Privacy Notice

Privacy Notice

Last updated: [DATE OF PUBLICATION]

This is what happens to your information when you use this site. It is short because the site does very little.

1. Who is responsible

Hyper Viral LLC, trading as Totomoko (“Totomoko”, “we”), is the data controller for the information described here. Write to us at [CONTACT ADDRESS] about anything on this page.

2. What we collect, and why

What When Why Lawful basis
Your name, email address, and anything you type into the booking form When you book a discovery conversation To hold the conversation you asked for and to reply to you Steps taken at your request before entering a contract
Your email address and the content of your message When you email us To answer you Our legitimate interest in responding to people who contact us
Your name, role, organisation, and notes about the conversation If we talk about working together To keep track of a live conversation and follow it up Our legitimate interest in pursuing a business enquiry
Standard server and security logs — IP address, browser, page requested, time Whenever anyone loads a page To serve the page and to keep the site up and unabused Our legitimate interest in operating a secure site

That is the whole list.

3. What we do not do

Stated positively, because the absences are the point:

4. Who else sees it

Only the services that make the site work. Each has access to the narrow slice it needs and nothing else:

Who What they handle Where
[HOSTING / CDN PROVIDER — M4, A27(b)] Serving the site; security logs [REGION]
[SCHEDULING PROVIDER — A9, Cal.com per PLAN.md] Your booking and what you typed into it [REGION]
[EMAIL PROVIDER — Purelymail per PLAN.md dependencies] Email you send us and we send you [REGION]

(Each row is a marker until the corresponding step closes. A privacy notice that names a provider the site does not use is worse than one that names none.)

We will also disclose information if the law requires it. If that ever happens and we are permitted to tell you, we will.

No AI provider is on this list. Nothing you send through this website is sent to a foundation model. That changes only inside a paid engagement, where it is governed by the signed agreement and disclosed there.

5. Where your information goes

Some of the services above may process data outside the UK and the EEA. Where they do, the transfer relies on the safeguards in Article 46 UK/EU GDPR — Standard Contractual Clauses or an adequacy decision, depending on the provider and the country. The specific mechanism per provider is confirmed when the row above is filled in.

6. How long we keep it

What How long
Booking and enquiry correspondence that goes nowhere 12 months, then deleted
Notes on a live business conversation For as long as the conversation is live, plus 12 months
Anything that becomes part of a signed engagement Governed by that engagement’s agreement, not by this notice
Server and security logs The provider’s standard window, typically under 30 days

If you ask us to delete something sooner, we will, unless we are required to keep it.

7. Your rights

Under UK and EU data protection law you can ask us to give you a copy of what we hold, correct it, delete it, restrict what we do with it, or send it to you in a portable form. You can object to anything we do on the basis of legitimate interest, including the follow-up in row three of §2 — object and it stops.

Ask at [CONTACT ADDRESS]. We will answer within 30 days, and we will not charge you or make it difficult.

If you are unhappy with how we handle it, you can complain to the ICO in the UK (ico.org.uk) or to the supervisory authority where you live in the EU. We would rather you came to us first, but that is your right and not conditional on trying us.

If you are in California or another US state with its own privacy statute, you have comparable rights of access, deletion and correction, and a right not to be discriminated against for using them. The same address reaches us, and the answer is the same: we do not sell your information and there is nothing to opt out of.

8. Security

Traffic to this site is encrypted in transit. What we hold sits in the services named in §4 and is reached only through accounts protected by multi-factor authentication, with credentials held in a password manager rather than in files. /security describes the practices behind that in more detail.

If a breach affects your information and it is likely to be a risk to you, we will tell you — and we will tell the regulator within 72 hours of confirming it, as the law requires.

9. Children

The site is for people doing business. It is not directed at children and we do not knowingly collect anything from them.

10. Changes

If this notice changes, the version here changes and so does the date at the top. If a change is material and we hold your contact details, we will tell you rather than relying on you to re-read it.