Draft last updated 24 July 2026
This notice explains how Philip George Advisory ("we", "us") collects and uses personal data when you use the Policy Generator, in line with the EU GDPR and the Irish Data Protection Act 2018. Your data is hosted in the EU/EEA.
Philip George Ltd is the controller for your account and billing data, and a processor for the content you put into the service (your answers, tool register and generated policies), which you control. Contact: privacy@pgadvisory.io.
We do not sell your data. We use a small set of subprocessors under written data processing agreements — see our subprocessor list. All are used only to run the service.
We host your data in the EU/EEA. Where a subprocessor involves a transfer outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses. See the subprocessor list for details.
We keep account and service content for as long as your account is active, and delete it within a defined period after account closure unless we must retain records for legal or accounting reasons. We retain only what regeneration requires.
You have the right to access, correct, delete, restrict, port and object to the processing of your data, and to withdraw consent where we rely on it. You can export or delete your account data from your Settings, or contact us at privacy@pgadvisory.io. We respond within one month.
Please contact us first. You also have the right to complain to the Irish Data Protection Commission at www.dataprotection.ie.
Questions about how Philip George Advisory handles your data? privacy@pgadvisory.io.