Mindset Our Focus Security Stories Get in touch

Legal

Privacy Policy

How we collect, process, and protect the personal data provided by users of the Tenvalleys.com website.

§1 General

  1. This Privacy Policy outlines the rules governing the collection, processing, and protection of personal data provided by users of the Tenvalleys.com website.
  2. Tenvalleys respects the privacy of its users and is committed to protecting their personal data in accordance with applicable data protection regulations, including the GDPR (General Data Protection Regulation).
  3. By accessing or using our website, you agree to the terms of this Privacy Policy.
  4. Tenvalleys reserves the right to modify this Privacy Policy at any time. Any changes will be published on this page, and users will be informed via a notice on our website.
  5. Continued use of the website after any changes to the Privacy Policy constitutes acceptance of the revised terms.
  6. This Privacy Policy is governed by applicable data protection laws and regulations. Any disputes arising from this policy will be resolved according to the laws in force in the jurisdiction where Tenvalleys operates.

§2 Privacy Principles

  1. Data Collection: Tenvalleys collects personal data only when it is necessary for the provision of our services, such as contact information provided through the “Get in Touch” form or when you subscribe to our newsletter. Section §5 sets out in full what we collect for the newsletter and on what basis.
  2. Data Usage: Personal data is used solely for the purposes specified during collection, such as responding to inquiries, improving our services, or sending updates. We do not sell it, and we do not pass it to third parties for their own purposes without your consent, except where required by law. The service providers listed in §4 are a different matter: they handle data on our instructions and on our behalf, which is what makes running the website possible in the first place.
  3. Data Security: Tenvalleys implements appropriate technical and organizational measures to ensure the security of personal data and to prevent unauthorized access, alteration, or loss.
  4. Data Retention: Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by law.

§3 Your rights and third parties

  1. User Rights: Users have the right to access, correct, delete, or restrict the processing of their personal data. Additionally, users may withdraw their consent to data processing at any time.
  2. Access to Information: Users may request information about the data Tenvalleys holds about them and exercise their rights by contacting us via the details provided below.
  3. Cookies: Tenvalleys.com uses cookies, small files stored on your device. Cookies needed to run the site securely are set automatically. Cookies used to measure how the site is used, or to support our advertising on other platforms, are set only after you accept them, and you can change or withdraw that choice at any time. Section §7 lists every cookie in use.
  4. Analytics & Advertising Partners: Google Analytics tells us how the site is used, and LinkedIn’s advertising tools let us measure and improve our LinkedIn campaigns. The two behave differently before you have made a cookie choice: LinkedIn’s tag does not run at all, while Google Analytics loads with all storage switched off, storing nothing on your device but still reporting the page view to Google. Section §4 sets this out in full and names every company involved in running this website; §7 lists exactly which cookies these two set.
  5. International Transfers: Some of the companies we rely on are based outside the European Economic Area, in the United States. Where personal data reaches them, it is protected either by the EU-U.S. Data Privacy Framework or by the European Commission’s Standard Contractual Clauses. Section §4 states which of the two applies to each of them.
  6. Third-Party Links: Our website may contain links to third-party sites. Tenvalleys is not responsible for the privacy practices or content of these external sites.

§4 Service providers

  1. How we work with them: Running this website means relying on a small number of outside companies. Each of them handles personal data only for the purpose named below, and none of them is permitted to use it for its own purposes. Our agreement with each of them includes the data processing terms required by Article 28 GDPR. We deliberately serve our own fonts and scripts from our own servers rather than from a third-party network, so that opening a page on this site does not quietly hand your IP address to a company you have never heard of.
  2. Website hosting, security, and forms — Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, United States). This website runs on Cloudflare, so every request you make to tenvalleys.com passes through their network, which receives your IP address and browser information in order to deliver the page and to protect the site against attack. Cloudflare also provides Turnstile, the automated check that keeps bots out of our forms, and runs the code that receives what you submit through them. Cloudflare is certified under the EU-U.S. Data Privacy Framework, and our agreement with them additionally incorporates the European Commission’s Standard Contractual Clauses.
  3. Contact form delivery — Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). A message sent through the “Get in Touch” form is delivered into our own Microsoft 365 mailbox, so Microsoft handles your name, your e-mail address, and the content of your message on our behalf. Under Microsoft’s EU Data Boundary, this data is stored and processed within the European Union and EFTA.
  4. Cookie consent — Usercentrics A/S (Havnegade 39, 1058 Copenhagen, Denmark), the company behind Cookiebot. It presents the cookie banner, records which categories you accepted or declined, and keeps that record on servers in the European Union. Without it we could neither ask for your cookie consent nor prove that you gave it.
  5. Analytics and advertising — Google and LinkedIn. Google Analytics is provided to us by Google Ireland Limited and LinkedIn’s advertising tools by LinkedIn Ireland Unlimited Company; both may pass data to their parent companies in the United States, Google LLC and LinkedIn Corporation, each of which is certified under the EU-U.S. Data Privacy Framework. The two behave differently before you make a cookie choice, and it is worth being exact about it: LinkedIn’s tag stays completely inert until you accept Marketing cookies, whereas Google Analytics loads on every page with every storage type denied by default — in that state it saves nothing on your device and cannot recognise you on a later visit, but it does send Google a record of the page view, including your IP address. It starts using cookies only once you accept Statistics cookies. That record contains the address and title of the page you opened, your IP address, a randomly generated number, and the technical details every browser sends as a matter of course — screen size, language, operating system and browser version. It does not contain your name, your e-mail address, or anything you type into our forms. Because nothing is stored on your device, that number cannot be kept between page loads: a new one is generated for every page, so before you make a choice Google cannot join the pages you view into a single visit, nor recognise you if you come back. Two things here are easy to run together, so to be plain about it: the cookie banner governs what is stored on your device, and it does that faithfully — nothing is stored until you accept. Sending a record to Google is a separate act from storing a cookie, and that record is sent either way. Keeping it switched on is a deliberate choice on our part: it is what stops our visitor numbers from disappearing for everyone who never answers the banner. Section §7 lists every cookie they set.
  6. The newsletter — MailerLite Limited (Ireland). Section §5 covers the newsletter in full: what we collect, on what basis, and for how long we keep it.

§5 The AI Pulse newsletter

  1. What we collect: Your e-mail address, and nothing else. We do not ask for your name, your company, or any other detail in order to send you the newsletter.
  2. Legal basis: Your consent, under Article 6(1)(a) GDPR. We send the newsletter only to people who have asked for it.
  3. How consent is given (double opt-in): After you submit the sign-up form, we send you an e-mail containing a confirmation link. Your subscription begins only when you click that link. Until then your address is marked unconfirmed and receives no newsletter at all. If you never confirm, you never hear from us.
  4. Record of consent: When you confirm, the date, the time, and the IP address used to confirm are recorded. We keep this as evidence that the subscription was genuinely requested, and for no other purpose.
  5. What we use it for: Sending the weekly AI Pulse newsletter, and nothing else. We do not use subscriber addresses for sales outreach, we do not combine them with data from other sources, and we do not sell, rent, or share them.
  6. Spam protection: The sign-up form carries the same Cloudflare Turnstile check as the contact form, and the request that records your address is handled by Cloudflare before it reaches our newsletter provider. §4 names Cloudflare and the terms we hold them to.
  7. Who processes it: The newsletter is delivered by MailerLite Limited (88 Harcourt Street, Dublin 2, D02 DK18, Ireland), acting as our data processor. Their data processing agreement forms part of the terms under which we use the service. Subscriber data is stored on infrastructure in the European Union, and where MailerLite transfers personal data outside the EEA it does so under the European Commission’s Standard Contractual Clauses.
  8. Withdrawing your consent: Every newsletter contains an unsubscribe link. One click stops delivery immediately. You do not have to give a reason, and it has no effect on anything else between you and Tenvalleys.
  9. How long we keep it: If you unsubscribe, we stop sending immediately and keep your address on a suppression list. We do this so that a later import or sign-up cannot start mailing you again — it is the only way we can reliably honour your withdrawal. If you sign up but never confirm, your address is deleted within 30 days.

§6 The contact form

  1. What we collect: Your name, your e-mail address, and whatever you write in the message field. There are no other fields, hidden or otherwise, and we do not enrich what you send with data from anywhere else.
  2. Legal basis: Where your message is about working with us, Article 6(1)(b) GDPR — steps taken at your request before entering a contract. For anything else, Article 6(1)(f) GDPR — our legitimate interest in answering people who write to us. We deliberately do not ask you to tick a consent box: you started the correspondence, and consent that you could later withdraw is the wrong basis for a conversation we are already having with you.
  3. What we use it for: Replying to you, and continuing that conversation. Your address is not added to the newsletter, not used for unrelated sales outreach, and not sold, rented or shared.
  4. Spam protection: Before the message is sent, Cloudflare Turnstile checks that the request comes from a person rather than a bot. That check processes technical data such as your IP address and browser characteristics. It sets no advertising cookies and does not track you across sites. §4 names Cloudflare and the terms we hold them to.
  5. How long we keep it: For as long as your enquiry is live, and for as long afterwards as the exchange still matters to our relationship with you — while a proposal is open, for instance, or where the message belongs to work we went on to deliver. Where a message leads to a contract, the correspondence becomes part of that contract’s records and is kept for as long as accounting and tax law require. You can ask us to delete your message at any time, and unless we are required to keep it, we will.
  6. Your rights: You may ask us for a copy of what we hold, have it corrected or deleted, or ask us to restrict how we use it. Where we rely on legitimate interest, you also have the right to object under Article 21 GDPR — write to the address in §8 and we will stop unless we have compelling grounds not to.

§7 Cookies in use

  1. Your choice: You decide which cookies we may set. To review or change your decision, open the cookie settings. Withdrawing consent takes effect immediately and does not affect your ability to use the site.
  2. Full list: The table below is generated from an automated scan of this website and updates whenever the cookies we use change, so it always reflects what is actually running.

§8 Final clause

  1. Contact Information: For questions regarding this Privacy Policy or to exercise your data protection rights, please contact Tenvalleys at:
  2. Supervisory Authority: If you believe that Tenvalleys has infringed your rights under applicable data protection laws, you have the right to file a complaint with the relevant data protection authority.
  3. Final Clause: This Privacy Policy is effective as of the date it is published on the website. Tenvalleys reserves the right to make amendments to this policy, with changes taking effect upon publication on this page.