Skip to content
LEGAL

Privacy Notice

How Molfar Limited collects, uses, discloses and protects your personal data when you use the Minos site and services.

LAST UPDATED · 3 JULY 2026

This Privacy Notice (“Notice”) describes how we process and protect your personal data and related information (“Personal Data”) when you use our Site or Services. This Notice, together with our Terms of Service and any other applicable documents, constitutes the entire agreement between you and us (collectively, the “Agreement”).

The data controller is Molfar Limited, a company incorporated in England and Wales under company number 13558891, with its registered office at 20 Wenlock Road, London, England, N1 7GU (“Company”, “we”, “us”, or “our”), which operates this website minoscore.com (“Site”). Any capitalised term used in this Notice without definition shall have the meaning ascribed to it in our Terms of Service or applicable Data Laws.

Please read this Notice carefully. By accessing or using the Site or Services, you acknowledge that you have read and understood how we collect, use, disclose, and store your Personal Data as described herein. We reserve the right to amend this Notice at any time. If we make material changes, we will notify you by updating the date at the top of this Notice and, where required by Law, providing a more prominent notice (such as an email notification). The latest version is effective as of the last updated date indicated above. If you do not agree with any terms in this Notice, you must immediately cease using our Site and Services.

1. Definitions and interpretations

“Data Laws” means all applicable data protection and privacy legislation regulating the processing of Personal Data in connection with the Site or Services, including: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); (ii) the UK Data Protection Act 2018 and the UK GDPR; (iii) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”); (iv) the Virginia Consumer Data Protection Act (“VCDPA”); and (v) any other US state data privacy laws enacted and in effect, as amended from time to time.

“US Data Laws” means the applicable data privacy laws, statutes, or regulations of the United States that grant specific privacy rights to their residents, including but not limited to the laws of California, Virginia, and other US states privacy legislation in force.

2. Lawful Basis for Personal Data Processing

Our lawful bases for processing Personal Data depend on the context of the processing operations and the categories of data subjects:

  • Performance of a Contract: We process our users’ Personal Data where it is necessary to perform our contract with you to provide the Services, or to take steps at your request prior to entering into a contract.
  • Legitimate Interests: We process Personal Data based on our legitimate interests (or those of third parties), provided that your rights and freedoms do not override those interests. This includes operating and improving our Site/Services functionality, ensuring network security, and processing public data when users conduct searches through our search engine.
  • Legal Obligation: We may process Personal Data where necessary to comply with a legal obligation to which we are subject.
  • Consent: Where required by Law (such as for certain cookies or marketing communications), we will obtain your explicit consent. You have the right to withdraw your consent at any time.

3. Collecting data

We collect information about you directly from you, automatically through your use of our Site or Services, and, where applicable, from publicly available sources when executing search queries. Providing your Personal Data is voluntary; however, if you refuse to provide necessary information or disable cookies, you may experience a significant reduction in the quality of the Services, or an inability to use some or all of our Services.

Age Restrictions and Eligibility

Our Site and Services are not intended for, or targeted at, individuals under 18 years of age. We do not knowingly collect, maintain, or process Personal Data relating to children under the age of 18. If you are a parent or guardian and discover that your child under 18 has provided us with their Personal Data, or if we otherwise become aware that we have inadvertently collected personal information from a minor, we will promptly take all necessary steps to permanently delete such information from our systems.

Data We Collect Directly from You

We collect data when you communicate with us or interact with our Services:

  • Your full name, telephone number, email address, and account credentials (such as password parameters) directly from you when you register an account, log in, or complete a contact form on the Site;
  • Your email address when you sign up to receive newsletters, marketing updates, or product insights;
  • Any records of correspondence or information you provide when contacting our support team (please note that we may record telephone calls and logs of written communications for training, quality assurance, and security purposes, in compliance with applicable Laws);
  • Information you provide when submitting feedback, testimonials, participating in customer surveys, promotions, competitions, or product feature launches.

Data We Collect Automatically Through the Site

When you browse our Site or use our Services, we automatically collect certain technical and usage information, some of which may constitute Personal Data:

  • Log Information: Your IP address (assigned by your Internet Service Provider), browser type and version, device type, operating system, domain name, the referring website, the exit website, your approximate location (such as city or country), and the dates and time stamps of your access;
  • Usage Information: User behaviour patterns, pages viewed, search queries entered, search history, and related technical communication logs;
  • Cookies and Tracking Technologies: Pseudonymised analytics and technical data about how you interact with our Site, which we collect using cookies, web beacons, and related technologies. Please see our Cookies section below for detailed information.

Data Processed Via Search Queries (Third-Party Data)

Because our Services include search engine functionality powered by third-party APIs (including Google Gemini), we process information users enter into search queries. If a user queries information regarding a third-party individual, we process that data dynamically to fetch and display relevant web links and public summaries. We do not actively monitor, filter, or moderate the content of these queries, except as required to comply with applicable Data Laws or binding legal orders.

4. Retaining and storing your data

We will only retain your Personal Data for as long as is necessary to fulfil the purposes outlined in this Notice, unless a longer retention period is required or permitted by Law.

When we have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymise it. If deletion is not immediately possible (for example, because your Personal Data has been stored in backup archives), we will securely store your Personal Data and isolate it from any further processing until deletion becomes feasible.

Notwithstanding anything to the contrary, we retain the right to store certain technical and transactional logs to the extent necessary to enforce our terms, prevent fraud, comply with technical and legal requirements, ensure the security and integrity of our Site, or respond to regulatory requests and legal disputes.

International Data Transfers & Storage

We store your Personal Data on secure servers located within the United Kingdom (UK), the European Union (EU), and the United States (USA).

If you are a resident of the UK or the European Economic Area (“EEA”), please be aware that your Personal Data may be transferred to, and processed in, countries outside the UK and EEA (including the USA).

Where we control the transfer of Personal Data to our direct processors outside the UK or EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:

  • We transfer your data to countries that have been deemed to provide an adequate level of protection by the relevant regulatory authorities; or
  • We utilise specific Standard Contractual Clauses (“SCCs”) approved for use in the EU and/or the UK International Data Transfer Addendum (“IDTA”).

Please note that the above safeguards apply strictly to data managed within our own infrastructure and do not extend to real-time data processing handled independently by third-party free API architectures, as detailed below.

Processing of Queries via Free AI Services

Our free search engine functionality utilises the free tier of the third-party Google Gemini API to process your search queries in real-time.

Important Privacy Notice on AI Training: Please be explicitly informed that when you use this free search functionality, your search prompts, inputs, and any generated responses are transferred to and processed by Google LLC in the United States. Under Google’s standard terms for its free API tier, Google may retain, analyse, and use this data to train, improve, and develop its AI models and other machine-learning products. This data may also be reviewed by human moderators.

Your Responsibility: Because this specific service runs on a free public infrastructure, you are strictly prohibited from entering any confidential information, sensitive data, or non-public personal details of third parties into the search field. By submitting a query through this free tool, you acknowledge that your prompt is transferred directly to Google and will be processed in accordance with the Google Privacy Policy and Google AI Terms of Service.

User Content and Query Restrictions

Our Site operates as a technical interface and does not technically restrict, monitor, or moderate the specific words, names, or phrases you enter into the free AI search tool. Consequently, you remain solely responsible for the content of your queries.

  • Searching for Yourself: If you choose to input your own Personal Data, you acknowledge and agree that this data will be processed by Google Gemini under its free-tier terms (including potential use for AI training).
  • Searching for Third Parties: You are strictly prohibited from entering non-public, confidential, or sensitive personal data of third parties (e.g., private financial, medical, or national identification details). You represent and warrant that any third-party data you input for searching consists solely of publicly available information, or that you possess an appropriate and valid lawful basis under applicable Data Laws to process and input such data.

The Company acts merely as a passive technical conduit and disclaims all liability for the nature of the data you choose to search for, or for how third-party AI models process, retain, or share it thereafter.

5. How we use the information we collect

We process your Personal Data strictly based on valid legal grounds under applicable Data Laws (including the performance of a contract, compliance with legal obligations, or our legitimate business interests). Specifically, we use your information for the following purposes:

To Provide and Improve the Services:

  • To provide, operate, and maintain our Site and Services, and to fulfil your requests for our products and Services;
  • To process and execute your search queries through automated third-party Artificial Intelligence (AI) models (specifically the free tier of the Google Gemini API) acting as a technical interface;
  • To improve, optimise, and analyse our Site and Services, including monitoring usage patterns and activity trends;
  • To perform essential technical and organisational operations, such as updating our systems, databases, and security infrastructure;
  • To develop and test new features, programs, products, or services.

To Communicate and Market (Subject to Your Choices):

  • To communicate with you, respond to your enquiries, and notify you when we make material changes to our terms, conditions, or policies;
  • To provide you with updates, newsletters, special offers, and promotional materials from us and our affiliates, where permitted by Law and subject to your explicit consent or marketing preferences (such communications may be sent via email).

To Ensure Security and Legal Compliance:

  • To protect the safety, rights, property, or security of our Company, our users, the Services, or any third party;
  • To detect, prevent, or otherwise address fraud, security breaches, or technical malfunctions;
  • To prevent, investigate, or stop any activity which we consider to be, or to have a risk of being, illegal, unethical, or unlawful (including following notifications from law enforcement or third-party rightsholders);
  • To use as evidence in litigation, civil disputes, or criminal matters;
  • To enforce this Notice, our Terms of Service, or other applicable operational rules; and
  • To comply with applicable legal, statutory, or regulatory obligations, including responding to a subpoena, warrant, court order, or formal/informal request from law enforcement or government authorities.

Use of Aggregated and De-Identified Data:

For the avoidance of doubt, where data is completely anonymised, aggregated, or de-identified such that it can no longer identify an individual, it does not constitute Personal Data under applicable Data Laws. We reserve the right to use, store, and share such anonymous technical data to improve the design, functionality, and content of our Site, to analyse usage trends, and for general research, analytical, and statistical purposes without restriction.

6. Sharing and Disclosure of Your Data

We may disclose your Personal Data as described in this Notice or where required or explicitly permitted by applicable Data Laws. We do not sell your Personal Data. However, we may share your data under the following circumstances:

Sharing with AI API Providers (Real-Time Search Processing)

  • As detailed in Section 4 of this Notice, when you execute search queries, your input prompts and text phrases are transferred directly to Google LLC (USA) via their free-tier Gemini API. This data transfer is an inherent and essential technical part of providing our search engine functionality. Google processes this data in accordance with its own privacy policies and may use it for machine-learning training.

Sharing with Third-Party Service Providers

  • We share your Personal Data with our trusted vendors, service providers, contractors, or agents who perform operational functions on our behalf. These include providers assisting us with infrastructure hosting, database management, IT security, email communications, and customer support. All such third parties are bound by strict contractual obligations to maintain the confidentiality and security of your data, and they are prohibited from using it for any purpose other than providing services to us.

Sharing for Corporate Activity Purposes

  • In the event of a corporate reorganisation, restructuring, merger, acquisition, joint venture, assignment, transfer, or sale of all or any portion of our business assets, the information we have collected (including Personal Data) will generally be transferred as part of the business assets. We may disclose your data to:
  • Other companies within our corporate group;
  • A buyer or prospective buyer of our business or assets;
  • Our professional advisers (such as lawyers, auditors, insurers, or financial consultants) where necessary for them to provide professional advice to us.

Sharing for the Protection of Rights, Interests, and Safety

  • We may disclose your data to protect the safety, rights, property, or security of our business, our users, the Services, or the general public. This includes sharing data to detect, prevent, or otherwise address fraud, security vulnerabilities, technical issues, or to mitigate a serious threat to life or physical safety. We will only disclose such data based on a reasonable and objective assessment that such activity is necessary, or when triggered by legitimate notifications from law enforcement or third-party rightsholders.

Sharing for Legal or Regulatory Compliance

  • We may be legally compelled to disclose your Personal Data to courts, law enforcement, regulators, or government authorities within or outside your country of residence. This may occur in response to a binding court order, subpoena, warrant, or to comply with statutory and regulatory obligations. We may also disclose data to investigate potential violations of our Terms of Service, defend against legal claims, or address allegations of intellectual property infringement (such as copyright or trademark claims) anywhere in the world.

Sharing of Aggregated and De-Identified Information

  • We may share aggregated, anonymous, or de-identified technical information that cannot reasonably be used to identify you with third parties for marketing, advertising, industry analysis, research, or compliance purposes. Where third-party analytics cookies are used on our Site, such processing is subject to your consent and is detailed in our Cookies Section below.

7. Marketing and Communications

We may use your Personal Data, in conjunction with our affiliates, to develop and deliver targeted advertising, newsletters, and promotional offers regarding our products and Services, including by contacting you via the email address you have provided. Any marketing email received from us will clearly state that it is being sent by the Company and will be subject to your prior explicit consent where required by applicable Data Laws.

You have the right to opt out of receiving marketing communications from us at any time. If you change your mind regarding your marketing preferences, you can:

  • Utilise the “unsubscribe” link contained at the bottom of any marketing email; or
  • Contact us directly by emailing [email protected].

We will process your opt-out request without undue delay and in accordance with statutory timeframes under applicable Data Laws (which, for certain jurisdictions, may take up to ten (10) business days from receipt of your request). Please note that opting out of marketing communications will not affect transactional, administrative, or operational emails that are necessary for the performance of our contract with you, or which are required to address support requests, legal enquiries, or regulatory compliance matters.

8. Safeguarding and security

We implement appropriate technical and organisational measures designed to safeguard and protect your Personal Data from unauthorised access, accidental loss, alteration, or unlawful disclosure.

However, please be aware that no method of transmission over the Internet or method of electronic storage can be guaranteed as absolutely secure. Consequently, while we strive to use commercially appropriate and legally compliant standards to protect your Personal Data, any transmission of data to our Site is executed at your own risk.

To provide the Services, certain data inputs (such as search queries) must be transferred to third-party infrastructure partners (including Google Gemini API), as detailed in Section 4 and Section 6 of this Notice. To the maximum extent permitted by applicable Data Laws, the Company shall not be held liable for any data disclosure, alteration, or loss resulting from unauthorised third-party actions (such as targeted cyberattacks or hacking) or transmission errors that occur entirely beyond our reasonable control, provided that we have maintained and executed all statutory security measures required under applicable Data Laws.

Third-Party Links and Applications

Our Site and Services may contain hyperlinks to third-party websites, plug-ins, or applications. Any access to and use of such linked platforms is not governed by this Notice but is strictly subject to the privacy policies of those respective third parties. We do not monitor, endorse, or accept responsibility for the privacy practices or content of third-party websites, and we strongly advise you to exercise caution and thoroughly review their applicable privacy statements.

9. Your rights

General Provisions

Applicable Data Laws grant you specific rights regarding your Personal Data. We endeavour to apply the core privacy rights afforded by the UK GDPR and EU GDPR to all our users globally, regardless of their jurisdiction. We will respond to your privacy requests without undue delay and in any event within one (1) month of receipt. This period may be extended by a further two (2) months where necessary, considering the complexity and number of the requests. If an extension is required, we will inform you within the first month.

To protect your privacy and security, we require you to provide valid proof of identification to verify your identity before executing any changes. Any identification documents requested during this verification process will be processed strictly for identity validation and will be permanently deleted immediately upon the completion of your request.

Where you object to processing or successfully request the erasure of your data, we will retain your email address on our internal suppression (opt-out) list to ensure we respect your preferences in the future, while deleting or anonymising all other data held in our systems.

Important Disclosures on Third-Party Data Subjects (Search Engine Functions)

Please be informed that our Site operates both as a platform for ordering professional bespoke services and as a technical search interface. In connection with our automated search engine functionality, we may process publicly available data regarding individuals who are not direct users of our Site or customers of our Services (third-party data subjects). If you are a third party whose public information appears within our search outputs, you possess the same rights under applicable Data Laws to object to such processing or to request erasure (specifically, the removal or restriction of your details from our search results interface).

Crucial Limitation Regarding AI Processing: If Personal Data (whether your own or that of a third party) is entered into our free AI search tool, it is transferred in real-time to Google LLC via the Google Gemini API and may be used by Google for machine-learning training as described in Section 4 and Section 6. While the Company will permanently delete all logs, operational records, and search histories within our direct possession upon a valid request, we possess no technical capability to retroactively delete, recall, modify, or remove data that has already been transmitted to or processed by third-party AI models. To request removal from AI training datasets, you must contact Google LLC directly.

Specific Rights of Data Subjects

  • Right of Access: You have the right to request a copy of the Personal Data we hold about you. To exercise this right, please email [email protected] and include your name, email address, and any relevant details to assist us in locating your information. Following identity verification, we will provide the permitted data. This service is generally free of charge; however, under UK/EU Data Laws, if your requests are manifestly unfounded, repetitive, or excessive, we reserve the right to charge a reasonable administrative fee or refuse to act on the request.
  • Right to Rectification (Correction): You have the right to request that we correct or update any inaccurate or incomplete Personal Data we hold about you. Please email [email protected] with your details and the specific corrections required.
  • Right to Erasure (Right to be Forgotten) & Search Restriction: You have the right to request the complete erasure of your Personal Data from our active systems.
  • For Customers and Users: Upon valid identity verification, we will delete your account details, communication records, and information related to services ordered through our platform, subject to statutory retention requirements (such as retaining billing data for tax compliance or fraud prevention).
  • For Third-Party Data Subjects: If you are a third-party individual who wishes to prevent your name or public profiles from being queried or displayed via our automated search interface, you may submit a request to be placed on our internal search blocklist by emailing [email protected]. Upon identity verification, we will take all reasonable, practical, and technically feasible steps to restrict your data from being retrieved or displayed within our interface.
  • Right to Object to Processing: You have the absolute right to object to the processing of your Personal Data for direct marketing purposes, and a qualified right to object to processing based on our legitimate interests. Please email [email protected] to submit an objection.
  • Right to Data Portability (UK and EU Residents Only): If you reside in the United Kingdom or the European Union, you have the right to receive the Personal Data you provided to us in a structured, commonly used, and machine-readable format, or request its direct transfer to another data controller, where technically feasible. Email [email protected] to initiate this request.
  • US State-Specific Rights (CCPA/CPRA & VCDPA): US State-Specific Rights: If you are a resident of California, Virginia, or another US state with comprehensive privacy laws, you possess specific statutory rights regarding your Personal Data. These include the right to know and access the categories and specific pieces of Personal Data collected about you; the right to request deletion (erasure); the right to correct inaccuracies; the right to opt out of the “sale” of your data, as well as the “sharing” or processing of data for targeted advertising (including via automated opt-out mechanisms or global privacy controls); and the right to non-discrimination, ensuring we will not deny you services, restrict functionality, or alter prices should you choose to exercise your privacy rights.

10. Cookies

Overview of Cookies

We, and/or third-party service providers acting on our behalf, may collect information about your computer or mobile device by using cookies, web beacons, and related tracking technologies (collectively, “Cookies”).

Cookies are small text files placed on your device when you visit websites. They help us gather technical and statistical data regarding your browsing behaviours. While this data typically does not identify you directly by name, under applicable Data Laws (including the UK/EU GDPR and CCPA/CPRA), certain online identifiers such as IP addresses, unique cookie IDs, and device metrics are categorised as Personal Data (specifically, pseudonymised data).

We use Cookies to enhance platform security, customise your user experience, and analyse web traffic trends. When you access the Site, a temporary session identifier Cookie is deployed, which automatically expires when you close your browser.

Purposes for Which We Use Cookies

Enabling Cookies allows us to:

  • Estimate our audience size, geographical distribution, and general usage patterns;
  • Store information regarding your preferences, allowing us to customise our Site and Services according to your individual interests;
  • Speed up your user interface navigation and system responsiveness;
  • Recognise you automatically when you return to our Site;
  • Secure our infrastructure against malicious activity, spam, and cyber threats.

Technical and usage data may be gathered on our behalf using Cookies, log file fragments, and script code embedded on our Site by specific third-party partners, including Google, Microsoft, Cloudflare, and Sentry.

Your Choices and Consent Management

Under UK and EU Data Laws, you have the right to choose whether to accept or decline non-essential Cookies. Non-essential Cookies (such as analytics trackers) will only be deployed upon your explicit, affirmative consent via our Cookie banner.

Please note that even if you reject or ignore the Cookie consent request, we will still deploy Strictly Necessary Cookies that are technically indispensable for the operation, safety, and core features of our Site.

You can amend, manage, or revoke your Cookie preferences at any time through our interactive Cookie banner, your device settings, or your browser configuration. Comprehensive information regarding how to view, manage, or delete deployed Cookies can be found at www.aboutcookies.org and www.youronlinechoices.eu. If you choose to completely block all Cookies, you may experience a reduction in functionality or an inability to use certain parts of our Site or Services.

Cookie Categories Deployed on Our Site

  • Strictly Necessary & Security Cookies: These tools, including CSRF tokens, Cloudflare settings, and CAPTCHAs, are required to keep the Site safe, operational, and secure, protecting our infrastructure and user interactions from fraud, automated bots, and spam attacks. This category also covers our application error monitoring service, Sentry (Functional Software, Inc.), which records technical diagnostics when something on the Site fails so that we can repair it. Sentry is configured not to send your IP address, Cookies, or request headers, and identifies your account only by a pseudonymous reference rather than your name or email address.
  • Performance & Functional Cookies: These tools allow our Site to remember operational choices you make (such as language preferences or regional settings) and provide enhanced, personalised features. They ensure pages load rapidly and respond efficiently to your technical requests.
  • Analytics and Research: To keep our Site and Services relevant, we track user interaction trends, page popularity, and system error logs. These analytics Cookies process pseudonymised data. We utilise Google Analytics and Microsoft Clarity to compile aggregated reports that show overall patterns of usage rather than an individual’s isolated activity, Google Tag Manager to load and govern those measurement scripts, and Sentry Session Replay to reconstruct the sequence of interactions that led to a technical fault. Session Replay records page structure and interactions only: every item of text and every form field is masked before the recording leaves your browser, and images, video and network content are excluded entirely. Session Replay recording is suspended for as long as you are on our sign-in, password-reset, or account-setup pages, and neither it nor Microsoft Clarity is ever started on them. You can specifically opt out of Google Analytics tracking by installing the official browser add-on available here: https://tools.google.com/dlpage/gaoptout. If you have entirely disabled Cookies within your browser, Microsoft Clarity tracking will not be initiated.

Do Not Track and Global Privacy Control (GPC)

Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Our Site does not currently respond to automated browser DNT signals due to a lack of uniform industry standards. However, we fully recognise and support the Global Privacy Control (“GPC”) signal. If you are a US resident utilising an active GPC signal or a compatible browser extension designed to opt out of automated tracking under US Data Laws, our system automatically detects and honours this choice by disabling non-essential marketing and analytics trackers for your session. Alternatively, you may manually adjust your tracking preferences at any time directly through our Cookie consent banner.

11. Contact Information, Enquiries, and Supervisory Authorities

How to Contact Us

If you have any questions, concerns, or complaints regarding this Privacy Notice, the processing of your Personal Data, or if you wish to exercise any of your statutory rights detailed in Section 9, please contact our privacy compliance team via:

  • Email: [email protected]
  • Postal Address: Molfar Limited, 20 Wenlock Road, London, England, N1 7GU

To ensure the security of your account and data, please note that all requests submitted via email must be sent from the email address associated with your registration or service history. We will require valid proof of identification before responding to or executing your requests.

Data Protection Officer (DPO)

Due to the nature and scale of our operations, we are not statutorily required to appoint a formal Data Protection Officer under UK/EU Data Laws. However, we have designated an internal privacy compliance team to handle all personal data enquiries. You can reach them directly at [email protected].

The Right to Lodge a Complaint with Supervisory Authorities

We encourage you to contact us directly in the first instance if you believe our processing of your Personal Data violates applicable Data Laws, so that we may investigate and resolve your concerns swiftly.

However, you possess an absolute right to lodge a formal complaint with a data protection authority at any time. Depending on your location, the relevant supervisory authorities are detailed below:

  • United Kingdom Residents: You can complain directly to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.
  • Website: www.ico.org.uk
  • Helpline: +44 (0)303 123 1113
  • European Union (EU) / European Economic Area (EEA) Residents: You have the right to lodge a complaint with the national Data Protection Authority (DPA) in the EU member state where you reside, work, or where the alleged data protection infringement occurred. A comprehensive list of EU DPAs and their contact links can be found via the European Data Protection Board website at www.edpb.europa.eu.
  • United States Residents: If you are a resident of a US state with comprehensive privacy laws (such as California or Virginia) and you are unsatisfied with our response to a privacy rights request, you have the right to appeal our decision by contacting us via email. If your appeal is denied, or if you wish to report a systemic privacy violation, you may submit a formal complaint directly to your state’s regulatory body (e.g., the California Privacy Protection Agency (CPPA) or your state’s Attorney General’s Office).

11. US State Privacy Addendum: Notice to Residents of Eligible US States

Scope and Applicability

This Section applies solely to individual residents of the State of California, the Commonwealth of Virginia, and other US states that have enacted comprehensive state privacy laws (collectively, “US Residents”). This US State Privacy Addendum supplements the information contained in our global Privacy Notice above by detailing the specific categories of personal information we collect, store, process, and disclose, alongside the statutory rights afforded to US Residents under applicable US State Privacy Laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and the Virginia Consumer Data Protection Act (“VCDPA”).

Categories and Sources of Personal Information Collected

In addition to the disclosures provided in Section 3 of our Notice, we collect (and have collected during the preceding 12-month period) the following statutory categories of personal information:

  • Identifiers (“Identifier Data”): Full names, phone number, email addresses, internet protocol (IP) addresses, unique device identifiers, business email addresses, job titles, employer or company names, and business mailing addresses.
  • Internet or Electronic Network Activity (“E-Data”): Technical data regarding your interaction with our Site, forms, and automated services across your devices, including search queries inputted into our AI-powered features.
  • Geolocation Data (“Location Data”): Approximate physical location derived from IP addresses or business location coordinates.
  • Employment-Related Information (“Employment Data”): Professional metrics, business contact data, job titles, and corporate affiliations.

Important Statutory Exclusion: Under applicable US Data Laws, personal information does not include data that is lawfully made available from federal, state, or local government records, or information that is widely distributed via public mass media channels.

Sensitive Personal Information: We do not intentionally collect, store, or process Sensitive Personal Information (as defined by US Data Laws). Users are strictly prohibited from submitting any sensitive personal information within text prompts or search queries. However, if a user voluntarily provides such data within a query, it will be processed solely to execute the requested automated service.

Sources of Information: The metadata listed above is sourced directly from you (via online form submissions, search queries, and account registration) or indirectly through your automated technical interaction with our Site infrastructure.

Purposes and Sharing of Personal Information

The operational and commercial purposes for which we collect your personal information are fully detailed in Section 5 of our Notice. We will not collect or process personal information for materially different, unrelated, or incompatible purposes without updating this text.

Data Sharing and Disclosure: Our mechanisms for disclosing personal data are governed by Section 6 of our Notice. For the explicit purposes of US Data Laws:

  • We do not sell your personal information for monetary compensation, nor do we share your account metrics with third parties for cross-context behavioural advertising.
  • AI-Powered Third-Party Transfer Notice: Please be aware that when you utilise our AI-powered features, the search queries and text prompts you input are processed via the free tier of the third-party API (Google’s Gemini). In accordance with Google’s terms for non-paid API usage, these inputs may be used by Google LLC for AI model improvement and training purposes and may be reviewed by human evaluators. By voluntarily submitting prompts into our AI tool, you acknowledge and direct this transfer of data to Google LLC as an integrated part of the service execution.

Data Retention: We strictly limit the retention of your data to the minimum period necessary to execute our services, comply with financial audit requirements, or resolve legal disputes, as described in Section 4 and Section 10 of our Notice.

Automated Profiling: Except for the automated execution of AI-generated search results initiated directly by your queries, we do not engage in automated decision-making, consumer profiling, or targeted advertising.

Your Statutory Privacy Rights in the US

  • Right to Access and Portability: You have the right to request that we disclose what personal information we have collected, used, and shared about you over the preceding 12-month period. Upon valid identity verification, we will provide a machine-readable copy of the data. You may execute this request free of charge up to twice within any 12-month period.
  • Right to Correction: You have the right to request that we rectify any inaccurate or incomplete personal information maintained within our active records.
  • Right to Erasure (Deletion): You have the right to request the deletion of your personal information maintained in our systems. Please note that this right is subject to statutory exceptions (e.g., data required for financial audits, legal compliance, or fraud prevention). Furthermore, because text prompts submitted to our AI tools are processed by Google LLC (Gemini API Free Tier) instantly upon submission, we cannot retrieve or delete any personal information you voluntarily inputted into those third-party AI systems.
  • Right to Opt-Out of Sale or Sharing: You have the right to restrict data transfers that may be broadly categorised as “selling” or “sharing” under US State Privacy Laws. To exercise this, please visit our dedicated page: Limit/Do Not Sell/Share My Personal Information, or utilise a recognised Global Privacy Control (GPC) signal. Please note that activating an opt-out will disable non-essential marketing and tracking tools; however, it cannot prevent the technical processing of prompts via the Google Gemini API if you continue to interact with our AI features. If you object to AI processing entirely, you must refrain from using our AI-powered tools or request the deletion of your account. We will act upon valid opt-out requests within fifteen (15) business days.

How to Submit a Request and Identity Verification

To exercise your right to access, correction, or deletion, please submit a formal request by emailing [email protected].

To protect your security and prevent identity theft, we must verify your identity before executing any statutory modification or deletion. We will primarily attempt to verify your identity using the information already associated with your account (such as requiring a response from your registered email address or verification via account login). We will only request supplemental information, which may in exceptional circumstances include a government-issued photographic identification, if we cannot reasonably verify your identity through standard operational methods. Any document submitted during this exceptional process will be utilised strictly for identity validation and will be permanently deleted immediately upon completion of the verification.

We will respond to verified requests from you within forty-five (45) days of receipt. If an extension is reasonably required due to technical complexity, we will inform you of the extension period (up to an additional 45 days) in writing within the initial response window. Requests to opt-out of data sale or sharing will be processed within fifteen (15) business days, as detailed above.

Statutory Exceptions and Limitations

Your privacy rights are not absolute and are subject to specific legal exceptions. We are entitled to deny deletion or access requests if fulfilling them poses an unreasonable risk to our network security, or if retaining the data is strictly required to:

  • Complete the transaction or perform the bespoke service for which the personal information was collected;
  • Detect and prevent security incidents, malicious fraud, or illegal activities;
  • Comply with a binding court order, statutory legal obligation, or assist law enforcement agencies;
  • Maintain internal data records in a manner compatible with the context in which you originally provided the information.

State-Specific Processing Notices: In accordance with applicable US State Privacy Laws (including the VCDPA), if you opt out of data processing, we are not required to honour the opt-out if the disclosure involves data shared with direct processors (hosts/analytics), corporate affiliates, or information that you have intentionally made available to the general public via public mass media channels without restriction.

Authorised Agents

You have the statutory right to appoint an authorised agent to submit an opt-out, access, or deletion request on your behalf. If you utilise an authorised agent, they must provide their full name, email address, telephone number, and explicit written permission signed by you that includes your direct contact information.

Upon receiving a request from an authorised agent, we will contact you directly using the provided details to verify your identity and confirm that the agent possesses valid authorization. We reserve the right to deny any request if we cannot verify your identity or the agent’s legal authority to act on your behalf. Written permission from you is not required if the authorised agent provides certified proof of a valid Power of Attorney pursuant to applicable state laws.

Right to Non-Discrimination

You have the right not to be discriminated against by us for exercising any of your privacy rights. We will not deny you services, charge different prices, or alter the quality of our Services if you choose to exercise your statutory rights. However, you acknowledge and agree that it may not be technically or operationally possible for us to provide certain Services (such as executing specific paid agreements, custom inquiries, or AI-powered features) if we do not possess the minimum necessary technical information required to perform them.

Appealing a Decision (Virginia Residents Only)

If you reside in a US state with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, or Texas) and we refuse to act upon your statutory data protection request, you possess the right to appeal our decision. To initiate an appeal, please write to our privacy compliance team at [email protected] within thirty (30) days of receiving our refusal notice.

We will respond to your appeal in writing within forty-five (45) or sixty (60) days of receipt (depending on applicable state statutory timelines), explaining the reasons for our decision. If your appeal is denied, or if you wish to escalate the matter further, you are entitled to submit a formal complaint directly to the Attorney General’s Office of your respective state. For Virginia residents, complaints may be directed to:

  • Email: [email protected]
  • Postal Address: Office of the Attorney General, 202 North Ninth Street, Richmond, VA 23219
  • Website: www.oag.state.va.us