Current version: 22 May 2026
Serium Digital Ltd decides why and how personal information on this website is used. For people in the United Kingdom and the European Union, Serium Digital Ltd is the controller under the UK GDPR and the EU GDPR. For people in New York, the New York SHIELD Act applies. For people in Florida, the Florida Digital Bill of Rights (FDBR) applies where its conditions are met. Those US statutes stand apart from GDPR article numbers.
Serium Digital Ltd
32 London Bridge St
London SE1 9SG
United Kingdom
+1 (212) 555-0143
hello@serium.digital
Data protection officer
Privacy questions can be sent to:
Alexander James Miller
32 London Bridge St, London SE1 9SG, United Kingdom
Email hello@serium.digital
What this notice covers
1. How much information we use
We use personal information only to run this website, answer messages, send newsletters someone asked for, and review job applications. We do not use it for unrelated purposes.
2. Legal grounds, by region
United Kingdom and European Union, consent. Where we ask you to agree, the ground is Article 6(1)(a) of the UK GDPR and the EU GDPR. Consent covers optional cookies, analytics, advertising tools, and the newsletter.
United Kingdom and European Union, contract. Where we need information to carry out a contract, or to take steps you asked for before a contract exists, the ground is Article 6(1)(b) of the UK GDPR and the EU GDPR.
United Kingdom and European Union, legitimate interests. Where we use information to keep the site secure, host it, or answer a message, and your rights do not outweigh that use, the ground is Article 6(1)(f) of the UK GDPR and the EU GDPR.
New York. The SHIELD Act requires reasonable administrative, technical, and physical safeguards for private information. The New York State Office of the Attorney General (NY OAG) oversees that duty. The SHIELD Act does not use GDPR article numbers. You can opt out of tracking and targeted marketing in your browser, or by emailing hello@serium.digital.
Florida. Where the Florida Digital Bill of Rights (FDBR) applies, you can opt out of tracking and targeted advertising. The Florida Attorney General is the relevant office. The FDBR does not use GDPR article numbers.
3. When information is deleted
We erase or restrict personal information once the reason for holding it has ended, unless a statute requires a longer period. If a contract is still open, we keep what that contract needs until the work is finished.
If you are in the United Kingdom or the European Union, you can use the rights below under the UK GDPR and the EU GDPR. Article numbers in these headings belong only to those two laws. If you are in New York or Florida, use the United States choices later on this page.
1. Access (Article 15 of the UK GDPR and the EU GDPR)
You can ask whether we hold personal information about you.
If we do, you can ask us to tell you:
Why we use it
Which kinds of information are included
Who has received it, or who is expected to receive it
How long we plan to keep it, or how that period is chosen
That you can ask for correction, deletion, a pause on use, or an objection
That you can complain to a supervisory authority
Where it came from, if we did not get it from you
Whether a decision is made only by automated means, including profiling, with a plain explanation
of the method and what it is likely to mean for you
Whether it is sent outside the UK or the EU
2. Correction (Article 16 of the UK GDPR and the EU GDPR)
If information we hold about you is wrong or incomplete, you can ask us to put it right. We will correct it without undue delay.
3. Restriction (Article 18 of the UK GDPR and the EU GDPR)
You can ask us to limit how we use your information when one of these points applies:
You dispute its accuracy, for as long as we need to check.
The use is unlawful, you do not want deletion, and you prefer a limit on use.
We no longer need it for our purpose, but you need it for a legal claim.
You have objected, and it is not yet clear whether our reasons override yours.
4. Erasure (Article 17 of the UK GDPR and the EU GDPR)
You can ask us to delete your information without delay when one of these points applies:
We no longer need it for the purpose it was collected.
You withdraw consent, and no other UK or EU ground remains.
You object and there is no overriding reason to continue, including an objection to direct marketing under Article 21 of the UK GDPR and the EU GDPR.
It has been used unlawfully.
A UK or EU legal duty requires us to delete it.
It was collected through an online service offered to a child, which Article 8 of the UK GDPR and the EU GDPR addresses.
Article 8 is a UK and EU rule. It is not a provision of the New York SHIELD Act or the Florida Digital Bill of Rights (FDBR).
Deletion can be refused where the UK GDPR or the EU GDPR still allows us to keep information, for example for freedom of expression, a legal duty, or a public-interest task. Those GDPR exceptions are not applied as article numbers under the SHIELD Act or the FDBR.
A refusal can also rest on public-health reasons recognised by the UK GDPR or the EU GDPR.
Public archiving, research, or official statistics can also justify keeping information where those UK and EU rules allow it.
We may keep information that is needed to bring, exercise, or defend a legal claim.
5. Portability (Article 20 of the UK GDPR and the EU GDPR)
You can ask for the information you provided, in a structured format a computer can read, and you can ask for it to be passed to another organisation where this right applies.
Where Article 20 applies, we will not stand in the way of that transfer.
6. Objection (Article 21 of the UK GDPR and the EU GDPR)
Where your circumstances give you a reason, you can object to use based on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR, including related profiling. That article number is not used for the SHIELD Act or the FDBR.
United States opt-out. People in New York and Florida can opt out of tracking and targeted marketing. Under the New York SHIELD Act we keep reasonable administrative, technical, and physical safeguards for private information, and the NY OAG is the oversight office. Where the Florida Digital Bill of Rights (FDBR) applies, the same opt-out is available and the Florida Attorney General is the relevant office. Use browser controls, a script blocker, or email hello@serium.digital. Marketing emails stop when you use the unsubscribe link.
7. Where to raise a concern
People in the UK can contact the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. People in the EU can contact the supervisory authority in their country. People in New York can contact the New York State Office of the Attorney General (NY OAG) about the SHIELD Act. People in Florida can contact the Florida Attorney General about the FDBR. ICO helpline
0303 123 1113. ICO website: https://www.ico.org.uk
1. What the logs contain
Each visit causes our systems to note a few technical facts about the browser that requested the page.
Those facts can include:
Browser name and version
Operating system
A limited marketing signal, only where a tag is allowed
The notes are written to server logs.
They are stored separately from details you type into a form.
2. Why logs are kept
An IP address is held for the length of the visit so the page can be returned to that browser.
Logs also show whether the site is working, help us improve it, and support the security of our systems.
3. Which law covers logs
For people in the UK and the EU, logs rest on legitimate interests in Article 6(1)(f) of the UK GDPR and the EU GDPR. For people in New York, logs support the reasonable safeguards required by the SHIELD Act. For people in Florida, they support security measures relevant to the FDBR. Those US laws are not labelled with GDPR article numbers.
4. How long logs are kept
Log data is removed once the visit no longer needs it. The session record ends when the page has been delivered.
Files in the log are deleted within seven days. If a security matter requires a longer hold, the IP address is removed or altered so it no longer identifies a device.
5. Objecting to logs
Some logging is required to deliver the site. You can still object, and we will weigh that objection against the need to keep the site available and secure.
1. What cookies do here
A cookie is a small record placed in your browser. On the first visit, and whenever you change your mind, you can allow or refuse optional cookies in the browser or in our consent choices.
Optional cookies do more than simply load the page.
Optional cookies may record:
An IP address
An approximate location
The date and time of the request
Whether an advert was tailored
Which pages were opened
A connection to a social platform
2. Why cookies are used
Optional cookies show which pages are useful and how people move through the site, so we can improve what we publish.
They may be used for measurement, advertising, or a link to a social platform. Cookies that are strictly necessary only keep the site working.
3. Which law covers cookies
For people in the UK and the EU, optional cookies rely on consent under Article 6(1)(a) of the UK GDPR and the EU GDPR. Strictly necessary cookies rely on legitimate interests under Article 6(1)(f) of those laws. For people in New York or Florida, you can opt out of tracking and targeted marketing under the SHIELD Act and the FDBR. Those US laws are not given GDPR article numbers.
1. What sign-up collects
You can join a free newsletter on the site. Whatever you enter in the sign-up field is sent to us.
The field we ask for is:
Your email address
That address is used only to send the newsletter, through Mailchimp.
2. Why the address is collected
The address is how the newsletter reaches the person who asked for it.
Any extra sign-up detail is used only to spot misuse of the form or of the address.
3. Which law covers the newsletter
For people in the UK and the EU, the newsletter relies on consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, sign-up is optional and you can leave at any time. The SHIELD Act and the FDBR do not use that GDPR article number.
4. How long newsletter details are kept
The newsletter email address stays on the list until you unsubscribe. After you leave, it is removed from the mailing list.
Other details captured at sign-up are deleted within seven days.
5. How to leave the list
You can unsubscribe at any time. Each message carries an unsubscribe link.
That link also withdraws permission for the sign-up details we stored.
1. What an email to us includes
If you write to the address published on the site, we keep the personal details contained in that message.
Those details are used only to deal with that conversation.
2. Why the message is kept
We keep the message so we can read it and send a reply.
3. Which law covers email
For people in the UK and the EU, replying to email relies on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR.
The interest is to answer the message you chose to send.
If the email is about forming a contract, Article 6(1)(b) of the UK GDPR and the EU GDPR also applies.
For people in New York and Florida, the exchange is protected with reasonable safeguards under the SHIELD Act and, where it applies, the FDBR. Those statutes are not cited as GDPR articles.
4. How long email threads are kept
We delete the thread once the matter is finished and the messages are no longer needed.
Extra technical details created when the message was sent are deleted within seven days.
5. How to object to an email record
You can withdraw an earlier permission, or object to us keeping the thread, at any time.
Email hello@serium.digital and say what you want corrected or removed.
If the thread is deleted, the contact details held for that exchange are deleted with it.
1. What the form collects
The site has a form for getting in touch. If you use it, the details you enter are sent to us and stored.
Sending the form also records:
Email address used on the form
Surname
Given name
Phone number
Time the form was sent
2. Why the form is used
We use the form fields only to reply to you. Other details recorded at send time help us stop misuse and protect our systems.
3. Which law covers the form
For people in the UK and the EU, the form relies on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR, so we can answer you. If the message is about a contract, Article 6(1)(b) of those laws also applies. For people in New York and Florida, the form is handled with reasonable safeguards under the SHIELD Act and, where it applies, the FDBR, without using GDPR article numbers.
4. How long form messages are kept
We delete the form message once the conversation is finished and we no longer need it.
Extra technical details from the send are deleted within seven days.
5. How to object to a form message
If you used the form or emailed us, you can object to us keeping those details at any time.
Email hello@serium.digital with the change or deletion you want.
We then delete the personal details stored for that contact.
A form on the site accepts job applications. If you use it, the details you enter are sent to us and stored. They are:
Salutation
Surname
Given name
Phone number
Email address on the application
CV or resume
You can also apply by email. We then keep that email address and whatever you include in the message.
After you apply, we email you to confirm the papers arrived.
We also keep an optional pool of candidates for future roles, only if you agree.
Application details are not sold onward. They are used to consider your application.
2. Why applications are reviewed
We use the application only to assess the role you applied for. An email application is kept for the same reason.
Other details recorded when the form is sent help us stop misuse and protect our systems.
3. Which law covers hiring
For people in the UK and the EU, reviewing an application you sent us relies on steps toward a contract under Article 6(1)(b) of the UK GDPR and the EU GDPR. For people in New York and Florida, application files are kept with reasonable safeguards under the SHIELD Act and, where it applies, the FDBR. Those US laws are not given GDPR article numbers.
The candidate pool is used only with your clear permission.
For people in the UK and the EU, that permission is consent under Article 6(1)(a) of the UK GDPR and the EU GDPR. People in New York or Florida can withdraw from the pool by emailing hello@serium.digital.
4. How long applications are kept
After the hiring process ends, application records, including CVs, are kept for up to three months and then deleted, unless a law forces a longer hold.
Extra technical details from sending the application are deleted within seven days.
Pages are served by Cloudflare, which also acts as the content delivery network in front of the site.
The host we use is:
Cloudflare
Cloudflare's servers record a short technical log that your browser sends when a page loads. The log can include:
Browser name and version
Operating system
A limited marketing signal, only where a tag is allowed
These hosting logs are not mixed with form answers. For people in the UK and the EU, the ground is legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR.
The interest is a site that loads correctly and stays protected. Server logs exist for that reason.
Cloudflare may handle connection data in the United Kingdom and in other places where its network runs. For people in New York and Florida, that processing is covered by reasonable safeguards under the SHIELD Act and, where it applies, the FDBR, not by a GDPR article number.
Location-based content
We may read an IP address, or a postcode you gave us, to show material that fits a region.
That can mean a regional offer or advert is more likely to match the visitor. For people in the UK and the EU, this relies on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR. For people in New York and Florida, you can opt out of this kind of targeting. The SHIELD Act and the FDBR do not use a GDPR article number for that opt-out.
Only part of the IP address, and any postcode you supplied, is used for this. We do not build a separate location file from it.
You can reduce location matching with a VPN or proxy, or by turning location features off in the browser where the browser allows it.
We use region matching for:
Regional advertising
Choosing a nearby delivery server
1. What Cloudflare receives
Cloudflare, Inc. provides the content delivery network and security layer in front of this site. A European contracting entity has been CloudFlare Germany GmbH,
Rosental 7, 80331 Munich, Germany. In this notice, Cloudflare means that service.
A content delivery network places copies of the site on servers in more than one region so pages, including large files, arrive faster. Cloudflare also filters abusive traffic. When you open a page, your browser connects to Cloudflare and Cloudflare can log the page requested, the IP address, and the browser or operating system. Cloudflare's own privacy notice is here: https://www.cloudflare.com/en-...
2. Why Cloudflare is used
Cloudflare hosts delivery of the site, shortens load times through its network, and blocks misuse.
3. Which law covers Cloudflare
For people in the UK and the EU, Cloudflare logs rest on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR, because we need the site to load reliably and stay secure. For people in New York and Florida, the same arrangement is part of reasonable safeguards under the SHIELD Act and, where it applies, the FDBR. Those US laws are not given GDPR article numbers.
4. How long Cloudflare records are kept
Information Cloudflare holds for us is kept only as long as this notice describes, or as long as a statute requires.
After that, it is deleted or anonymised under Cloudflare's retention rules and applicable law.
5. How to limit Cloudflare
Choices for objecting to Cloudflare's own use of information are described at:
https://www.cloudflare.com/en-...
Tools embedded on the site
The tools below are the ones active on this site. Each note says what the tool does, why it is there, and how you can stop it.
1. What the pixel collects
The Facebook Pixel is a tag from Meta Platforms, Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, and Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.
After someone sees or clicks a Meta advert, the pixel can record the pages opened, buttons used, device and browser details such as IP address and operating system, and whether an advert was shown or clicked. We use those events to judge whether Meta advertising is working. We do not receive a name from the pixel itself.
Meta stores the event on its side.
If you are signed in to Facebook or Instagram, Meta may connect the event to that account.
Meta may also use the event under its own terms. Meta's notice is here:
See Meta's privacy notice:
https://en-gb.facebook.com/pol...
2. Why the pixel is used
The pixel tells us which Meta adverts lead to visits, so we can judge spend and stop adverts that do not work.
3. Which law covers the pixel
For people in the UK and the EU, the pixel runs only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of this tracking and of targeted marketing. The SHIELD Act, overseen by the NY OAG, and the FDBR, overseen by the Florida Attorney General, do not use GDPR article numbers.
4. How long pixel data is kept
We keep pixel-related records only while we need them to measure advertising, and Meta keeps its copy under its own rules.
A statute, for example a tax rule, can require a longer hold.
5. How to opt out of the pixel
You can withdraw consent at any time. Withdrawal stops later use. It does not undo use that was already allowed.
Block the pixel by refusing third-party cookies, using your browser's Do Not Track setting where it exists, turning scripts off, or installing a blocker such as NoScript (https://noscript.net/) and Ghostery is here (https://www.ghostery.com). Meta's own notice is linked below.
Further opt-out detail from Meta:
https://en-gb.facebook.com/pol...
1. What GA4 collects
Google Analytics 4 (GA4) is supplied by Google LLC, 1600 Amphitheatre Parkway,
Mountain View, CA 94043, USA, and by Google Ireland Ltd., Gordon House,
Barrow Street, Dublin, Ireland. GA4 counts visits, shows which pages are opened, and records roughly how long a visit lasts, using a cookie. It can include device and browser details. Google may store that measurement in the United States. Where IP masking is on, Google shortens the IP address in the UK or the EU first.
A full IP address reaches the United States only in uncommon cases.
In those cases Google shortens it there.
Google prepares reports for us about site use. We use the reports to see what is working. We do not ask Google to merge the GA4 IP address with a named Google account for our reports.
You can refuse analytics cookies in the browser. Some site features may then be limited.
Google's privacy notice explains its own storage:
Google privacy notice:
https://policies.google.com/pr...
2. Why GA4 is used
GA4 shows where visitors come from and which pages they use, so we can improve the site.
3. Which law covers GA4
For people in the UK and the EU, GA4 runs only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of this measurement and of related targeting. The SHIELD Act and the FDBR do not use GDPR article numbers. Oversight sits with the NY OAG and the Florida Attorney General.
4. How long GA4 data is kept
We retain GA4 reports only while we need them to understand the site.
Google states that it anonymises parts of advertising logs, including portions of the IP address and cookie data, on its own timetable of about 9 and 18 months.
5. How to opt out of GA4
You can withdraw consent at any time. Later collection stops. Earlier lawful collection stays valid.
Refuse third-party cookies, use Do Not Track if your browser offers it, disable scripts, or install a blocker such as NoScript
(https://noscript.net/) or Ghostery (https://www.ghostery.com). You can also install Google's analytics opt-out add-on:
https://tools.google.com/dlpag...
Google's ad settings, where you can switch off ad personalisation:
https://adssettings.google.comMore from Google on objecting:
https://policies.google.com/pr...
1. What the Instagram tool collects
Instagram features come from Meta Platforms, Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, and Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Buttons and embeds let us show Instagram posts and link to our profile. If a page includes that embed, your browser contacts Meta and can send the IP address, the time, the page address, and browser or system details, even if you do not click the post.
If you are signed in to Instagram and you use the button, Instagram can tie the visit to your profile. Sign out of Instagram before you open the page if you want to avoid that link.
Instagram's notice:
https://help.instagram.com/519...
2. Why Instagram is embedded
The embed shows selected Instagram posts on our pages and offers a route to our profile.
3. Which law covers Instagram
For people in the UK and the EU, Instagram embeds run only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of this embed and of related targeting. The SHIELD Act and the FDBR do not use GDPR article numbers.
4. How long Instagram data is kept
We do not keep a separate copy of Instagram's log. Meta keeps what its embed collects under Meta's rules.
A statute can require us to keep our own related records for longer, for example for tax.
5. How to opt out of Instagram embeds
You can withdraw consent at any time. Later loads of the embed stop if you refuse the tool. Earlier lawful use remains valid.
Refuse third-party cookies, use Do Not Track where the browser has it, disable scripts, or add a blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com). Instagram's notice is below.
Instagram opt-out and privacy detail:
https://help.instagram.com/519...
1. What LinkedIn receives
LinkedIn features are provided by LinkedIn Ireland Unlimited Company, Wilton Place,
Dublin 2, Ireland. Opening a page that includes a LinkedIn feature contacts LinkedIn, which learns the IP address and that the page was requested. If you are signed in and use a LinkedIn button, LinkedIn can attach the visit to your account, including pages viewed and device details. We do not see the contents of LinkedIn's own file. LinkedIn's notice:
https://www.linkedin.com/legal...
2. Why LinkedIn is used
The feature lets visitors open our LinkedIn page from this site. Loading it can send LinkedIn the page address and device details such as the IP address.
3. Which law covers LinkedIn
For people in the UK and the EU, LinkedIn features run only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of this feature and of related targeting. The SHIELD Act and the FDBR do not use GDPR article numbers.
4. How long LinkedIn data is kept
LinkedIn keeps what its feature collects under LinkedIn's rules. We keep only what we need for the purpose in this notice, or for a statutory period such as tax.
5. How to opt out of LinkedIn
You can withdraw consent at any time. Later use stops. Earlier lawful use remains valid.
Refuse third-party cookies, use Do Not Track if available, disable scripts, or install a blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com). Signing out of LinkedIn before you open the page also stops the visit being tied to your account.
LinkedIn guest controls:
https://www.linkedin.com/psett...
LinkedIn's privacy notice:
https://www.linkedin.com/legal...
1. What Mailchimp stores
Newsletter email is sent with Mailchimp, operated by The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318, USA. If you subscribe, the address you enter is passed to Mailchimp and stored there. Mailchimp can also see whether a message was delivered, opened, or unsubscribed, plus device and browser details such as IP address.
Mailchimp holds that list so the newsletter can be sent. We do not authorise Mailchimp to sell the list. Mailchimp sends a confirmation email after sign-up and provides counts of sends, bounces, and unsubscribes.
Mailchimp's notice:
https://MailChimp.com/legal/pr...
2. Why Mailchimp is used
Mailchimp is the tool that delivers the newsletter and related email updates to people who subscribed.
We may also email subscribers if the list itself changes, for example if the sending setup changes.
3. Which law covers Mailchimp
For people in the UK and the EU, Mailchimp is used with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, the list is optional and you can opt out of these marketing emails. The SHIELD Act and the FDBR do not use GDPR article numbers.
4. How long Mailchimp keeps the address
The address stays in Mailchimp until you unsubscribe or ask for deletion. A statute can require a longer hold. You can also ask Mailchimp to delete its copy.
5. How to opt out of Mailchimp
You can withdraw consent at any time. Later sends stop. Earlier lawful sends remain valid.
Use the unsubscribe link in any newsletter, or email hello@serium.digital. Mailchimp's notice:
https://MailChimp.com/legal/pr...
1. What a YouTube embed collects
Video embeds use YouTube, provided by Google through YouTube LLC, 901 Cherry Ave, San Bruno, CA 94066, USA, and Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Playing or loading a video contacts YouTube. YouTube can receive the page, device details, and IP address. If you are signed in to YouTube, the visit can be linked to that account. We do not control YouTube's player.
Google's privacy notice:
https://policies.google.com/pr...
2. Why YouTube is embedded
YouTube is how we place videos on a page. Starting a video can send device and viewing data to YouTube, as Google's notice describes.
3. Which law covers YouTube
For people in the UK and the EU, YouTube embeds run only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of the embed and of related targeting. The SHIELD Act and the FDBR do not use GDPR article numbers.
4. How long YouTube data is kept
YouTube keeps player data under Google's rules. We keep our own related records only as long as this notice or a statute requires.
5. How to opt out of YouTube
You can withdraw consent at any time. If you refuse the embed, later videos do not load from YouTube. Earlier lawful use remains valid.
Refuse third-party cookies, use Do Not Track if your browser offers it, or disable scripts. You can also install a blocker such as NoScript or Ghostery.
NoScript is here (https://noscript.net/) or Ghostery (Ghostery). Google ad settings:
https://adssettings.google.com
Google's privacy notice:
https://policies.google.com/privacy?hl=en-GB
1. What Tag Manager does
Google Tag Manager, from Google LLC (https://marketingplatform.goog...), loads other tags. The provider is Google LLC,
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and Google Ireland Ltd., Gordon House, Barrow Street, Dublin, Ireland. Tag Manager ships a small configuration to the browser that says which tags may fire, including Google Analytics 4 and marketing pixels. The tags it launches can collect data. Tag Manager is the switchboard, not the analytics store.
What each tag collects is described in that tag's section above. Tag Manager is not our analytics database.
Google's Tag Manager page and privacy notice: https://marketingplatform.goog... and see Google's privacy policy: https://policies.google.com/pr...
2. Why Tag Manager is used
Tag Manager lets us turn GA4 and marketing tags on or off in one place, instead of pasting each tag separately.
3. Which law covers Tag Manager
For people in the UK and the EU, Tag Manager and the optional tags it fires run only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of the tags it would launch, including tracking and targeted marketing. The SHIELD Act and the FDBR do not use GDPR article numbers.
4. How long Tag Manager data is kept
Tag Manager itself is used to organise tags. Records created by a tag it launches follow that tag's retention, including Google's statement that parts of advertising logs are anonymised after about 9 and 18 months.
5. How to opt out of Tag Manager
You can withdraw consent at any time. Optional tags then should not fire. Earlier lawful use remains valid.
Refuse third-party cookies, use Do Not Track if available, disable scripts, or install a blocker such as NoScript
(https://noscript.net/) or Ghostery (https://www.ghostery.com). Google's analytics opt-out add-on:
https://tools.google.com/dlpag...
Google ad settings:
Google's privacy notice:
https://policies.google.com/pr...
1. What retargeting collects
Facebook Retargeting is an advertising feature from Meta Platforms, Inc. and Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. It is used to show a Meta advert to someone who already visited this site, for example after viewing a page and leaving. Meta places a cookie on the device for that purpose.
Meta can process:
Actions on the site
The page that was opened
Items that were shown
Adverts that were clicked
Device type and IP address
A Meta account, if the person is signed in
Meta processes this on servers of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California
94025, USA. Meta's notice:
https://www.facebook.com/priva...
2. Why retargeting is used
Retargeting shows Meta adverts to people who have already been on this site, and it shows us whether those adverts were used.
3. Which law covers retargeting
For people in the UK and the EU, retargeting runs only with consent under Article 6(1)(a) of the UK GDPR and the EU GDPR.
For people in New York and Florida, you can opt out of this targeted marketing. The SHIELD Act, overseen by the NY OAG, and the FDBR, overseen by the Florida Attorney General, do not use GDPR article numbers.
4. How long retargeting data is kept
We keep our own campaign reports only as long as we need them to measure advertising, or as long as a statute such as a tax rule requires. Meta keeps its copy under Meta's rules.
5. How to opt out of retargeting
You can withdraw consent at any time. Later retargeting stops. Earlier lawful use remains valid.
Refuse third-party cookies, use Do Not Track where the browser offers it, disable scripts, or install a blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com).
Signed-in Meta users can also turn off personalised adverts here:
https://www.facebook.com/setti...
Meta's notice on this feature: