Privacy Policy

Last updated: [DATE]

This Privacy Policy explains how [LEGAL ENTITY NAME] (“VentiveMail”, “we”, “us”, “our”) collects, uses, shares, and protects personal information when you visit [WEBSITE URL], submit a form, book a call, or communicate with us.

If you become a client, additional terms in your signed service agreement and any data processing agreement will also apply.

Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]

Privacy contact: [PRIVACY EMAIL]

[IF APPLICABLE] EU / UK representative: [NAME AND ADDRESS]

1. Information we collect

1.1 Information you give us

Through application forms, booking pages, email, and calls, we may collect:

  • name, business email address, phone number

  • company name and website or store URL

  • role or job title

  • ecommerce platform, monthly revenue band, average order value, current email platform and setup

  • information about your marketing goals, current performance, and challenges

  • anything else you choose to tell us in a form field, email, or on a call

1.2 Information collected automatically

When you visit the Site we and our providers may collect:

  • IP address and approximate location derived from it

  • device type, operating system, browser type and language

  • pages viewed, time on page, scroll depth, referring URL, exit pages

  • video engagement data on our sales video, such as play, pause, and watch duration

  • click IDs and campaign parameters passed through from ads (for example fbclid, gclid, utm_source)

  • cookie and similar identifiers

1.3 Information from third parties

We may receive information from advertising platforms, analytics providers, scheduling tools, and enrichment or verification services, and from publicly available business sources such as your website or LinkedIn, used to assess fit before a call.

1.4 Call recordings

Discovery and strategy calls may be recorded or transcribed for quality, training, and internal reference. Where recording takes place we will tell you at the start of the call and proceed only with your consent. You can decline recording and still take the call.

1.5 Client account data

If you engage us, you may grant us access to your marketing platforms, for example Klaviyo, your ecommerce platform, and your domain or DNS records. That access may expose personal data about your customers and subscribers. In relation to that data we act as a processor or service provider on your behalf, and we handle it only on your documented instructions and only for the purpose of delivering the service. See section 9.

1.6 What we do not collect

We do not knowingly collect payment card numbers through the Site. Payments, where applicable, are handled by a third-party payment processor. We do not seek special category data (health, biometric, political, religious, or similar). Please do not submit it.

2. Why we use your information, and our legal bases

  • Purpose: Respond to enquiries, qualify applications, schedule and conduct calls — Legal basis (UK/EU GDPR): Steps taken at your request prior to entering a contract

  • Purpose: Provide services and manage the client relationship — Legal basis (UK/EU GDPR): Performance of a contract

  • Purpose: Send marketing emails and SMS — Legal basis (UK/EU GDPR): Consent, or legitimate interests for existing business contacts where permitted

  • Purpose: Measure and improve ad campaigns and Site performance — Legal basis (UK/EU GDPR): Consent for non-essential cookies and tracking; otherwise legitimate interests

  • Purpose: Site security, fraud prevention, and abuse detection — Legal basis (UK/EU GDPR): Legitimate interests

  • Purpose: Keep records and comply with legal, tax, and accounting duties — Legal basis (UK/EU GDPR): Legal obligation

  • Purpose: Establish, exercise, or defend legal claims — Legal basis (UK/EU GDPR): Legitimate interests

Where we rely on legitimate interests, we have assessed that our interest in operating and growing a business does not override your rights and freedoms. You can object at any time (see section 7).

3. Cookies, pixels, and tracking

We use cookies and similar technologies, including advertising pixels, to run the Site and to measure and target advertising. Categories:

  • Strictly necessary. Required for the Site to function and to remember your cookie choices.

  • Analytics. Aggregate usage measurement, for example [Google Analytics 4].

  • Advertising and retargeting. For example the [Meta Pixel], [TikTok Pixel], [Google Ads tag]. These may set cookies and share event data with the platform so we can show ads to you and to similar audiences, and measure conversions.

Conversions API / server-side tracking. Where we use server-side event forwarding, we may send hashed identifiers such as a hashed email address to advertising platforms to attribute conversions. Hashing reduces but does not eliminate identifiability.

Your choices. Where required by law, non-essential cookies are set only after you consent through our cookie banner. You can change or withdraw consent at any time via [COOKIE SETTINGS LINK]. You can also block cookies in your browser, though parts of the Site may not work properly. Global Privacy Control signals are honoured where legally required.

A full, current list of the cookies we set is available at [COOKIE POLICY LINK].

4. Marketing emails and SMS

Email. We send marketing email only where you have given consent or where permitted for business contacts under applicable law. Every marketing email includes an unsubscribe link.

SMS. If you provide a mobile number and opt in, we may send SMS about your enquiry or our services. Consent to marketing SMS is never a condition of purchase. Reply STOP to opt out and HELP for help. Message frequency varies. Message and data rates may apply. Mobile opt-in data and consent records are not shared or sold to third parties for their own marketing.

Transactional messages. Even after opting out of marketing, you may receive messages needed to service an active enquiry or engagement, such as booking confirmations and project updates.

5. How we share information

We do not sell your personal information for money. We share it with:

  • Service providers acting on our instructions, including website and form hosting, scheduling, email and SMS delivery, CRM, cloud storage and document tools, analytics, transcription, and accounting. Current categories and named providers: [LIST YOUR ACTUAL STACK, e.g. Calendly, Klaviyo, Google Workspace, Notion, Slack, Zapier, Stripe].

  • Advertising and analytics platforms, as described in section 3. Under the California CPRA and some other US state laws, this cookie-based advertising activity may be treated as “sharing” for cross-context behavioural advertising, or as a “sale”. You can opt out (see section 8).

  • Professional advisers, such as lawyers and accountants, under duties of confidentiality.

  • Authorities, where required by law, court order, or to protect our legal rights.

  • A successor entity, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We do not share your information with unrelated third parties for their own independent marketing.

6. International transfers and storage

We operate from [COUNTRY] and use providers located in the United States, the European Economic Area, the United Kingdom, and [OTHER]. Your information may therefore be transferred to and processed in countries whose data protection laws differ from your own.

Where we transfer personal data out of the UK or EEA, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses (and the UK Addendum where relevant) together with supplementary measures as needed. You can request a copy of the safeguards by contacting [PRIVACY EMAIL].

7. Your rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you

  • correct inaccurate or incomplete information

  • request deletion

  • restrict or object to processing, including direct marketing and profiling

  • receive your data in a portable format

  • withdraw consent at any time, without affecting processing already carried out

  • not be subject to unlawful discrimination for exercising these rights

To exercise any right, contact [PRIVACY EMAIL]. We will verify your identity before acting, and will respond within the period required by applicable law (generally 30 days, or one month under UK/EU GDPR). You may use an authorised agent where the law allows.

If you are in the UK or EEA and are unhappy with our response, you can complain to your local supervisory authority, such as the UK Information Commissioner’s Office at ico.org.uk.

8. US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Texas, or another state with comprehensive privacy legislation, you have the rights described in section 7, plus the right to opt out of the sale or sharing of personal information and of targeted advertising.

To opt out of advertising cookies and cross-context behavioural advertising, use [COOKIE SETTINGS LINK] or enable Global Privacy Control in your browser.

Categories of personal information collected in the last 12 months: identifiers; commercial information; internet and network activity; approximate geolocation; professional or employment information; audio recordings where calls are recorded; and inferences drawn from the above.

We do not knowingly collect or process the personal information of anyone under 16 for sale or sharing.

9. When we act as a processor for client data

For clients, we access marketing platforms containing personal data about your subscribers and customers. In that context you are the controller (or business) and we are the processor (or service provider). We:

  • process that data only on your documented instructions

  • do not use it for our own marketing purposes

  • do not sell or share it

  • bind our team and any subprocessors to confidentiality

  • apply appropriate technical and organisational security measures

  • return or delete the data, and revoke our access, at the end of the engagement on your request

A separate Data Processing Agreement is available and is recommended where GDPR or similar laws apply. Ask at [PRIVACY EMAIL].

10. Retention

We keep personal information only as long as needed for the purposes described here:

  • Enquiries that do not convert: [24] months from last contact, then deleted or anonymised

  • Client records: for the engagement plus [7] years, to meet tax, accounting, and legal claim periods

  • Marketing lists: until you unsubscribe, plus a suppression record kept indefinitely so we do not re-contact you

  • Call recordings and transcripts: [12] months unless part of an active engagement

  • Analytics and advertising data: per the retention settings of each platform

11. Security

We use measures appropriate to the risk, including access controls, least-privilege access to client platforms, unique credentials, multi-factor authentication where supported, encrypted transmission, and vetted providers. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required timeframe.

12. Children

The Site is intended for business owners aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, contact [PRIVACY EMAIL] and we will delete it.

13. Third-party sites

The Site links to third-party websites and platforms. We are not responsible for their privacy practices. Read their policies before providing information.

14. Changes to this Policy

We may update this Policy. The “Last updated” date will change, and material changes will be notified by a notice on the Site or by email where appropriate.

15. Contact us

[LEGAL ENTITY NAME]

[REGISTERED ADDRESS]

[PRIVACY EMAIL]