Legal
Privacy Policy
This policy explains what ED Consulting Group collects when you use this site, why we collect it, who processes it on our behalf, and the rights you have over it.
Effective 2026-08-24
Who we are
ED Consulting Group is the controller responsible for the personal information described here. You can reach us about anything on this page at privacy@edcogroup.io.
What we collect
We collect two kinds of information.
Information you give us. When you use the assistant or the contact form, that means your name, email address, phone number, company, and whatever you choose to write about your project. You decide how much to share, though we cannot respond without a way to reach you.
Information collected automatically. When you use the assistant or submit an enquiry we record your IP address, browser, operating system, device type, referring page and language. We use this to understand where enquiries come from, to keep the forms free of abuse, and as a secondary signal that helps confirm a returning visitor. We do not use it to track you across other websites or to build an advertising profile.
An identifier stored in your browser. So the assistant can recognise you and continue an earlier conversation on this device, it stores one small random value in your browser and sends it back to us. It has no meaning on its own, is never shared with anyone else, and you can remove it at any time by clearing your browser storage for this site, which makes the device anonymous to us again.
We do not collect special category data, and we ask that you do not send it.
Why we use it, and our legal basis
We use what you give us to answer your enquiry, prepare a proposal, and stay in contact about the work you asked about.
Where the GDPR applies, our legal basis is legitimate interests: you contacted a consulting firm to ask about services, and replying is the reason you got in touch. Where consent is required for marketing that goes beyond answering your enquiry, we ask for it separately and you can withdraw it at any time.
We do not use your information for automated decision-making that produces legal or similarly significant effects.
The assistant on this site
The chat assistant is powered by Anthropic's Claude API. The messages you type are sent to Anthropic to generate a reply, and are stored by us so we can follow up on the conversation. Do not paste credentials, customer data, or anything confidential into it.
Anthropic processes this content as our service provider under its commercial terms and does not use it to train its models.
Recognising you when you return
To make the assistant more useful, it can recognise you on a later visit and briefly recall your earlier conversation instead of starting from nothing. It does this primarily through the identifier stored in your browser, which reliably identifies the same device. If you have shared your email address, that lets us recognise you across your own devices as well.
IP address and device details are used only to help confirm a match, never on their own, precisely so that one person's conversation is never shown to a different person who happens to share a network. Your stored contact details and conversations are matched only to you.
Where the GDPR applies, our legal basis for this is legitimate interests in giving you a coherent, helpful experience. You can opt out at any time by clearing the identifier in your browser, or by asking us to delete what we hold, and the assistant will simply treat you as a new visitor.
Who else processes your information
We keep the list of processors short and name all of them:
- Google Cloud, hosting, database and network infrastructure, United States.
- Anthropic, the language model behind the site assistant, United States.
- Brevo, delivery of the notification email that reaches our team, European Union.
Each acts on our instructions under a data processing agreement. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
International transfers
Our infrastructure runs in the United States. If you contact us from outside the United States, your information is transferred there. Where the GDPR or UK GDPR applies, those transfers rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, held with each processor named above.
How long we keep it
Enquiries and the contact details attached to them are kept for 730 days from your last contact with us, then deleted automatically. Assistant conversations are deleted after 180 days. The returning-visitor record, meaning the identifier and any name or email attached to it, is deleted 730 days after your last visit, and the device becomes anonymous to us again. Where an enquiry becomes an engagement, the associated records are kept for as long as the contract and our tax and professional obligations require.
Deletion is enforced by a scheduled job, not by hand, so it happens whether or not anyone remembers.
Cookies and browser storage
This site sets no advertising or analytics cookies. A single essential cookie is used only when an administrator signs in. The assistant stores one small identifier in your browser so it can recognise you and continue an earlier conversation on this device; you can clear it any time through your browser, and doing so makes this device anonymous to us again.
We show no cookie banner because we run no advertising or analytics tracking, and there is nothing about you being sold, shared or profiled for marketing. The one identifier we do store exists solely to let the assistant continue your own conversation, and clearing your browser storage for this site removes it and any effect it has.
If you would rather we did not recognise you between visits at all, clear that storage, use a private window, or email privacy@edcogroup.io and we will delete the record at our end. Nothing about the site stops working if you do.
Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. We will not treat you differently for asking.
If you are in the European Economic Area or the United Kingdom, you also have the right to restrict or object to processing, the right to data portability, and the right to complain to your local supervisory authority.
If you are a California resident, you have the right to know what we collect and why, the right to delete, the right to correct, and the right to opt out of sale or sharing. As stated above, we do neither, so there is nothing to opt out of.
To exercise any of these, email privacy@edcogroup.io. We answer within 30 days and may ask you to confirm your identity first so we do not disclose your information to someone else.
How we protect it
We hold personal information to a level of security appropriate to its sensitivity. The site is served over HTTPS only, with HSTS and a strict content security policy, and data is encrypted in transit and at rest.
On top of the encryption our hosting provides, the most sensitive fields, your name, email, phone number, the details you write to us, and your assistant conversations, are encrypted again by us at the application level with AES-256-GCM before they are written to the database. The key is held separately in a managed secrets service and is never stored in the database, so a copy of the database alone cannot reveal that content.
Access to the admin panel and the database is limited to authorised people on a least-privilege basis, protected by passwords stored as salted scrypt hashes. Sessions can be revoked centrally, and administrative activity is logged so access can be reviewed.
Every processor we use maintains its own recognised security programme, such as SOC 2 or ISO 27001, and we only work with providers that commit to those standards in writing under a data processing agreement.
No system is perfect. If you believe you have found a vulnerability, please write to us at privacy@edcogroup.io before disclosing it publicly, and we will work with you.
If there is a breach
If a security incident affects your personal information and is likely to create a risk to your rights, we will notify the relevant supervisory authority without undue delay, and within 72 hours where the GDPR requires it.
Where the risk to you is high, we will also contact you directly, explain what happened, what we are doing about it, and the steps you can take to protect yourself.
Children
This site and its services are meant for businesses and the professionals who run them. They are not directed to children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, contact us at privacy@edcogroup.io and we will delete it.
Changes
If we change this policy we will update the effective date above. If the change materially affects how we use information you already gave us, we will contact you about it rather than rely on you rereading this page.