Privacy Policy & Data Governance Framework

Last Updated: August 2026 | UK GDPR, EU GDPR & PECR Statutory Compliance Notice

1. Data Controller Identification & Principles

This Privacy Policy governs the processing of personal data by TECHIECOACHIO LIMITED (Company No. 17036505, registered in England and Wales, registered office: Cotton Court, Church Street, Preston, England, PR1 3BY) ("Company", "we", "us", "our"), acting as the Data Controller under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the EU GDPR (Regulation (EU) 2016/679), and the Privacy and Electronic Communications Regulations 2003 (PECR).

We operate strictly under data-minimisation and zero-trust security principles. All data collected through our Executive GTM Diagnostic funnels, intake forms, and advisory portals is limited exclusively to what is strictly necessary to evaluate systems, deliver technical roadmaps, and fulfil contractual obligations.

2. Categories of Personal Data & Lawful Bases for Processing

We collect and process personal data strictly aligned with statutory lawful bases under UK GDPR Article 6:

  • Identity & Business Contact Data: Full name, corporate email address, business domain name, and company metadata.
    Lawful Basis: UK GDPR Art. 6(1)(b) (Performance of a contract / Pre-contractual steps requested by data subject).
  • Technical & Telemetry Data: Public domain diagnostic metrics, system performance telemetry, API response rates, LCP timing, DMARC/DNS configurations, and selected operational friction points.
    Lawful Basis: UK GDPR Art. 6(1)(f) (Legitimate interests to provide technical diagnostic reports and ensure infrastructure security).
  • Transaction & Billing Telemetry: Payment processing references, transaction amounts, and settled currency (GBP/USD/EUR). Raw payment card data is processed directly by Stripe under PCI-DSS Level 1 compliance and is never stored on our servers.
    Lawful Basis: UK GDPR Art. 6(1)(b) (Contract fulfilment) and Art. 6(1)(c) (Legal obligation for tax and accounting compliance).

3. Bot Mitigation, Security & Automated Analysis

Our intake forms utilise Cloudflare Turnstile (Invisible Mode) to protect our API endpoints against automated abuse, credential stuffing, and bot attacks. Turnstile evaluates browser telemetry, header signatures, and non-interactive characteristics without presenting intrusive visual challenges.

Automated AI Diagnostic Processing (UK GDPR Art. 22 Notice)

Domain telemetry inputs are processed using automated serverless routines and specialised AI language models (including Gemini Flash) to synthesise diagnostic teasers and technical risk matrices. This processing does not produce legal effects or similarly significantly affect you within the meaning of UK GDPR Article 22; all strategic recommendations undergo human engineering review prior to tier engagement.

4. Verified Sub-Processor Ecosystem & International Transfers

To deliver serverless execution, multi-currency processing, and zero-trust delivery, submitted data is handled through verified sub-processors under binding Data Processing Agreements (DPAs) incorporating UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs):

  • Cloudflare, Inc.: Edge worker proxy layer executing request ingestion, CORS isolation, security filtering, and geo-IP routing.
  • Stackby Inc.: Encrypted cloud database platform utilised for lead persistence, order tracking, and audit lifecycle management.
  • Stripe, Inc.: PCI-DSS Level 1 certified gateway handling multi-currency checkout transactions and payment intent webhooks.
  • Resend Inc.: Transactional email service dispatching tokenised onboarding magic links and security notifications.
  • FuseBase / TechieCoachio Portal: Encrypted client workspace hosting completed audit deliverables, video walkthroughs, and technical topography maps.
  • Reoon Email Verifier: Real-time API verification checking corporate email deliverability, MX records, and domain configurations.
  • ApiX-Drive Middleware: Encrypted webhook transport layer routing verified submission payloads into internal logging infrastructure.
  • Google LLC (Analytics 4 & PageSpeed API): Public performance diagnostic checks and anonymised website analytics (Property ID: G-8M8RK1G2CP). IP anonymisation is strictly enforced.

5. Zero Data Retention (ZDR) & Storage Schedules

All web interfaces enforce SSL/TLS 1.3 encryption in transit and AES-256 encryption at rest. In accordance with TECHIECOACHIO LIMITED's Zero Data Retention (ZDR) framework:

  • Transient Debug Logs & Caches: Temporary server execution traces, cURL outputs, and client header dumps stored in Cloudflare KV are permanently purged within 120 minutes of audit delivery handover.
  • Account & Order Records: Basic corporate contact metadata and transactional logs in Stackby are retained for the duration of the active advisory relationship or a maximum of 12 months for non-converting leads.
  • Financial Records: Invoicing and payment transaction logs are retained for 7 years to satisfy statutory UK tax legislation (HMRC requirements).

6. Statutory Data Subject Rights & Regulatory Recourse

Under UK GDPR and EU GDPR, you hold statutory rights regarding your personal data, including the Right to Access, Right to Rectification, Right to Erasure ("Right to be Forgotten"), Right to Restrict Processing, Right to Data Portability, and Right to Object.

To exercise any of your statutory rights, submit a written request to our Data Protection Officer at privacy@techiecoach.io. Requests are fulfilled free of charge within 30 calendar days.

You also have the right to lodge a privacy complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or with your local EU Data Protection Authority.