This policy explains what personal data LOYALTY / CONSULTANT collects on loyaltyconsultant.co.uk, why we collect it, and how long we keep it. It describes the site as it actually works today. We do not run advertising pixels, analytics products, a newsletter, a customer login, or payment collection on this website.

Who we are

The controller is Çağrı Burak Sürer, trading as LOYALTY / CONSULTANT. We provide independent loyalty advisory for hospitality, retail and multi-site brands.

For privacy requests, use the consultation form or email [email protected].

The data we collect

Browsing the site

You can read the public pages without giving us your name or email. Our web server and hosting environment will typically see the usual connection data that any website sees, such as IP address, browser type, pages requested and the time of the request. We have not added Google Analytics, Meta Pixel, LinkedIn Insight Tag, or similar tracking tools.

Stylesheet files for layout and icons are loaded from jsDelivr so the pages can render. Google Fonts are loaded only if you allow third-party fonts in . Those providers may see your IP address when the files are requested. That is not a marketing tag.

Consultation form

If you submit the form on the Contact page, we collect:

  • full name and work email (required)
  • company name, website, industry and the topic you want help with (optional)
  • your message (required)
  • your confirmation that we may store the enquiry
  • the page path you submitted from
  • your IP address and browser user agent, stored with the enquiry so we can limit spam and abuse

We do not ask for a payment card. A hidden honeypot field is used to catch automated submissions; if it is filled in, the message is rejected and not stored.

Each accepted enquiry is saved in our database and emailed to our working inbox so we can reply. We typically aim to respond within two working days. The email is sent from [email protected] through our mail server. The working inbox we use to read enquiries may be provided by a third-party email service (currently Google).

Loyalty Health Check

The Health Check is a scored diagnostic conversation. If you start it, we create an assessment record and store:

  • your answers about the business — for example sector, number of sites, visit pattern, typical transaction value, whether you already run a loyalty programme, how you measure repeat visits, and similar operational questions
  • the chat transcript of the questions and replies shown on screen
  • the six dimension scores and overall score, which are calculated from your answers against a fixed framework — the scores are not decided by AI
  • the written report generated at the end
  • a one-way hash of your IP address, plus your browser user agent, used to limit automated or repeated starts
  • a random results token, used to open the report URL

We also ask for contact details during the assessment: full name, work email, company name, optional website, and the country the business is based in. You can finish the assessment on screen even if you do not agree to email follow-up.

If you agree, we email the report to the work address you gave and may send relevant follow-up from LOYALTY / CONSULTANT. If you choose “Not now”, we do not email the report to you. If a work email has been provided, we may still send an internal copy of the completed assessment to our working inbox so we can see that a report was produced. Chat and results pages are excluded from search indexing. Anyone who has the results link can open that report; the token is long and is not listed in the sitemap.

You can pause and continue later on the same device while the browser session is still valid. We do not use local storage or session storage in the browser for this.

Returning-customer calculator

The calculator runs in your browser. The figures you type are used only to illustrate contribution on that page. They are not submitted to our server or stored in our database.

Anti-spam and session security

The site uses a PHP session cookie so we can keep a short-lived session: CSRF protection on forms, error messages after a failed submission, and Health Check progress on the same device.

Where Cloudflare Turnstile is switched on, the Contact form and the Health Check start form use it to reduce bot submissions. Cloudflare receives the Turnstile token and the connecting IP address to decide whether the request looks automated. Turnstile may set its own cookie or similar storage. See the Cookie Policy.

We also keep short-lived rate-limit records (a hash of the IP address or email, plus a timestamp) so the same connection cannot flood the form or start unlimited assessments. Those records are cleared after about two days.

Why we use the data

We use personal data to:

  • answer consultation requests and keep a record of what was asked
  • run the Health Check, produce the scores and report, and show the results page
  • email the Health Check report and related follow-up when you have agreed
  • see internally that an assessment was completed, so we can follow up as a consultancy if that is appropriate
  • protect the site against spam, abuse and automated use
  • keep the forms and Health Check working securely

We do not sell personal data. We do not use it for advertising networks. We do not add people to a bulk marketing list — there is no newsletter product on this site.

Lawful bases

Under UK GDPR we rely on:

  • Consent — storing a consultation enquiry (you must tick the box), and emailing you the Health Check report or related follow-up (you must agree in the assessment).
  • Legitimate interests — running the diagnostic you asked for; keeping the assessment record; sending ourselves an internal copy of a completed Health Check when an email address was given; holding IP and user-agent data, hashed IP data and rate-limit records to keep the site usable and to reduce abuse. You can object to processing based on legitimate interests.
  • Steps towards a contract — using the details you send so we can consider and reply to a request for advisory work.

AI used in the Health Check

Scores are calculated from your answers. They are not generated by a language model.

If an OpenAI API key is configured, we send a structured summary of the non-contact answers and the pre-calculated scores to OpenAI so it can write the report narrative and match relevant Loyalty Growth Tools. We do not send your name, work email, company name, website or consent choice in that API request. Country, sector and the operational answers are included because they are part of the diagnostic. OpenAI processes that request as our provider. If the API is unavailable or not configured, the site still produces a fallback report from the same scoring rules, without calling OpenAI.

This is not automated decision-making that produces a legal or similarly significant effect. The Health Check is an initial diagnostic. It does not approve or refuse a service, and it is not a substitute for a full review of customer, transaction and programme data.

Who receives the data

People who operate this consultancy can see enquiries and assessments in the password-protected admin area and in the inbox copies described above.

Depending on which features are in use, the following providers may process data on our behalf:

  • our web hosting and mail hosting provider, which stores the website, database and mailbox
  • OpenAI, when a Health Check report is generated through the API
  • Cloudflare, when Turnstile is used to check a form or Health Check start
  • Google, for fonts loaded on the public pages, and for the working inbox if that mailbox is provided by Google
  • jsDelivr, which serves some CSS and icon files

We do not pass your details to software vendors as a sales lead. The site does not pitch a loyalty platform at the end of the Health Check.

International transfers

The public site is aimed at UK and international clients. Some providers above are based outside the United Kingdom — in particular OpenAI and, where used, Cloudflare and Google. When that happens, UK GDPR transfer rules apply. We use those providers only for the functions described here.

How long we keep it

We do not currently run an automatic deletion job for consultation enquiries or Health Check records. We keep them so we can reply, refer back to a report if you contact us again, and understand completed assessments. Rate-limit records are removed after about two days.

If you ask us to delete your enquiry or Health Check, we will do so unless we need to keep a limited record — for example to show that we handled a request, or to defend a legal claim. Server access logs on the host are outside this application and follow the host’s own rotation.

Security

The live site is served over HTTPS. Forms include CSRF checks. The Health Check results URL uses a long random token. Admin pages are password-protected and are not indexed. Assessment IP addresses are stored as a hash rather than in plain form. Consultation enquiries currently store the IP address in plain form, as described above.

No method of transmission or storage on the internet is completely secure. We do not claim otherwise.

Your rights

If UK GDPR applies to you, you can ask us to:

  • access the personal data we hold about you
  • correct it
  • delete it
  • restrict how we use it
  • object to processing based on legitimate interests
  • receive a copy of data you provided, where portability applies
  • withdraw consent where we are relying on consent — that does not undo sending we have already done

To use these rights, email [email protected] or use the consultation form. You can also complain to the Information Commissioner’s Office at ico.org.uk.

Children

This website is written for business operators. It is not aimed at children, and we do not knowingly collect data from children.

Changes

If we add a feature that collects personal data — for example analytics, a newsletter, or a payment form — we will update this policy. The date at the top of the page will change.