Home / Privacy Policy
Your data, handled with care
Privacy Policy.
This policy explains what personal information we collect through this website and through working with us, why we collect it, and the rights you have over it.
Last updated: 2 August 2026
1. Who we are
This website is published by 3rd4 Public Relations, a public relations, communications and AI governance consultancy. In this notice, "we", "us" and "our" mean the company named in section 18, which is the data controller for the personal data described here.
For any question, request or complaint about personal data, email pr@3rd4.com.
2. What this notice covers
Two different things, and it is worth separating them:
- Visiting this website. Almost nothing. There is no account, no analytics and no tracking cookies.
- Enquiring about working with us. The brief you send, and the correspondence that follows.
Some things a privacy notice often has to cover simply do not happen here, and it is quicker to say so:
- There is no mailing list and we send no marketing.
- Nothing is bought or paid for on this website. There is no checkout and no payment processor. Where we go on to work together, fees are agreed in a separate written agreement.
- We do not take client material through this website. Work reaches us by referral and through industry contacts, and anything you send us for an engagement is handled under that agreement rather than through a form.
3. What you send us
We only collect what you choose to give us.
If you submit a brief through the contact form, we receive your first name, last name, email address, the topic you selected, and the message you typed. That is everything the form asks for and everything it sends. The form is submitted from your browser directly to our form provider, which emails it to us — so that provider also sees your IP address as part of receiving the submission. Nothing is stored on this website; there is no database behind it.
If you email us directly, or ask to book one of the sessions listed on the contact page, we hold whatever you put in that message: your name, your email address, your organisation if you mention it, and the substance of your enquiry, together with our reply.
Please do not send confidential, sensitive or special-category personal data by email unless it is genuinely necessary and we have agreed to receive it. Ordinary email is not a secure channel.
4. What the hosting collects automatically
Serving a web page requires the server to receive your request. Our hosting provider processes, in its logs:
- IP address.
- Browser, device and operating-system information.
- The page requested and the referring URL.
- Date and time of access.
- Server errors and security events.
This is standard infrastructure logging, used to keep the site running and secure. It may still be personal data even though it does not name you. We do not use it to build a profile of you, and we do not combine it with anything else.
5. If you arrive from the AI Human Proof assessment
We publish a free readiness assessment at aihumanproof.com. It runs entirely inside your own browser and sends us none of your answers.
There is one exception, and you trigger it. At the end of that report there is a
button through to our AI governance service. If you click it, the
web address you arrive on carries two things: your overall score as a
percentage, and a tag identifying which page you came from — for example
?utm_source=aihumanproof-assessment&score=38.
Being straight about what that means:
- What travels. One number, and the source tag. Nothing else.
- What does not. Your individual answers, the specific findings, your organisation's name and your sector all stay in your browser. We do not receive them and we have not built any way to.
- Where it lands. In our hosting provider's ordinary request logs, as every web address does, alongside the IP address that requested it. It is held for the short period described in section 11 and we do not export or copy it anywhere.
- Where it does not land. This site runs no analytics and no advertising pixel, so the score is not recorded in any analytics product. If that ever changes, we will configure it to strip the
scoreparameter before recording, and this section will say so. - What we do with it: nothing. No page on this site reads the number. It is not used to route your enquiry, to prioritise you as a lead, or to decide what we say to you — we do not connect it to anything. It sits in a log file and expires with it. If we ever start using it, that is a different activity and this section will say so before we do.
We will not widen this. Passing individual findings, your organisation's name or your sector through the address would turn a disclosed handoff into an undisclosed transfer of commercially sensitive information, and we are not going to do that. If you would rather not send the number at all, reach the service page through this site's own navigation instead of the button.
6. Cookies, fonts and tracking
This website sets no cookies. There is no analytics, no tag manager, no advertising pixel and no cross-site tracking, so there is nothing to consent to and no consent banner. The small notice you may see in the corner simply tells you this — it asks for nothing.
Our typefaces are served from our own domain, not from Google Fonts or any other third-party service. Loading a page here means your browser talks to this website and nobody else — no third party receives your IP address or anything else as part of rendering the site.
One small exception, stated so this notice stays exact: if you close the
"no tracking" notice, we remember that choice in your browser's own local storage
(under the key 3rd4.notice.v1) so it does not reappear on every
visit. That value is a single yes/no flag. It identifies nothing about you and it
never leaves your device.
7. Working with us as a client
If an enquiry becomes an engagement, we process more than the website collects.
Contract and correspondence. The names and contact details of the people we deal with, the scope agreed, and the correspondence around delivering it.
Material you give us for AI governance work. An audit or assessment means you send us material about your own systems — configurations, prompts, logs, policies, incident records, and sometimes screenshots or extracts that contain personal data belonging to your staff or customers. Where that material contains personal data, you are the controller of it and we process it on your instructions as your processor, under the terms of our engagement.
We use it only to carry out the work you asked for. It is seen only by the people working on your engagement. We do not use client material to train AI models, and we do not reuse one client's material for another's benefit.
None of that arrives through this website. There is no upload form and no client portal here — material reaches us directly, by whatever secure route we agree with you. How long we keep it, and when it is returned or destroyed, is set out in the written agreement covering the engagement, because it varies with the work and with what your own retention obligations require. You can ask us to delete it earlier.
Fees. Nothing is transacted on this website. We take no card details, and there is no payment processor involved in this site at all. Fees for an engagement are agreed in writing beforehand and invoiced directly. Where we invoice, the resulting accounting records are kept for the period UK company and tax law requires — see section 11.
8. Why we process it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Reading and replying to your enquiry, and arranging a consultation | Legitimate interests — responding to people who contact us — and, where you are asking us to quote or scope work, steps taken at your request before entering a contract |
| Delivering an engagement you have signed up to | Performance of a contract |
| Keeping accounting and tax records | Legal obligation |
| Running, securing and troubleshooting this website | Legitimate interests — maintaining a reliable and secure service |
| Preventing spam, abuse, fraud and security incidents | Legitimate interests, and legal obligation where one applies |
| Establishing, exercising or defending legal claims | Legitimate interests, and legal obligation where one applies |
Where we rely on legitimate interests, we have considered whether those interests are proportionate and whether your rights override them.
There is no row above for marketing, because we do not do any. We have no mailing list, we run no newsletter, and we will not add you to one because you sent us a brief.
9. Who else sees it
A small number of suppliers, acting as our processors:
- Website hosting. Vercel Inc., which serves this site and keeps the request logs described in section 4. See the Vercel Privacy Notice.
- Contact form delivery. Web3Forms, and only for the contact form — it is used nowhere else on this site. It receives the submission from your browser and emails it to us. It relays the message; we keep no copy here, and we do not use it to store or market to you. It holds its own sending records for its own operational purposes, under the Web3Forms privacy policy.
- Email in transit. Team Blue Internet Services UK Limited, trading as names.co.uk and hosts.co.uk, which receives mail sent to our address and passes it on. See the names.co.uk privacy policy.
- Where enquiries are read and kept. Google, whose mailbox the correspondence is forwarded into and held in, and where our replies are written. See the Google Privacy Policy.
These providers process information only to deliver their service to us, under contract. Our typefaces are not among them: they are served from this site's own domain rather than a font service, so no third party takes any part in rendering a page — see section 6.
We may also disclose information where the law, a court, a regulator or another competent authority requires it, or where it is reasonably necessary to establish, exercise or defend a legal claim.
We do not sell personal data and we do not give it to advertisers.
10. Transfers outside the UK
Some of our suppliers are outside the United Kingdom. Rather than assert a mechanism on their behalf, here is what each of them publishes:
Vercel Inc. is a United States company, so serving this site involves transferring the log data in section 4 outside the UK. Vercel states in its own privacy notice that it complies with the EU–U.S. Data Privacy Framework, the UK Extension to it and the Swiss–U.S. framework, and that it otherwise uses standard contractual clauses or another appropriate legal mechanism.
Google states that Google LLC complies with the EU–U.S. and Swiss–U.S. Data Privacy Frameworks and the UK Extension to the EU–U.S. DPF, and that it relies on standard contractual clauses where a transfer is not covered by an adequacy decision. That covers both the mailbox in section 9 and the font requests in section 6.
Team Blue Internet Services UK Limited is a UK-established company, and transfers it makes are governed by its own privacy notice, linked above.
11. How long we keep it
| Information | Kept for |
|---|---|
| Contact form submissions | Not retained by this website. Once emailed, the message lives in our mailbox and is kept on the same basis as any other correspondence. |
| Enquiry correspondence and our replies | 24 months after our last contact, unless we go on to work together, in which case the engagement record applies instead. |
| Client engagement files, including AI governance material | For the engagement, and afterwards for the period set out in the written agreement covering it. Not collected through this website. Deleted earlier on request. |
| Accounting and tax records, including invoices | Six years from the end of the financial year they relate to, as UK company and tax law requires. |
| Request and security logs, including any score parameter in the address | A short period set by the hosting platform, not by us. Vercel documents runtime log retention of one hour on its Hobby plan and one day on Pro. We do not extend it, export it or copy it anywhere. |
We may keep something longer where a legal obligation, an unresolved dispute or a security investigation requires it. You can ask us to delete your data sooner at any time, and we will unless one of those applies.
12. Security
We use proportionate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. The site is served over HTTPS, and the contact form carries a spam trap so that automated submissions are discarded rather than emailed on.
No system is completely secure, and ordinary email in particular is not. Do not send us anything highly confidential by email — for governance engagements we will agree a suitable channel with you.
13. Your rights
Under UK data protection law you have the right to:
- Be told how your data is used — this notice.
- Ask for a copy of the personal data we hold about you.
- Ask us to correct anything inaccurate or incomplete.
- Ask us to delete it.
- Ask us to restrict how we use it.
- Object to our use of it where we rely on legitimate interests.
- Receive the data you gave us in a portable format, where we hold it on the basis of your consent or a contract with you.
- Withdraw consent at any time, where we have asked for it. Withdrawing does not affect anything done beforehand.
- Complain about how it has been handled.
These rights carry conditions and exemptions in the legislation. Where we hold material as a processor for a client, requests about that material are for the client as controller to answer — tell us and we will pass it on promptly.
To exercise a right, email pr@3rd4.com. We may need enough information to be satisfied of your identity. We will respond within one month.
14. Complaints
Please raise it with us first — it is usually quicker. You also have the right to complain to the UK Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
ico.org.uk
15. Children
This website and our services are directed at organisations and professional users. They are not aimed at children, and we do not knowingly collect personal data from them.
16. Other sites we link to
We link out to other websites, including aihumanproof.com, where our AI Human Proof standard and its readiness assessment are published. We are not responsible for the privacy practices of sites we link to. Where a link carries information with it, we say so — see section 5.
17. Changes to this notice
If what we do changes, this notice changes with it, and the date at the top changes too. The current version is always the one on this page.
18. Contact us
For any question, request or complaint about personal data, email pr@3rd4.com, or write to us at 3rd Dimension Media (3rd4) Ltd, Sandfield House, St Albans, Hertfordshire AL1 4JZ, England. Registered in England and Wales, company number 06752007. Trading as 3rd4 Public Relations.