Skip to content

Privacy

Privacy policy

This page explains how robertfurman.co.uk handles information submitted through the website, the Business Bottleneck Review and the shared contact form.

Who is responsible

Robert Furman is responsible for robertfurman.co.uk and the personal information submitted through this website.

The supported contact route is the contact form on this site. I do not publish a postal address, company registration number or data protection officer details on this website.

Information this site may collect

The Business Bottleneck Review may collect your questionnaire answers, optional audio supplied for transcription, generated report/session information, report reference, name, business name, email address, required report/privacy/no-secrets acknowledgements and separate optional marketing consent.

The shared contact form may collect your name, business name, email address, enquiry type, message, optional report reference, optional discovery-call availability, preferred meeting format where relevant, required acknowledgements and separate optional marketing consent. The current shared contact form does not ask for a telephone number.

The site may also generate necessary technical and security information through normal web-server operation, such as request metadata needed to operate, secure and troubleshoot the service.

Browser-local drafts and cookies

The Business Bottleneck Review can optionally save your questionnaire answers in first-party browser local storage on your device so you can recover an interrupted review. This is off by default, is used only for draft recovery and the review works without it.

If you choose to save progress, recent answers may be recovered for up to 24 hours. Stale or unreadable saved progress is not restored and the review screen lets you clear or disable saved progress. A successfully accepted review that creates the normal report-session flow clears the saved browser draft.

Where report persistence is enabled, the site uses a necessary HttpOnly report-session cookie so the browser can recover the saved report. The cookie stores an opaque access token, not the public report reference, email address or business name. The current configured report-cookie window is 7 days unless Robert changes the server-side setting.

Analytics cookies are not currently implemented. The current first-party analytics foundation does not use browser analytics storage, visitor IDs, session IDs, fingerprinting, page-view tracking, referrer/source attribution or third-party tags.

Why information is used

I use the information submitted through the Business Bottleneck Review to provide the requested review, transcribe an answer when you choose audio, generate and provide the report, send transactional report delivery messages where configured, recover a saved report session and operate, secure and troubleshoot the service.

I use shared contact-form information to respond to enquiries, arrange requested discovery discussions, send transactional acknowledgements and internal notifications where configured, and administer the enquiry safely.

When you request follow-up about a Business Bottleneck Review, I may use your submitted contact details and existing report findings to prepare for that requested conversation. A private preparation summary may be included in my internal notification, but this does not trigger another OpenAI analysis and raw questionnaire answers are not copied into that private preparation brief.

The site may keep first-party aggregate counts of whether specific funnel actions were accepted, such as a Business Bottleneck Review analysis request, successful analysis, contact completion, PDF request, report-email retry, general contact submission or discovery-call request. These counts are stored by UTC date and metric name only, not as visitor event logs.

Optional marketing consent is used only where you have separately opted in to occasional relevant updates. It is not bundled with report delivery or ordinary enquiry handling.

Lawful bases

Legitimate interests: operating this website and the Business Bottleneck Review, responding to ordinary enquiries, providing requested review functionality, maintaining security, preventing abuse and administering the service, subject to your rights and interests.

Contract or steps requested before entering a contract: where you specifically ask me to take steps towards a possible engagement, such as requesting a discovery discussion, proposal, quote or similar pre-contractual action.

Consent: optional direct-marketing communications only. The required privacy and request acknowledgements confirm that you understand the service boundary; they are not used as GDPR consent for the core requested service.

OpenAI

The Business Bottleneck Review may send questionnaire material to the OpenAI API for analysis. If you choose audio, the audio is sent server-side to OpenAI for transcription so you can review and edit the transcript before it is used.

The application is intentionally designed so that contact details, shared contact-form messages and report references are not supplied to OpenAI as part of the Business Bottleneck Review analysis boundary. However, free-text review answers could contain personal information if you type it yourself, so please do not include unnecessary personal, confidential or special-category information.

The implemented Responses API analysis integration uses store:false. OpenAI states that API data is not used to train OpenAI models by default unless the API customer opts in to sharing. Provider abuse-monitoring data may still be retained under OpenAI's applicable API data-retention controls. I do not claim Zero Data Retention or that OpenAI retains nothing.

Mailchimp Transactional

Mailchimp Transactional, also known as Mandrill, is used to send relevant transactional emails when email delivery is enabled and configured.

For a Business Bottleneck Review report email, the message uses the recipient email address, report reference and generated PDF attachment. For shared contact emails, the visitor acknowledgement uses the visitor's email address and enquiry reference, while the internal notification includes the enquiry details needed for Robert to respond. Where you request a discovery call about a securely linked Business Bottleneck Review, that internal notification may also include the private preparation summary described above.

Transactional emails are separate from optional marketing consent. The application disables open and click tracking in its Mandrill message payloads.

International processing

Service providers including OpenAI and Mailchimp may process data outside the UK, including in the United States. Where UK personal data is transferred internationally, those providers publish contractual safeguards for those transfers, including Standard Contractual Clause-based arrangements and UK-specific transfer provisions where applicable.

Retention

The approved application retention settings are: anonymous saved Business Bottleneck Review records up to 7 days; completed Business Bottleneck Review and report records 90 days; Business Bottleneck Review delivery-attempt records 90 days; general contact enquiries 90 days; report-linked contact enquiries 90 days; and contact delivery-attempt records 90 days.

First-party aggregate funnel counts use a 24-month retention window. They store only UTC date, allowlisted metric name and count, and do not store IP addresses, user agents, cookies, report references, contact details, questionnaire answers, report content or raw URLs.

Records are assigned configured expiry periods and are removed through the site's protected cleanup process.

Marketing consent is stored separately from report delivery and contact enquiries. Consent or withdrawal/suppression records may need to be retained as necessary to administer consent and honour opt-outs; the application does not currently implement a separate automatic deletion period for those records.

Ordinary technical/server logs are kept only for as long as needed for operation, security, troubleshooting and abuse prevention, using minimised content where practical. The application does not define a fixed public log-retention period in source code.

Your rights

Under UK data protection law, you may have rights to access your personal information, ask for inaccurate information to be corrected, ask for erasure where applicable, ask for restriction where applicable and object to processing based on legitimate interests.

You can withdraw optional marketing consent at any time. These rights are not always absolute, and some requests may require identity checks or may be limited where retention is needed for legal, security or administrative reasons.

You can also complain to the Information Commissioner's Office if you are unhappy with how your personal information is handled.

Contact

Use the contact form on this site if you want to ask about this privacy notice or make a privacy request.