1. Who is responsible
ImpactLayer is operated by Dylan Powell in South Wales, United Kingdom. ImpactLayer is responsible for personal information collected through this website.
For privacy questions or requests, email dylan@impactlayer.co.uk. If paid work begins, the proposal or order form will also identify the legal contracting party for that work.
2. Information we collect
Enquiries and correspondence
When you enquire, we collect the name, work email, business or organisation, business type, message, and any walkthrough scheduling preference or focus you submit. We also keep relevant correspondence and notes needed to respond, prepare a proposal or manage a business relationship.
Targeted business prospecting
For limited, relevant business-to-business outreach, we may record a business name, a contact's public business role and business contact details, the source and date, whether the subscriber is a corporate body or must be treated like an individual, the applicable lawful basis, when this notice was provided, correspondence and sales status. Sources may include the business's own website, Companies House, professional networks, an event or a referral.
We do not treat public contact details as blanket permission. Before electronic marketing, we assess the business type and whether consent or the soft opt-in is required. We do not send unsolicited electronic marketing to sole traders or ordinary partnerships without the required permission, and we do not make live business calls unless the number has been screened against TPS, CTPS and our own do-not-contact records.
Objections and suppression records
If a business contact asks us to stop direct marketing, we stop and retain only the minimum needed to honour that request. The suppression record uses a one-way fingerprint of the normalised email address, phone number or social handle, its channel, a limited hint, date and reason. It is used to prevent future contact, not for further marketing.
App concepts and uploaded logos
If you use the member growth blueprint, we also collect the business, active-member band, proposed app name, brand colour and tone, primary outcome, engagement or retention priority, requested capabilities, current system, intended launch timing, indicative investment band, first 90-day success measure and any optional notes you provide. If you choose to upload a logo, we store the image and basic file information with that blueprint.
A submitted concept is recorded as a sales enquiry. The confirmation provides a short-lived, browser-only continuation for that exact concept. We link it only after the submitted work email is verified; signing in with an email alone does not claim other unowned concepts. Creating this account does not create a customer contract or a production app workspace.
Voice and chat assistant
If you use the assistant on this website, or ring our line, your conversation is handled by a speech and language provider acting as our processor. It says it is AI and the conversation may be recorded and transcribed. The provider holds the audio and transcript for 90 days by default and then deletes them. We keep a short summary of each conversation, its timing, its outcome and the evaluation results, not the transcript, so we can see what visitors ask and improve the assistant. If you give a name and a number or email so we can call, text or email you back, that is kept as an enquiry record. Ask us at any time to delete it. See the AI use notice for the standards every ImpactLayer deployment follows.
Public-form abuse prevention
To keep the public enquiry form and app builder available, our edge provider supplies the network address making a submission. We use it only in memory to create a secret-keyed, daily rotating fingerprint for short-lived hourly rate-limit counters. We do not store the raw address, and the fingerprint is not used for analytics, advertising or recognising a visitor on another day.
Privacy-friendly website analytics
For each successful public page view, we record the page path without its query string, the date and time, the referring website's hostname where supplied, a coarse device category such as mobile, tablet or desktop, and the Cloudflare country code where available.
These page-view analytics do not store IP addresses, names, emails, user IDs, full browser user agents, full referring URLs, query parameters, cookies, local storage or a persistent visitor identifier. They measure page views, not unique people, and are not used to follow anyone across websites.
Fit-call and campaign attribution
When you choose to submit a fit-call request or member blueprint, we may save a limited source page, CTA label and allowlisted campaign tags such as UTM source, medium and campaign with that enquiry. We do not retain the full query string or create a persistent visitor identifier. A page visit, email open or raw link request is not treated as confirmed human engagement or a sales-stage change.
Client and staff access
If you use a protected client or staff area, the sign-in service may provide basic account information, such as an account identifier, name and email, so we can authenticate you and decide whether access is permitted. The sign-in provider also handles information under its own privacy terms.
Submission emails
When an enquiry or concept is saved, our secure Control Plane asks Resend to process the recipient address and necessary message content so it can send a simple acknowledgement and alert authorised ImpactLayer staff. We record only the delivery type, status, attempt time and a safe failure description; API credentials and complete email bodies are not stored in the sales record.
3. Why we use information
- To answer enquiries, assess fit and take requested steps before a contract.
- To save, display and review an app concept and link it to the correct verified account.
- To prepare and manage proposals, projects and client relationships.
- To understand which website pages are useful and improve the site.
- To understand which submitted fit-call requests came from a particular page, CTA or campaign.
- To secure the website, prevent misuse and control protected access.
- To meet legal, accounting or regulatory obligations.
We rely on steps requested before entering a contract, performance of a contract, legal obligations and our legitimate interests in operating and improving a secure B2B service. For targeted business prospecting, legitimate interests are used only after considering the purpose, necessity, relevance, source, reasonable expectations and privacy impact; consent or the soft opt-in is used where electronic-marketing rules require it. We do not add someone to a general consumer marketing list simply because they submit an enquiry.
4. Cookies and similar technology
ImpactLayer does not use advertising cookies, cross-site analytics cookies or a persistent analytics identifier. Infrastructure and security providers may set cookies that are strictly necessary to deliver or protect the website and its sign-in areas.
5. Who receives information
Information may be processed by carefully selected hosting, database, authentication and professional-service providers where needed to run ImpactLayer, and by Resend for the submission emails described above. We may also disclose information where required by law, to protect legal rights or in connection with a business reorganisation.
We do not sell personal information. Where a provider processes information outside the United Kingdom, we use the provider's applicable contractual and legal safeguards.
6. How long we keep it
- Privacy-minimised page-view records and limited page, CTA and campaign attribution saved with a submitted enquiry are kept on a rolling basis for up to 13 months, unless the enquiry becomes active work and a longer business or legal retention period applies.
- Public builder rate-limit counters and their daily rotating fingerprints stop counting after about 26 hours. Expired rows are deleted during later form activity or database maintenance rather than by a guaranteed timer at the expiry moment.
- Enquiries, submitted app concepts and associated logos that do not become active work are normally kept for up to 24 months after the last meaningful contact, unless there is a good reason to keep them for less or longer.
- Outbound prospect records with no meaningful response are normally kept for up to 12 months after the last contact, then deleted or reduced unless a current business reason or legal obligation requires more.
- Minimal suppression fingerprints are kept for as long as reasonably necessary to honour a direct-marketing objection and are not used for another purpose.
- Contract, project, invoicing and legal records may normally be kept for up to six years after the relationship ends where required for business, tax or legal purposes.
7. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or object to use of your information, and to receive certain information in a portable form. You may also withdraw consent where consent is the basis being used. You can object to direct marketing at any time; we will stop and add the minimum suppression record needed to honour the request.
Send a request to dylan@impactlayer.co.uk. We may need to verify your identity. You can also complain to the Information Commissioner's Office.
8. Children
This is a business-to-business website and its enquiry and concept forms are not intended for children. Please do not submit information about a child through either public form. Any child or player information used in a customer app is governed by the customer agreement, safeguarding responsibilities and a product-specific privacy notice.
9. Changes to this notice
We may update this notice when the website, services or legal requirements change. The date at the top shows the latest published version.
