Privacy Policy

Effective: 09/04/2026 · Last updated: 25/09/2026

In plain English

We collect only the personal data we need to provide our services and run our business. If you work at a business we think we could help, we may email you once or twice about our services, using contact details we found publicly — tell us to stop and we will, straight away and for good. We don't sell your data, we don't use it for advertising, and we share it only with the service providers named in section 5 below, who help us run this website and our services. You have the right to access, correct, or delete your data at any time.

This summary is provided for convenience only. The full legal terms below take precedence in all cases.

1. Who We Are

1.1 Geeky Code Ltd ("Company", "we", "us", or "our") is a company registered in England and Wales (Company Number: 12200751), with its registered office at 24 Downsview, Chatham, Kent, ME5 0AP, United Kingdom. We are the data controller for the personal data described in this policy.

1.2 If you have any questions about this Privacy Policy or how we handle your data, you can contact us at: hello@geekyco.de

2. What Data We Collect

2.1 Account Information – When you sign up for one of our services, we collect your name, email address, and any other information you provide during registration.

2.2 Payment Information – If you subscribe to a paid service, payment details are collected and processed by our payment provider, Stripe. We do not store your full card details on our systems.

2.3 Usage Data – We collect information about how you interact with our services, including login times, features used, and service interaction logs. This helps us maintain and improve our services.

2.4 Communications – If you contact us by email or through our website, we keep a record of that correspondence. The contact form on this website collects your name, email address, company (optional) and message, and delivers them to our mailbox by email, sent through Amazon Simple Email Service (AWS).

2.5 Cookies – We use only essential cookies as described in our Cookie Policy. We do not use analytics, marketing, or advertising cookies.

2.6 Website analytics – This website uses Umami, a privacy-focused analytics tool that we host ourselves on our own servers with Hetzner in Germany. It sets no cookies and does not store your IP address. It records pages viewed, the referring site, and your browser, operating system, device type and country, and we only look at the results in aggregate. No analytics data is shared with any third party.

2.7 Spam and bot protection – The contact form and the Ned Lasso page use Cloudflare Turnstile to check that a visitor is human. When those pages load, your browser connects to Cloudflare, which processes technical information such as your IP address and browser characteristics to make that check. Cloudflare's handling of this data is described in its privacy policy.

2.8 Ned Lasso – Ned Lasso asks you to choose a job and a task from fixed lists. Those two choices are sent to OpenAI to generate the pep talk, and are stored with the result so the same request can be answered again. Nothing that identifies you is sent or stored.

2.9 Business contact details – If you work at a business we think could benefit from our services, we may collect your name, job title, work email address and the name of your organisation from publicly available sources, mainly your organisation's own website. We only contact people at incorporated organisations, such as limited companies and LLPs, and never sole traders or partnerships without their consent. We do not buy contact lists. If you tell us you do not want to hear from us, we keep your email address on a suppression list so that we never contact you again.

3. How We Use Your Data

We process your personal data for the following purposes:

  • To provide, operate, and maintain our SaaS services.
  • To manage your account and process payments.
  • To communicate with you about your account, service updates, or support requests.
  • To reply to enquiries you send us through our website or by email.
  • To contact people at businesses by email about services of ours that are relevant to their role.
  • To understand, in aggregate, how our website is used, so we can improve it.
  • To detect, prevent, and address security issues or technical problems.
  • To comply with legal obligations.

We only send marketing emails to people in their capacity at a business, and only about services relevant to their role. We never send unsolicited marketing to individuals in a personal capacity, and we do not use data from our SaaS services, website analytics or Ned Lasso for marketing.

Under the UK GDPR, we rely on the following lawful bases to process your personal data:

  • Contract – Processing is necessary to perform our contract with you (i.e., to provide our services).
  • Legitimate interests – Processing is necessary for our legitimate business interests, such as improving our services and website, answering enquiries, contacting businesses about services relevant to them, and protecting our website from spam and abuse, provided these interests do not override your rights.
  • Legal obligation – Processing is necessary to comply with a legal obligation to which we are subject.
  • Consent – Where we rely on consent, you have the right to withdraw it at any time.

5. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We share data only with the following recipients, and only as necessary to run this website and provide our services:

RecipientPurposeLocation
Hetzner Online GmbHInfrastructure and data hostingGermany (EU)
Amazon Web Services (AWS)Cloud infrastructure services, and sending contact-form emails (Amazon SES)EU/UK regions
StripePayment processingUnited States (with EU/UK safeguards)
Cloudflare, Inc.Spam and bot protection on website forms (Turnstile)United States (with EU/UK safeguards)

For full details of the sub-processors we use to deliver our SaaS services, see our Data Processing Agreement.

6. International Data Transfers

6.1 Your data is primarily stored in data centres within the EU and UK.

6.2 Where personal data is transferred outside the UK or EEA (for example, to Stripe or Cloudflare in the United States), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or reliance on an adequacy decision.

7. How Long We Keep Your Data

7.1 We retain your personal data only for as long as necessary to provide our services and fulfil the purposes described in this policy.

7.2 Upon termination of your account, we will delete or anonymise your personal data within 90 days, unless retention is required by law.

7.3 Business contact details collected under section 2.9 are deleted 12 months after we last contacted you if you have not replied, unless you become a client or ask us to stay in touch.

7.4 If you ask us not to contact you again, we keep your email address on our suppression list indefinitely. This is the only way to make sure you are never contacted again.

7.5 You may request early deletion of your data at any time by contacting us.

8. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access – You can request a copy of the personal data we hold about you.
  • Right to rectification – You can ask us to correct inaccurate or incomplete data.
  • Right to erasure – You can ask us to delete your personal data (the "right to be forgotten").
  • Right to restrict processing – You can ask us to limit how we use your data.
  • Right to data portability – You can request your data in a structured, commonly used format.
  • Right to object – You can object to processing based on legitimate interests. You can object to direct marketing at any time and for any reason; this right is absolute, and replying to any of our emails asking us to stop is enough.

To exercise any of these rights, please contact us at hello@geekyco.de. We will respond within one month, as required by law.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Security

9.1 We implement appropriate technical and organisational measures to protect your personal data, including encryption of data in transit and at rest, access controls, and regular security monitoring.

9.2 In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, notify you without undue delay.

10. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.

12. Governing Law

This Privacy Policy is governed by the laws of England and Wales.