Overview
Nely Rose ("we", "us") operates nelyrose.com (the "Site"). This Privacy Policy explains what information we collect when you visit the Site or submit a contact or privacy rights request, and how we use it.
Last updated: 2026-07-16
Nely Rose ("we", "us") operates nelyrose.com (the "Site"). This Privacy Policy explains what information we collect when you visit the Site or submit a contact or privacy rights request, and how we use it.
Nely Rose is the data controller for personal information collected through nelyrose.com. Privacy contact: [email protected].
We are not required to appoint a Data Protection Officer. For all privacy matters, contact us at [email protected].
We may collect information you voluntarily provide — such as your name, email address, company name, and message content — when you book a discovery call, complete a contact form, submit a privacy rights request, or email us directly.
When you submit a contact or privacy rights form, we also store your IP address and browser user agent to help prevent abuse, investigate security issues, and respond to your request. When the Site is served through Cloudflare, we record the visitor IP address Cloudflare provides rather than the proxy edge address.
If you arrive from a campaign link that includes standard marketing parameters (for example utm_source, utm_medium, utm_campaign, or gclid), we may store those parameters with your contact-form submission and may pass them to Calendly when you open a booking link, so we can understand which campaigns lead to inquiries. This first-party attribution uses the nr_attribution cookie described in our Cookie Policy.
We may collect standard technical data automatically, including IP address, browser type, device type, referring pages, and general usage analytics through server logs or privacy-respecting analytics tools when you have given consent.
We set a first-party cookie (nr_tz) so dates can be formatted in your local time. See our Cookie Policy for details.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
We use collected information to respond to inquiries, schedule consultations, fulfill privacy rights requests, deliver GTM consulting services, improve the Site, and communicate about relevant services you have expressed interest in.
We do not sell your personal information to third parties.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
The Site uses a cookie consent banner so you can accept, reject, or customize optional cookies before they are set. See our Cookie Policy at https://nelyrose.com/cookie-policy for a full list of cookies and storage we use.
Essential cookies and storage are used for consent preferences, contact-form and privacy-request security (including a session cookie for CSRF protection), local date formatting (nr_tz), inbound campaign attribution (nr_attribution), and Cloudflare Turnstile spam protection — controls that support our SOC 2 Type I security program design.
Optional analytics and functional cookies are enabled by default. You can turn them off at any time via the Cookie settings button in the footer copyright row (next to Sitemap).
We use Google Analytics 4 to understand how visitors use the Site (for example, pages viewed, traffic patterns, and campaign parameters when analytics storage is allowed). The Google Analytics script may load in your browser; you can disable analytics storage via Cookie settings.
We may load Calendly to embed a booking calendar when functional cookies are enabled. Calendly may set its own cookies subject to its privacy policy at calendly.com/privacy. Booking links may include campaign parameters from nr_attribution so Calendly can record source. You can disable the embed via Cookie settings or book via the external Calendly link instead.
If your browser sends a Global Privacy Control (GPC) signal and you have not saved a consent choice, we apply reject-all optional cookie preferences automatically.
We use trusted service providers who process personal data on our behalf:
Some providers are located outside your country, including in the United States. Where required, we rely on appropriate safeguards such as the provider's standard contractual clauses or equivalent transfer mechanisms described in their privacy documentation.
These providers process data under their own privacy policies and our instructions where applicable.
We retain personal information only as long as necessary for the purposes described in this policy:
We implement reasonable technical and organizational measures to protect your data, though no method of transmission over the internet is completely secure.
If you are in the EEA, UK, or another jurisdiction with similar laws, you may have the right to:
California residents: we do not sell or share personal information for cross-context behavioral advertising. You may opt out via Cookie settings, Global Privacy Control, or a request on our Your Privacy Rights page.
To exercise your rights, submit a request at https://nelyrose.com/your-privacy-rights or email [email protected]. We aim to respond within one month, or the period required by applicable law.
The Site is not directed at children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact [email protected] and we will take appropriate steps to delete it.
Our website security program is designed to meet SOC 2 Type I Trust Service Criteria for Security and Privacy. Controls include encrypted transport (HTTPS/TLS), access controls and MFA for the admin panel (with automatic logout after 8 hours of admin inactivity), CSRF and bot protection on public forms, append-only audit logging, encrypted database backups, server-side session data stored outside the public document root (same boundary as the SQLite database), automated removal of unused session files within 24 hours, and automated retention aligned with this policy.
See our Security page at https://nelyrose.com/security for a summary, including how we govern web archiving and AI training crawler signals (robots.txt and Content-Signal). Those signals address automated content use and are separate from this Privacy Policy's rules on personal data. When an independent SOC 2 Type I attestation report is available, we will publish the report date and scope on that page.
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes to how we use cookies may require renewed consent.
Questions about this policy can be directed to [email protected].