Legal
Privacy Policy
How we collect, use, and protect your data · Last updated: 10 March 2026
1. Introduction
TrustedTraceMed complies with EU GDPR and UK GDPR. This policy explains how we handle your personal data when you use our website or engage our services.
3. What We Collect
You provide: Name, email address, company, role, and project details when you contact us or use our services.
Automatically collected: IP address, browser type, pages visited, and cookies when you browse our website.
4. Legal Basis
- Contract — to provide our consulting services
- Legitimate interests — website improvement and security
- Consent — marketing communications and analytics cookies (opt-in only)
- Legal obligation — compliance with applicable laws
5. How We Use Data
- Provide and deliver our consulting services
- Respond to enquiries and support requests
- Send resources or updates (with your consent)
- Improve our website and user experience
- Comply with legal and regulatory obligations
6. Data Sharing
We do not sell your data. We may share data with:
- Service providers (email platforms, analytics, hosting) — bound by data processing contracts
- Legal authorities — only when required by law
7. Data Retention
- Client data: Duration of engagement + up to 10 years
- Marketing data: Until consent is withdrawn
- Website analytics data: Up to 26 months (Google Analytics)
8. Your Rights
Under GDPR and UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erasure ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with the ICO (UK) or EDPB (EU)
To exercise your rights, email [email protected].
9. Cookies
We use essential and analytics cookies. See our Cookie Policy for full details.
10. Changes
We may update this policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review it periodically.