Who we are
FAMYSYS is responsible for the personal data described in this policy. If you want to ask about anything here, or to exercise one of the rights set out below, write to the address shown with this document and say what you need.
What this policy covers
It covers this website and the enquiry form on it. It also covers the administration area used by our own staff to run the site.
It does not cover personal data we process on behalf of a client during an engagement. There we act on the client's instructions under the data protection terms of that engagement's contract, and the client's own privacy notice applies.
What we collect when you send an enquiry
The contact form asks for what a first conversation would have to establish anyway:
- your first and last name
- your work email address
- your company, and its website if you give one
- your role, and the size of your organisation
- the brief — what you told us you are trying to do
Everything in that list is what you chose to type. We do not ask for a budget, and we do not ask for anything about your customers or your staff. Please do not send us information about other people through this form.
What we collect automatically
Stored alongside an enquiry, and used to spot abuse of the form and to make sense of a submission that arrived twice:
- the IP address the submission came from
- the browser user-agent string it sent
- the date and time it arrived
Our servers also keep ordinary operational logs of requests. Signing in to the administration area records the attempt and, once signed in, the actions taken — that record exists so a change to the site can be traced to the person who made it.
We do not run analytics, advertising, tracking pixels or social media embeds on this website. The typeface is served from this site rather than from a font network, so simply reading a page does not send a request to a third party.
Why we hold it
We hold enquiry data because you asked us to get in touch and because we have a legitimate interest in responding to business enquiries and keeping a record of the work we were asked about. We hold technical and sign-in records because we have a legitimate interest in keeping the site secure and accountable.
Where the law that applies to you requires consent for something, we ask for it rather than assuming it.
How long we keep it
- Enquiries: 24 months. After that the identifying fields — name, email, company, website, the brief, the IP address and the user-agent string — are overwritten, and what remains is the fact that an enquiry arrived, when, and how it was handled. We redact rather than delete so the commercial record survives without the personal data in it.
- Sign-in sessions and password-reset tokens: 7 days past expiry.
- Failed sign-in attempts: 90 days, as the record of attacks on the site.
- The administrative audit trail: kept, because it is the evidence of who changed what.
If we are replying to you, or if there is a live commercial conversation, the enquiry stays until that conversation is over and then runs out its window.
Who else can see it
Nobody buys this data from us and nobody is sent it for marketing. It is seen by:
- our own staff, where their role requires it
- the providers that host this site and run our systems
- the email service we use to reply to you
- a professional adviser, a regulator or a court, where we are legally required to disclose it
Where it is handled
We work across the United States and India, so an enquiry may be read by colleagues in either country and is stored on infrastructure we operate or rent. Where personal data moves between countries, we rely on the safeguards the applicable law provides for such transfers.
Your rights
Depending on where you live, you can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything that is wrong
- delete what we hold, where we have no overriding reason to keep it
- stop or limit what we do with it, including objecting to our legitimate interests
- withdraw consent, where the processing rests on consent
Write to the address shown with this document. We will respond within 30 days, and we will tell you if we need longer and why. If you are not satisfied with our answer, you can complain to the data protection authority where you live.
Security
Traffic to this site is encrypted in transit. Administrative access needs a named account with a password stored only as a modern one-way hash, sign-in attempts are rate-limited and locked out after repeated failures, and every change made through the administration area is recorded against the account that made it. Access to enquiry data is limited to the roles that need it.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data and the law requires us to tell you, we will.
Children
This site is aimed at businesses. It is not directed at children, and we do not knowingly collect personal data from them.
Changes to this policy
We update this policy when what we do with personal data changes. The version on this page is the one that applies, and its effective date is shown with it. Where a change is significant, we will say so on the page rather than expecting you to compare two versions.
How to contact us
Questions, requests and complaints about this policy go to the address shown with this document.