This policy explains what GGT Risk Management collects through ggtrisk.com, why, and what happens to it.
What we collect
- Information you send us. When you submit the enquiry form we receive your name, email address, chosen topic and message. That is the entire set of fields — we do not ask for financial account credentials, account numbers or identification documents, and you should never send them through this form.
- Server logs. Our host records standard technical data on every request: IP address, browser user agent, requested URL and timestamp. This is generated automatically by the web server and is used for security, abuse prevention and diagnostics.
- Anti-spam data. The enquiry form applies a short-lived rate limit keyed to a one-way hash of your IP address, to prevent automated abuse.
What we do not do
- We do not sell, rent or trade your personal information. Ever.
- We do not run third-party advertising or behavioural tracking on this site.
- We do not load third-party fonts, analytics scripts or social media trackers on this site.
- We do not set marketing or tracking cookies. WordPress may set functional cookies if you log in as an administrator; ordinary visitors are not given cookies.
Why we hold it
Enquiry details are used solely to respond to your enquiry and, if you become a client, to deliver the services you have engaged us for. Server logs are used for security and troubleshooting.
How long we keep it
Enquiry emails are retained for [X] months and then deleted unless you have become a client, in which case client records are retained for [X] years as required for business and tax purposes. Server logs are retained per our host’s standard retention period.
Who else sees it
Our web host processes data on our behalf in order to operate the site. Our email provider processes enquiry messages in order to deliver them. We do not share your information with anyone else except where required by law.
Security
This site is served over HTTPS. Administrative access is restricted, protected by strong credentials, and the in-dashboard file editor is disabled. Backups are taken daily. No system is perfectly secure, and we do not claim otherwise — which is why we do not ask you for sensitive financial information through this website.
Your choices
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email [PRIVACY EMAIL] and we will respond within 30 days. Depending on where you live you may have additional statutory rights, including under the California Consumer Privacy Act; we honour those requests regardless of whether we are strictly required to.
Children
This site is not directed at anyone under 18, and we do not knowingly collect information from children.
Changes
Material changes to this policy will be reflected in the date below.
Last updated: [DATE]. Questions: [PRIVACY EMAIL].
Note for the site owner: replace the bracketed values. If you later add analytics, a newsletter tool, a scheduling embed or a payment processor, this page has to be updated to name them — that is the part everyone forgets.