Legal
Privacy
This page is not a privacy policy yet, and it does not pretend to be one. Below are the details of the entity behind the site, and the list of things the published policy has to answer.
Status.
Awaiting counsel-reviewed copy
Pointerflow handles UK and EU visitor data and processes client data under engagement, so this document has to be written and reviewed by someone qualified to write it. It is deliberately blank rather than filled with boilerplate nobody has read — a policy that misdescribes what actually happens to the data is worse than an honest gap.
What the policy has to cover.
A checklist for whoever drafts it, and a straight answer for anyone reading this page in the meantime. None of the wording below is legal text.
- What data is collected Every field the site asks for, listed by form: the five audit-booking fields (name, email, brand URL, monthly revenue band, subscription platform), the five contact fields, and the email address the calculator PDFs ask for. Plus whatever the analytics layer records, and what the server logs keep.
- Why, and on what lawful basis Each category above mapped to a basis under the UK GDPR and the EU GDPR, and — where the basis is consent — how consent is obtained, recorded and withdrawn.
- Client data during an engagement Audits run on read access to a client’s Shopify, ESP, subscription platform and helpdesk. That is personal data belonging to their customers, processed on their instruction. The controller/processor split has to be stated, and it is separate from the visitor data above.
- Processors and sub-processors Every third party the data touches — hosting, the email platform, the scheduler, analytics, and any storage used to hold audit findings — named, with where each one processes.
- International transfers The company is registered in the United States, the team works from Bangladesh, and visitors and clients are in the UK and EU. The transfer mechanism relied on for that route has to be named, not implied.
- Retention How long each category is kept, and what triggers deletion — including audit working files and the read access itself once an engagement ends.
- Rights, and how to use them Access, rectification, erasure, restriction, portability and objection; the right to withdraw consent; and the right to complain to the ICO in the UK or the relevant supervisory authority in the EU. Each with the actual route to exercise it.
- Who to contact A named contact and a working address for privacy requests, and the response commitment attached to them. hello@pointerflow.com is the current address.
- Changes How a revision is published, and how anyone affected finds out it happened.
The entity behind the site.
These details are accurate now and will not change when the policy is published.
- Entity
- Pointerflow LLC
- Registered
- Wyoming, USA
- Operating from
- Dhaka, Bangladesh
- Visitors and clients in
- US, UK, EU, Canada & Australia
- Contact
- hello@pointerflow.com
Until the policy is published, a privacy question sent to that address gets a written answer within one business day — including a plain description of what we hold, if you ask for one.