Legal

Privacy

How this site and our engagements handle personal data.

Draft — pending legal review. Not yet in force.

Who is responsible

Birdtold is the controller for personal data processed through this website and in the course of client engagements. Data protection enquiries go to privacy@birdtold.me.

What we collect on this website

One strictly-necessary cookie, __cf_bm, is set on load by our content delivery network to separate automated traffic from human traffic and protect the site from abuse. It expires within the hour. No analytics cookie and no advertising cookie is set, we load no third-party fonts, we run no tracking scripts, and we retain no visitor identifier of our own. The detail is at /legal/cookies.

Our analytics are cookieless and aggregate; they record page views without identifying individuals.

If you submit the sample-request form we collect the work email address, organisation, role and message you provide. We do not store your IP address or raw user agent.

If you choose to load the booking widget, that provider is contacted only after you click, and sets cookies in its own context. Nothing is requested from it before that click.

Why we process it, and on what basis

We process form submissions to respond to your enquiry and, if it proceeds, to form and perform a contract. Our lawful basis is the legitimate interest in responding to a business enquiry, and, once an engagement begins, performance of a contract. We do not use your details for marketing and we do not sell, rent or share them for anyone else's marketing.

Data collected during engagements

Our investigative work concerns businesses, not consumers. Where personal data appears incidentally in collected material, it is minimised at capture, retained only where it is necessary to the evidential integrity of a finding, and released only to the party entitled to receive that finding.

Who else sees it

We use a small number of processors for hosting, email delivery and scheduling. Each is bound by a data processing agreement. The current list is supplied on request and on engagement. We do not transfer personal data outside the EEA without an appropriate transfer mechanism in place.

How long we keep it

Enquiries that do not proceed are deleted within [RETENTION PERIOD]. Records relating to an engagement are retained for as long as the engagement requires and for the period necessary to meet legal and evidential obligations afterwards, then deleted.

Your rights

You may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interest. Write to privacy@birdtold.me. We respond within one month.

If you are not satisfied you may complain to your national supervisory authority; ours is [SUPERVISORY AUTHORITY].

Security

Access to personal data is limited to those who need it. Data is encrypted in transit and at rest. Suspected breaches are assessed immediately and notified where the law requires.

Changes

Material changes to this notice are published here with a revised date. Last updated [DATE].

We buy from the criminals you can't see.Then we tell you who banked them.