Legal

Privacy Policy

Last updated: 2 October 2026

This policy explains what personal information Bright Reference collects through this website, why, and the choices you have. We have kept it plain on purpose: the site is small and collects very little.

Before publishing: complete every [bracketed] detail, delete this note, and have this policy reviewed by a qualified professional for the places you operate (for example GDPR / UK GDPR, CCPA / CPRA). It describes this site as built; update it if you add analytics, a newsletter, a chat widget or other plugins.

1. Who we are

Bright Reference (“we”, “us”) is a Forward-Deployed Engineering and AI systems consultancy. This website is operated by [legal entity name], [registered address]. For privacy questions, contact us at [contact email].

2. What we collect

Information you send us

If you use the contact form on this site we collect the details you enter: your name, work email, company and role, and your message describing the workflow you want help with. Please share only what you are comfortable sharing. Do not include passwords, credentials, personal data about other people, or confidential information you are not entitled to disclose.

Booking a discovery call

The “Book a Discovery Call” button may open or embed an online scheduling service ([scheduling provider, e.g. Calendly]). If you book there, you give your details to that provider directly and its privacy policy applies to them. We receive the booking details you provide.

Technical information

Like most websites, our hosting provider ([hosting provider]) may automatically log technical data such as IP address, browser type, pages requested and time of access. This is used to run and secure the site.

Spam protection

The contact form uses a hidden field, a timing check and a rate limit to deter automated spam. The rate limit stores a short-lived, hashed marker of your connection (about 30 seconds). We do not use a third-party CAPTCHA.

3. How we use information

  • To read and reply to your enquiry and, if you wish, arrange a discovery conversation.
  • To operate, maintain and secure this website.
  • To meet legal and regulatory obligations and to establish or defend legal claims.

We do not sell personal information, and we do not send marketing emails unless you ask us to or we have your consent.

4. Legal bases (where GDPR / UK GDPR applies)

  • Legitimate interests — responding to business enquiries and keeping the site secure.
  • Steps at your request before entering a contract — when you ask to discuss working together.
  • Consent — only where we explicitly ask for it, which you may withdraw at any time.
  • Legal obligation — where the law requires us to keep or disclose information.

5. Cookies and similar technologies

As built, this site does not set analytics or advertising cookies. Fonts, scripts and artwork are served from our own server rather than third-party services. WordPress sets essential cookies only for team members who log in. If we later add analytics, or embed a third-party tool such as a booking calendar, that tool may set its own cookies; we will update this policy and request consent where the law requires it. [Confirm this section matches your final plugins and tools.]

6. Who we share information with

We share personal information only with providers that help us run the site and respond to you, under appropriate terms:

  • Hosting and infrastructure: [hosting provider].
  • Email delivery: [email provider].
  • Scheduling: [scheduling provider], if you book a call.
  • Professional advisers (such as lawyers or accountants), and authorities where the law requires.

7. International transfers

[If any provider processes information outside your region, describe the safeguards, for example standard contractual clauses. Delete this section if not applicable.]

8. How long we keep information

We keep contact-form enquiries for [12 months] after our last communication, unless we begin working together, in which case information is kept as set out in our agreement and as the law requires. Server logs are kept for the period set by our hosting provider ([retention period]).

9. Security

We use reasonable technical and organisational measures, including encrypted connections (HTTPS), restricted administrator access and keeping the amount of data we collect to a minimum. No online service can be guaranteed completely secure.

10. Your rights

Depending on where you live, you may have the right to access, correct or delete your personal information; restrict or object to our processing; receive a portable copy; and withdraw consent. You also have the right to complain to your local data-protection authority. To exercise any right, email [contact email]. We may need to verify your identity first.

11. Children

This website is intended for business audiences and is not directed at children under [16]. We do not knowingly collect their personal information.

12. Links to other sites

This site may link to third-party websites and services. We are not responsible for their content or privacy practices.

13. Changes to this policy

If we change this policy we will post the new version here and update the date at the top. Material changes will be highlighted where appropriate.

14. Contact

Bright Reference — [legal entity name], [registered address]. Email: [contact email].