complaints
This policy explains what Symphony 100 does with personal data, in plain terms. If you only read one thing: we collect what we need to sell and deliver training, we do not sell your data, and you can ask us to show you what we hold or delete it at any time using the contact details in section 17. The one thing we do not hold at all is assessment data — that sits with the publisher, and section 5 explains what that means for you.
1. Who we are
Symphony 100 operates through two legal entities. Which one is responsible for your data depends on where you are and what you bought.
| Entity | Role | Applies to |
|---|---|---|
| Symphony 100 Ltd. Registered in Israel Company registration number 516786621 Carlebach 4A, Tel Aviv-Yafo 6713229, Israel |
Owns and administers the websites and the content on them. Controller for site visitors, marketing contacts, and customers in Israel and the MENA region. | All website visitors; customers in Israel and MENA |
| Symphony 100 North America LLC Registered in Wyoming, USA 30 Gould Street, Suite N, Sheridan, WY 82801, USA |
Contracts with and delivers to customers in the United States and Canada. Controller for those customer relationships. | Customers in the US and Canada |
Where both entities are involved in the same activity — for example, a North American customer browsing a site the Israeli entity administers — they act as independent controllers for their own part of the processing. You can raise any request with either entity using the contact details in section 17 and we will route it correctly.
Not affiliated with the assessment publisher. Symphony 100 is an independent authorized partner of Everything DiSC® and The Five Behaviors®. Symphony 100 is not affiliated with, owned by, or a subsidiary of John Wiley & Sons, Inc. or any of its companies.
2. Which sites this covers
This policy is published at symphony100.com and is the single authoritative version. Our other websites link to this page rather than keeping their own copy, so there is only ever one policy to read and one to keep current.
It applies to the websites we operate, including:
- symphony100.com — our corporate site, blog, and shop
- chaostoalignment.com — the Chaos to Alignment course site and checkout
- symphony100academy.com — course and membership delivery
- go.symphony100.com — product and offer pages
It also applies to any other domain we own that redirects to the sites above, and to email, calendar bookings, and support conversations that start from any of them.
Platforms we do not operate
Some of what you buy from us is delivered on the publisher's own platforms rather than ours:
- Certification — the Wiley Online Training Center, learn.wileyworkplace.com
- Everything DiSC® on Catalyst™ profiles — catalyst.everythingdisc.com, where your profile stays live and you can add comparison reports over time
- All other Everything DiSC® and The Five Behaviors® profiles — myeverythingdisc.com
While you are on those platforms, the publisher's own privacy policy and terms apply, not this one. We pass them the information needed to set up your account and issue your assessment, and we receive results back — that exchange is covered by this policy. What happens inside their platform is governed by theirs. The same is true of any other third-party site we link to.
3. What we collect
Data you give us
- Contact details — name, email address, phone number, company, job title, country
- Account details — username and password for course and membership access
- Purchase details — what you bought, when, currency, billing name and country, and the last four digits and type of card. We never see or store your full card number. Card data goes directly to our payment processor.
- Booking details — availability, timezone, and anything you write in a booking form
- Course activity — lessons opened, quiz and knowledge-check answers, workbook entries, and feedback form responses
- Anything you write to us — support emails, replies, survey comments
Data collected automatically
- Device and connection data — IP address, browser and operating system, screen size, language, referring page
- Usage data — pages viewed, time on page, clicks, scroll depth, files downloaded, video watch progress
- Identifiers stored on your device — cookies and similar technologies, described in our Cookie Policy
Data from other sources
- Advertising platforms — Meta and LinkedIn tell us, in aggregate, which campaigns produced visits and sign-ups
- Referrals — if a colleague or sponsor enrolls you in a program, we receive your name and work email from them
- Public professional profiles — where you have made them public and they are relevant to a business enquiry you initiated
4. Why we use it, and our legal basis
Where the GDPR or UK GDPR applies to you, this is the legal basis for each use. Where Israeli or US law applies, the same purposes hold; the "legal basis" column simply describes our justification.
| What we do | Data used | Legal basis |
|---|---|---|
| Sell you a course, assessment, or workshop and give you access | Contact, account, purchase | Performance of a contract |
| Deliver the course, track your progress, issue completion records | Account, course activity | Performance of a contract |
| Send transactional email — receipts, access links, schedule changes | Contact, purchase | Performance of a contract |
| Answer enquiries and provide support | Contact, correspondence | Legitimate interests (running a responsive business) |
| Send marketing email and newsletters | Contact, engagement | Consent, or legitimate interests for existing customers where local law allows. You can unsubscribe from every message. |
| Measure how the sites perform and improve them | Device, usage | Consent, via the cookie banner |
| Run and measure advertising | Device, usage, hashed email where you have consented | Consent |
| Take payment and prevent fraud | Purchase, device | Performance of a contract, and legitimate interests in preventing fraud |
| Keep accounting, tax, and contract records | Purchase, contact | Legal obligation |
| Improve our programs using aggregated feedback | Course activity, feedback | Legitimate interests. We aggregate; we do not publish individual responses. |
5. Assessment data
We do not hold your assessment data. No assessment responses and no profile reports are stored on Symphony 100 systems at any point. They live on the publisher's platforms, which carry the publisher's own security program and privacy commitments. What we hold is the commercial record of the order — who bought what, and for whom — which sits under purchase records in section 9.
- Where your assessment lives. Assessments are administered and scored on the publisher's platforms — Catalyst™ (catalyst.everythingdisc.com) for Catalyst-based profiles, and MyEverythingDiSC (myeverythingdisc.com) for the rest. Their handling is governed by the Wiley Privacy Policy.
- International transfers are covered. John Wiley & Sons, Inc. and its subsidiary Inscape Publishing, LLC — the entity behind these assessments — are certified under the EU–US Data Privacy Framework, its UK Extension, and the Swiss–US Data Privacy Framework. For EU and UK participants that means the transfer to the publisher rests on a recognized adequacy mechanism rather than on contract clauses alone. See section 8.
- Retention is set by the publisher, not by us. The publisher keeps assessment data for as long as it is needed for the purposes it was collected for, under its own retention policy — it is not held permanently by default. Ask us or the publisher if you need the period that applies to a specific account.
- Deleting a profile. An account administrator can generally remove a learner's profile from the account — for example when someone leaves the organization. You can also exercise your rights directly with the publisher at [email protected] or +1-877-762-2974. We will point you to the right route and support the request, but because the data is not on our systems we cannot execute a deletion ourselves.
- Catalyst privacy control. If your profile is on Catalyst™, the Your Colleagues feature shows your DiSC® style to colleagues in the same account. You can switch this off at any time in the Privacy tab of your Catalyst account settings; if you do, colleagues will not see your style information and you will not see theirs. You can change it back whenever you like.
- Your individual profile report belongs to you. We release it to you.
- Where an employer or sponsor has paid for a group program, we share completion status with them, and we share individual profile reports with them only where you have been told this in advance and have agreed. Group-level and aggregated results may be shared with the sponsor without individual attribution.
- These assessments describe workplace behavioral preferences. They are not clinical instruments, and we do not use them or supply them for hiring, selection, promotion, or termination decisions.
6. Cookies and tracking
We use cookies and similar technologies. Non-essential cookies — analytics, advertising, and personalization — load only after you agree through our banner. You can change your choice at any time by clicking Cookie settings in the footer of any page.
The full list of what we set, what each one does, and how long it lasts is in our Cookie Policy.
7. Who we share data with
We do not sell your personal data. We share it with service providers who process it on our instructions, and only for the purposes below.
| Provider | What it does for us | Data involved |
|---|---|---|
| HighLevel (LeadConnector) | Funnels, checkout, CRM, course membership delivery, email and SMS automation | Contact, account, purchase, course activity |
| Stripe | Card payment processing | Purchase and billing data. Stripe receives your card details directly; we do not. |
| Wix (including its Visitor Analytics and Searchanise add-ons) | Legacy hosting for parts of symphony100.com while we complete our move to HighLevel. Being retired; once the move is complete this row comes out. | Device, usage, search terms, and any form you submit there |
| Cloudflare | DNS, security, and content delivery | Device and connection data |
| Google (Analytics 4, Tag Manager, Fonts, Cloud, Workspace) | Site measurement, tag delivery, web fonts, backend infrastructure; our email, calendar, and document storage | Device, usage, contact, correspondence |
| HighLevel calendar and Calendly | Discovery and session booking | Name, email, calendar availability, timezone |
| Mailgun (via HighLevel) | Delivery of bulk and automated email sent from mail.symphony100.com | Contact, engagement |
| Meta and LinkedIn | Advertising delivery and measurement | Device, usage, and hashed identifiers — only with your consent |
| Airtable | Storage of course feedback responses | Course feedback, and your identifier where the form asks for it |
| Zoom | Live sessions and working calls | Contact, and recordings where you have been told a session is recorded |
| Assessment publisher (John Wiley & Sons, Inc. / Inscape Publishing, LLC) | Assessment delivery, scoring, and report generation on the publisher's platforms, under the publisher's own privacy policy | Name, email, and organization for account set-up; assessment responses are entered by you directly on the publisher's platform |
We also disclose personal data:
- to our accountants, auditors, and legal advisers, under confidentiality
- where we are required to by law, court order, or a regulator
- to a buyer or successor if either entity is sold or restructured, with notice to you
8. International transfers
We operate from Israel and the United States and use providers based mainly in the United States and the European Union. That means your data will cross borders.
- Israel holds an adequacy decision from the European Commission, so transfers from the EEA to Symphony 100 Ltd. are permitted on that basis.
- Transfers to providers outside the EEA or UK rely on the European Commission's Standard Contractual Clauses, the UK Addendum where relevant, or the provider's participation in the EU–US Data Privacy Framework.
- Assessment data. John Wiley & Sons, Inc. and its subsidiary Inscape Publishing, LLC are certified under the EU–US Data Privacy Framework, the UK Extension, and the Swiss–US Data Privacy Framework. Transfers of assessment data to the publisher therefore rest on that certification. You can view it at dataprivacyframework.gov. Complaints about the publisher's handling go to [email protected], with unresolved DPF complaints referable to JAMS at no cost to you.
- You can ask us for a copy of the safeguards that apply to a specific transfer.
9. How long we keep data
| Data | Kept for |
|---|---|
| Course and membership accounts | For as long as your access is active, then 24 months |
| Purchase, invoice, and tax records | 7 years, or longer where tax law requires it |
| Marketing contacts | Until you unsubscribe, or after 36 months of no engagement |
| Enquiries and support correspondence | 24 months after the conversation closes |
| Assessment responses and profile reports | Not held by us at all. Retained by the publisher on its platform under the publisher's own retention policy. See section 5. |
| Analytics and advertising identifiers | Up to 14 months, or the shorter period set in the tool |
| Session recordings | 12 months, unless you ask us to delete sooner |
10. Security
We protect data with encryption in transit (TLS on every site), access limited to the people who need it, multi-factor authentication on our core business accounts, and payment handling delegated entirely to a PCI-compliant processor so card numbers never reach our systems.
No system is perfectly secure. If a breach affects your rights, we will notify you and the relevant regulator within the timeframes the law requires.
11. Your rights
If you are in the EEA or the UK
You have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. You can also object to direct marketing at any time, and we will stop.
If you are in Israel
Under the Privacy Protection Law and Amendment 13, you have the right to review the data we hold about you, to request that it be corrected or deleted where it is inaccurate, incomplete, unclear, or out of date, and to be told the purposes for which it is held, who receives it, and how long it is retained. You may also ask to be removed from any direct-marketing database.
If you are in the United States
Depending on your state, you have the right to know what we collect and why, to get a copy, to correct it, to delete it, to opt out of targeted advertising and of any sale or sharing of your data, and not to be discriminated against for exercising any of these rights. California residents may also designate an authorized agent to act for them. We honor Global Privacy Control signals as an opt-out of targeted advertising.
If you are in Canada
You have the right to access the personal information we hold about you, to challenge its accuracy, and to withdraw consent, subject to legal and contractual limits.
One limit worth knowing up front. These rights apply to the data we hold. Your assessment responses and profile reports are not on our systems — they sit with the publisher, under the publisher's own policy. So we cannot delete them for you, and we will not pretend we can. Your routes there are your account administrator, who can generally remove a profile from the account, or the publisher directly at [email protected]. We will point you to the right one and support the request. Everything else described above we handle ourselves. See section 5.
12. How to exercise your rights
Email [email protected] with the subject line "Privacy request" and tell us what you want. You do not need to use any particular form of words.
- We will ask you to confirm your identity, usually by replying from the email address we hold.
- We respond within 30 days, or 45 days for US state requests, and will tell you if we need an extension.
- Exercising your rights is free. We may charge only for a request that is repetitive or clearly excessive, and we will tell you before we do.
- If we cannot act on a request, we will explain why and how to appeal.
13. Sale and sharing of personal data
We do not sell personal data for money. Some US state laws define "sale" and "sharing" broadly enough to capture the use of advertising cookies. To be clear about it: when you consent to advertising cookies, identifiers about your visit are shared with Meta and LinkedIn for advertising measurement, which those laws may treat as sharing for cross-context behavioral advertising. Declining advertising cookies, or sending a Global Privacy Control signal, stops it.
We do not knowingly sell or share the personal data of anyone under 16.
14. Children
Our services are for working adults. They are not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
15. Automated decisions
We do not make decisions that produce legal or similarly significant effects about you using automated processing alone. Assessment reports are generated automatically from your own answers, but they are descriptive tools for your development — they are not used to decide anything about your employment.
16. Changes to this policy
We update this policy when our tools or practices change. The date at the top always shows the current version. If a change materially affects your rights, we will tell you by email or by a notice on the site before it takes effect.
17. Contact and complaints
Symphony 100 Ltd. — Carlebach 4A, Tel Aviv-Yafo 6713229, Israel
Symphony 100 North America LLC — 30 Gould Street, Suite N, Sheridan, WY 82801, USA
Email: [email protected]
If you are not satisfied with how we have handled your data, you can complain to a regulator:
- Israel — the Privacy Protection Authority
- EEA — the supervisory authority in your country of residence
- UK — the Information Commissioner's Office
- Canada — the Office of the Privacy Commissioner of Canada, or your provincial commissioner
- United States — your state Attorney General
We would rather hear from you first, and we will always try to resolve it directly.