Introduction and scope
This Privacy Policy explains how CordyTraff ("CordyTraff", "we", "us") collects, uses, shares and protects personal data when you visit cordytraff.com, contact us, apply for a role, or engage us as a service provider.
It applies to personal data we process as a controller — that is, where we decide why and how the data is used. Where we process personal data on behalf of a client as a processor (for example, when we access analytics or CRM data belonging to a client), the relevant client's own privacy notice governs that processing, and our obligations are set out in the Data Processing Agreement signed with that client.
Deployment note. Placeholders in square brackets below must be completed with the operating entity's registered details, and this document reviewed by a qualified lawyer in the relevant jurisdiction, before this site goes live.
Who we are and how to contact us
Controller: CordyTraff [legal entity name], registered in [jurisdiction] under company number [registration number], registered office [registered address].
- General privacy enquiries and data subject requests: privacy@cordytraff.com
- General enquiries: hello@cordytraff.com
- Postal address: [registered address]
We have appointed [a Data Protection Officer / a privacy contact] who can be reached at the address above. If you are in the EEA or the UK, you may also contact us through our representative at [EU/UK representative details, where Article 27 applies].
What personal data we collect
We collect only what we need for the purposes described in this policy.
| Category | Examples | Source |
|---|---|---|
| Identity and contact data | Name, job title, company, work email, telephone number | You, via forms, email or calls |
| Enquiry data | Website URL, target markets, budget range, timeline, the content of your message | You |
| Client relationship data | Contract details, billing contacts, correspondence, project records | You, during an engagement |
| Recruitment data | CV, work history, portfolio links, task submissions, interview notes, right-to-work confirmation | You, or a recruiter acting for you |
| Technical and usage data | IP address, device and browser type, pages viewed, referring URL, approximate location derived from IP | Cookies and server logs |
| Marketing data | Subscription status, email engagement, communication preferences | You, and our email platform |
We do not deliberately collect special category data (such as health, political opinions or biometric data). Please do not include such information in enquiry forms or applications unless we have specifically asked for it.
How we collect personal data
- Directly from you — when you complete a form, email us, apply for a role, book a call or sign a contract.
- Automatically — through cookies and similar technologies when you use the site. See the Cookie Policy.
- From third parties — such as recruitment partners, professional networks including LinkedIn where you have made information available, referral partners, and publicly available business sources used for B2B prospecting.
Purposes and legal bases
Under the UK GDPR and the EU GDPR we must have a lawful basis for each purpose. Ours are:
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to enquiries and preparing proposals | Identity, contact, enquiry | Steps at your request prior to entering a contract; legitimate interests in responding to business enquiries |
| Delivering contracted services and managing the relationship | Identity, contact, client relationship | Performance of a contract |
| Invoicing, accounting and tax records | Identity, contact, billing | Legal obligation |
| Recruitment and hiring | Recruitment data | Steps at your request prior to a contract of employment; legitimate interests in assessing suitability |
| Keeping strong applications on file | Recruitment data | Consent |
| Site security, fraud and abuse prevention | Technical, usage | Legitimate interests in protecting our systems |
| Analytics and site improvement | Technical, usage | Consent, given through the cookie banner |
| Marketing emails and campaign measurement | Contact, marketing | Consent, or legitimate interests for existing business contacts in the same sector, subject to an opt-out in every message |
| Establishing, exercising or defending legal claims | As relevant | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for a summary of that assessment at any time.
Who we share personal data with
We never sell personal data. We share it only with:
- Service providers acting as processors — hosting and infrastructure providers, email and CRM platforms, analytics providers, scheduling tools, applicant tracking systems, accounting software and payment processors. Each is bound by a written agreement limiting them to our documented instructions.
- Professional advisers — lawyers, auditors and insurers, where necessary and bound by confidentiality.
- Subcontractors and specialist freelancers — for example native-language writers or outreach specialists working on your project, under confidentiality and data protection terms.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims.
- A successor entity — if the business is reorganised, merged or acquired, subject to the protections in this policy.
A current list of the processors we use is available on request from privacy@cordytraff.com.
International transfers
We are a distributed team and some of our providers operate outside the European Economic Area and the United Kingdom. Where personal data is transferred outside those areas, we rely on one of the following safeguards:
- An adequacy decision by the European Commission or the UK government covering the destination country;
- The European Commission's Standard Contractual Clauses (2021 modular set), together with the UK International Data Transfer Addendum where UK data is involved; or
- Another mechanism permitted under Chapter V of the GDPR.
Where required, we carry out a transfer impact assessment and apply supplementary technical and organisational measures. You may request a copy of the safeguards in place by emailing privacy@cordytraff.com.
How long we keep personal data
| Data | Retention period |
|---|---|
| Enquiries that do not become clients | 24 months from last contact |
| Client relationship and project records | Duration of the engagement plus 6 years |
| Invoices and accounting records | As required by applicable tax law, typically 6–10 years |
| Unsuccessful job applications | 12 months from the hiring decision, unless you ask us to delete sooner |
| Talent pool applications held with consent | 12 months, then deleted or re-consented |
| Marketing subscriptions | Until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again |
| Cookie consent records | 12 months |
| Server and security logs | Up to 12 months |
When a retention period ends we delete the data or irreversibly anonymise it.
How we protect personal data
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), access control on a least-privilege basis, multi-factor authentication on business systems, managed endpoints, vendor due diligence, and contractual confidentiality obligations for everyone working with us. No system is perfectly secure, but we take these obligations seriously and review them regularly.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the risk is high, notify you directly.
Your rights
Subject to the conditions in applicable law, you have the right to:
- Be informed about how your data is used — this policy is part of that;
- Access a copy of the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure of your data where we no longer have grounds to keep it;
- Restriction of processing in certain circumstances;
- Data portability — receiving data you provided in a structured, machine-readable format;
- Object to processing based on legitimate interests, and to object at any time to direct marketing, which we will always honour;
- Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
To exercise any right, email privacy@cordytraff.com. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no fee unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity.
Cookies and similar technologies
We use strictly necessary cookies to operate the site, and optional analytics and marketing cookies only where you consent. Optional cookies are off by default, rejecting is as easy as accepting, and you can change your choice at any time through cookie settings.
Full detail, including the categories and providers involved, is in the Cookie Policy.
Marketing communications
We send marketing email only where you have opted in, or where you are an existing business contact and the content is relevant to services you have enquired about. Every message contains a one-click unsubscribe link, and unsubscribing is honoured immediately. Unsubscribing from marketing does not stop service or transactional messages relating to an active engagement.
Children
Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@cordytraff.com and we will delete it.
Third-party links
This site may link to third-party websites, tools and social platforms. We do not control those sites and are not responsible for their privacy practices. Read their policies before providing personal data to them.
Changes to this policy
We may update this policy to reflect changes in our practices or the law. The version and effective date at the top of this page always show the current release. Where a change materially affects how we use your personal data, we will notify you directly or by a prominent notice on the site before it takes effect.
Complaints
If you are unhappy with how we have handled your personal data, please contact us first at privacy@cordytraff.com — we would rather fix it directly.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU or UK member state of your habitual residence, place of work, or where the alleged infringement took place. Our lead supervisory authority is [name of supervisory authority, e.g. the Irish Data Protection Commission / the UK Information Commissioner's Office].