Privacy Policy
Privacy Policy
Last updated 25 June 2026
1. Who we are
Responsible party / data controller: Imperium Negotiation Solutions (Pty) Ltd, registered in South Africa.
US affiliate (processor): Imperium Negotiations LLC processes data on behalf of and under instruction from the South African entity.
Contact: [email protected]
2. What we collect and why
We collect only the information you actively provide. We do not collect data passively through analytics—no analytics service is installed on this site.
| Source | Data collected | Purpose |
|---|---|---|
| Newsletter signup | Email address | Sending the newsletter |
| Scorecard assessment | Name, email, company, role, country, profession, revenue band, and your answers | Generating your scorecard report |
| Strategic intake form | Email, name, company, goals, constraints | Preparing a statement of work |
3. Legal basis for processing
- Consent (GDPR Art. 6(1)(a)) — you submit your information voluntarily through our forms.
- Performance of a contract (GDPR Art. 6(1)(b)) — processing needed to deliver the scorecard report or statement of work you requested.
- Legitimate interest (GDPR Art. 6(1)(f)) — replying to enquiries and improving our service.
4. Cookies
This site does not set any cookies. No analytics cookies, no advertising cookies, no tracking cookies of any kind. For full details, see our Cookie Policy.
5. Analytics
No analytics service is installed on this site. We do not track page views, sessions, or visitor behaviour.
6. Third-party processors
- MailerLite (UAB MailerLite, Lithuania / EU) — newsletter subscriber email addresses are synced to MailerLite for email delivery.
- Cloudflare — provides SSL termination and CDN services. Cloudflare may process IP addresses and request metadata in transit.
We do not sell, rent, or trade your personal information.
7. How your data is stored
Scorecard results, intake submissions, and newsletter subscriber records are stored as plaintext flat files (JSON / NDJSON) on our VPS, hosted by Hostinger. Data is not encrypted at rest. We are working toward encrypting personally identifiable information; until that work is complete, access is restricted to authorised personnel only.
8. Data retention
No automated deletion mechanism is currently in place. Your data is retained until you request its deletion. Upon receiving a deletion request, we will remove your information within 30 days and confirm by email.
9. International transfers
Your data may be transferred to and processed in South Africa (where our primary servers are hosted via Hostinger) and in the European Union (MailerLite). If you are located outside these regions, by submitting your information you consent to this transfer.
10. Your rights under GDPR
If you are in the EU/EEA, you have the following rights under Articles 15–22 of the General Data Protection Regulation:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right not to be subject to automated decision-making (Art. 22)
11. Your rights under POPIA
If you are in South Africa, the Protection of Personal Information Act gives you the following rights under sections 23–25:
- Right to access your personal information (s.23)
- Right to request correction or deletion (s.24)
- Right to object to processing (s.11(3)(a))
- Right to submit a complaint to the Information Regulator
12. Your rights under CCPA
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know — you may request the categories and specific pieces of personal information we have collected about you.
- Right to delete — you may request that we delete the personal information we have collected from you.
- Right to opt out of sale — we do not sell your personal information. We have never sold personal information.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise any CCPA right, email [email protected] with the subject line “CCPA Request”.
13. Children's privacy
This site and our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will delete it.
14. Data breach notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours (GDPR Art. 33).
- Notify the Information Regulator and affected data subjects as soon as reasonably possible (POPIA s.22).
- Notify affected individuals without undue delay.
15. Changes to this policy
We may update this policy from time to time. Material changes will be noted by updating the date at the top of this page. Continued use of the site after changes constitutes acceptance of the revised policy.
16. Contact
For any privacy-related questions, requests, or complaints, email [email protected]. We respond within seven working days.