Legal

Privacy Policy

Last updated: [DATE]

Working draft for [COMPANY LEGAL NAME]. It must be reviewed against the privacy law that actually applies to you (GDPR, UK GDPR, CCPA/CPRA or state equivalents) before launch.

1. Who controls your data

[COMPANY LEGAL NAME], [REGISTERED ADDRESS], is the controller for data collected through this website. For the customer contact details our clients send us, the client is the controller and we act as their processor. Data protection contact: [DPO OR PRIVACY EMAIL].

2. What we collect on this site

  • What you type. Name, business name, email address, phone number, city, the competitor you name, and anything you write in the contact form or the chat widget.
  • Technical data. Your IP address and browser user-agent, recorded with each submission to prevent abuse and rate-limit spam.
  • Local browser storage. The chat widget remembers, on your own device only, that you have already been greeted. It is not sent to us and is not an advertising cookie.

The Review Gap calculator runs entirely in your browser. Nothing you type into it is transmitted to us unless you separately submit the contact form or the chat widget.

3. Why we use it, and our lawful basis

We use what you submit to reply to you, prepare a Review Gap report, and — if you become a client — deliver the service. The lawful basis is your consent when you submit a form, and our legitimate interest in responding to business enquiries and keeping the site free of abuse. [CONFIRM BASIS WITH YOUR ADVISER.]

We do not sell your data. We do not use it for advertising profiling.

4. Third parties

This site makes no third-party requests. Fonts, styles, scripts and images are all served from our own server, so no outside company — Google included — sees your visit. There are no analytics or advertising trackers. [LIST ANY OTHER PROCESSORS — hosting, email, CRM — WITH THEIR LOCATIONS.] We are not affiliated with or endorsed by Google.

5. Where it is stored, and for how long

Enquiries are stored on our server in [HOSTING REGION] and kept for [RETENTION PERIOD], after which they are deleted. Client customer data is retained for the life of the contract and deleted or returned within [PERIOD] of termination.

6. Your rights

Depending on where you live, you may ask us for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, ask for it in a portable format, or withdraw consent at any time. Exercising these rights costs nothing and we will not treat you differently for it.

Email [PRIVACY EMAIL] and we will respond within [RESPONSE PERIOD]. If you are unhappy with the outcome you can complain to [SUPERVISORY AUTHORITY].

7. Security

Submissions are transmitted over TLS and stored with restricted file permissions on a server only our administrators can reach. No system is perfectly secure; if a breach affects you we will notify you and the relevant authority as the law requires.

8. Children

This is a service for businesses. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact [PRIVACY EMAIL] and we will delete it.

9. Changes

If we change this policy we will update the date above, and tell clients directly where the change is material. See also our Terms of Service.