Legal
Privacy Policy
How we collect, use and look after your personal data, and the rights you have over it.
Last updated: [DATE]
Pre-launch note, delete before this page goes live: the square-bracket placeholders below are still to be filled, and this policy has not yet been through legal review.
1. About this policy
Gone Rogue Ltd (“Gone Rogue”, “we”, “us”) is an integrated marketing agency with offices in Belfast and Dublin. This policy explains what personal data we collect, how we use it, and the rights you have over it.
It covers this website and enquiries made to us by email or telephone. It does not cover our clients’ own websites, or any third-party site we link to.
2. Who is responsible for your data
Gone Rogue Ltd is the data controller for the personal data described here. We are a company registered in Northern Ireland, company number [COMPANY NUMBER], with a registered address at Unit 2, 405 Holywood Road, Belfast, BT4 2GU.
Where we handle personal data on behalf of a client, for example while running a campaign or managing a social channel, we act as a processor and the client is the controller. In those cases the client’s own privacy policy governs how that data is used.
Questions about this policy, or about data we hold, should go to [PRIVACY CONTACT EMAIL].
3. What we collect
Information you give us
If you email us, call us or meet us, we collect what you choose to give: typically your name, the organisation you work for, your email address, your telephone number, and whatever you tell us about your enquiry.
This website has no contact form. Nothing is gathered from you as you browse and then submitted on your behalf.
Information collected automatically
Our hosting provider keeps standard server logs each time a page is requested. These record the IP address making the request, the date and time, the page requested, and the browser and operating system your device reports. We use them only to keep the site available and secure.
Preferences stored on your device
The site remembers whether you chose light or dark mode. That preference is held in your browser’s local storage. It stays on your device, is never sent to us, and contains no personal data. Clearing your browser data removes it.
Embedded video
Some pages embed video hosted by Vimeo. The player loads only once you scroll to it. When it loads, Vimeo receives your IP address and may set its own cookies. That processing is governed by Vimeo’s privacy policy rather than this one.
4. Why we use your data, and our lawful basis
- To reply to your enquiry and discuss work you may want us to do. Lawful basis: legitimate interests, namely responding to someone who has contacted us.
- To provide services to clients and administer the relationship. Lawful basis: performance of a contract, or legitimate interests where the contract is with your employer rather than with you personally.
- To keep the website available, secure and working. Lawful basis: legitimate interests.
- To send marketing about our services. Lawful basis: consent, or legitimate interests where you are an existing client and the marketing relates to similar services. You can opt out at any time.
- To meet legal, accounting and regulatory obligations. Lawful basis: legal obligation.
We do not sell personal data, and we do not use it for automated decision-making or profiling.
5. Marketing
We may send occasional email about our work and services to people who have asked to hear from us, and to existing clients. Every marketing email carries a way to unsubscribe, and you can opt out at any time by writing to [PRIVACY CONTACT EMAIL]. Opting out of marketing does not stop us contacting you about work already in progress.
6. Who we share it with
We share personal data only where there is a reason to:
- Suppliers who provide services to us, including website hosting, email and file storage. They act on our instructions and may not use your data for their own purposes. [LIST NAMED PROCESSORS]
- Professional advisers such as accountants and solicitors, where necessary.
- Public authorities, where the law requires it.
In respect of embedded video, Vimeo acts as an independent controller rather than as our processor.
7. Where your data is held
We operate in Northern Ireland and in Ireland, so we work under both UK data protection law and the EU GDPR. Some of our suppliers process data outside the UK and the EEA. Where that happens we rely on the relevant adequacy decisions, or on standard contractual clauses with the UK Addendum where no adequacy decision applies. [CONFIRM ONCE PROCESSORS ARE LISTED]
8. How long we keep it
- Enquiries that do not lead to work: [PERIOD] from our last contact with you.
- Client records: for the life of the relationship, and [PERIOD] afterwards to cover contractual and tax obligations.
- Marketing preferences: until you withdraw them, and a record of the withdrawal afterwards.
- Server logs: [CONFIRM WITH HOSTING PROVIDER]
We review what we hold periodically and delete what we no longer need.
9. Keeping it secure
We take reasonable technical and organisational measures to protect personal data, including encryption in transit, access restricted on a need-to-know basis, authenticated accounts on staff systems, firewalls, and anti-virus and email filtering. [CONFIRM AGAINST CURRENT MEASURES]
No system is completely secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority, and you where the law requires it, within the timescales set out in law.
10. Your rights
Subject to the conditions set out in data protection law, you have the right to:
- be told how we use your data, which is what this policy is for
- receive a copy of the data we hold about you
- have inaccurate data corrected
- have data erased where we no longer have good reason to hold it
- restrict how we use it while a question about it is resolved
- receive certain data in a portable format, or have it sent to another organisation
- object to processing we base on legitimate interests, and to direct marketing at any time
- withdraw consent, where consent is the basis we rely on
To exercise any of these, write to [PRIVACY CONTACT EMAIL]. We will respond within one month. There is normally no charge.
11. Complaints
If you are not satisfied with how we have handled your data, you can complain to a supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). In Ireland it is the Data Protection Commission (dataprotection.ie). We would rather you came to us first, so we have a chance to put it right.
12. Cookies and similar technologies
This website uses no analytics, advertising or tracking cookies. It stores a single preference on your device, your choice of light or dark mode, using local storage rather than a cookie.
Embedded Vimeo players may set their own cookies once a video loads. You can block or delete cookies through your browser settings, though embedded video may not work properly if you do.
13. Other websites
This site links to other websites, including our clients’ sites and our own social profiles. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
14. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
15. Changes to this policy
We review this policy from time to time and publish any updates on this page, with the date at the top amended. Where a change is material we will tell clients directly rather than rely on them noticing.
16. How to contact us
Gone Rogue Ltd, Unit 2, 405 Holywood Road, Belfast, Northern Ireland, BT4 2GU.
Gone Rogue, 51–52 Upper Fitzwilliam Square, Dublin 2, Ireland, D02 X504.
[PRIVACY CONTACT EMAIL] · +44 (0)28 9042 5555 · +353 (0)1 665 0444