Legal

Privacy notice

This notice explains how Software Systems Limited, trading as TallTree® Technologies (“we”, “us”), handles personal data collected through talltree.tech. Software Systems Limited is the data controller. It is written to comply with the UK GDPR and the Data Protection Act 2018.

What we collect

  • Contact form. Your name, email, company (optional), and your message.
  • Mailing-list signup. Your email address only.
  • Call bookings. When you book a call through our Cal.com booking page, we receive your name, email, the time you picked, and any note you include with the booking.
  • Purchases. The Readiness Snapshot is paid on Stripe’s own checkout pages. Stripe reports your name, email, and billing details to us; your card details never touch our systems.
  • Campaign attribution. If you arrived via a campaign link (utm_*, gclid, or ref parameters), the site remembers those parameters and your landing page for the duration of your browser session, and attaches them — along with the page the form was on — to form submissions and analytics events, so we know which campaign brought an enquiry. The mechanics are on the cookies & website storage page.

Form submissions travel through a relay we run on Cloudflare (mayo.talltree.tech), which emails them to our inbox and records them — including mailing-list confirmations — in our Cloudflare-hosted database, so we can answer follow-ups and honour deletion requests. Retention follows the periods below.

Analytics and security monitoring

  • PostHog product analytics runs in cookieless mode: page views, clicks on key buttons and forms, and clicks on links that leave the site (we record the destination address and the page you clicked from — nothing about what you do after leaving). Events carry the page path and campaign parameters where present and travel first-party via ketchup.talltree.tech (a PostHog-managed proxy on our domain) to PostHog’s EU cloud. No cookies, no cross-site tracking, no fingerprinting.
  • Short links (go.talltree.tech). Links we share off-site — on LinkedIn, in newsletters, in email — pass through our own shortener. Clicking one records the link name, the destination, the referring page where your browser sends one, campaign parameters and your coarse country (never your IP address) to the same cookieless analytics, then redirects you. No cookies are set.
  • Security reports. Browsers send Content-Security-Policy and network-error reports to URIports (talltree.uriports.com) so we can spot attacks and breakage. These reports can include IP-derived metadata.
  • Google measurement (cookieless, consent denied). To measure our Google Ads campaigns we run Google’s tag (Google Analytics 4, linked to our Ads account) with its consent state permanently set to denied: it sets no cookies, uses no browser storage, and sends only anonymous, consent-flagged pings that Google uses for aggregate and statistically modelled campaign measurement. The tag and its pings stay on our domain (relish.talltree.tech, a proxy we operate on Cloudflare); your browser never connects to Google, and the proxy strips your IP address before relaying, so Google does not receive it. No remarketing and no ad personalisation are enabled. Details are on the cookies & website storage page.

We use analytics in aggregate — which pages are read, which buttons work, which campaigns bring visitors. There are no cross-site trackers on this site, nothing here builds an advertising profile of you, and we never sell data.

Why we collect it

  • Legitimate interest — responding to inbound business enquiries, understanding (in aggregate) which pages and campaigns work, and keeping the site secure. When you contact us or buy from us, we may also send you the occasional field note on the same subject — we say so where you submit, and every email carries an unsubscribe link that works immediately. The sample report asks nothing of you: it is published openly, with no form in front of it.
  • Consent — the mailing list proper. Signing up is double opt-in: we email you a confirmation link, and you are only added once you click it (the link expires after seven days; ignoring it means nothing is kept). You get occasional field notes on firmware security regulation, roughly monthly; it is not a drip campaign. Unsubscribe at any time by replying or using the link in any email. The list is never shared or sold.
  • Contract — purchases: taking payment, delivering what you bought, and keeping the records the law requires.

Who else has access

The following processors handle data on our behalf:

  • Cloudflare, Inc. — hosts the website, relays form submissions to our inbox via Cloudflare Email Sending, runs the Turnstile bot-check on forms (which transiently processes your IP address, TLS fingerprint and user-agent as strictly necessary bot protection — no cookies in the mode we use). Cloudflare additionally logs IP addresses and request metadata for the operation and security of the site, retained per their published retention policy. We do not access those logs directly.
  • PostHog, Inc. — product analytics, processed in PostHog’s EU cloud.
  • Cal.com, Inc. — appointment scheduling for call bookings (confirmed bookings sync to our Google Workspace calendar).
  • Stripe Payments Europe, Ltd. and Stripe, Inc. — payment processing for online purchases.
  • Google Ireland Limited — receives the anonymous, consent-denied, IP-stripped measurement pings described above (Google Analytics 4 / Google Ads campaign measurement). No cookies, no advertising profile, no remarketing.
  • URIports — receives the browser security reports described above.
  • Our business email provider, where your message is delivered and read.

How long we keep it

  • Enquiries — while we are actively considering an engagement with you, plus a reasonable follow-up period: typically up to 24 months from the last interaction.
  • Mailing list — until you unsubscribe.
  • Analytics — held as aggregate usage data, not as a profile of you.
  • Purchase records — for as long as UK tax and accounting law requires.

You can ask us to delete your data sooner at any time.

Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you,
  • ask us to correct or delete it,
  • restrict or object to our processing,
  • request a copy in portable form,
  • withdraw consent at any time — for the mailing list, that is the unsubscribe link,
  • complain to the Information Commissioner’s Office (ICO) at ico.org.uk if you believe we have mishandled your data.

To exercise any of these rights, write to info@talltree.tech. We will respond within 30 days.

Cookies

talltree.tech sets no cookies at all — which is why there is no cookie banner. The complete inventory of what the site does store in your browser (one session-scoped attribution entry) and the cookieless tools it uses is on the cookies & website storage page. Third-party pages you choose to visit — Stripe checkout, Cal.com booking — set their own cookies under their own policies.

Updates

We will revise this notice if our processing activities change. Material changes will be reflected here with a new “last updated” date.

Contact

Privacy enquiries: info@talltree.tech

Software Systems Limited, 7 Bell Yard, London WC2A 2JR, United Kingdom · Company No. 14466340 (England & Wales).

Last updated: .