Privacy notice

Last updated: 21 September 2026.

Who we are. Optimize Manager is a UK trading name operated by its founder, who is the data controller for this website. Contact: [email protected].

What we collect. Only what our forms ask for: name, work email, business details, phone (if you give it), and the answers you give our tools. Mini-audit answers are used to prepare your findings sheet. When you submit a form we also record where you arrived from — the referring page and any UTM campaign tags in the link you followed — so we can tell which outreach actually works. We receive standard server logs (IP, user agent) via our hosting provider.

Lawful basis — per purpose.
  • Enquiry, mini-audit and verification replies — contract, or steps before a contract, at your request.
  • Optional marketing emails and calls — consent (separate unticked boxes; never bundled with your report).
  • Server logs, Turnstile bot-checks and rate-limit keys — legitimate interest in keeping the site and forms secure.
  • Referrer and UTM attribution — legitimate interest in measuring our own marketing; stored only against the submission it arrived with.
  • Data about a named third party in a verification request — legitimate interest in confirming who works with us, balanced by the Article 14 notice below.

Processors. This site is hosted on Cloudflare Pages; form submissions are emailed to us via Resend and stored in our email mailbox (Migadu); bot protection uses Cloudflare Turnstile. Cloudflare also stores short-lived rate-limit keys (a hashed client IP, ~1 hour TTL) in its KV store to throttle form floods. Each processes personal data on our behalf under its own terms. This site runs no analytics or tracking scripts. A current processor list is available on request.

International transfers. Some processors operate outside the UK. Where personal data is transferred internationally we rely on an appropriate safeguard (UK IDTA, the UK Addendum to EU SCCs, or an adequacy regulation). Our Sri Lanka delivery arrangements are governed the same way — Sri Lanka is not an adequacy country, so engagement contracts are designed to carry IDTA terms and a transfer risk assessment.

Data about you from others (Article 14). Our employment-verification form lets third parties (lenders, landlords, referees) name a person they want verified. Where we receive personal data about you from someone else we inform you within one month, unless you already know or an Article 14(5) exemption applies.

Retention. Enquiry and mini-audit data is kept for up to 24 months, then deleted unless an engagement begins. Engagement records are kept for the contract term plus the statutory limitation period.

What we never do. Sell your data, cold-call from a bought list, or send SMS unless you explicitly opt in.

Your rights. Access (a "subject access request"), correction, deletion, restriction, portability, objection — email us and it happens. You can withdraw consent at any time. Formal complaints: the Information Commissioner's Office (ico.org.uk).

A full data-processing schedule — including the IDTA schedule for delivery data — will be provided with every engagement agreement.