01 Who is responsible
Chris Wells, trading as lowob, Los Angeles, California, is the controller of the personal data described here. lowob is not yet incorporated; when it is, this policy will name the entity, and the commitments below carry over unchanged. For people in the EU, UK or Switzerland, the same entity is responsible; we work from Lisbon as well as Los Angeles and New York, and your data may be handled in any of them. Contact for anything in this policy: chris@lowob.com.
02 What we collect, and where it comes from
The brief. When you send one from Contact we receive your name, email address, company, the problem you chose, the budget band you chose, and whatever you write in the box. We keep it so we can reply and, if it becomes an engagement, so we have the starting point.
Research subscription. Your email address, the date you subscribed, and whether each piece was opened, which the email provider reports to us.
Site usage. Pages viewed, the page you came from, approximate location from your IP address, browser and device type. Collected by a privacy-focused analytics tool in aggregate; we do not use it to identify you.
Correspondence. Email you send us, and notes from calls, kept as part of the record of a conversation or an engagement.
We do not buy data about you, and we do not collect payment card details on the site; engagements are invoiced.
03 Why we use it, and on what basis
To reply to your brief and hold the conversation it starts (our legitimate interest in running the business, and the steps toward a contract with you). To send Research to people who asked for it (your consent, which you can withdraw with the unsubscribe link in any email). To understand which pages are read and keep the site working (our legitimate interest, using aggregate data). To meet legal, accounting and tax obligations (legal obligation). We do not use your data for automated decisions that have a legal or similarly significant effect on you.
04 Who sees it
The people at lowob who need it to reply to you or do the work. Specialists we bring into an engagement, under confidentiality, only for that engagement. Service providers who process it on our instructions: the form processor that delivers the brief, the email provider that sends Research, the analytics provider, our email and document hosting, and our accountants and lawyers. Authorities where the law requires. The company lowob becomes when it incorporates, and a buyer of the business if lowob is ever sold, under the same commitments.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. Media partners we coordinate for a client never receive data about visitors to this site.
05 Cookies
The site sets no advertising or tracking cookies. Analytics runs without cookies or with a single first-party cookie that expires when you close the browser, depending on the provider in use. The Research subscription form and the brief form set nothing beyond what is needed to submit them. Because there is nothing to opt into, there is no cookie banner; if that changes, a banner will appear and the default will be off.
06 Where it goes
Data is stored in the United States and, for the team in Lisbon, accessed from the EU. Where data about people in the EU, UK or Switzerland is transferred to the US, we rely on the European Commission's standard contractual clauses (and the UK addendum) with each provider, or on that provider's certification under the EU-US Data Privacy Framework. A copy of the clauses is available on request.
07 How long we keep it
A brief that does not become an engagement: twenty-four months from our last exchange, then deleted. A brief that does: for the life of the engagement and seven years after, as part of the business record. Research subscription: until you unsubscribe, then thirty days. Aggregate analytics: twenty-six months. Email and call notes: as long as the conversation or engagement they belong to.
08 Your rights
Wherever you are, you can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, ask for a copy in a usable format, object to our using it on the basis of legitimate interest, and withdraw consent where consent is the basis. Write to chris@lowob.com; we answer within thirty days, or forty-five where California law applies, and we will not treat you differently for asking.
California. The rights above are the rights under the CCPA as amended by the CPRA, including the right to know, to delete, to correct, and to limit the use of sensitive personal information (we collect none). You may use an authorised agent. We do not sell or share personal information, so there is nothing to opt out of.
EU, UK and Switzerland. You may also complain to your local supervisory authority. For Portugal that is the CNPD; for the UK, the ICO.
09 Security
Data is held with providers that encrypt it in transit and at rest, behind accounts with two-factor authentication, and is accessible only to the people named in section 04. No system is perfectly secure; if a breach affects your data we will tell you and the relevant authority as the law requires.
10 Children
The site is for businesses. We do not knowingly collect data from anyone under eighteen, and we delete it if we learn we have.
11 Changes
When this policy changes, the date at the top changes with it, and if the change matters to how we use data you already gave us, we email you first. Questions go to chris@lowob.com.