Privacy Policy
This site sets no cookies, runs no analytics, and embeds no trackers. The only personal data we hold is what you deliberately send us through the contact form. Here is the detail, including why you have not been shown a cookie banner.
Last updated · 5 September 2026
01
The short version
We collect almost nothing. This website sets no cookies, runs no analytics, and embeds no third-party trackers, advertising pixels, or social media widgets.
The only personal data we collect through this site is what you type into the contact form and send to us deliberately. We use it to reply to you, and for nothing else. We do not sell it, we do not share it with advertisers, and we do not add you to a mailing list.
Everything below is the same statement in the detail the law requires.
02
Who is responsible for your data
BinarySync is the data controller for personal data collected through this website. [TO CONFIRM: registered entity name, registered address, and a data protection contact address before launch.]
Where we process personal data inside a system we have built or operate for a client, we act as a processor on that client instructions, not as a controller. That processing is governed by our contract with that client, not by this policy.
You can contact us about anything in this policy using the details in the footer of this site.
03
What we collect and why
Through the contact form, and only when you choose to submit it, we collect the name, work email address, company name, the service area you selected, and the message you wrote.
We use this on the basis of our legitimate interest in responding to a business enquiry you sent us, and, where the enquiry leads to a proposal, on the basis of taking steps at your request before entering into a contract. We use it to read your enquiry, reply to it, and continue the conversation. We do not use it for marketing, we do not enrich it with data bought from anywhere else, and we do not profile you.
Our hosting provider keeps standard server logs, which will typically include the IP address a request came from, the time, the page requested, and the browser user-agent string. These exist so the site can be operated and defended against abuse, they are not used to identify or track individual visitors, and they are retained on the provider default schedule.
06
Where your data is held
Data submitted through this site is stored on infrastructure operated by our hosting and email providers. Where a provider processes data outside the European Economic Area, that transfer is covered by an adequacy decision or by Standard Contractual Clauses.
[TO CONFIRM: name the hosting provider and its processing region. Briefs submitted through the contact form are delivered by email over SMTP to a Microsoft 365 mailbox; see app/api/contact/route.ts and lib/mail.ts.]
07
How long we keep it
We keep contact form enquiries for as long as the conversation is live, and for up to 24 months afterwards so that we can pick up a thread you started earlier. After that they are deleted.
Where an enquiry becomes an engagement, the relevant records are kept for as long as the contract requires and for as long afterwards as tax and limitation law requires, and then deleted.
You can ask us to delete your enquiry sooner and we will, unless we are required to keep it.
08
Your rights
If you are in the UK, the EEA, or another jurisdiction with equivalent law, you have the right to:
- Ask what personal data we hold about you and receive a copy of it.
- Have inaccurate data corrected.
- Have your data deleted, where we have no overriding reason to keep it.
- Ask us to restrict how we use it while a question about it is resolved.
- Receive the data you gave us in a portable, machine-readable format.
- Object to our processing on the basis of legitimate interest, including at any time and for any reason where the processing is for direct marketing.
- Complain to your data protection supervisory authority, though we would rather you raised it with us first so we can put it right.
09
Security
The site is served over HTTPS. Access to enquiries is limited to the people who need it to reply to you.
We build security systems for a living and we hold our own to the same standard we would recommend to a client: least privilege, multi-factor authentication on every account that supports it, and patching as a routine rather than an incident.
If a breach affects your personal data and is likely to present a risk to you, we will tell you and the relevant authority without undue delay, and in any case within 72 hours of becoming aware of it.
10
Children
This is a business-to-business website and it is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
11
Changes to this policy
If we change this policy we will change the date at the top of this page. Where a change is significant, such as a new category of data, a new purpose, a new recipient, or the introduction of any cookie, we will make it prominent rather than relying on you to notice a date.
