Effective date: December 14, 2024
1. Introduction
At duo&co, we value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you interact with our website or services. It also outlines your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.
By using our website or services, you agree to the practices described in this policy.
2. Who we are
- Business Name: RMJV Consulting OÜ
- Location: Tallinn, Estonia
- Contact email for data inquiries: privacy@duoand.co
- Data protection contact person: Swann Vichot, co-founder
3. What data we collect
We may collect the following types of personal data:
- Identity data: Name, phone number, job title, company, location.
- Contact data: privacy@duoand.co
- Technical Data: IP address, browser type, and version (via cookies).
- Usage data: Information on how you use our website, gathered via analytics tools.
- Marketing preferences: Consent for receiving direct and marketing communications
We do not collect payment data directly, as our website does not process payments..
4. How we collect your data
- Direct interactions: Through form submissions for inquiries or sign-ups.
- Automated technologies: Cookies and similar tracking technologies (Google Analytics, Hotjar).
- Third-party sources: Integrated tools like GTM, Webflow, and MailerLite.
5. Why we collect your data
We process your personal data for the following purposes:
- To provide our services (marketing services, events, and coaching).
- To manage client relationships and respond to inquiries.
- To analyze website performance and improve user experience.
- To send marketing communications (only with your explicit consent).
6. Legal basis for processing data
We process your data under the following lawful bases:
- Consent: When you opt-in to cookies or marketing communications.
- Contract: When data processing is necessary to fulfill a contract with you.
- Legitimate interests: For website analytics and customer relationship management.
- Legal obligations: To comply with applicable laws and regulations.
7. Data retention
We retain personal data for no longer than 6 months unless:
- Required by law.
- Necessary for ongoing contractual obligations or legitimate interests.
After this period, data is securely deleted or anonymized.
8. Sharing your data
We may share your data in the following situations:
- Partners from “the collective”: When required to fulfill contracts.
- Third-party tools and providers: Such as Google Workspace, Google Analytics, GTM, Webflow, Notion, Typeform, and Hotjar, for operational purposes.
Some data may be transferred outside the EU to non-EU-based partners or US-based tools like Google. We ensure such transfers comply with GDPR through mechanisms like Standard Contractual Clauses (SCCs) or similar safeguards.
9. Your rights under GDPR
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectify: Correct inaccurate or incomplete data.
- Delete: Request the deletion of your data where legally permissible.
- Restrict processing: Limit the way we use your data.
- Object: Oppose certain data uses, such as for direct marketing.
- Portability: Request your data in a structured, machine-readable format.
- Withdraw consent: At any time, for cookies or marketing communications.
To exercise these rights, contact us at privacy@duoand.co.
10. Cookies and tracking technologies
We use cookies for the following purposes:
- Essential cookies: To ensure website functionality.
- Analytics cookies: To analyze site performance and improve user experience.
- Marketing cookies: To deliver relevant ads and track marketing performance.
You can manage cookie preferences via our Axeptio cookie consent tool, which allows you to accept, reject, or customize cookies.
11. Security measures
We take the following measures to protect your data:
- Encryption: SSL encryption to secure data transmission.
- Access controls: Restricted access to personal data.
- Data minimization: Collecting only the data necessary for specific purposes.
12. Marketing communications
We send marketing emails and newsletters only to users who have explicitly opted in.
- Opt-in methods: Form submissions and/or checkbox consent.
- Opt-out methods: Unsubscribe link in all marketing emails.
13. Data breach notification
In the event of a data breach:
- We will notify affected individuals and the relevant supervisory authority within 72 hours, as required by GDPR.
14. Updates to this policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Please revisit this page to stay informed.
15. Contact information
For any questions, concerns, or to exercise your rights, contact us at: privacy@duoand.co