1. Who we are
TRACIO ("we", "us", "our") is an independent advisory practice specialising in real-time location systems (RTLS), RFID, IIoT, and applied AI.
The data controller for personal data submitted through tracio.com is TRACIO LIMITED, a private limited company registered in England and Wales (company number 17236113), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. TRACIO LIMITED is registered with the UK Information Commissioner's Office (ICO) under registration number ZC261443. Further company details are on our Imprint page.
2. What personal data we collect
We collect only what is needed to respond to enquiries, deliver our services, and operate the website:
- Contact-form submissions: name, work email, optional phone number, company, job title, country/region, industry, project context you choose to share, and your message.
- Download forms: work email (required), first name and company (optional), which download you requested, the page you requested it from, and whether you asked for a follow-up email.
- Ad and campaign details: if you reach our site through an ad, the ad click identifier in the page address (gclid, gbraid or wbraid from Google, msclkid from Microsoft) and the UTM campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) are stored with your enquiry for attribution, so we know which ad or campaign it came from. The address of the site that sent you to us (its host name only, for example a search engine or an AI assistant) is stored with your enquiry in the same way. If you book a call, these values go to Cal.eu with the booking. If you have rejected cookies, no ad click identifier is stored with your enquiry or sent with a booking; the UTM parameters and the referring site still are. We store them with your details only when you send a form or book; until then our own copy stays in your browser, for the current tab. As part of the page address, they also reach Google and Microsoft with each page view, as set out in the Google and Microsoft items of this policy.
- Email correspondence: the content of any messages you send us and the metadata that comes with them.
- Engagement data: for active clients, the information needed to deliver the engagement (project documents, technical environment details, stakeholders).
- Technical data: IP address, user agent, language preference, pages visited, referrer. Stored briefly in server logs and used for security and basic operational analytics.
- Cookies: see our Cookie Policy.
3. Why we use it (lawful basis under GDPR Art. 6)
- Legitimate interests (Art. 6(1)(f)): responding to your enquiry, providing requested information, securing the website, and improving our services.
- Performance of a contract (Art. 6(1)(b)): once you become a client, processing necessary to deliver the agreed engagement.
- Consent (Art. 6(1)(a)): for non-essential cookies and any marketing communications you specifically opt in to.
- Legal obligation (Art. 6(1)(c)): tax records, statutory accounting, regulatory requirements.
4. Who we share it with
We do not sell personal data. We share it only with:
- Sub-processors needed to operate the site and our business: Microsoft 365 (email and file storage), GoDaddy (our Microsoft 365 reseller, domain registrar and DNS host), Netlify (website hosting, including form handling), Cal.eu (meeting booking) and our accounting software provider.
- HubSpot (our CRM): when you submit the contact form, the newsletter signup or one of the resource download forms (buyer’s guide, procurement templates, checklists and workbooks), the details you submit, together with the address and title of the page, are sent to HubSpot’s form interface (api-eu1.hsforms.com, with api.hsforms.com as a fallback) and are also submitted through the form-handling service of our hosting provider, Netlify, Inc. (United States), which keeps a copy of each submission as a backup. This happens whatever your cookie choice. HubSpot’s tracking script (js-eu1.hs-scripts.com) loads only if you accept analytics or marketing cookies; it sets the cookies listed in our Cookie Policy. HubSpot may process this data in the EU and the US; transfers are covered by Standard Contractual Clauses.
- Google (Google Ireland Limited; processing also by Google LLC in the United States): our pages load the Google tag for Google Analytics 4 and Google Ads conversion measurement only after you accept analytics or marketing cookies; until then, Google Consent Mode v2 keeps everything denied by default. If you accept analytics or marketing cookies, Google receives the page address and referrer, your IP address, device and browser details and a pseudonymous cookie identifier. If you decline, the Google tag does not load. Ad personalisation and remarketing are switched off. See our Cookie Policy. Transfers to the US are covered by Google’s certification under the EU-US Data Privacy Framework and by Standard Contractual Clauses.
- PostHog (PostHog Inc.; EU cloud at eu.i.posthog.com): only if you accept analytics cookies, our pages load PostHog for product analytics and session replay (form inputs masked). See our Cookie Policy.
- Microsoft Advertising (Microsoft Ireland Operations Limited; processing also by Microsoft Corporation in the United States): only if you accept marketing cookies, our pages load Microsoft’s UET tag (bat.bing.com); until then, Microsoft’s consent mode stays set to denied. If you accept marketing cookies, Microsoft receives the page address and referrer, your IP address, device and browser details and cookie identifiers, and records whether a visit from one of our Microsoft or Bing ads led to an enquiry. Microsoft may also use this data to show TRACIO ads to people who have visited our site. If you decline, the tag does not load. See our Cookie Policy. Transfers to the US are covered by Microsoft’s certification under the EU-US Data Privacy Framework and by Standard Contractual Clauses.
- LinkedIn (LinkedIn Ireland Unlimited Company; processing also by LinkedIn Corporation in the United States): only if you accept marketing cookies, our pages load the LinkedIn Insight Tag (snap.licdn.com). LinkedIn then receives the page address and referrer, your IP address, device and browser details and cookie identifiers, which LinkedIn can match to its members. We use it to measure our LinkedIn ads and to see anonymous, aggregated statistics about visitors (such as industry or job function). LinkedIn may also use this data to show TRACIO ads to people who have visited our site. For collecting this data and using it for ads, we and LinkedIn are joint controllers under LinkedIn’s joint controller terms, and you can exercise your rights with either of us. If you decline, the tag does not load. See our Cookie Policy. Transfers to the US are covered by LinkedIn’s certification under the EU-US Data Privacy Framework and by Standard Contractual Clauses.
- Authorities where legally required (subpoena, regulator request, fraud investigation).
We do not transfer personal data to third countries without appropriate safeguards (Standard Contractual Clauses or an adequacy decision).
5. How long we keep it
- Contact form enquiries: 24 months from last interaction, then deleted unless an active engagement starts.
- Financial and contract records (contracts, invoices and payment records): for the duration of the engagement and 7 years after it ends, for statutory accounting and HMRC requirements.
- Client project documents (for example drawings, technical environment details and stakeholder notes): for the duration of the engagement and 12 months after it ends, unless the contract says otherwise, then deleted.
- Download-form requests: 24 months from last interaction, then deleted.
- Server logs: 90 days rolling.
- Marketing-consent records: until you withdraw consent.
6. Your rights
Under GDPR / UK DPA you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request erasure (the "right to be forgotten") subject to legal retention obligations.
- Restrict or object to processing.
- Data portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time.
- Complain to a supervisory authority (e.g. the UK ICO, your national DPA, or the data protection authority of the EU member state where you live or work).
To exercise any of these rights, email our privacy contact at hello@tracio.com. We will respond within one month.
7. Security
Our email and documents are held in Microsoft 365, which Microsoft encrypts at rest; website form submissions are held by HubSpot and Netlify as described in section 4. Connections to Microsoft 365 and to tracio.com use TLS. Access is limited to the people who need it, multi-factor authentication (Microsoft Authenticator) is required on all TRACIO accounts, our devices lock automatically when left idle, and we review our list of sub-processors at least once a year. We carry out project work ourselves, including RF site surveys and on-site installation. On some projects we may bring in a delivery partner, only with the client’s written agreement and under a written contract with confidentiality, data protection and security terms. We do MES, WMS and OPC UA integration only together with the client’s IT and OT team and under the client’s change control, we do not run client production systems day to day, we have no access to client systems unless a client grants it for a project, and we never process patient data.
No system is perfectly secure; if a breach occurred we would notify affected parties and supervisory authorities within the legally required timeframes.
Reporting a security issue
If you think you have found a security vulnerability on tracio.com, email security@tracio.com with a description, the affected page and the steps to reproduce it. Please do not access, change or delete other people's data, do not disrupt the site (for example with denial-of-service tests or heavy automated scanning), and give us reasonable time to fix the issue before sharing details publicly. We will acknowledge your report and keep you informed. Our contact details for security researchers are also published in security.txt.
8. Children
TRACIO services are B2B. We do not knowingly collect personal data from anyone under 16.
9. Changes
If we change this policy materially, we will update the effective date and, where appropriate, notify clients directly. Continued use of the site after a change indicates acceptance.
10. Contact
Privacy contact: hello@tracio.com
Legal enquiries: legal@tracio.com
Security disclosure: security@tracio.com · security.txt
General: hello@tracio.com
Last updated: