Skip to content
Feedback.

Legal

Privacy policy

This policy explains what happens to personal data when you visit this website, when you write to us, and when you take part in research we run. It is written to be read, not to be survived.

Last updated 26 August 2026

The short version

  • This site sets no cookies, runs no analytics, and loads no third-party scripts, fonts or pixels.
  • The contact form never sends anything to us — it opens a message in your own mail application.
  • We hold only what you deliberately send us, plus the technical logs our host keeps.
  • We do not sell personal data and never share it for advertising.
01

Who is responsible

Feedback Agency (TODO: registered legal name, company number and registered address) operates feedback-agency.com and is the controller of the personal data described in this policy.

For anything in this document — including any request to exercise the rights set out below — write to [email protected]. A named person reads that inbox; it is not a ticketing queue.

TODO: if you are established outside the EEA but offer services to people in it, you must appoint a representative under GDPR Art. 27 (and, separately, under UK GDPR Art. 27) and name them here.

02

What this website collects

Nothing that identifies you. Specifically:

  • No cookies are set — first-party or third-party.
  • No analytics, heatmaps, session recording or advertising scripts run on any page.
  • Nothing is written to localStorage, sessionStorage or IndexedDB.
  • Fonts, images and diagrams are served from our own origin, so no other company is told that you were here.

Because we set no cookies and carry out no tracking, no consent banner is required of us under the ePrivacy Directive or the GDPR. The absence of a banner is the point, not an oversight.

03

Server logs

Our hosting provider (TODO: name the provider, e.g. Vercel, Hetzner, AWS) records standard technical logs when a page is requested: IP address, timestamp, the URL requested, HTTP status, referrer and user-agent string. These exist to keep the site available and to investigate abuse.

Legal basis: our legitimate interest in the security and reliability of our own systems (GDPR Art. 6(1)(f)). Retention: TODO — state the provider's actual log retention, commonly between 7 and 30 days.

04

The contact form

The form on the home page does not submit anything to this website. When you press send, your browser assembles what you typed into a draft message and hands it to your own email application. No request reaches our servers, nothing is stored in your browser, and you stay in control of the message until you send it yourself.

This is why the form works with no backend, no database and no third-party form service — and why there is nothing here for us to lose.

05

When you write to us

Once you send that message, we hold what it contains: your name, your email address, your company, and whatever you chose to tell us about your service and the decision in front of you. We use it to reply, to scope the work, and — if we go ahead — to run the engagement.

Legal basis: taking steps at your request prior to entering into a contract (GDPR Art. 6(1)(b)), and our legitimate interest in responding to business enquiries (Art. 6(1)(f)).

Retention: enquiries that do not become projects are deleted after TODO (12 months is a defensible default). Correspondence with clients is kept for the term of the engagement plus the period required by the applicable limitation and tax rules — TODO: state the period for your jurisdiction.

06

If you took part in our research

This section is for research participants and mystery shoppers, not for prospective clients.

Your data is handled under the consent notice you were given before the session, which takes precedence over this page. In most engagements our client is the controller of that data and we act as their processor, on documented instructions and under a data processing agreement.

  • Participation is voluntary, and declining costs you nothing.
  • Recordings and transcripts are made only where you gave explicit, informed consent.
  • Findings are reported by theme. Verbatim quotes are pseudonymised unless you agreed otherwise in writing.
  • You may withdraw consent at any time, and we will delete your recording and transcript — this does not affect the lawfulness of processing before you withdrew.

To withdraw consent or ask what we hold, write to [email protected]. If our client is the controller, we will pass your request to them and tell you who they are.

07

Who else sees the data

We do not sell personal data. We do not share it for advertising, and we do not disclose it for cross-context behavioural advertising.

We do rely on a small number of processors, each bound by a data processing agreement and permitted to act only on our instructions:

  • Hosting and content delivery — TODO: name the provider.
  • Email and calendar — TODO: name the provider.
  • Transcription and recording storage — TODO: name the provider, and say whether recordings are used to train its models. If they are, change provider.
  • Payments and accounting — TODO: name the provider.

We will also disclose data where we are legally required to, and we will tell you when that happens unless the law forbids it.

08

International transfers

We operate from TODO: name the country. Where a processor listed above is outside the EEA or the UK, the transfer relies on an adequacy decision, or on the European Commission's Standard Contractual Clauses together with a transfer risk assessment (and the UK Addendum where UK data is involved). A copy of the safeguards is available on request.

09

Your rights in the EEA, the UK and Switzerland

Under the GDPR and UK GDPR you may ask us to:

  • confirm whether we hold data about you, and give you a copy (Art. 15);
  • correct anything inaccurate or incomplete (Art. 16);
  • erase it (Art. 17);
  • restrict how we use it while a dispute is resolved (Art. 18);
  • hand it over in a portable, machine-readable form (Art. 20);
  • stop processing carried out on the basis of legitimate interest (Art. 21);
  • withdraw consent, where consent was the basis, at any time (Art. 7(3)).

We answer within one month and there is no charge. We may ask you to confirm your identity before we act, and only for that purpose.

If our answer does not satisfy you, you may complain to your national supervisory authority. TODO: name your own lead supervisory authority and link it — for example the Irish DPC, the Dutch AP, or the UK ICO.

10

Your rights in the United States

If you are a resident of California, Colorado, Connecticut, Virginia, Texas or another state with a comprehensive privacy law, you have the right to know what personal information we have collected, to obtain a copy, to have it corrected or deleted, to opt out of its sale or of targeted advertising, and to be free from discrimination for exercising any of these rights.

We have not sold or shared personal information, as those terms are defined by the CCPA as amended by the CPRA, in the preceding twelve months, and we do not process sensitive personal information for the purpose of inferring characteristics about you. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link on this site.

Categories of personal information we collect are limited to identifiers and professional information you send us, plus internet activity in the server logs described above. We keep them for the periods stated in this policy.

To exercise any of these rights, write to [email protected]. An authorised agent may act for you on proof of authorisation. If we refuse a request, you may appeal by replying to our decision, and we will respond in writing with our reasons.

11

Security

Traffic to this site is encrypted in transit. Research recordings and transcripts are held in encrypted storage with access limited to the people working on that engagement. Access is reviewed when someone joins or leaves a project.

No system is perfect. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and tell you directly where the risk is high.

12

Children

This site and our services are directed at businesses, not at children. We do not knowingly collect personal data from anyone under 16, and we do not recruit minors as research participants. If you believe a child has sent us data, write to us and we will delete it.

13

Changes to this policy

When this policy changes we replace the text on this page and update the date at the top. Where a change materially affects how we handle data we already hold, we tell active clients and affected participants directly rather than relying on you to re-read the page.

TODO: this text is a working draft prepared for your review, not legal advice. Fill in every TODO above and have counsel in your operating jurisdictions check it before launch.