Privacy policy
Privacy policy
This is the policy that explains, plainly, what data JWA holds on your behalf when you\'re a client, why we hold it, how it\'s used, and how to ask for it back. This isn\'t legal review-grade copy yet — we\'re an in-progress founder business; please verify with your own counsel for final adoption.
What data we hold
When you sign up as a client we hold three categories of data:
- Account data — your name, business name, contact email, billing address (only what\'s needed to invoice you).
- Connected account tokens — OAuth tokens for the integrations you authorize (Google Search Console, Google Analytics, Google Business Profile, Meta, optionally Google Ads, Cal.com). Tokens are encrypted at rest. We never read your password for these services; OAuth means you authorise our app through Google / Meta etc. and revoke access the same way.
- Performance + business data — keyword rankings, backlink profiles, GBP insights, traffic estimates, social engagement, etc. We hold this on your behalf in our database so the dashboard can show you year-over-year history.
What we use it for
Three purposes only:
- To render your dashboard.
- To produce the work deliverables (GBP posts, outreach drafts, monthly reports) that you\'ve contracted us for.
- To invoice you.
We do not sell your data, rent it, share it with third parties for advertising purposes, or use it to train other businesses\' models on. The connected-account tokens are used only to make API calls back to those services on your behalf.
Retention
- Active client: data retained for the duration of the engagement + 30 days after termination (the data-export window per the contract terms).
- After the export window: business-name + anonymised aggregate snapshots may be retained for case-study purposes (you can opt out in the contract).
- Connected-account tokens: deleted within 7 days of contract termination.
Your rights
- Request a full data export at any time. We deliver within 14 days, in CSV + JSON format.
- Request deletion. We delete within 30 days, with the exception of records we\'re legally required to keep (invoices, accounting records — UK requires 6 years for VAT-registered businesses).
- Revoke Google / Meta OAuth tokens at any time from the dashboard or by asking us.
For any of these, email [email protected].
Lawful basis (UK GDPR)
The UK GDPR requires us to declare our lawful basis for processing. We rely on contract (the engagement contract you\'ve signed with JWA) for performance and deliverables, and on legitimate interest for invoice / accounting record-keeping. Marketing emails would be consent — but we don\'t send marketing emails outside of operational service updates.
Cookies
The dashboard uses a single first-party session cookie for authentication. The marketing site uses no third-party trackers unless you explicitly opt into email capture.
Data Processing Agreement
If you need a DPA for your compliance programme (common with larger clients), email [email protected] and we\'ll send a signed copy within one business day.
This policy is a working draft and not yet legal review-grade. Verify with your counsel before relying on it.