Legal · Privacy & data
Privacy & Data Processing
What The Holm Team records about visitors to this site, and how it handles the client data it maintains but does not own.
What this covers, and the two hats
The Holm Team is a sole proprietorship. The proprietor is the controller of the records described below rather than a company, and there is no corporate parent, affiliate or group anywhere in this policy. It covers three things: this website, the client hub, and the systems we administer for clients.
Those last two are not the same kind of data, and conflating them is how privacy policies become useless. We wear two hats:
- Our own records. Enquiries, quotes, invoices, payments, correspondence, and this site’s analytics. We decide what is collected and why, and sections 02–04 describe it.
- Your data, in your systems. Everything inside a client environment we administer — mailboxes, files, directories, backups. We maintain that data; we do not own it and we do not decide what happens to it. You do. Section 06 sets out the terms.
We are a business-to-business provider. If you are here as a consumer, the practical answer is section 03: a first-party cookie, a server-side page-view record, and nothing sold to anyone.
Information we collect about you
When you contact us, request an assessment, or become a client, we hold the information you give us and the records the work generates:
- Business contact details — your name, business name, work email, work phone, and the site address where work is performed.
- What you told us — the description of your environment, your current provider, your renewal date, your compliance obligations, and anything else you put in the form or an email.
- Engagement records — quotes, statements of work, jobs, appointments, time records, invoices, payments and their status.
- Correspondence — email we exchange, chat threads, and notes we make about the work.
- Documentation of your environment — inventories, configurations, diagrams and runbooks we produce to support you.
We use it to quote, deliver, invoice and support the work, and to meet tax and record-keeping obligations. We do not sell it, share it for cross-context advertising, or use it to build a profile of you. There is no advertising network, no data broker, and no analytics warehouse in this business.
Card numbers never reach us. Online payments go through Stripe, which handles the card details end to end; we see the result, not the number.
What this website records
This site records its own visitor analytics, on its own server, with no third party involved. There is no Google Analytics, no advertising pixel, no tag manager, no session replay. What follows is what the code actually does.
On a normal page request — a real navigation, not a prefetch, not an API or administrative route — the server writes one page-view row containing:
- Your IP address, as forwarded by Cloudflare.
- The path you requested, and roughly how long you stayed on the previous page.
- The referring page or link, and any utm_source, utm_medium or utm_campaign tag on the URL you arrived through.
- The user-agent string your browser sends, from which we derive a browser and operating system name.
- The two-letter country Cloudflare attributes to your IP as the request passes through it.
- The two first-party cookie identifiers described in the next section.
Nothing is sent anywhere else. The rows are written to a database on hardware this business owns. No visitor IP address is sent to an outside geolocation service: the platform has an optional city-lookup feature and it is switched off. Analytics are never sold, never shared, never used for advertising, and never combined with data purchased from anyone.
Why we bother. Knowing which pages get read and which link brought you here is how the site improves — and when you send an enquiry, seeing what you were reading lets us answer it properly instead of asking you to explain twice.
The limits. These records are deleted automatically after 90 days by a nightly job — see section 10. A browser sending a Global Privacy Control or Do Not Track signal is not recorded at all (section 13). Blocking cookies or using private browsing leaves us with nothing to count, and the site works exactly the same either way.
The chat window
If the chat window is open on this site, the assistant behind it runs on this business’s own hardware. Your messages are not sent to OpenAI, Anthropic, Google, or any other model provider, because there is no external model provider in the path.
The transcript, and any name, email or phone number you type into it, is stored with our own records and is read by the owner. Treat it as you would an email: it is a good place to describe a problem and a bad place to paste a password. If you want a thread deleted, ask.
Client data we maintain on your behalf
When we administer your systems we necessarily maintain personal information about your employees, your customers and your patients. You remain responsible for it. We process it only to deliver the services in your statement of work. These are the commitments that go with that, and they sit in the Data Processing Addendum to your agreement.
- Reasonable security is our own statutory duty. California Civil Code §1798.81.5 requires a business that owns, licenses or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect it from unauthorised access, destruction, use, modification, or disclosure. Because we maintain your data, that duty binds us directly — not merely through your contract.
- We flow it down. The same section requires that a nonaffiliated third party receiving personal information be contractually held to the same standard. Every subcontractor or vendor we route client data through carries that clause in its contract with us.
- Service-provider terms. Where you are a business covered by the CCPA/CPRA, we act as your service provider. We will not sell or share your personal information; will not retain, use or disclose it for any purpose other than the business purposes specified in the contract, or outside our direct business relationship with you; will not combine it with personal information received from other sources except as the statute permits; will comply with the obligations the statute applies to us; will notify you if we determine we can no longer meet them; and will bind our subcontractors to the same terms. These terms are not negotiable in either direction — the statute requires them.
- Your right to check. You may take reasonable and appropriate steps to monitor our compliance, including an audit. The mechanics — reasonable notice, business hours, at your expense, and satisfied where we can provide an existing report covering the same ground — are set out in the DPA.
- Protected health information. If you are a HIPAA covered entity, we are your business associate, we are directly liable under the Security Rule and the breach-notification rules, and a Business Associate Agreement is signed before we touch a system holding protected health information.
- Return and deletion. On termination your data is exported and returned in a usable format within thirty days, and deleted from our systems after that window. Media taken out of service is sanitised to the NIST SP 800-88 standard rather than simply reformatted, as California Civil Code §1798.81 requires.
We encrypt data in transit and at rest wherever we control the storage, and we recommend the same inside your environment. That is not a slogan: California’s breach statutes and its private right of action turn on whether the exposed data was unencrypted, so encryption is the difference between a manageable incident and a class action with a per-record price.
If a breach happens
California Civil Code §1798.82 was amended by SB 446 with effect from 2026-01-01, and the amendment matters to anyone whose data we hold.
- Data we maintain for a client: immediate notice to the client. §1798.82(b) requires a business that maintains computerised personal information it does not own to notify the owner or licensee immediately following discovery of a breach. There is no thirty-day grace period on that duty and we do not treat it as though there were. On discovering a breach of data we hold for you, you hear from us immediately and in writing, with what we know at that point — not a tidy summary days later. We record both the time of discovery and the time you were notified, and you can ask for both.
- Data we own: thirty days. §1798.82(a) requires disclosure to affected California residents within thirty calendar days of discovery. If a breach reaches our own records, that is the outside limit, not the target.
- More than 500 residents: the Attorney General. A single breach affecting more than 500 California residents also requires a sample notice to be submitted to the California Attorney General within fifteen calendar days.
A notice from us will say what happened, what categories of information were involved, when it happened as far as we can establish, and what we are doing about it — in plain language, from the person who actually holds the data.
Where the data lives
This platform is self-hosted on infrastructure this business owns and operates, in the United States. Your records do not sit in a third-party CRM, a shared SaaS database, or an analytics warehouse. The practices behind that, stated plainly:
- All traffic to this website and the client hub is encrypted in transit.
- Access to client records is limited to the owner. There are no employees with database access.
- Card numbers are never stored, because they never reach us — Stripe handles them end to end.
- Client hub access uses a private, unguessable link unique to you; administrative access is password-protected with expiring sessions.
- Backups run on a schedule and are replicated to more than one offsite target.
None of that is a guarantee against every threat, and section 09 of the Terms says so explicitly. It is a description of what is actually in place.
Subprocessors and subcontractors
We keep the list short on purpose. Today, the third parties that can touch data relating to you are:
- Stripe — card payment processing. Receives the payment details and the invoice reference; we never receive the card number.
- Cloudflare — sits in front of this website. Sees the request, including your IP address, as it passes through.
- Outbound mail — quotes, invoices and notifications are delivered by the mail service configured for this business. Where that service is a third-party relay, it necessarily handles the message in transit.
Analytics, chat, documents and client records are handled on our own hardware. Where an engagement needs a specialist subcontractor with access to your systems, we tell you who they are before they have it, and they are contractually bound to the obligations in section 06. The DPA lists the subprocessors in use for your engagement and how you are told when that list changes.
How long we keep it
Records are kept while the work and the law require them, then deleted. One row of this table is enforced by a machine every night; the rest are reviewed and deleted on the stated schedule or on request. The distinction is deliberate — a policy is only as good as the thing that carries it out.
| Record | Retained | How it is enforced |
|---|---|---|
| Website analytics — IP, pages viewed, referrer, dwell time | 90 days | Automatically. A nightly job deletes every page view, event and visitor session older than the window. |
| Enquiries and assessment requests | 2 years | Reviewed and deleted on the schedule, or sooner on request. |
| Quotes, statements of work, invoices, payment records | 7 years | Held for tax and record-keeping obligations, then deleted. |
| Documentation, attachments and project files | Term of the engagement + 1 year | Returned to you at offboarding, then deleted after the handover window. |
| Chat transcripts | 2 years | Reviewed and deleted on the schedule, or sooner on request. |
When a record is past every retention obligation and no longer needed, it is deleted — not archived indefinitely on the theory that storage is cheap.
Your California privacy rights
Although The Holm Team does not meet CCPA/CPRA applicability thresholds, we honour those rights anyway, in full, for anyone who asks:
- Right to know — what personal information we hold about you, and its categories, sources and purposes.
- Right to delete — deletion of your information, subject only to records the law requires us to keep.
- Right to correct — correction of anything inaccurate.
- Right to portability — a copy in a readable, portable format.
- Right to non-discrimination — exercising any of these never affects the price, quality or availability of our services.
One routing note. If your data is in a system we administer for one of our clients, the client decides — we are their service provider and we act on their instruction. Send the request to them, or send it to us and we will pass it on and tell you we did.
How to exercise them
Email team@holm.team saying what you want — know, delete, correct, or a copy. Verification is proportionate to our size: we confirm you are you by corresponding through the email address or phone number already on file, or by matching details of your engagements. We respond within 45 days, and in practice far faster. You may designate an authorised agent; we will verify their authority with you directly.
The one limit: records we are legally required to keep — issued invoices and payment records within their retention period — cannot be deleted until that obligation expires. We will tell you exactly what remains and why.
Do Not Track and Global Privacy Control
Some browsers send a Global Privacy Control or Do Not Track signal. There is no sale or sharing of personal information here for such a signal to opt out of, so strictly speaking it has nothing to act on.
We honour it anyway, before anything is written. If your request carries Sec-GPC: 1 or DNT: 1, the server returns before it touches the database: no identifier cookie is issued, no IP address is stored, no page view is recorded. Nothing is written down. This is not a preference we apply later — it is the first check in the request path.
Children
This is a business-to-business service. The website and our services are directed at businesses and the adults who run them, not at children, and we do not knowingly collect personal information from anyone under 16. Since we never sell or share personal information, the CCPA’s opt-in rules for minors have nothing to attach to. If you believe a minor has submitted information to us, write to team@holm.team and we will delete it.
Changes to this policy
If this policy changes, the effective date above changes with it, and any material change is noted plainly rather than buried. Changes never apply retroactively to reduce protections on information collected under an earlier version. Where a signed DPA or BAA covers the same ground, that document governs until it is amended in writing.
Contact
Questions about anything on this page — or anything about how your information is handled that this page does not answer — go to team@holm.team. You will get an answer directly from the business owner who maintains the data.