Privacy
Privacy policy.
Last updated: 18 July 2026.
This policy explains how I handle personal data when you visit patrickrobinson.consulting, make an enquiry, receive relevant business-to-business outreach, or buy a Citation Audit or Citation Engine scope.
1. Who is responsible for your data
The data controller is Patrick Robinson, trading as Patrick Robinson Consulting, a sole trader in the United Kingdom.
Patrick Robinson66 Paul Street
London
EC2A 4NA
United Kingdom
Contact for this policy, including data-rights requests, is through the contact form or by post to the address above.
2. Personal data I collect
Website use: Cloudflare may process technical request data needed to deliver and secure the site, such as an IP address, browser information, timestamps, and requested pages. Cloudflare Web Analytics provides aggregated, cookie-free usage measurements. I do not place advertising pixels on the site.
Enquiries and correspondence: your name, email address, role, company, message, attachments, contact preferences, and the history of our correspondence.
Report and update requests: if you ask for a tool result by email or sign up for updates, I collect your email address, the request source, and any website domain you submitted, so I can send what you asked for.
Business prospects: a professional name, role, company, company domain, business email address, public professional profile, source and verification details, relevant business signal, outreach history, reply status, and opt-out status.
Clients and transactions: your name, role, business, contact details, billing address, written scope and acceptance, invoices, payment status and references, tax information you provide, support history, and access or approval records needed for the service. Stripe handles payment-card data. I do not receive or store your full card number.
Audit and implementation records: agreed company and competitor names, public buyer-intent queries, dates, AI-answer responses, cited public URLs, source classifications, measurement metadata, findings, deliverables, and re-measurement history. Public sources and answers can contain publicly available individual names. The standard Audit does not require your customer or CRM data.
3. Where the data comes from
I receive data directly from you, your business, your colleagues, and the services you choose to use with me. For carefully targeted B2B outreach, I may obtain professional information from company websites, public professional profiles, public funding or business announcements, and business-data or verification providers such as Apollo or Deepline. Audit evidence comes from public websites, DataForSEO, and the AI-answer services covered by the accepted measurement scope.
4. Why I use personal data and the legal bases
I use personal data for the following purposes:
- To answer an enquiry, prepare a scope, and take steps you request before a contract. The basis is steps before entering a contract and my legitimate interest in responding to genuine business enquiries.
- To accept payment, deliver an agreed service, provide support, and administer the relationship. The basis is performance of our contract.
- To keep invoices, tax records, acceptance evidence, and records required by law. The basis is compliance with a legal obligation and, where applicable, my legitimate interest in establishing or defending legal claims.
- To run, secure, measure, troubleshoot, and improve the website and service. The basis is my legitimate interest in operating a secure and effective business.
- To research a small number of relevant corporate prospects and send proportionate B2B messages about the Citation Audit. The basis is my legitimate interest in developing the business, balanced against the recipient's rights and expectations, and only where electronic-marketing law permits it.
- To send optional updates where I have specifically asked for and received consent. You can withdraw that consent at any time.
I do not sell personal data or use it for third-party advertising.
5. B2B outreach and your right to object
Targeted outreach is directed to relevant people at corporate subscribers where I have a lawful basis and the message is connected to their professional role. I identify myself, explain why the message may be relevant, and provide a working opt-out route. I do not use this approach for sole traders or other individual subscribers where consent is required by electronic-marketing law.
You can object to direct marketing at any time by replying to the message or using the contact form. I will stop the marketing and may retain only the minimum suppression record needed to respect your choice.
6. Who receives personal data
I use service providers only where they are needed for the relevant activity. Depending on the route and accepted scope, recipients may include:
- Cloudflare for website hosting, security, and cookie-free analytics;
- Paperform for the website enquiry form;
- Google Workspace for business email, files, and working documents;
- Stripe for private invoicing and payment processing;
- Supabase and Airtable for prospect, engagement, Audit, and evidence records;
- Railway for the authenticated hosted scan runtime when that route is used;
- DataForSEO and the AI-answer services covered by the scan, which may include OpenAI, Anthropic, Google, and Perplexity, for public-query measurement;
- Gamma, when used, for generating a draft client deliverable from the agreed findings;
- Google NotebookLM, when used, for assembling a prospect or client deliverable from agreed source material;
- YouTube, when an unlisted prospect or client video is used; and
- business-data and verification providers, including Apollo and Deepline when used, for professional contact research and verification.
I also use secured local devices and backups. I disclose data to professional advisers, regulators, courts, law-enforcement bodies, or another party where the law requires it or where reasonably necessary to establish, exercise, or defend legal rights. Providers may act as processors or as separate controllers for parts of their service under their own privacy terms.
7. International transfers
Some providers process data outside the United Kingdom. Where UK data protection law restricts that transfer, I use an applicable UK adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with any required data-protection risk assessment. You can ask for more information about the safeguard used for your data.
8. How long I keep data
- Enquiries and prospect records that do not become an engagement are normally kept for up to 12 months after the last substantive activity.
- A minimal suppression record may be kept for as long as needed to make sure I do not contact someone who has opted out.
- Accepted scopes, acceptance evidence, invoices, payment references, and core client correspondence are normally kept for seven years after the engagement ends for tax, accounting, dispute, and legal-claims purposes.
- Audit evidence and delivered findings are normally kept for up to 24 months after delivery so that the result can be checked and any agreed re-measurement can be compared.
- Client source material and access records are kept only for the accepted scope and are normally deleted, returned, or revoked within 30 days after that scope ends.
I may keep a record longer where a legal hold, dispute, security incident, or different written requirement applies. Provider backups and security logs are removed on their own managed cycles. At the end of the applicable period, I delete or irreversibly anonymise the record where practical.
9. Security
I use reasonable technical and organisational measures to protect personal data. These include access controls, multi-factor authentication where available, limited access, secured devices, and using Stripe rather than storing full payment-card details. No internet or storage system is completely secure, but I review the controls in proportion to the data and risk.
10. Your rights
Depending on the circumstances, UK data protection law may give you the right to access, correct, erase, restrict, or receive your personal data, to object to processing, and to withdraw consent. The right to object to direct marketing is absolute. Other rights can have legal limits or exceptions.
To exercise a right, use the contact form or write to the address above. I may need enough information to confirm your identity. There is normally no fee, and I will respond within the period required by law.
You can complain to the UK Information Commissioner's Office. Details are available at ico.org.uk. I would appreciate the chance to address the issue first, but you do not have to contact me before approaching the ICO.
11. Automated decisions and children
I do not use personal data to make solely automated decisions that have legal or similarly significant effects. The site and services are for businesses and are not directed at children. I do not knowingly collect children's data.
12. Cookies and external services
This site does not set tracking or advertising cookies. Cloudflare Web Analytics is configured as a cookie-free service. A service embedded in or opened from this site, such as Paperform, Stripe, YouTube, or another external service, may use its own cookies under its own notice.
13. Client data processed on your behalf
The standard Audit uses public-query evidence and does not require customer or CRM data. If an accepted service would require me to process personal data only on a client's instructions, the client and I will put the legally required processor terms in place before that processing begins.
14. Changes and contact
I may update this policy when the service, providers, or law changes. The current version is published here with its update date. If a change materially affects an active client relationship, I will provide a proportionate notice.
Questions or privacy requests can be sent through the contact form or by post to the address above.