Privacy Policy
1. Who we are, how to contact us and what this policy covers
1.1. The controller of your personal data is PPC ONE s.r.o., Company ID 05931631, with its registered office at Korunní 2569/108, 101 00 Prague 10, entered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 272749. In the rest of this text, we refer to ourselves as "we".
1.2. You can contact us about personal data protection in three ways: through our contact form, by replying to our work communication, or by post to the address of our registered office. To exercise your rights, you do not have to order a service or give us details about a project that have nothing to do with your request. We have not appointed a data protection officer.
1.3. This policy describes the processing in which we are the controller. It concerns visitors to our website and to our profiles on Facebook, Instagram and LinkedIn, prospective clients for our services, job applicants, contact persons of our clients and suppliers, and people featured in our client testimonials.
1.4. This policy does not cover personal data that we process on behalf of our clients, for example the data of a client's customers when we manage their campaigns. In those cases the client is the controller, and we follow the client's instructions and our contract with the client. This applies even when the client sends us the data by email, in a message, as a screenshot or as an attachment. The mere fact that such data is stored in our communication archive does not change our role.
2. What data we process, why and for how long
| Purpose | Who it concerns | What data | Legal basis | Retention period |
|---|---|---|---|---|
| Handling an enquiry and negotiating a contract | Prospective clients negotiating a contract of their own (individuals, sole traders) | Name, email, telephone number, website, the chosen plan, the content of the message, the source of the enquiry | While the negotiations are under way, Article 6(1)(b) GDPR; the subsequent limited storage, which allows us to follow up on a recent enquiry, rests on our legitimate interest under Article 6(1)(f) | For as long as the negotiations last; if no contract is concluded, we keep the necessary record of the enquiry and of the outcome of the negotiations for no longer than 6 months from the end of the negotiations, so that we can pick up where we left off if you approach us again; we do not keep attachments we no longer need; after that we erase the record; this storage does not entitle us to send you marketing offers |
| Communicating with the representatives and employees of companies (companies making an enquiry, clients, suppliers) | Contact persons of legal entities | Name, work email and telephone number, position, the content of work communications, including messages sent through messaging services; we also store the communications in our own archive on our server (part 4) | Our legitimate interest in communicating and working with the company concerned, Article 6(1)(f) | For as long as we work together and for no longer than 3 years after that ends; after that only the documents required by law (see the row on accounting and taxes below) |
| Supporting our work with AI tools (see part 5) | Contact persons of clients and suppliers and their ordinary work communication; not job applicants and not individuals negotiating a contract of their own before it is concluded | Name, work contact details and the part of a message or document that is necessary for the specific task | Our legitimate interest in preparing replies, working with materials and organising how we work together, Article 6(1)(f); you can object to this use (part 8) | The source communication is retained according to its own original purpose; conversations in AI tools that contain personal data are retained only for as long as the specific task requires; for retention by the providers, see point 5.5 |
| Providing services and performing a contract | A contracting party who is an individual | Identification and contact details, the content of the contract and of our communication | Performance of a contract, Article 6(1)(b) | For as long as the contract lasts; we cancel access rights to accounts when the service is handed over or ends |
| Accounting and taxes | Clients, suppliers | Billing details, account numbers, payment history | Legal obligation, Article 6(1)(c) | Accounting documents for 5 years from the end of the accounting period; financial statements and annual reports for 10 years (Section 31 of Act No. 563/1991 Coll.); tax documents for 10 years from the end of the tax period in which the supply took place (Section 35 of Act No. 235/2004 Coll.) |
| Offering our similar services to existing customers | Customers whose contact details we obtained when we provided a service | Email, name, the history of our work together | Legitimate interest, Article 6(1)(f), and Section 7(3) of Act No. 480/2004 Coll. | Until you opt out, and for no longer than 3 years from the last time we worked together; you can opt out when we obtain your contact details and in every offer, easily and free of charge |
| Recruitment process | Job applicants | Name, email, telephone number, LinkedIn, CV, the content of the message | Steps taken at the applicant's request before entering into an employment contract, Article 6(1)(b) | Until the recruitment process ends |
| Keeping a record for further job offers | Applicants who have asked us to do so | The same as in the row above | Separate consent, Article 6(1)(a) | 12 months from the end of the process, or until consent is withdrawn |
| Defending against claims arising from the recruitment process | Applicants | Only the advertisement, the decision and the correspondence relating to the process, not the whole CV | Legitimate interest, Article 6(1)(f) | 12 months from the end of the process; for successful applicants, we transfer the data we need to our employee records |
| Protecting our rights and defending ourselves in any dispute | Contracting parties and persons with whom a dispute or a complaint has arisen | The contract, proof of performance and the communication from which a claim may arise | Legitimate interest, Article 6(1)(f) | 3 years from the end of the contract or from the event from which the claim arises (Section 629 of Act No. 89/2012 Coll.); in a dispute, for as long as it lasts; this row does not cover prospective clients without a contract or job applicants, for whom the shorter periods above apply |
| Securing the website and protecting it against spam and attacks | Visitors to the website | IP address, technical data about the browser, the result of the Turnstile check | Our legitimate interest in protecting the website and its users, Article 6(1)(f) | Ordinary security logs for no longer than 180 days; records relating to a specific incident separately, for as long as we are dealing with it and protecting related claims |
| Measuring website traffic | Visitors who have given consent | A pseudonymous identifier (a browser code by which a repeat visit can be recognised), the pages visited, the device, the approximate location | Consent, Article 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll. | In Google Analytics we have set 14 months for event data; this does not apply to aggregate reports without an identifier; for cookie lifetimes see part 7 |
| Analysing how the website is used (heatmaps and session recordings) | Visitors who have given consent | A pseudonymous identifier, mouse movements and clicks, scrolling, the pages visited, the device, the approximate location | Consent, Article 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll. | In Microsoft Clarity under the rules of the service; currently, session recordings are kept as a rule for 30 days, and selected recordings and heatmaps are kept for no longer than 9 months; data that Microsoft processes for its own purposes under its own policy; for cookie lifetimes see part 7 |
| Targeting and measuring advertising | Visitors who have given consent | A pseudonymous identifier, behaviour on the website | Consent, Article 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll. | Google Ads and Sklik audiences based on behaviour on the website for no longer than 12 months; cookie lifetimes are given separately in part 7 and are not the retention period for conversion data; Google and Seznam also keep conversion data as independent controllers under their own policies |
| Communicating on our social networks | Visitors to our profiles on Facebook, Instagram and LinkedIn, and people who communicate with us | Name or profile label, the public data you make available to us, comments, reactions and private messages | Our legitimate interest in running our profiles, communicating and presenting our services, Article 6(1)(f); for an individual negotiating a contract of their own, Article 6(1)(b) | Private messages according to their purpose and the periods for enquiries or work communication above; public comments and reactions for as long as the post is published, or until they are removed earlier by the user, by us or by the platform; any working copies according to their own purpose |
| Evaluating traffic to our profiles | Visitors to our profiles on Facebook, Instagram and LinkedIn | Aggregate statistics on reach, traffic and interactions; when the platform creates them it also processes data about users and their activity | For our own evaluation, our legitimate interest in understanding the level of interest in our services and improving our content, Article 6(1)(f); the platform's own legal bases are explained by its operator | The underlying data is kept by the platform under its own policies referred to in point 4.6; aggregate outputs that do not allow anyone to be identified are not personal data |
| Publishing client testimonials and case studies | People who have allowed us to publish their testimonial | Name, job role, company, the text of the statement and, where applicable, an approved photograph or audiovisual recording | Consent, Article 6(1)(a), for the content and manner of publication agreed in advance | For the period stated in the consent, and no longer than until it is withdrawn; once it ends we remove the personal data from the places we manage; we keep limited proof of the consent under the following row |
| Keeping a record of consents and of their withdrawal | People whose data we process on the basis of consent | The necessary identifier, the content and version of the consent, the date and manner in which it was given, any changes or withdrawal; to prove a cookie choice we do not ask for a name | Meeting the obligation to demonstrate consent under Article 7(1) GDPR, Article 6(1)(c); once the processing ends, our legitimate interest in demonstrating that it was lawful, Article 6(1)(f) | For as long as the processing based on consent lasts, and after that a limited evidential record for no longer than 3 years from the end of that processing; in a specific dispute or inspection, for as long as we are dealing with it |
| Handling requests relating to personal data protection | People exercising their rights | Contact details, the content of the request, the necessary verification of identity, our reply and a record of the measures we took | Meeting our obligations under Articles 12 to 22 GDPR, Article 6(1)(c); the limited record that follows rests on our legitimate interest, Article 6(1)(f) | For as long as we are dealing with the request, and after that the necessary record for no longer than 3 years from the closure of the request; in a specific dispute or inspection, for as long as we are dealing with it; we delete verification materials we no longer need once we have verified your identity |
| Complying with a refusal of marketing and with an objection to AI | People who have refused marketing or the use of their communication in AI | The necessary contact identifier, the date and the scope of the restriction | For direct marketing, meeting a legal obligation, Article 6(1)(c); for an objection to AI that we have accepted, our legitimate interest in complying with the restriction, Article 6(1)(f) | For as long as we keep the communication concerned, or for as long as the contact could be brought back into the processing concerned; we review on an ongoing basis whether we still need the record; we do not use the record for marketing or as an input for AI |
| Responding to lawful requests from public authorities | Depends on the situation | The data covered by the specific request | Legal obligation, Article 6(1)(c) | According to the relevant obligation |
2.1. Mandatory fields are marked in our forms; we ask for the data we need in order to deal with your request, and the rest is optional. We ask for billing details to the extent our legal obligations require. Without the contact details we need we cannot reply to an enquiry, and without the data necessary to conclude and perform a contract we may not be able to provide the service. Not giving us optional data, and refusing or withdrawing consent to analytics, advertising or the publication of a testimonial, has no effect on your ability to order and use our services.
2.2. The retention periods also apply to working copies in our communication systems and in our other systems. For copies entered into AI, the rule in part 5 applies: only for as long as the specific task requires. We overwrite the backups of our systems in a regular cycle, within 90 days at the latest, and they serve only to restore operation after a failure. When we restore a backup, we take steps to prevent data that was erased or restricted earlier from returning to ordinary use. Retention at AI providers is governed by point 5.5, not by the rules for our backups.
2.3. For client testimonials we agree in advance on the specific content, on where it will be published and on how long it will be used. Consent can be withdrawn through the contact details in part 1. We do not treat the mere publication of a review on someone else's platform as consent to republishing it, together with your personal data, on our website. Company data that does not identify an individual is not personal data; its use is governed by our agreement with the client and by the other applicable rules.
3. Where we obtain data
3.1. We obtain most of the data directly from you. In the case of business contacts we may obtain data from public sources (the Commercial Register, a company's website, professional networks) or from a client who named you as a contact person. Where we have a duty to inform you under Article 14 GDPR, we provide the information within one month of obtaining the data at the latest; if we communicate with you for the first time before that, we provide it in that first communication; and if we first pass the data to another recipient before that, we provide it when we do so at the latest. The mere availability of this page does not replace the provision of that information. We will tell you the specific source of your data on request.
4. Providers and other recipients of data
4.1. We pass data only to those who need it for the purpose concerned.
| Category | Recipient | Role | Purpose | Processing outside the EEA |
|---|---|---|---|---|
| Hosting of the website, the enquiry database, our internal systems and our communication archive | Hetzner Online GmbH, Falkenstein data centre, Germany | Processor | Running the website, storing enquiries, invoicing, internal applications, the communication archive | No |
| Website protection, CDN and form verification | Cloudflare, Inc. | Processor for website protection; it also uses technical signals from form verification (Turnstile) to improve its own protection, for which it is responsible itself | Security and availability of the website, protection of forms | USA, EU-U.S. Data Privacy Framework |
| Company email, calendar, documents | Google Ireland Limited (Google Workspace) | Processor | Company communication and documents | USA, EU-U.S. Data Privacy Framework (Google LLC) |
| Traffic measurement | Google Ireland Limited (Google Analytics) | Processor | Analytics, only with consent | USA, EU-U.S. Data Privacy Framework |
| Analysis of how the website is used | Microsoft Ireland Operations Limited (Microsoft Clarity) | Recipient of data about the use of the website; for Microsoft's own purposes, an independent controller | Heatmaps and session recordings, only with consent | USA; Microsoft Corporation participates in the EU-U.S. Data Privacy Framework; for the safeguards see part 6 and the Microsoft Privacy Statement |
| Advertising | Google Ireland Limited (Google Ads) | Independent controller for conversion measurement and remarketing | Measuring how effective advertising is and targeting it, only with consent | USA, EU-U.S. Data Privacy Framework |
| Advertising (Sklik) | Seznam.cz, a.s., Company ID 26168685 | Recipient of advertising data and an independent controller for the purposes of its own advertising system | Measuring conversions and retargeting for PPC ONE, only with consent | A Czech provider; its policy allows further transfers outside the EU with contractual safeguards; for the exact scope and the safeguards see part 6 and Seznam's privacy policy (in Czech) |
| Facebook and Instagram profiles | Meta Platforms Ireland Limited | Operator of the platform; for Facebook page statistics, joint controllership to the extent of the relevant addendum, see point 4.6 | Communication, running our profiles and statistics | Ireland and other countries including the USA under the rules of the platform; Meta Platforms, Inc. participates in the EU-U.S. Data Privacy Framework; for the safeguards see part 6 |
| LinkedIn profile | LinkedIn Ireland Unlimited Company | Joint controller for Page Insights; for its other own purposes, an independent controller of the platform | Communication, running our profile and statistics | Ireland and other countries including the USA under the rules of the platform; LinkedIn Corporation (Microsoft group) participates in the EU-U.S. Data Privacy Framework; for the safeguards see part 6 |
| Customer support | Help Scout PBC | Processor | Email communication with clients and prospective clients; the customer support window (Beacon) on the website | USA, EU-U.S. Data Privacy Framework |
| Internal communication and task management | Slack Technologies, LLC (Salesforce group); Asana, Inc. | Processor | Organising our work, including contact details from communication with clients | USA, EU-U.S. Data Privacy Framework |
| Communication with clients via a messaging service | WhatsApp Ireland Limited | Provider of the communication service; the encryption applies to the transmission; messages we receive from you are stored like any other communication | Communication with clients | Ireland; subsequent processing in the USA, WhatsApp LLC is in the EU-U.S. Data Privacy Framework |
| AI tools (see part 5) | Anthropic Ireland, Limited (Claude); OpenAI Ireland Limited (ChatGPT, Codex) | Recipients of the content; the processing is governed by the providers' policies, including their own purposes, for which they act as controllers | Preparing texts and analyses and assisting with business communications under part 5 | Ireland; subsequent processing also outside the EEA, including the USA; for the safeguards see part 6 |
| Accounting and tax services | An external accounting firm | Processor | Keeping our accounts | No |
4.2. The cookie consent bar (Cookies správně) runs in your browser. It is operated by CRS a.s., Company ID 28387741, with its registered office at Klapkova 546, Prague 8. It sends the following to cookies-spravne.cz: a visitor identifier, information that the bar was displayed, and your choice for each consent category.
4.3. Independent controllers: public authorities to the extent of our legal obligations; our legal and tax advisers; and banks when payments are made.
4.4. Depending on the nature of the work, external marketing specialists, content creators and IT support suppliers may also have access to the data they need. We limit their access to the data needed for their task and make that access conditional on a confidentiality undertaking. Where a supplier processes data on our behalf, we conclude a contract with them under Article 28 GDPR. For data that we process on behalf of a client, bringing in a further processor (a sub-processor) is also governed by the client's prior written authorisation and by the relevant data processing agreement. Part 6 applies to any transfers outside the EEA.
4.5. Data included in a published testimonial is accessible, to the extent agreed, to visitors to our website or to another publication channel we have agreed on. Public content can be indexed by search engines. Removing it from the places we manage does not in itself guarantee that every copy held by third parties is erased immediately; this is without prejudice to any further obligations under GDPR.
4.6. Social networks and statistics. When we communicate and manage content on our profiles, we are responsible for the processing that we decide on. For Facebook Page Insights and LinkedIn Page Insights, joint controllership covers the processing carried out to create page statistics, not automatically all processing across the whole platform. The essential allocation of responsibilities is set out in Meta's Page Insights Controller Addendum and LinkedIn's Page Insights Joint Controller Addendum. For statistics on our Instagram profile we follow Meta's current terms; where those terms result in joint controllership, the same applies to them as to Facebook Page Insights. The operator of the platform carries out the processing of the underlying data for the statistics and deals with related rights to the extent of the arrangement, and we provide the necessary cooperation. You can also exercise your rights with us; we will pass the relevant request on to the platform. The processing that takes place when you use Facebook and Instagram is described further in the Meta Privacy Policy, and for LinkedIn in the LinkedIn Privacy Policy. Public comments can be seen by other users; we do not publish private messages. The fact that we run a social profile does not in itself mean that we use that network's advertising pixel or any other tracking on our website.
5. How we use AI tools
5.1. In our work we use artificial intelligence tools: Claude and Claude Code (Anthropic) and ChatGPT and Codex (OpenAI).
5.2. Accounts and the providers' role. We use individual accounts with these services. The providers process the content we enter under their own policies, including for their own purposes, for example ensuring security and preventing misuse.
5.3. What goes into AI. Materials for our work; aggregate data on campaign performance that does not identify particular people; and selected parts of ordinary work communication with clients and suppliers. These can contain a name, work contact details and the text of a message. We limit personal data to the part that is necessary for the specific task.
5.4. Excluded inputs. We do not put the following into AI: communication from job applicants; enquiries from individuals before a contract is concluded; personal data of our clients' end customers; login and payment details; birth numbers (national identification numbers); and special categories of personal data, for example health data. This restriction also applies to automatic retrieval from our communication archive and from connected sources.
5.5. Training and retention. In our work accounts we have turned off the use of content to train models. We keep conversations that contain personal data only for as long as the specific task requires. Retention by the providers, including any longer retention for security and legal reasons, is governed by their rules: Anthropic's data retention information, Anthropic's privacy policy and OpenAI's EU privacy policy.
5.6. Legal basis and objection. Where we support our ordinary work communication, we rely on our legitimate interest under Article 6(1)(f) GDPR in preparing replies, working with materials and organising how we work together. You can object to this use under part 8.
5.7. Decisions about people. AI helps with analysis and suggestions, and a person decides. We do not use AI for decisions based solely on automated processing that produce legal effects or similarly significant effects under Article 22 GDPR.
5.8. Content created with the help of AI. We check content prepared with the help of AI before we publish it. We label its artificial origin where the law requires us to, in particular Regulation (EU) 2024/1689 (AI Act).
5.9. AI and our clients' data. The use of AI when working with data that we process on behalf of clients is governed by our contracts with them and by their instructions (see point 1.4). This is without prejudice to the restrictions in point 5.4 and to our obligations when a further processor is brought in under point 4.4.
6. Processing data outside the European Economic Area (EEA)
6.1. Some recipients also process data outside the EEA, in particular in the USA. For recipients that participate in the EU-U.S. Data Privacy Framework, the transfer rests on a European Commission decision under Article 45 GDPR, to the extent of their certification. We state this for those recipients in part 4.
6.2. For the AI services listed in part 4, the European providers are companies in Ireland. The providers then also process the content outside the EEA, including in the USA, and their policies describe how they use adequacy decisions or standard contractual clauses under Article 46(2)(c) GDPR. You can ask for information about a specific safeguard through the contact details in part 1. Links to the providers' policies are in point 5.5.
6.3. If the mechanism on which a specific transfer outside the EEA rests were to cease to apply, for example the decision on the EU-U.S. Data Privacy Framework or the relevant certification, we will check for another valid safeguard and for any supplementary measures. Without them we will suspend the transfers concerned.
7. Cookies and similar technologies
7.1. Cookies are short text files that a website stores in your browser.
7.2. Without consent we use only the technologies that are necessary to transmit a communication or to provide a service that you have asked for:
| Cookie or technology | Purpose and lifetime |
|---|---|
ppcone_lang | The language you have chosen; 365 days |
cc_cookie | Your choice in the consent bar; 182 days |
| The Help Scout Beacon customer support window | Lets you contact us directly from the website; it loads without consent and stores in your browser only the technical data that the window and your conversation need in order to work; for the provider see part 4 |
7.3. Our forms are protected by Cloudflare Turnstile, which evaluates technical signals in order to tell a person apart from automated traffic (the Cloudflare security cookie cf_clearance, with a lifetime of up to 365 days). We process the personal data needed for security on the basis of our legitimate interest (part 2).
7.4. With your consent we use:
| Category | Technology, purpose and lifetime |
|---|---|
| Analytics cookies | Google Analytics: _ga and _ga_MVSQBDWF4X, a lifetime in the browser of up to 2 years, renewed on your next visit |
| Analytics cookies (Microsoft Clarity) | _clck (a pseudonymous visitor identifier), lifetime 1 year; _clsk (links the pages you view into a single session), lifetime 1 day; when Clarity loads, Microsoft may also set cookies on its own domains (for example MUID, CLID) under its own policy |
| Advertising cookies (Google Ads) | Where the relevant measurement is used, the cookies _gcl_au and _gcl_aw may be stored to measure how effective advertising is; Google states a lifetime of 90 days for _gcl_ cookies. What is actually stored depends on the measurement in place, on your consent and on how you arrived at the website; see Google's information about cookies. |
| Advertising cookies (Seznam) | Where the relevant measurement is used, the cookies sid for identifying a device and sznaiid for matching conversions may be stored; Seznam states a lifetime of 30 days for both. What is actually stored depends on the measurement in place and on your consent; see Seznam's cookie overview (in Czech). How long membership of an advertising audience lasts is given in part 2. |
7.5. You can refuse the optional analytics and advertising technologies in the first layer of the bar. You can change your choice at any time through the cookie consent bar. When you withdraw consent, we stop any further processing based on that consent. Three things need to be kept apart: the lifetime of a cookie in your browser; the retention period for data in analytics and advertising systems (part 2); and the validity of your consent (until you withdraw it or until cc_cookie expires). The legal basis is Section 89(3) of Act No. 127/2005 Coll. and Article 6(1)(a) GDPR.
7.6. With your consent we pass data about your behaviour on the website, linked to a pseudonymous identifier, to advertising systems. We currently do not use customer lists built from our own data, nor enhanced conversions with contact details. If we change this, we will update this policy and, for data that requires consent, we will ask for it in advance.
7.7. You can also delete or block cookies in your browser settings, for example by following the instructions for Chrome, Firefox, Safari on Mac, Safari on iPhone and Edge. Blocking necessary cookies can limit how the website works. To withdraw consent to our analytics and advertising technologies, use the settings in our cookie bar; simply deleting cookies does not replace changing your consent, and it can also remove the choice you have stored. For supported browsers and Google Analytics implementations you can also use the Google Analytics Opt-out Browser Add-on. This add-on does not switch off Microsoft Clarity or advertising technologies, and it does not replace consent management on our website.
8. Your rights
8.1. You have the right of access to your data and to a copy of it (Article 15); the right to rectification (Article 16); the right to erasure (Article 17); the right to restriction of processing (Article 18); the right to the portability of the data you have given us and that we process by automated means on the basis of consent or a contract (Article 20); and the right to withdraw consent at any time, without this affecting the lawfulness of the processing carried out before the withdrawal (Article 7(3)).
8.2. Right to object. You can object to processing based on legitimate interest through the contact details in part 1. We will always comply with an objection to direct marketing. We will tell you about the measures we have taken without undue delay and within one month at the latest. For other processing based on legitimate interest, including the use of your communication in AI tools, we will not continue after an objection unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of legal claims under Article 21 GDPR.
8.3. You can lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
8.4. You exercise your rights through the contact details in part 1. We deal with requests free of charge. We can charge a reasonable fee that reflects our administrative costs, or refuse to act on a request, only where the request is manifestly unfounded or excessive. When we assess whether a request is excessive, we can also take into account the fact that it is repetitive. We have to demonstrate that these conditions are met (Article 12(5) GDPR). We will tell you how we have dealt with your request without undue delay and within one month of receiving it at the latest. Taking into account how complex the requests are and how many there are, this period can be extended by a further two months; we will tell you about the extension and the reasons for it within one month. If we do not comply with a request, we will give you the reasons within the same basic period and tell you that you can lodge a complaint and seek a judicial remedy. If we have reasonable doubts about your identity, we will ask only for the data we need to verify it.
8.5. We will notify any rectification, erasure or restriction we carry out to the recipients to whom we have disclosed the data, unless this proves impossible or would involve disproportionate effort. We will tell you about those recipients on request. We keep only the necessary record of a request and of how it was dealt with, in line with part 2.
9. Security
9.1. We protect data with technical and organisational measures: encrypted transmission (HTTPS), access control, protection of the website and its forms (Cloudflare, Turnstile), backups, and internal rules for working with AI tools and with client data.
9.2. Only authorised people have access to personal data, and only to the extent they need it for their work. We bind our employees and external collaborators to confidentiality and require them to follow our rules for working with data. When our cooperation changes or ends, we adjust or remove access accordingly.
9.3. Personal data breaches. We document an incident, assess its scope and its risks, and take measures to limit its consequences. Unless it is unlikely to result in a risk to the rights and freedoms of individuals, we report it to the Office for Personal Data Protection without undue delay and, where feasible, within 72 hours of the moment we become aware of it. Where an incident is likely to result in a high risk, we inform the people concerned without undue delay, unless a statutory exemption applies; we set out in clear terms what happened, its likely consequences, the measures we have taken, what we recommend you do, and a contact point for further information. If an incident affects data that we process on behalf of a client, we inform the client without undue delay.
10. Changes to this policy
10.1. We update this policy in line with changes to our services, our tools and the law. The current version, with its effective date, is always on this page. Before we process data for a new purpose, we will tell you about that purpose and about the related changes in an appropriate way. If new consent is needed, we will ask for it in advance.
Effective from: 17 September 2026. It replaces the version dated 15 September 2026.