Who we are
ToJupiter Limited ("ToJupiter", "we", "our", "us") is the data controller for the personal data described in this policy.
- Company number 16132539, registered in England
- Registered address: 86-90 Paul Street, London, Greater London, EC2A 4NE, United Kingdom
- VAT number GB483191282
- Email: hello@tojupiter.com
- Website: tojupiter.com
This policy explains what we do with your personal data when you visit tojupiter.com or get in touch with us. We handle personal data in line with UK GDPR and the Data Protection Act 2018.
What we collect
Information you give us. When you submit the Book a call form, we collect your first name, last name, email address and anything you write in the message field. If you email us or speak to us, we collect whatever you choose to share, which in a business context usually means your name, company, role and contact details.
Information our web server records. Like any website, our hosting provider keeps standard server logs. These include your IP address, browser and device type, the pages requested and the time of the request. We use these to keep the site running and secure, not to profile you.
Information from cookies, but only if you allow it. If you accept analytics or marketing cookies, our measurement tools record how you use the site: the pages you view, how you arrived, the approximate area you are in, and the device and browser you use. If you decline, none of that is collected. See the cookies section below.
How we use it, and our legal basis
Under UK GDPR we must have a lawful basis for using your personal data. Ours are:
- Responding to your enquiry and discussing working together. Legal basis: legitimate interests (replying to a business enquiry you started), and where relevant, taking steps at your request before entering into a contract.
- Providing our services and managing our relationship with clients. Legal basis: performance of a contract.
- Sending marketing emails, such as our demand generation learnings. Legal basis: your consent, or our legitimate interests where you are an existing client and the content is closely related to what we already do for you. You can opt out at any time, using the unsubscribe link in any email or by emailing us.
- Keeping the website available, secure and free of abuse. Legal basis: legitimate interests.
- Meeting our legal, tax and accounting obligations. Legal basis: compliance with a legal obligation.
Cookies and tracking
We use Google Tag Manager to load our measurement and advertising tags. It runs with Google Consent Mode, which means every non-essential cookie is switched off until you choose. On your first visit a banner asks what you allow. Nothing analytics or advertising related runs before you answer, and if you decline, none of it runs at all.
There are three categories:
- Essential. Always on. These make the site work and remember the choice you made here. They do not track you. Your cookie choice is stored in your browser's local storage rather than in a cookie, so declining genuinely leaves nothing behind.
- Analytics. Which pages get read, how people arrive and where they drop off, so we can make the site better.
- Marketing. Lets us measure how our advertising performs and show relevant ads on other platforms. These are the cookies that can follow you across websites.
The tools we load through Google Tag Manager are:
- Microsoft Clarity (analytics). Records how visitors move through the site, as heatmaps and session replays, so we can see which pages confuse people. Sensitive content and form fields are masked.
- HubSpot (analytics). Our CRM. Its tracking script connects your visit to your record if you contact us.
- Snitcher (marketing). Looks up your IP address to work out which company you are visiting from, so we know which businesses are researching us. It identifies organisations, not individuals.
- Google (analytics and marketing). Google Tag Manager loads the tools above, and we may use Google's own analytics and advertising tags.
None of this loads until you allow it. Google Tag Manager itself is not placed on the page until you accept analytics or marketing, so if you reject, none of these tools load and nothing is sent to any of them. The set of tools may change over time, but the categories and this rule will not.
You can change your mind at any time using the "Cookie settings" link in the footer of every page.
Separately, and regardless of your cookie choice, if you already have a HubSpot tracking cookie on your device, the Book a call form will read it when you submit the form so that HubSpot can connect your enquiry to any earlier contact with us. If that cookie is not there, nothing is read.
Who we share it with
We do not sell your personal data, and we do not share it for anyone else's marketing. We share it only with providers who help us run our business, and only so far as they need it:
- Google. Google Tag Manager loads our measurement and advertising tags. If you allow analytics or marketing, Google receives information about your visit, including your IP address, through those tags. If you decline, Google Tag Manager is never loaded and no data is sent.
- Microsoft. If you allow analytics, Microsoft Clarity receives a recording of how you used the site, along with your IP address, browser and device.
- Snitcher. If you allow marketing, Snitcher receives your IP address in order to identify the company you are visiting from.
- HubSpot. Our CRM. Enquiries submitted through the Book a call form are stored here, along with any marketing preferences. If you allow analytics, HubSpot's tracking script also records your visit.
- Our calendar booking provider. After you submit the form we send you to a booking page to choose a time. Your name, email and chosen slot are processed there so we can create the meeting.
- Our hosting provider. Serves the website and keeps the server logs described above.
- Professional advisers and authorities. Where we are required to share information by law, or need to establish, exercise or defend legal claims.
If ToJupiter is ever involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction. We would tell you before your data became subject to a different privacy policy.
Sending data outside the UK
Some of our providers, including Google and HubSpot, are based in the United States. Where your personal data is transferred outside the UK, we rely on the safeguards allowed under UK data protection law. In practice that means transferring to a country the UK has deemed adequate, to an organisation certified under the UK Extension to the EU-US Data Privacy Framework, or under an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
How long we keep it
We keep enquiry and CRM records for as long as we are in contact with you about working together, and for up to 24 months after our last meaningful contact, unless you ask us to delete them sooner.
Where you are or have been a client, we keep records for as long as we need them for the relationship, and then for as long as we are legally required to, which for tax and accounting records in the UK is generally six years.
Server logs are kept for a short period for security and troubleshooting, and are then deleted or overwritten by our hosting provider.
Your rights
Under UK data protection law you have the right to:
- Ask for a copy of the personal data we hold about you
- Ask us to correct data that is wrong or incomplete
- Ask us to delete your data
- Ask us to restrict how we use your data
- Object to our use of your data where we rely on legitimate interests
- Object to direct marketing at any time. This one is absolute, and we will always act on it
- Ask us to transfer your data to you or another provider
- Withdraw your consent at any time, where we rely on consent
To exercise any of these, email hello@tojupiter.com. We will respond within one month. You will not have to pay a fee.
If you are not happy with how we have handled your data, you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to sort it out first.
How we protect it
The website is served over HTTPS. Access to our CRM is restricted to the people who need it and protected by strong authentication. We use reputable providers who maintain their own security controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take it seriously and we will tell you and the ICO about a breach where the law requires it.
Links to other websites
Our website links to other sites, including LinkedIn and, on our articles, optional links that open the article in an AI assistant. Following those links takes you to services with their own privacy policies, and we are not responsible for how they handle your data.
Children
Our services are aimed at businesses, not individuals under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will change the "last updated" date at the top of this page. If the change is significant, we will make that clear.
Contact us
Questions about this policy, or about your data, go to hello@tojupiter.com, or write to ToJupiter Limited, 86-90 Paul Street, London, EC2A 4NE, United Kingdom.