Draft last updated 27 September 2026
This notice explains how Philip George Advisory ("we", "us") collects and uses personal data when you use the Policy Generator, in line with the EU GDPR and the Irish Data Protection Act 2018. Your data is hosted in the EU/EEA.
Philip George Ltd is the controller for your account and billing data, and a processor for the content you put into the service (your answers, tool register and generated policies), which you control. Contact: privacy@pgadvisory.io.
We do not sell your data. We use a small set of subprocessors under written data processing agreements — see our subprocessor list. All are used only to run the service.
We host your data in the EU/EEA. Where a subprocessor involves a transfer outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses. See the subprocessor list for details.
We keep account and service content for as long as your account is active, and delete it within a defined period after account closure unless we must retain records for legal or accounting reasons. We retain only what regeneration requires.
Snapshot results are kept for 12 months and then deleted. If you create an account, the answers become part of your account content and follow the rule above instead. Ask us at any time and we will delete a Snapshot sooner.
You have the right to access, correct, delete, restrict, port and object to the processing of your data, and to withdraw consent where we rely on it. You can export or delete your account data from your Settings, or contact us at privacy@pgadvisory.io. We respond within one month.
Please contact us first. You also have the right to complain to the Irish Data Protection Commission at www.dataprotection.ie.
Questions about how Philip George Advisory handles your data? privacy@pgadvisory.io.