Privacy & GDPR
Privacy and GDPR information
Last updated: 21 June 2026
Short version
- The public website is for enquiries and small anonymized samples only.
- Complete customer files are not requested through the public form.
- Production data is exchanged only after scope, confidentiality, transfer method and processing terms are agreed.
- When personal data is processed for a customer, the project is handled under documented instructions and, where required, a Data Processing Agreement under GDPR Article 28.
- For European customers, project files are handled on infrastructure located in the European Union or European Economic Area unless otherwise agreed in writing.
- Customer data is not used for training, resale, marketing lists or unrelated projects.
- Project files are deleted from our environments after project close, unless a different written agreement or legal obligation applies.
Who this policy is for
This policy explains how ImportReady Data handles personal data submitted through this website, contact forms, initial project enquiries and early sample reviews.
It also describes the intended GDPR-aligned workflow for later data-cleaning, migration and import-preparation projects that may involve customer files, CRM exports, databases or spreadsheet data.
Controller and processor roles
For website enquiries, ImportReady Data acts as the controller of the information submitted through the contact form and uses it to respond to the request, assess fit and maintain a business record.
For most customer projects involving CRM exports, databases, spreadsheets or migration files, the customer determines the purpose and means of processing and acts as controller. ImportReady Data acts as processor and processes the data only on documented customer instructions.
Information collected through the website
The contact form may collect the information you choose to provide: name, work email, company, website, requested service, approximate volume, deadline, source system, target system, project description and an optional anonymized sample file.
Technical logs may also record basic request information needed to keep the website secure, diagnose errors and prevent abuse.
Public form and anonymized samples
The public form is intended for project context and small anonymized samples. A sample should show structure, columns, format problems, duplicate patterns or import errors without exposing real people, customers, employees or confidential records.
Before uploading a sample, remove or replace names, email addresses, phone numbers, customer IDs, account numbers, addresses, free-text notes and any other information that could identify a person or customer.
Full customer files
Production files, complete CRM exports, databases, employee data, customer lists, financial records or other full datasets are handled only through an agreed private workflow.
Before full files are exchanged, the project scope, confidentiality expectations, transfer method, access rules, retention period and deletion or return process are agreed. Where personal data is processed on behalf of a customer, a Data Processing Agreement is put in place where required.
European customer data location
For customers in the European Union or European Economic Area, project files are handled on infrastructure located in the EU or EEA unless a different location is agreed in writing for a specific project.
This commitment applies to project file handling. Customer-specific contracts or Data Processing Agreements may define more detailed hosting, transfer, backup and subprocessor requirements.
Purposes and legal basis
Website enquiry data is used to respond to requests, provide a first assessment, prepare proposals, manage the business relationship, protect the website and keep appropriate records.
The legal basis may include steps taken before entering into a contract, performance of a contract, legitimate interests in responding to business enquiries and maintaining security, and legal obligations where applicable.
Data minimization
Only the information needed for the current stage should be shared. The initial stage should use context and anonymized samples. Larger or more sensitive datasets are requested only when they are necessary for the agreed work.
Data Processing Agreement
When ImportReady Data processes personal data on behalf of a customer, the DPA normally defines the subject matter, duration, nature and purpose of processing, categories of data, categories of data subjects, documented instructions, confidentiality, security, subprocessors, assistance obligations, deletion or return, audit support and breach notification process.
Subprocessors and service providers
Projects may require infrastructure, hosting, email, secure file transfer, storage, backup or analytics providers. Subprocessors used for a specific customer project are identified in the project terms or DPA when applicable.
Customer data is not sold and is not shared with third parties for advertising, data brokerage, model training or unrelated services.
Security measures
The intended workflow uses private project workspaces, limited access, confidentiality, secure transfer methods, separation from public website forms, defined retention and secure deletion or return after the project.
Security measures are adapted to the project risk. Higher-risk datasets may require additional review, stricter transfer methods, a dedicated workspace or extra contractual terms before acceptance.
Retention and deletion
Contact enquiries and anonymized samples are retained only as long as needed to answer the request, manage the relationship, improve the service and satisfy legal or security requirements.
Production project files are kept only for the duration of the work and are deleted from our environments after project close, unless a different written agreement or legal obligation applies.
Special category and high-risk data
Do not send health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, criminal-offence data or similar special category data through the public form.
Projects involving special category data or other high-risk information require prior review and additional written terms before any file is accepted.
International transfers
Where a project involves personal data from the European Economic Area, transfer location and provider choices are reviewed as part of the project setup. If personal data is transferred outside the EEA, appropriate safeguards are considered and documented where required.
Analytics and cookies
The site is designed to avoid unnecessary tracking. If analytics are enabled, the intended setup is privacy-focused Matomo analytics with no advertising profiling, no resale of analytics data and reduced personal-data collection where possible.
Google Analytics is not required for this site to work or to appear in search engines.
Your rights
Depending on applicable law, you may have rights to access, rectify, erase, restrict or object to processing, request portability and lodge a complaint with a supervisory authority.
For data processed during a customer project, requests from data subjects should normally be directed to the customer acting as controller. ImportReady Data assists the customer according to the agreed processing terms.
Contact
For privacy questions about this website or an enquiry, contact ImportReady Data through the website contact form or at importreadydata@wltig.com.
Customer-specific contracts, Data Processing Agreements and security annexes control the actual terms for a project and may contain more detailed information than this public page.