PRIVACY POLICY
Effective Date: October 3, 2025
Last Updated: October 3, 2025
INTRODUCTION
Welookup Insights (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website welookupinsights.com, use our services, or engage with us in any capacity.
This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy laws.
1. INFORMATION WE COLLECT
Personal Information
We may collect the following personal information:
- Contact Information: Name, email address, phone number, company name, job title
- Professional Information: Industry, company size, business challenges, project requirements
- Communication Data: Messages, emails, consultation notes, meeting recordings (with consent)
- Technical Information: IP address, browser type, device information, cookies, website usage data
- Financial Information: Billing address, payment information (processed securely by third-party providers)
Sensitive Business Data
In providing our analytics consulting services, we may access:
- Customer databases and CRM data
- Business performance metrics and KPIs
- Financial and operational reports
- Proprietary business information
2. HOW WE COLLECT INFORMATION
- Directly from you: Contact forms, consultation requests, email communications
- Automatically: Website cookies, analytics tools, server logs
- Third-party sources: HubSpot CRM, Calendly scheduling, Microsoft 365 integration
- During service delivery: Client data accessed for analytics consulting projects
3. HOW WE USE YOUR INFORMATION
Legitimate Business Purposes:
- Providing data analytics consulting services
- Responding to inquiries and scheduling consultations
- Communicating about projects, updates, and business matters
- Improving our services and website functionality
- Compliance with legal and regulatory obligations
- Marketing communications (with consent where required)
Legal Basis for Processing (GDPR):
- Contractual Performance: Delivering consulting services
- Legitimate Interests: Business operations, communications, improvements
- Consent: Marketing communications, cookies, non-essential data processing
- Legal Compliance: Regulatory requirements, data retention obligations
4. DATA SHARING AND DISCLOSURE
We may share your information with:
- Service Providers: HubSpot (CRM), Microsoft (email/collaboration), payment processors, hosting providers
- Professional Partners: Subcontractors, freelancers bound by confidentiality agreements
- Legal Requirements: Government authorities, law enforcement when legally required
- Business Transfers: In case of merger, acquisition, or business sale (with notification)
We do NOT:
- Sell personal information to third parties
- Share sensitive business data outside approved service delivery
- Use client data for competitive purposes
- Engage in unauthorized data mining or profiling
5. INTERNATIONAL DATA TRANSFERS
Cross-Border Processing:
- Data may be processed in the United States, European Union, Canada, and other jurisdictions
- We implement appropriate safeguards including Standard Contractual Clauses
- Client data remains subject to applicable local privacy laws
- Transfers comply with GDPR adequacy decisions and certification mechanisms
6. DATA SECURITY
Security Measures:
- Encryption: Data encrypted in transit and at rest
- Access Controls: Role-based access, multi-factor authentication
- Regular Audits: Security assessments, vulnerability testing
- Incident Response: Data breach notification procedures
- Employee Training: Privacy and security awareness programs
Industry Standards:
- SOC 2 Type II compliant service providers
- ISO 27001 aligned security practices
- Regular security updates and patches
- Secure data destruction procedures
7. DATA RETENTION
Retention Periods:
- Contact Information: 7 years from last interaction or as required by law
- Project Data: Duration of engagement plus 7 years for legal/tax purposes
- Financial Records: 7 years as required by accounting regulations
- Marketing Data: Until consent withdrawn or 3 years of inactivity
- Website Analytics: 26 months (Google Analytics standard)
Deletion Procedures:
- Automated deletion based on retention schedules
- Secure data destruction methods
- Client notification upon data deletion completion
- Legal hold procedures for litigation or investigation
8. YOUR PRIVACY RIGHTS
GDPR Rights (EU/UK Residents):
- Access: Request copy of personal data we hold
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of personal data (“right to be forgotten”)
- Restriction: Limit processing of personal data
- Portability: Receive data in machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdrawal: Withdraw consent for consent-based processing
CCPA Rights (California Residents):
- Know: What personal information is collected and how it’s used
- Delete: Request deletion of personal information
- Opt-Out: Opt out of sale of personal information (we don’t sell data)
- Non-Discrimination: Equal service regardless of privacy choices
PIPEDA Rights (Canadian Residents):
- Access: Request access to personal information
- Correction: Request correction of inaccurate information
- Complaint: File complaints with Privacy Commissioner of Canada
Exercising Your Rights:
- Email: privacy@welookupinsights.com
- Response Time: 30 days (GDPR), 45 days (CCPA), 30 days (PIPEDA)
- Verification: Identity verification required for security
- No Cost: Most requests processed free of charge
9. COOKIES AND TRACKING
Types of Cookies:
- Essential: Website functionality, security
- Analytics: Google Analytics, website performance (anonymized)
- Marketing: HubSpot tracking, conversion measurement
- Preference: User settings, language preferences
Cookie Management:
- Consent: Cookie banner for non-essential cookies
- Control: Browser settings to manage cookies
- Opt-Out: Google Analytics opt-out available
- Do Not Track: We respect Do Not Track signals
10. THIRD-PARTY SERVICES
Key Service Providers:
- HubSpot: CRM and marketing automation (US/EU data centers)
- Microsoft 365: Email and collaboration (US/EU data centers)
- Google Analytics: Website analytics (anonymized data)
- Calendly: Meeting scheduling (US data centers)
- Hosting Provider: Website hosting with security measures
Due Diligence:
- All providers meet applicable privacy standards
- Data Processing Agreements in place
- Regular security and compliance reviews
- GDPR-compliant service selection
11. CHILDREN’S PRIVACY
We do not knowingly collect personal information from children under 16 years of age. If we discover we have collected information from a child, we will delete it immediately. Parents or guardians concerned about data collection should contact us.
12. CHANGES TO THIS POLICY
- Updates: We may update this policy to reflect legal or business changes
- Notification: Material changes communicated via email and website notice
- Effective Date: Changes effective 30 days after notification
- Version Control: Previous versions available upon request
13. CONTACT INFORMATION
Privacy Inquiries:
Privacy Officer: Vishal Dhoble, Founder & CEO
Email: privacy@welookupinsights.com
Address: Welookup Insights, 1209 Orange Street, Suite 100, Wilmington, DE 19801, United States
Phone: Available upon request
Regulatory Authorities:
- EU/UK: Local Data Protection Authority
- California: California Attorney General
- Canada: Privacy Commissioner of Canada
- Germany: Federal Commissioner for Data Protection
