GLOBAL PRIVACY FRAMEWORK
Privacy Policy
This policy describes the current technical state of PSEO WEBSITE and the privacy framework required before any market is activated. It is a pre-publication policy draft, not legal advice or a statement that every jurisdictional requirement has been completed.
1. Current website state
This is a static website. The project-brief form is disabled because no receiving endpoint, legal operator, data recipient or retention process has been configured. No analytics, advertising pixels, non-essential cookies or payment integration are active in this build.
2. Data that may be collected after activation
When a secure enquiry service is approved and enabled, the form may collect name, work email, company, website, service description, requested markets and languages, selected scope, project details and the privacy acknowledgement. The final field list, recipients, security controls and retention period must be confirmed before the form is enabled.
3. Purpose and minimisation
Any enabled enquiry data may be used only to assess and respond to the relevant project brief, prevent abuse and meet confirmed legal obligations. The operator must collect only information needed for those purposes, limit access to authorised people and remove or anonymise data according to a confirmed retention schedule.
4. EEA and United Kingdom
For people in the EEA or United Kingdom, the applicable operator must complete the controller identity, lawful basis, rights-request contact, recipients, retention periods and any international-transfer safeguards before processing starts. Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, portability and objection. A complaint route to the relevant supervisory authority must also be published before launch.
5. United States and other markets
United States privacy requirements are state-specific and may depend on the operator, processing volume, revenue, categories of data and sharing practices. For example, if California law applies, a relevant notice and request process must address applicable rights such as knowing, correcting, deleting and opting out of sale or sharing. This static build has no feature that sells or shares form data, but that statement must be reviewed again before any service, analytics or advertising technology is activated.
For every additional country or region, the operator must verify the applicable privacy, consumer, marketing, cookie and data-transfer rules before targeting residents or accepting their data. No market is treated as legally activated merely because it appears in site content.
6. Service providers and international transfers
No processors or transfer mechanisms are configured in the current build. Before activation, the operator must publish the actual hosting, form-routing, analytics, payment and support providers, their processing roles, data locations and any required transfer safeguards.
7. Rights requests and contact
TODO before publication: publish the legal operator name, registration facts where applicable, postal address, privacy contact channel, identity-verification process, response timetable and complaint route. Until those facts are confirmed, this website does not provide an operational rights-request channel.
8. Changes
This policy must be reviewed whenever the operator, a target market, the form endpoint, tracking, payments, storage, recipients or retention practices change. The version and effective date must be added only after operator verification and qualified legal review where needed.