Legal
Privacy Policy
This policy explains what personal data AIM collects, why, and what your rights are. Short version: we collect the minimum needed to reply to you and deliver what you asked for, we never sell data, and you can see, correct or delete yours at any time.
Last updated: 1 July 2026
Who we are
AIM, AI-Powered Marketing Systems is a UK-based sole-trader business. For anything data-related, contact steffinxavier.work@gmail.com.
What we collect and why
Forms (audit, contact, guides, waitlist): name, email, website/Instagram, country and your message, used solely to deliver what you requested (audit findings, replies, downloads) and, where you've ticked the consent box, occasional useful emails.
Booking: when you book a call via Cal.com, they process your name, email and timezone under their own privacy policy.
Analytics: only after you accept cookies, we use Google Tag Manager / GA4 to understand how the site is used (pages visited, actions taken). Decline and no analytics run at all.
WhatsApp: if you message us, WhatsApp/Meta processes that data under their terms; we see your number and message.
Legal bases
Consent, for marketing emails and analytics cookies (both opt-in, both revocable).
Legitimate interest / pre-contract steps, replying to enquiries and delivering audits you requested.
Where your data lives
Form submissions are delivered to our email and stored in our email marketing tool (MailerLite or Brevo, EU-hosted options, GDPR-compliant processors). We don't sell or rent personal data to anyone, ever.
How long we keep it
Enquiries: up to 24 months after last contact, then deleted. Marketing list: until you unsubscribe (every email has a working one-click unsubscribe). Analytics: standard GA4 retention (14 months).
Your rights
You can request access, correction, deletion, or a copy of your data, and withdraw consent, at any time, email steffinxavier.work@gmail.com and it's handled within 30 days. You can also complain to the ICO (ico.org.uk) if we get it wrong.
International visitors
AIM serves clients worldwide. Data is processed in the UK/EU where possible; where a processor operates elsewhere, it's under standard contractual safeguards.
