Skip to content

EU GDPR and UK GDPR Notice

Last updated June 2, 2026

Purpose Of This Notice

This notice explains how W.S. Darley & Co. handles personal data for Darley Data under the EU General Data Protection Regulation and the UK General Data Protection Regulation.

This notice supplements the existing Terms & Privacy Policy. The existing privacy policy remains available.

Who This Notice Covers

This notice applies to personal data processed through Darley Data for site visitors, portal users, data-subject requesters, data-correction submitters, newsletter and marketing users, advertisers and shared-dashboard recipients, and visitors whose browsers load embedded Darley Data widgets on third-party pages.

Darley Data applies its cookie preference and data-rights workflow broadly rather than relying only on location-based gating.

Controller And Contacts

ItemDetails
ControllerW.S. Darley & Co.
Mailing addressAttn: Legal and Compliance, 325 Spring Lake Drive, Itasca, IL 60143, United States
RepresentativeTo be Announced

Personal Data Categories

  • Identity and contact data, such as name, email address, phone number, organization, department, and portal account details.
  • Account and authentication data, such as portal account status, password-reset metadata, login events, and security records.
  • Request and rights-workflow data, such as DSAR type, details, request ID, verification notes, status, and audit history.
  • Cookie and consent data, such as optional category choices, timestamps, version, and expiration.
  • Technical data, such as request metadata, minimized IP address, minimized user-agent, referring page, device/browser category, and coarse country or region.
  • Marketing and newsletter data, such as email address, submitted HubSpot form fields, consent status, and campaign metadata.
  • Advertising and shared-dashboard data, such as ad IDs, ad slots, campaign assets, impression/click events, shared report access controls, and aggregate performance reporting.
  • Embedded-widget data, such as FDID, selected widget, embed URL, minimized request metadata, and aggregate usage metrics.

Darley Data does not intentionally use the data-subject request form to collect browser cookies or localStorage contents.

Purposes And Lawful Bases

The table below summarizes the main processing activities, data involved, lawful bases, and current retention model.

PurposePersonal dataLawful basisRetention
Operate the site, portal, accounts, and security controlsRequest metadata, account and portal contact details, authentication records, login and password-reset security events, minimized IP address and user-agent where used for security.Contract where processing is needed to provide portal access or requested services; legitimate interests in operating, securing, debugging, and protecting the service; legal obligation where records are required for compliance.Account lifetime plus documented retention where applicable; login, security, and password-reset logs are retained for 12 months.
Remember cookie choices and run essential site functionsCookie-preference categories, preference version, timestamps, same-site preference cookie, and matching localStorage preference record.Legal obligation and legitimate interests in recording and honoring privacy choices; essential cookies are necessary to provide the site.Consent preferences expire after 6 months.
Optional analytics and session recorderOptional performance analytics events and recorder data loaded only after performance-cookie consent.Consent. You may withdraw consent by turning off performance cookies on the cookie preferences page.Optional analytics and session-recorder data are retained for 25 months.
Newsletter, HubSpot forms, and marketing communicationsEmail address, submitted form fields, marketing consent status, and related campaign or form metadata.Consent. You may withdraw consent through the data-subject request form, cookie preferences where applicable, or marketing unsubscribe controls where provided.Until consent is withdrawn or the record is no longer needed, subject to any legally required suppression list retention.
Advertising measurementAd identifier, slot, page, impression or click timestamp, campaign fields, and related ad-performance reporting data.Consent for marketing cookies and advertising measurement.Advertising click and impression analytics are retained for 25 months.
Embedded-widget analyticsFDID, widget identifier, widget title, referring page, minimized IP address, minimized user-agent, country, and region. Source IP is used transiently for coarse geolocation and is minimized before storage.Legitimate interests in aggregate usage reporting for embedded widgets.Embedded-widget analytics are retained for 25 months.
Data-subject request workflowFirst name, last name, email address, request type, request details, request ID, minimized request metadata, identity-verification notes, workflow status, and audit records.Legal obligation to receive, assess, and respond to privacy-rights requests; legitimate interests in audit, security, dispute management, and preventing abuse.DSAR audit records are retained for 6 years. Browser cookies and localStorage contents are not intentionally collected with DSAR submissions.
Data correction workflowCorrection details submitted by the requester, administrative workflow records, and audit notes.Legal obligation and legitimate interests in correcting data, maintaining accurate records, and keeping an audit trail.Data correction audit records are retained for 6 years.

Recipients

Darley Data shares personal data only where needed for the purposes described in this notice, subject to appropriate access controls and contracts.

  • Hosting, database, infrastructure, and storage providers.
  • Email delivery providers, including Brevo SMTP.
  • Analytics, recorder, advertising measurement, and marketing-form providers, including HubSpot where marketing forms are enabled.
  • Darley personnel, contractors, professional advisors, and service providers who need access for operations, security, support, compliance, or legal purposes.
  • Advertisers or shared-dashboard recipients where Darley provides campaign reporting or share-link access.
  • Courts, regulators, law enforcement, or other authorities where disclosure is required or permitted by law.

Processor And Provider List

The table below lists processors and providers that support Darley Data services, along with their roles and the personal data they process.

ProviderRoleData processed
Hosting and database providersApplication hosting and database operations.Account, portal, request, analytics, security, and operational records.
Brevo SMTPTransactional email delivery for reset and request notifications.Recipient email address and reset/request notification contents.
HubSpotNewsletter and marketing forms, consent-gated.Email address, submitted marketing form fields, consent status, and campaign or form metadata.
Darley analytics endpointOptional analytics and session recorder, performance-consent gated.Optional site analytics events and session-recorder data loaded only after performance-cookie consent.
IDrive e2S3-compatible image and asset storage for uploaded ad/media assets.Uploaded ad images, media assets, asset metadata, and storage access logs where applicable.

International Transfers

W.S. Darley & Co. is located in the United States. Darley Data and its service providers may process personal data in the United States and other countries that may not provide the same level of data protection as the European Economic Area or the United Kingdom.

Where EU GDPR or UK GDPR transfer rules apply, Darley relies on approved transfer mechanisms, such as European Commission standard contractual clauses, the UK International Data Transfer Agreement or UK addendum, Data Privacy Framework participation where applicable, adequacy decisions, or another lawful safeguard.

European And German Compliance

The following items document current EU and Germany-specific compliance assumptions and review statuses for Darley Data.

ItemStatus
US-only controller statusW.S. Darley & Co. remains the United States-only controller for Darley Data. Darley Data may process EU and German personal data in connection with site, portal, analytics, advertising, marketing, support, data-rights, and compliance workflows described in this notice.
EU/German representativeTo be Announced
German legal notice / Impressum statusTo be Announced
DPO determination under BDSGDarley Data currently assumes fewer than 20 people regularly handle automated personal-data processing for purposes relevant to the German BDSG threshold. Final DPO determination: To be Announced
TDDDG cookie and equipment-access basisOptional cookies and similar access to or storage on a user's device, including optional analytics, the session recorder, HubSpot forms or scripts, advertising measurement, ads, and marketing technologies, are handled on a consent basis. Essential storage for core site operation, security, and cookie-preference records is limited to necessary functions.
German email marketing under UWGEmail marketing to recipients in Germany is handled on a consent basis under UWG unless a legally reviewed exception applies. Marketing consent may be withdrawn through unsubscribe controls where provided, cookie preferences where applicable, or a consent-withdrawal request.
German public-data and source-attribution reviewGerman public fire, EMS, incident, department, and official-source datasets and related attribution practices are under review to confirm source terms, official-source labels, attribution, and personal-data minimization.
DSA applicabilityDarley Data currently assumes it does not operate a public user-generated-content platform or public hosting service that exposes user content. Final DSA applicability review: To be Announced

Retention

Darley Data keeps personal data only as long as needed for the purposes described in this notice, unless a longer period is required for legal holds, disputes, investigations, security incidents, regulatory inquiries, or compliance obligations.

RecordRetention period
Consent preferences6 months
Login, security, and password-reset logs12 months
Optional analytics and session-recorder data25 months
Advertising click and impression analytics25 months
Embedded-widget analytics25 months
DSAR audit records6 years
Data correction audit records6 years

Darley reviews or deletes records according to these retention periods unless a longer period is required for legal holds, disputes, investigations, security incidents, regulatory inquiries, or compliance obligations.

Your Rights

Depending on your location, the processing activity, and applicable limits or exemptions, you may have the following rights under the EU GDPR or UK GDPR:

  • Access: ask for confirmation that personal data is processed and request a copy of eligible personal data.
  • Rectification: ask us to correct inaccurate personal data or complete incomplete personal data.
  • Erasure: ask us to erase personal data where the law allows.
  • Restriction: ask us to restrict processing where the law allows.
  • Objection: object to processing based on legitimate interests, including profiling based on those interests, where applicable.
  • Portability: request a portable copy of eligible personal data processed by automated means based on consent or contract.
  • Withdraw consent: withdraw consent at any time for consent-based processing. Withdrawal does not affect processing that happened before withdrawal.
  • Complaint: lodge a complaint with an EU or UK supervisory authority.

Some requests may be limited where Darley must retain data for legal obligations, security, fraud prevention, legal claims, compliance, audit, or other documented legitimate reasons.

How To Make A Request

Use the data-subject request form to submit an access, correction, restriction or erasure, objection, portability, or consent-withdrawal request. Use the cookie preferences page to update or withdraw optional cookie consent.

Darley may ask for information needed to verify your identity, confirm your authority to act for someone else, understand the request, or determine whether an exception applies.

Consent Withdrawal

Where processing is based on consent, you may withdraw consent at any time. For optional cookies and similar technologies, turn off the relevant category on the cookie preferences page and save your choices. For marketing communications, use any unsubscribe method provided or submit a consent-withdrawal request.

Withdrawal does not affect processing that occurred before consent was withdrawn, and it does not prevent Darley from keeping records needed for legal, security, compliance, suppression-list, or audit purposes.

Data Sources

Darley Data collects some personal data directly from you and obtains some data from other sources.

  • You, when you browse the site, submit forms, manage cookie preferences, use the portal, request data rights, or submit corrections.
  • Your organization, account administrator, advertiser, or shared-dashboard sponsor when they provision access, campaign information, or report sharing.
  • Your browser, device, and network request metadata, including cookie preference records and minimized technical data.
  • Embedded pages that load Darley widgets, through referrer and request metadata associated with the widget request.
  • Public fire, EMS, incident, department, and official-source datasets used for analytics. These datasets are not intended to identify individual site visitors.
  • Service providers and vendors that provide delivery, authentication, analytics, form, email, security, or operational metadata.

Providing Data

Some data is necessary to provide requested services or comply with legal obligations. For example, portal account details are needed to provide portal access, security records are needed to protect the service, and request details are needed to process privacy-rights requests.

If required data is not provided, Darley may be unable to create or maintain an account, provide portal features, verify a data-rights request, respond to a correction request, deliver marketing communications, or provide requested support. Optional cookie categories are not required to use the core site, although declining them may limit optional functionality, analytics, marketing, or advertising measurement.

Automated Decision-Making And Profiling

Darley Data does not currently use personal data for automated decision-making or profiling that produces legal or similarly significant effects for individuals.