Draft for legal review. This document is a professional template and must be reviewed by a qualified lawyer before publication. Replace all bracketed placeholders.
Effective date: [EFFECTIVE DATE]. Last updated: [LAST UPDATED DATE].
Who we are
This website is operated by [COMPANY LEGAL NAME], trading as Axoria Marketing (“Axoria”, “we”, “us”). Our registered address is [BUSINESS ADDRESS]. For the purposes of applicable data protection law, we are the data controller for personal data collected through this website and in the course of marketing our own services.
When we deliver marketing services to a client, we generally act as a data processor on that client’s behalf. That processing is governed by the contract we hold with the client, not by this policy. Questions about a client’s data should be directed to that client.
Personal data we collect
We collect personal data in three ways: information you give us directly, information collected automatically when you use the website, and information we receive from third parties.
Information you provide
- Enquiry and audit forms. When you use the contact form, request a free marketing audit or book a strategy call, we collect your name, company, email address, phone number, website URL, approximate monthly marketing budget, the services you are interested in and any message you write.
- Job applications. If you apply for a role through our careers page, we collect the details in your application, CV and covering message.
- Correspondence. Emails, calls and meeting notes exchanged with you before, during or after an engagement.
- Client and billing data. Contact details, contract information and invoicing records for clients and suppliers.
Information collected automatically
When you visit the website, our servers and the analytics tools described below may record your IP address, approximate location derived from it, browser type and version, device type, operating system, referring URL, the pages you view, the links and buttons you click, form interactions and session recordings or heatmaps. Some of this data is collected through cookies and similar technologies; see our Cookie Policy for details and controls.
Information from third parties
We may receive data about you from scheduling tools (for example, when you book a call), business data providers, publicly available sources such as company websites or LinkedIn, and advertising platforms that report on the performance of our own campaigns.
Why we use your data and our legal bases
Where the GDPR, UK GDPR or a similar law applies, we rely on one of the legal bases listed below for each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to enquiries, audit requests and call bookings | Form submissions, correspondence | Steps prior to entering a contract; legitimate interest in responding to business enquiries |
| Delivering services and managing client accounts | Client and billing data, correspondence | Performance of a contract |
| Sending marketing emails and follow-ups | Name, email, company, interests | Consent, or legitimate interest for existing business contacts where permitted |
| Measuring and improving the website | Analytics and usage data | Consent (where required by cookie rules); otherwise legitimate interest |
| Advertising and remarketing | Advertising cookie data, hashed contact identifiers | Consent |
| Recruitment | Application data | Steps prior to entering a contract; legitimate interest in assessing candidates |
| Security, fraud prevention and record keeping | Server logs, billing records | Legitimate interest; legal obligation |
Where we rely on legitimate interest, we have balanced that interest against your rights and expectations. You can object to processing based on legitimate interest at any time using the contact details at the end of this policy.
Cookies, analytics and advertising technologies
This website uses cookies and similar technologies operated by us and by third parties. The tools we currently use, or may use, include:
- Google Analytics 4 and Google Tag Manager to understand how visitors use the site and to manage measurement tags.
- Microsoft Clarity to record anonymised session replays and heatmaps that show how pages are used.
- Google Ads and Meta Pixel to measure conversions from our own advertising and to build remarketing audiences.
Non-essential cookies are set only after you give consent through the cookie banner, where consent is legally required. You can change your choice at any time. The Cookie Policy lists the specific cookies, their purpose and how long they last.
Who we share data with
We do not sell personal data. We share it only with the categories of recipients below, and only to the extent needed for the purposes described in this policy.
- Service providers that host the website, deliver email, store files, run our CRM, process scheduling, and provide analytics and advertising measurement. These providers act on our instructions under written contracts.
- Advertising and affiliate platforms where we run our own campaigns or manage affiliate programmes, limited to the data those platforms require to operate.
- Professional advisers such as accountants, lawyers and insurers.
- Authorities and regulators where we are legally required to disclose information.
- A buyer or successor in the event of a merger, acquisition or sale of assets, subject to the same protections.
A current list of our sub-processors is available on request from [COMPANY EMAIL].
International transfers
Some of the providers listed above store or process data outside the country in which you are located, including in the United States. Where data protection law requires it, we rely on recognised transfer mechanisms such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or an equivalent safeguard, together with additional technical measures where appropriate. Details of the safeguard applied to a specific transfer are available on request.
How long we keep data
We keep personal data only for as long as it is needed for the purpose it was collected for, and then delete or anonymise it. Our standard retention periods are:
- Enquiries that do not lead to an engagement: [RETENTION PERIOD, e.g. 24 months] from last contact.
- Client records and contracts: the duration of the engagement plus [RETENTION PERIOD, e.g. 6 years] to meet accounting and legal obligations.
- Unsuccessful job applications: [RETENTION PERIOD, e.g. 6 months] after the decision, unless you ask us to keep your details for future roles.
- Analytics data: according to the retention setting configured in each tool, which we set to the shortest period that still supports reporting.
Security
We use technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), access controls, multi-factor authentication on core systems and vetted service providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify you and the relevant authority where the law requires it.
Your rights
Depending on where you live, you may have rights under laws such as the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), India’s Digital Personal Data Protection Act, or similar legislation. These rights typically include the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Restrict or object to certain processing, including direct marketing and processing based on legitimate interest.
- Withdraw consent at any time, without affecting processing that took place before withdrawal.
- Receive your data in a portable format.
- Opt out of the “sale” or “sharing” of personal data for cross-context behavioural advertising, as those terms are defined under California law.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email [COMPANY EMAIL] with the subject line “Privacy request”. We may ask you to verify your identity before acting. We aim to respond within one month, or within the period required by the law that applies to you. We will not treat you differently for exercising your rights.
You can unsubscribe from marketing emails using the link in any email we send. To opt out of analytics and advertising cookies, use the cookie settings link in the website footer.
Children
This website and our services are intended for businesses and professionals. We do not knowingly collect personal data from anyone under the age of [MINIMUM AGE, e.g. 16 or 18]. If you believe a child has provided us with personal data, please contact us and we will delete it.
Links to other websites
Our website and content link to third-party websites, including tools, platforms and publishers we reference in our blog. We are not responsible for the privacy practices of those sites and encourage you to read their policies.
Changes to this policy
We review this policy periodically and update it when our practices or the law change. The effective date at the top of the page shows when it was last revised. Where a change materially affects how we use your data, we will take reasonable steps to notify you, for example by email or a notice on the website.
How to contact us
Questions, requests and complaints about this policy can be sent to:
[COMPANY LEGAL NAME], trading as Axoria Marketing
[BUSINESS ADDRESS]
Email: [COMPANY EMAIL]
Phone: [PHONE NUMBER]
Data protection contact: [DATA PROTECTION CONTACT NAME OR ROLE]
This policy is governed by the laws of [JURISDICTION]. If you are not satisfied with our response, you have the right to contact the supervisory authority in your country.