Privacy policy
This policy explains what personal data danielyoung.io collects, why, and what rights you have. It applies to this website and to enquiries sent to Daniel Young LLC.
Last updated 29 July 2026
1. Who is responsible
The controller responsible for data processing on this website is:
Daniel Young LLC (formerly Thirteen East LLC)Registered office: 8 The Green, Suite 5433
Dover, DE 19901, United States
Office: 1 Broadway, 14th Floor
Boston, MA 02142, United States
Email: hello@danielyoung.io
Full company details are in the Impressum.
2. What data we collect
Contact form and email
When you use the contact form we collect the name, email address, company, role, enquiry type and message you provide, plus the date and time of submission. Technical data needed to protect the form from abuse, such as IP address, browser information and the result of an anti-spam check, may also be processed. We use this data to deliver and respond to your enquiry and, where relevant, to carry out the engagement or conversation you initiated.
Analytics data
If you allow analytics, Google Analytics 4 processes information about how you use the site, which may include a shortened or otherwise processed IP address, device and browser information, referring page, pages viewed, approximate location, session information and interaction events. We do not enable advertising personalisation for this site.
Information you send us otherwise
If you email, call or connect with us on LinkedIn, we process the contact details and content you choose to share for the same purpose.
What we do not do
- We do not sell or rent personal data.
- We do not add form submissions to a marketing mailing list.
- We do not run advertising or use analytics data for cross-site advertising profiles.
- We do not knowingly collect data from children.
3. Legal basis for processing
Where the GDPR applies, we rely on: Art. 6(1)(b) GDPR for steps taken at your request before entering a contract; Art. 6(1)(f) GDPR for our legitimate interests in responding to business enquiries, preventing abuse and operating a secure website; and Art. 6(1)(a) GDPR for optional Google Analytics and for the consent you give when submitting the contact form. You may withdraw consent at any time with effect for the future. Refusing analytics has no effect on your ability to use the site or contact us.
4. Hosting and server logs
This website and its contact endpoint are hosted on Microsoft Azure. Each request may be logged by Microsoft, typically including the requesting IP address, date and time, requested resource, referrer, browser and operating system. These logs are used to operate, troubleshoot and secure the site. Legal basis: Art. 6(1)(f) GDPR.
Web fonts are loaded from Adobe Fonts (Typekit). When a page loads, your browser requests the font files from Adobe's servers, which receives your IP address. Adobe states that it does not use Adobe Fonts data for advertising or set cookies for font delivery.
5. Service providers
We use the following categories of service providers to run the site, receive enquiries and organise business communications:
- Microsoft Azure and Microsoft 365 — website hosting, serverless form processing, Azure-hosted anti-spam and abuse prevention, email delivery and business email storage.
- Google Analytics 4 — optional website measurement, loaded only after you allow analytics. Google does not receive analytics events from this site before that choice is granted.
- OpenAI and Anthropic — selected business enquiry content may be processed by one of these providers through our communications system for limited classification, routing, prioritisation or summarisation. We minimise the content sent, do not use this processing to make decisions that produce legal or similarly significant effects, and do not use it for advertising.
- Adobe Fonts — delivery of the typefaces used on the site.
- Twilio — a short internal SMS alert that a new lead arrived. The alert is limited to basic contact context and does not include the full enquiry message.
Where a provider acts as our processor, it is engaged under appropriate contractual terms and may process personal data only for the relevant service. Provider use can change; this policy will be updated when a material processing activity changes.
6. How long we keep data
Enquiry correspondence is kept for as long as needed to handle the matter and afterwards for up to three years, so we can pick up a conversation and meet record-keeping obligations. Server and anti-abuse logs are kept for the operational retention periods configured with the providers. Google Analytics data is kept for the retention period configured in our Analytics property. We delete data earlier on request where no legal obligation or overriding legitimate interest requires us to keep it.
7. Cookies
Essential storage is used to remember your privacy choice and operate the contact form. Google Analytics is disabled by default. Its tag is loaded only after you choose “Allow analytics”, and the site sends Google Consent Mode signals with analytics storage denied until then. Advertising storage, advertising user data and advertising personalisation remain denied.
You can change or withdraw your choice at any time by selecting Privacy settings in the footer. Withdrawing consent stops future analytics collection on this device; it does not retroactively delete data already processed. You may contact us to exercise applicable data rights.
8. International transfers
Daniel Young LLC is established in the United States and works with clients in the United States and Europe. Personal data you send us is therefore processed in the US and may be processed in the EU. Where data is transferred out of the EEA or UK, we rely on the EU Standard Contractual Clauses or another lawful transfer mechanism with the provider concerned.
9. Your rights
Subject to the law that applies to you, you have the right to request access to the personal data we hold about you, its correction or deletion, restriction of processing, portability, and to object to processing based on legitimate interests. Where the GDPR applies you may also lodge a complaint with a supervisory authority in your country of residence or workplace.
To exercise any right, email hello@danielyoung.io. We respond within one month.
10. Security
This site is served over HTTPS. We apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. No method of transmission over the internet is completely secure; please do not send sensitive personal or health information through the contact form.
11. Changes to this policy
We may update this policy to reflect changes to the website or the law. The current version always applies and is dated at the top of this page.
