Privacy Policy
1. Data Controller
Originate, trading as 5 Pillar Fundamentals, is the data controller responsible for your personal data collected through this website.
Contact: privacy@weareoriginate.com
2. What Data We Collect
When you use our website audit service, we collect:
- Website URL you submit for auditing
- Email address
- Phone number
- Event reference code (optional, if provided via QR code)
- IP address
- Timestamp of your consent
3. Purpose of Processing
We process your personal data for the following purposes:
- Delivering the website audit service you requested
- Sending audit confirmation and results to you by email
4. Legal Basis for Processing
We rely on the following lawful bases under UK GDPR:
- Consent (Article 6(1)(a)) -- You explicitly consent via the form checkbox to receive email communications containing your audit results.
- Legitimate interest (Article 6(1)(f)) -- Processing your website URL and contact details is necessary to deliver the audit service you requested.
5. Data Retention
We retain your audit data for 12 months from the date of submission. After this period, your data is automatically deleted from our systems.
You may request earlier deletion at any time by contacting privacy@weareoriginate.com.
6. Third-Party Recipients
Your data may be shared with the following third-party service providers who act as data processors on our behalf:
- Resend -- Email delivery service (US-based, operating under EU Standard Contractual Clauses)
- Neon -- Database hosting (US-based, SOC 2 compliant)
- Vercel -- Website hosting and serverless infrastructure (US-based)
7. International Transfers
Your personal data is processed in the United States by our third-party service providers (Resend, Neon, and Vercel). These transfers are safeguarded by Standard Contractual Clauses approved by the UK Information Commissioner and/or relevant adequacy decisions.
8. Your Rights
Under UK GDPR, you have the right to:
- Access -- Request a copy of your personal data
- Rectification -- Request correction of inaccurate data
- Erasure -- Request deletion of your data
- Restriction -- Request that we limit processing of your data
- Portability -- Request your data in a machine-readable format
- Objection -- Object to processing based on legitimate interest
To exercise any of these rights, contact privacy@weareoriginate.com. We will respond within one month.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
This website uses essential cookies only. We do not use analytics, tracking, or advertising cookies. Your cookie consent preference is stored in your browser's localStorage and is not transmitted to our servers.
10. Changes to This Policy
This policy was last updated on 1 February 2026. We may update this policy from time to time. Material changes will be communicated via a notice on this website. We encourage you to review this page periodically.
11. No Automated Decision-Making
We do not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects. Website audit scores are generated from publicly available technical data about your website and do not involve profiling of individuals.