Legal · version 3.0 · last updated 19 August 2026

Privacy policy

The data controller is Lanex Group, LLC, a limited liability company incorporated in the State of Delaware, United States, trading as First Person Marketing. This policy explains exactly what we collect through this website, the audit, the subscription signup and the checkout, the lawful basis for each category, how long we keep it, who processes it on our behalf, where it goes, and how you exercise every right you hold. We do not sell personal information and we do not share it for cross-context behavioural advertising.

  • No sale or sharing of personal information, ever
  • Retention schedule published per data category
  • Deletion on request, confirmed in writing within 5 Working Days
  • GDPR, UK GDPR, CCPA/CPRA and PIPEDA rights honoured worldwide

What we collect, why, and the lawful basis

Each row states the category, the purpose, the lawful basis under GDPR Article 6, and the retention period. Nothing outside these categories is collected through this website.

Identity and contact data
First name, last name, work email, phone number with country code, job role. Purpose: to send your audit report or written scope and to reply to you. Basis: consent and legitimate interest in answering an enquiry. Retention: 24 months from last contact.
Business and financial context
Company name, sector, business model, revenue band, marketing budget band, gross margin band, current channels, goals and constraints. Purpose: to produce the written audit and an honest plan recommendation. Basis: consent. Retention: 24 months, or the life of the contract plus 7 years for clients.
Website and public visibility data
The URL you supply, its public pages, and third-party visibility, backlink and keyword data about that domain. We never access private systems or logged-in areas without written authorisation. Basis: legitimate interest in preparing the requested analysis. Retention: 24 months.
Submission metadata
A 10 digit reference, progress step, status history, device type and timestamps. Purpose: to locate, manage and audit your record and to let you quote a reference. Basis: legitimate interest. Retention: 24 months.
Order and billing data
Plan selected, fee, subscription and payment status, invoice history, and the Stripe customer and subscription identifiers. We never receive full card numbers. Purpose: to fulfil the contract, tax and accounting obligations. Basis: contract and legal obligation. Retention: 7 years.
Support correspondence
Emails, call notes and meeting summaries relating to your enquiry or account. Purpose: continuity of service and dispute evidence. Basis: legitimate interest and contract. Retention: 24 months for enquiries, contract term plus 3 years for clients.
Technical and analytics data
IP address truncated at collection, browser and device type, referring page and aggregate page views. Purpose: security, fraud prevention and improving the site. Basis: legitimate interest for strictly necessary logging, consent for any non-essential analytics. Retention: 14 months maximum.
Client operational data
Data inside your advertising, analytics, CRM and CMS accounts that we access to deliver the services. Here we act as processor, not controller, under a written data processing agreement. Retention: per your instructions, deleted or returned on termination.

How we handle it

01What we never do

We do not sell personal information, share it for cross-context behavioural advertising, disclose it to data brokers, or use your audit answers to build advertising audiences. If you decline a report at the end of the audit, we stop: no follow-up sequence, no call, no list. We do not use special category data, and we do not knowingly collect data from anyone we understand to be a child.

02Automated processing and profiling

The audit uses conditional logic to decide which questions to show and to draft an indicative recommendation, but every recommendation, decline and price is reviewed and issued by a person. No decision with legal or similarly significant effect is made solely by automated means, and no profiling is used for advertising.

03Processors and sub-processors

We use a small, documented set of processors, each bound by a data processing agreement with confidentiality, security and deletion obligations.

  • Cloud application hosting and edge delivery, for serving this website.
  • Managed database and authentication infrastructure, for storing submissions and orders.
  • Stripe, Inc., for card payment processing and subscription billing. Stripe is an independent controller for payment data and never passes us full card details.
  • Transactional email delivery, for sending reports, scopes and order confirmations.
  • Brand logo and public data providers, used only for non-personal reference material.
  • Advertising, analytics and CRM platforms you instruct us to operate on your behalf as part of the services.

04International transfers

Our infrastructure is located in the United States, so data you submit is processed there. Where personal data originates in the European Economic Area, the United Kingdom or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable, supported by a transfer risk assessment. A copy of the relevant mechanism is available on request.

05Security measures

Data is encrypted in transit with TLS and at rest by the storage provider. Access to submission and order records is limited to personnel who need it for a defined purpose, protected by unique credentials and multi-factor authentication, and logged. Row-level access controls prevent one record being read from another. We never ask for, and never store, your platform passwords or card details, and we require delegated access rather than shared credentials. Suspected personal data breaches are assessed immediately and notified to affected individuals and regulators where the law requires, normally within 72 hours of becoming aware.

06Your rights

Wherever you live, we honour the following rights.

  • Access: a copy of the personal data we hold about you, with its source and purpose.
  • Rectification: correction of anything inaccurate or incomplete.
  • Erasure: deletion of your record, subject only to tax and legal retention we must observe.
  • Restriction and objection: including an absolute right to object to direct marketing.
  • Portability: a machine-readable export of the data you provided to us.
  • Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
  • CCPA/CPRA rights: to know, delete, correct, and to opt out of sale or sharing, which we do not carry out, plus freedom from retaliation for exercising them.
  • Authorised agents: may act for you where identity and authority are verified.

07How to exercise a right

Email privacy@firstpersonmarketing.com quoting your 10 digit reference if you have one. We verify identity proportionately, act, and confirm completion in writing, normally within 5 Working Days and always within 30 calendar days (extendable once by a further 30 days for complex requests, with notice). There is no charge for a reasonable request.

08Marketing communications

We do not run an unsolicited marketing list. You receive email from us only where it relates to a report or scope you asked for, or an order you placed. Every non-transactional email carries a one-click unsubscribe, honoured immediately, and unsubscribing never affects service delivery.

09Complaints and supervisory authorities

Raise it with privacy@firstpersonmarketing.com first and a director will respond. You also have the right to complain to your local supervisory authority, including any EEA data protection authority, the UK Information Commissioner's Office, or your state attorney general in the United States. We will cooperate fully with any such enquiry.

10Changes to this policy

The version and date at the top of this page change with every revision. Where a change materially affects how your data is used, we notify affected individuals by email at least 30 days before it takes effect and, where the law requires it, ask for fresh consent.

Want your record removed right now?

Email privacy@firstpersonmarketing.com with your 10 digit reference. We delete it and confirm in writing, normally the same week. No questions, no retention argument, no exit survey.

Controller: Lanex Group, LLC, State of Delaware, United States, trading as First Person Marketing. See also the cookie policy for on-device storage and the service terms for our role as processor of client data.