Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME] (“VentiveMail”, “we”, “us”, “our”) collects, uses, shares, and protects personal information when you visit [WEBSITE URL], submit a form, book a call, or communicate with us.
If you become a client, additional terms in your signed service agreement and any data processing agreement will also apply.
Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
Privacy contact: [PRIVACY EMAIL]
[IF APPLICABLE] EU / UK representative: [NAME AND ADDRESS]
1. Information we collect
1.1 Information you give us
Through application forms, booking pages, email, and calls, we may collect:
name, business email address, phone number
company name and website or store URL
role or job title
ecommerce platform, monthly revenue band, average order value, current email platform and setup
information about your marketing goals, current performance, and challenges
anything else you choose to tell us in a form field, email, or on a call
1.2 Information collected automatically
When you visit the Site we and our providers may collect:
IP address and approximate location derived from it
device type, operating system, browser type and language
pages viewed, time on page, scroll depth, referring URL, exit pages
video engagement data on our sales video, such as play, pause, and watch duration
click IDs and campaign parameters passed through from ads (for example fbclid, gclid, utm_source)
cookie and similar identifiers
1.3 Information from third parties
We may receive information from advertising platforms, analytics providers, scheduling tools, and enrichment or verification services, and from publicly available business sources such as your website or LinkedIn, used to assess fit before a call.
1.4 Call recordings
Discovery and strategy calls may be recorded or transcribed for quality, training, and internal reference. Where recording takes place we will tell you at the start of the call and proceed only with your consent. You can decline recording and still take the call.
1.5 Client account data
If you engage us, you may grant us access to your marketing platforms, for example Klaviyo, your ecommerce platform, and your domain or DNS records. That access may expose personal data about your customers and subscribers. In relation to that data we act as a processor or service provider on your behalf, and we handle it only on your documented instructions and only for the purpose of delivering the service. See section 9.
1.6 What we do not collect
We do not knowingly collect payment card numbers through the Site. Payments, where applicable, are handled by a third-party payment processor. We do not seek special category data (health, biometric, political, religious, or similar). Please do not submit it.
2. Why we use your information, and our legal bases
Purpose: Respond to enquiries, qualify applications, schedule and conduct calls — Legal basis (UK/EU GDPR): Steps taken at your request prior to entering a contract
Purpose: Provide services and manage the client relationship — Legal basis (UK/EU GDPR): Performance of a contract
Purpose: Send marketing emails and SMS — Legal basis (UK/EU GDPR): Consent, or legitimate interests for existing business contacts where permitted
Purpose: Measure and improve ad campaigns and Site performance — Legal basis (UK/EU GDPR): Consent for non-essential cookies and tracking; otherwise legitimate interests
Purpose: Site security, fraud prevention, and abuse detection — Legal basis (UK/EU GDPR): Legitimate interests
Purpose: Keep records and comply with legal, tax, and accounting duties — Legal basis (UK/EU GDPR): Legal obligation
Purpose: Establish, exercise, or defend legal claims — Legal basis (UK/EU GDPR): Legitimate interests
Where we rely on legitimate interests, we have assessed that our interest in operating and growing a business does not override your rights and freedoms. You can object at any time (see section 7).
3. Cookies, pixels, and tracking
We use cookies and similar technologies, including advertising pixels, to run the Site and to measure and target advertising. Categories:
Strictly necessary. Required for the Site to function and to remember your cookie choices.
Analytics. Aggregate usage measurement, for example [Google Analytics 4].
Advertising and retargeting. For example the [Meta Pixel], [TikTok Pixel], [Google Ads tag]. These may set cookies and share event data with the platform so we can show ads to you and to similar audiences, and measure conversions.
Conversions API / server-side tracking. Where we use server-side event forwarding, we may send hashed identifiers such as a hashed email address to advertising platforms to attribute conversions. Hashing reduces but does not eliminate identifiability.
Your choices. Where required by law, non-essential cookies are set only after you consent through our cookie banner. You can change or withdraw consent at any time via [COOKIE SETTINGS LINK]. You can also block cookies in your browser, though parts of the Site may not work properly. Global Privacy Control signals are honoured where legally required.
A full, current list of the cookies we set is available at [COOKIE POLICY LINK].
4. Marketing emails and SMS
Email. We send marketing email only where you have given consent or where permitted for business contacts under applicable law. Every marketing email includes an unsubscribe link.
SMS. If you provide a mobile number and opt in, we may send SMS about your enquiry or our services. Consent to marketing SMS is never a condition of purchase. Reply STOP to opt out and HELP for help. Message frequency varies. Message and data rates may apply. Mobile opt-in data and consent records are not shared or sold to third parties for their own marketing.
Transactional messages. Even after opting out of marketing, you may receive messages needed to service an active enquiry or engagement, such as booking confirmations and project updates.
5. How we share information
We do not sell your personal information for money. We share it with:
Service providers acting on our instructions, including website and form hosting, scheduling, email and SMS delivery, CRM, cloud storage and document tools, analytics, transcription, and accounting. Current categories and named providers: [LIST YOUR ACTUAL STACK, e.g. Calendly, Klaviyo, Google Workspace, Notion, Slack, Zapier, Stripe].
Advertising and analytics platforms, as described in section 3. Under the California CPRA and some other US state laws, this cookie-based advertising activity may be treated as “sharing” for cross-context behavioural advertising, or as a “sale”. You can opt out (see section 8).
Professional advisers, such as lawyers and accountants, under duties of confidentiality.
Authorities, where required by law, court order, or to protect our legal rights.
A successor entity, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We do not share your information with unrelated third parties for their own independent marketing.
6. International transfers and storage
We operate from [COUNTRY] and use providers located in the United States, the European Economic Area, the United Kingdom, and [OTHER]. Your information may therefore be transferred to and processed in countries whose data protection laws differ from your own.
Where we transfer personal data out of the UK or EEA, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses (and the UK Addendum where relevant) together with supplementary measures as needed. You can request a copy of the safeguards by contacting [PRIVACY EMAIL].
7. Your rights
Depending on where you live, you may have the right to:
access the personal information we hold about you
correct inaccurate or incomplete information
request deletion
restrict or object to processing, including direct marketing and profiling
receive your data in a portable format
withdraw consent at any time, without affecting processing already carried out
not be subject to unlawful discrimination for exercising these rights
To exercise any right, contact [PRIVACY EMAIL]. We will verify your identity before acting, and will respond within the period required by applicable law (generally 30 days, or one month under UK/EU GDPR). You may use an authorised agent where the law allows.
If you are in the UK or EEA and are unhappy with our response, you can complain to your local supervisory authority, such as the UK Information Commissioner’s Office at ico.org.uk.
8. US state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Texas, or another state with comprehensive privacy legislation, you have the rights described in section 7, plus the right to opt out of the sale or sharing of personal information and of targeted advertising.
To opt out of advertising cookies and cross-context behavioural advertising, use [COOKIE SETTINGS LINK] or enable Global Privacy Control in your browser.
Categories of personal information collected in the last 12 months: identifiers; commercial information; internet and network activity; approximate geolocation; professional or employment information; audio recordings where calls are recorded; and inferences drawn from the above.
We do not knowingly collect or process the personal information of anyone under 16 for sale or sharing.
9. When we act as a processor for client data
For clients, we access marketing platforms containing personal data about your subscribers and customers. In that context you are the controller (or business) and we are the processor (or service provider). We:
process that data only on your documented instructions
do not use it for our own marketing purposes
do not sell or share it
bind our team and any subprocessors to confidentiality
apply appropriate technical and organisational security measures
return or delete the data, and revoke our access, at the end of the engagement on your request
A separate Data Processing Agreement is available and is recommended where GDPR or similar laws apply. Ask at [PRIVACY EMAIL].
10. Retention
We keep personal information only as long as needed for the purposes described here:
Enquiries that do not convert: [24] months from last contact, then deleted or anonymised
Client records: for the engagement plus [7] years, to meet tax, accounting, and legal claim periods
Marketing lists: until you unsubscribe, plus a suppression record kept indefinitely so we do not re-contact you
Call recordings and transcripts: [12] months unless part of an active engagement
Analytics and advertising data: per the retention settings of each platform
11. Security
We use measures appropriate to the risk, including access controls, least-privilege access to client platforms, unique credentials, multi-factor authentication where supported, encrypted transmission, and vetted providers. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required timeframe.
12. Children
The Site is intended for business owners aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, contact [PRIVACY EMAIL] and we will delete it.
13. Third-party sites
The Site links to third-party websites and platforms. We are not responsible for their privacy practices. Read their policies before providing information.
14. Changes to this Policy
We may update this Policy. The “Last updated” date will change, and material changes will be notified by a notice on the Site or by email where appropriate.
15. Contact us
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[PRIVACY EMAIL]