Legal
Privacy Policy
1. Who is responsible
The Research Desk (“TRD”, “we”) is responsible for the personal data described here. TRD is operated by its founder, Omer Farrukh, as a sole proprietorship. For anything about privacy, email info@theresearchdesks.com.
When we build systems for clients, the personal data inside those systems belongs to the client, and we handle it only on their written instructions under our agreement with them. This policy covers our own website and enquiries.
2. What we collect
Enquiry and partner forms. Your name and email address, and anything else you choose to give us: company, phone or WhatsApp number, country, the service you're interested in, budget, timeline and your message. We also record the page you sent the form from, the address of the page that referred you (without any query string) and any campaign (UTM) tags in the link you followed.
Spam and abuse protection. To limit repeated submissions we store a keyed, one-way code derived from your network address for 30 days. We never store the address itself, and we don't store your browser's identifying details.
Page views. We count how many times each page is viewed per day. The count is anonymous: it records only the page and the date, uses no cookies and no identifiers, and can't be linked to you.
Messages you send us by email or WhatsApp, and the information you share while we scope or deliver a project.
Staff sign-in. People who work on TRD sign in to a private area of this site; their name, email address and role are stored for that purpose. Visitors never need an account.
3. Why we use it
- To reply to your enquiry and prepare a scope or quote, which are steps you ask us to take before a contract (UK/EU GDPR Article 6(1)(b)).
- To deliver and invoice work you engage us for, under our contract with you (Article 6(1)(b)).
- To keep the site secure, prevent spam and understand which pages are useful, in our legitimate interest in running the website (Article 6(1)(f)).
- To keep financial and tax records, where the law requires it (Article 6(1)(c)).
We don't send marketing emails, we don't sell personal data or share it for advertising, and we don't make automated decisions about you.
4. Who handles it for us
We use a small number of service providers, each bound by a data processing agreement:
- Supabase: the database and file storage behind this site, including form submissions.
- Vercel: hosting and delivery of the website.
- Resend: sends our team an email notification when a form is submitted.
- Our email provider: for the emails you exchange with us.
If you choose to message us on WhatsApp, WhatsApp (Meta) processes that conversation under its own privacy policy. The WhatsApp buttons on this site are plain links: nothing is sent to WhatsApp unless you click one.
We don't embed third-party videos, maps, social widgets, advertising or tracking scripts on this website.
5. International transfers
We work with clients in several countries, and our providers may process data outside the country where you live, including in the United States. Where the law requires it, transfers rely on safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, included in our providers' data processing terms.
6. How long we keep it
- Enquiries that don't become projects: deleted after 24 months.
- The spam-protection code: removed from each enquiry after 30 days.
- Client and project records, including invoices: kept for as long as we work together and afterwards for as long as tax and accounting law requires.
- Daily page-view counts: 25 months.
7. Security
Data is encrypted in transit, stored with access limited by role and enforced in the database, and only the people who need it can see it. Form submissions are protected against spam and repeated submissions. No system is perfectly secure, but we'll tell you promptly, and the authorities where required, if a breach affects your data.
8. Your rights
You can ask us for a copy of your data, to correct or delete it, to restrict or object to how we use it, or to receive it in a portable format. Email info@theresearchdesks.com and we'll reply within one month.
- UK and EU: you can also complain to your data protection authority, for example the Information Commissioner's Office in the UK.
- United States (including California): you can ask to know, correct or delete the personal information we hold. We don't sell or share personal information for cross-context behavioural advertising, and we won't treat you differently for using your rights.
- Canada, Australia and the Middle East: you can ask to access and correct your personal information, and complain to your privacy regulator if you're not satisfied with our reply.
10. Children
This website and our services are intended for businesses and adults. We don't knowingly collect data from children under 16.
11. Changes
If we change how we handle personal data, we'll update this page, and tell existing clients directly about any significant change.