Legal
Privacy notice
Plain-English version: we hold as little personal data as we can, we use it only to talk to you about work, and you can tell us to stop or delete it at any time.
Last updated: 27 September 2026
1. Who we are
Tactics Unit (“Tactics Unit”, “we”) is a software and automation studio. We are the controller of the personal data described here. Contact us about privacy at privacy@tacticsunit.com.
2. If you send us a project brief
When you use the form at /start or email us, we collect what you give us:
- your name, email address, company website, and optionally your company name, phone number and how you heard about us;
- your description of the project, how it is done today, the tools you use, and your timeline and budget range;
- basic technical data: a one-way hashed (non-reversible) version of your IP address used for spam and rate limiting, your browser’s user-agent string, the page you arrived on and any campaign (UTM) tags in the link you followed.
We use this only to reply to you, scope and quote your project, and keep a record of the conversation. The legal basis is taking steps at your request before entering into a contract, and our legitimate interest in running and protecting our business (for example, spam prevention). We do not add you to a mailing list, and we never sell your data.
The form is protected by Cloudflare Turnstile, which checks that you are a human. Cloudflare processes limited technical signals to do this.
3. If we contacted you first
Short version: we may have emailed you because your business looks like one we can help. To stop hearing from us, reply “no” to any of our emails, or email privacy@tacticsunit.com. We’ll stop, and delete your details except for the minimum needed to make sure we never contact you again.
What we hold
Business contact information only: your name, job title or role, work email address, company name, company website, country, and notes about your business that are relevant to our services (for example, which public tools your website uses or what you sell). We also keep a record of the emails we have exchanged. We do not collect sensitive or special-category data.
Where it comes from
- Company websites — contact details your business publishes, such as on a contact or team page;
- Business data providers — commercial databases of business contacts that state they collect data lawfully;
- Manual research — public professional sources we look at individually, such as your company’s site, public profiles and podcast or event pages;
- Referrals — someone who knows you suggested we get in touch.
We record where each contact came from and when. We do not use scraped social-network data, lists of unknown origin, or data belonging to our clients or employers.
Why, and on what basis
We use this information to send a small number of relevant, personally written business emails about services that may help your company, and to follow up a limited number of times. Our legal basis is legitimate interest: telling businesses about relevant services in a proportionate way. We have weighed this against your interests — we contact business addresses only, keep volumes low, include a simple way to opt out in every message, and honour objections promptly. We do not contact people in jurisdictions where this type of outreach requires prior consent.
How long we keep it
If you don’t reply, we delete your details 12 months after our last contact. If you ask us to stop, we delete your details but keep your email address on a suppression list so we never contact you again — that list is kept indefinitely for that purpose only.
How to object or ask for deletion
Reply “no” (or anything like “unsubscribe” or “remove me”) to any email from us, or write to privacy@tacticsunit.com. We act on automatic opt-outs immediately and on other requests within two business days. You can also ask for a copy of what we hold about you.
4. This website
This site does not use advertising or tracking cookies. We may use Cloudflare Web Analytics, which counts visits without cookies and without building a profile of you. The start form remembers campaign tags and your landing page in your browser tab (session storage) so we know how you found us; this is cleared when you close the tab. Fonts are loaded from Google Fonts, which receives your IP address when your browser requests them.
5. Who processes data for us
We use a small number of service providers, under their data-processing terms:
- Cloudflare — website hosting, database, security (Turnstile), email routing and analytics;
- Google Workspace — email and documents;
- Anthropic — an AI model we use to help summarise enquiries and research publicly available information about businesses. Drafts are always reviewed by a person; nothing is sent automatically.
If we start a project together, the tools used for that project are set out in the proposal.
6. International transfers
Our providers may process data in the United States and other countries. Where required, transfers rely on the providers’ standard contractual clauses or equivalent safeguards.
7. How long we keep data
- Project enquiries: 24 months from your last message, unless you become a client.
- Client records: for as long as we work together and afterwards as required for tax and accounting.
- Outreach contacts: 12 months after last contact if there is no reply (see section 3).
- Suppression list: indefinitely, containing only what is needed to not contact you.
8. Your rights
Depending on where you live, you may have the right to access, correct or delete your data, to object to or restrict how we use it, to data portability, and to complain to your data protection authority. To use any of these rights, email privacy@tacticsunit.com. We may need to confirm your identity, and we will respond within one month.
9. Changes and contact
We will update this page when our practices change and note the date at the top. Questions: privacy@tacticsunit.com.