Privacy Notice
Privacy Notice
Last updated: [DATE OF PUBLICATION]
This is what happens to your information when you use this site. It is short because the site does very little.
1. Who is responsible
Hyper Viral LLC, trading as Totomoko (“Totomoko”, “we”), is the data controller for the information described here. Write to us at [CONTACT ADDRESS] about anything on this page.
2. What we collect, and why
| What | When | Why | Lawful basis |
|---|---|---|---|
| Your name, email address, and anything you type into the booking form | When you book a discovery conversation | To hold the conversation you asked for and to reply to you | Steps taken at your request before entering a contract |
| Your email address and the content of your message | When you email us | To answer you | Our legitimate interest in responding to people who contact us |
| Your name, role, organisation, and notes about the conversation | If we talk about working together | To keep track of a live conversation and follow it up | Our legitimate interest in pursuing a business enquiry |
| Standard server and security logs — IP address, browser, page requested, time | Whenever anyone loads a page | To serve the page and to keep the site up and unabused | Our legitimate interest in operating a secure site |
That is the whole list.
3. What we do not do
Stated positively, because the absences are the point:
- No analytics. We do not run Google Analytics or any other analytics product. We do not know how many people read this page.
- No advertising or tracking pixels. None. Not ours, not anyone’s.
- No non-essential cookies, and so no cookie banner. The site sets nothing that needs your consent, which is why you were not asked for any.
- No profiling, no automated decision-making that has any effect on you.
- We do not sell your information, and we do not share it for anyone else’s marketing. There is no arrangement under which we could.
- We do not put anything you send us into an AI model’s training data, and we do not opt into any provider programme that would.
4. Who else sees it
Only the services that make the site work. Each has access to the narrow slice it needs and nothing else:
| Who | What they handle | Where |
|---|---|---|
| [HOSTING / CDN PROVIDER — M4, A27(b)] | Serving the site; security logs | [REGION] |
| [SCHEDULING PROVIDER — A9, Cal.com per PLAN.md] | Your booking and what you typed into it | [REGION] |
| [EMAIL PROVIDER — Purelymail per PLAN.md dependencies] | Email you send us and we send you | [REGION] |
(Each row is a marker until the corresponding step closes. A privacy notice that names a provider the site does not use is worse than one that names none.)
We will also disclose information if the law requires it. If that ever happens and we are permitted to tell you, we will.
No AI provider is on this list. Nothing you send through this website is sent to a foundation model. That changes only inside a paid engagement, where it is governed by the signed agreement and disclosed there.
5. Where your information goes
Some of the services above may process data outside the UK and the EEA. Where they do, the transfer relies on the safeguards in Article 46 UK/EU GDPR — Standard Contractual Clauses or an adequacy decision, depending on the provider and the country. The specific mechanism per provider is confirmed when the row above is filled in.
6. How long we keep it
| What | How long |
|---|---|
| Booking and enquiry correspondence that goes nowhere | 12 months, then deleted |
| Notes on a live business conversation | For as long as the conversation is live, plus 12 months |
| Anything that becomes part of a signed engagement | Governed by that engagement’s agreement, not by this notice |
| Server and security logs | The provider’s standard window, typically under 30 days |
If you ask us to delete something sooner, we will, unless we are required to keep it.
7. Your rights
Under UK and EU data protection law you can ask us to give you a copy of what we hold, correct it, delete it, restrict what we do with it, or send it to you in a portable form. You can object to anything we do on the basis of legitimate interest, including the follow-up in row three of §2 — object and it stops.
Ask at [CONTACT ADDRESS]. We will answer within 30 days, and we will not charge you or make it difficult.
If you are unhappy with how we handle it, you can complain to the ICO in the UK (ico.org.uk) or to the supervisory authority where you live in the EU. We would rather you came to us first, but that is your right and not conditional on trying us.
If you are in California or another US state with its own privacy statute, you have comparable rights of access, deletion and correction, and a right not to be discriminated against for using them. The same address reaches us, and the answer is the same: we do not sell your information and there is nothing to opt out of.
8. Security
Traffic to this site is encrypted in transit. What we hold sits in the services named in §4 and is reached only through accounts protected by multi-factor authentication, with credentials held in a password manager rather than in files. /security describes the practices behind that in more detail.
If a breach affects your information and it is likely to be a risk to you, we will tell you — and we will tell the regulator within 72 hours of confirming it, as the law requires.
9. Children
The site is for people doing business. It is not directed at children and we do not knowingly collect anything from them.
10. Changes
If this notice changes, the version here changes and so does the date at the top. If a change is material and we hold your contact details, we will tell you rather than relying on you to re-read it.