LEGAL
Privacy Notice
Draft: requires legal review
This document is a working draft, structured to be legally complete but not yet checked by qualified counsel or signed off by the business. It is not legal advice and it has not been published. Every bracketed placeholder marks an open fact, such as an entity name, a contact, a jurisdiction, or a date, that still needs confirmation before this page can be treated as binding.
Draft v0.1 · Last updated: [pending, not yet published]
This notice explains what personal data controlloop.tech collects, why, and what rights a visitor has over it. It is written in the shape UK/EU GDPR requires (lawful basis, retention, rights, transfers, controller identity), but every business-specific fact below is still a placeholder pending client and counsel sign-off. See the draft notice above.
Who we are
Control Loop ("we", "us", "our") is the data controller for personal data collected through controlloop.tech. Controller identity: [registered company name, registration number, and registered address, pending client sign-off].
Contact for privacy matters: hello@controlloop.tech (the site's general inbox; a dedicated privacy alias is [to be confirmed]). Data Protection Officer, if one is appointed: [DPO name and contact, or a statement that none is required, pending confirmation].
What we collect
Submitted directly:
- Name, work email, company, role, one or more service interests, budget band, timeline, and message content, submitted through the contact form at
/contact.
Collected automatically:
- IP address, browser and device metadata, and page interaction data, only once analytics consent is given (see the Cookie Notice). No analytics tooling runs on this site today; see that notice for the current, factual state.
- Two technical anti-spam signals on the contact form (a hidden honeypot field and a submission-timing check). Neither identifies a visitor; both exist only to catch automated form abuse.
We do not knowingly collect financial account details, government ID numbers, or special category data such as health or biometric information through this site.
Why we process it
| Purpose | Data | Lawful basis |
|---|---|---|
| Responding to a contact-form inquiry | Contact fields, message | Legitimate interest (Art. 6(1)(f)), responding to inbound business inquiries |
| Preventing spam and abuse on the contact form | Honeypot value, submission timing | Legitimate interest (Art. 6(1)(f)), keeping the form usable |
| Evaluating a job application, once that flow exists | Application materials | Contract or pre-contract steps (Art. 6(1)(b)) |
| Site analytics, if and when enabled | Device and behavior metadata | Consent (Art. 6(1)(a)), gated by the cookie banner described in the Cookie Notice |
| Legal or regulatory obligations | Any of the above, as required | Legal obligation (Art. 6(1)(c)) |
Retention
Contact-form submissions: [proposed default: 24 months from last contact, then deleted or anonymized, pending confirmation], unless a resulting engagement requires longer retention under contract or law. Job applications, once that flow exists: [proposed default: 12 months from the close of the role, pending confirmation], unless the candidate consents to a talent pool. Analytics data, if enabled: [retention window, depends on the analytics vendor eventually chosen].
The figures above are proposed working defaults for engineering to build against, not confirmed policy. They must be reviewed by counsel and matched exactly to what is actually implemented before this notice is published.
Who we share it with
Sub-processors currently in use: [none confirmed yet; will list each email, CRM, or analytics vendor actually adopted, each linking to that vendor's own privacy policy]. We do not sell personal data. Data may be disclosed if required by law, by court order, or to protect our legal rights.
International transfers
Where a sub-processor stores or processes data outside the visitor's jurisdiction, for example UK/EU data processed in the US, any such transfer will rely on [Standard Contractual Clauses, an adequacy decision, or another approved mechanism, to be confirmed per vendor].
Your rights
Subject to applicable law (UK GDPR, EU GDPR, and equivalents), you may have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure, restrict or object to processing, receive your data in a portable format, and withdraw consent at any time where processing is consent-based. To exercise any of these, contact hello@controlloop.tech.
You also have the right to lodge a complaint with your local supervisory authority. For the UK, that is the Information Commissioner's Office (ico.org.uk). For other jurisdictions: [relevant authority, to be confirmed].
Children
This site is directed at business professionals and is not intended for individuals under 16. We do not knowingly collect data from children.
Automated decision-making
We do not use the personal data collected on this site to make solely automated decisions with legal or similarly significant effects.
Changes to this policy
We will update the last-updated date and version number above whenever this policy changes materially, and will highlight material changes on this page for [a stated notice period, e.g. 30 days, to be confirmed].