1. Introduction and scope
This Privacy Policy explains what PC MAW Media (“PC MAW”, “we”, “us”) does with information about you when you visit pcmaw.com, subscribe to our newsletter, submit a form, or engage us for professional services. It is written to be read rather than to be survived, and we have tried to say plainly what many policies obscure.
It applies to this website and to the client-services work we carry out under our own name. It does not apply to third-party websites we link to, each of which has its own policy, nor to information you give directly to a third party such as a payment processor operating under its own terms.
Every numbered section below opens with a heading you can scan. If you only want the practical facts: we collect your name and email when you write to us, we keep a truncated server log for ninety days, we set no advertising cookies, we share data with five categories of processor, and you can have everything deleted by sending one email.
1.1 The short version
We collect very little. We do not sell, rent or share your information for anyone else’s marketing. We run no advertising cookies, no cross-site identifiers and no session-replay tooling. If you subscribe and later unsubscribe, we delete your record rather than keeping it on a suppression list indefinitely. The detail below explains exactly how that works and what your rights are.
2. Who we are and how to contact us
PC MAW Media is the data controller for information processed through this website. That means we decide what is collected and why, and we are responsible for it.
- Controller: PC MAW Media
- Registered address: 44 Kestrel Lane, Suite 12, Syracuse, NY 13202, United States
- Privacy contact: [email protected]
- General contact: [email protected]
We are a small organisation and are not required to appoint a Data Protection Officer. Privacy requests are handled by a named member of the editorial leadership team and logged in a register that records the request, the date and the outcome.
3. What information we collect
We collect information in three ways: you give it to us, it is generated automatically when you browse, or it comes from a service acting on our behalf. Here is every category, in full.
3.1 Information you give us
| Where | What | Required? |
|---|---|---|
| Contact form | Name, email address, optional phone and website, chosen topic, optional budget range, your message, consent flag | Name, email, topic, message and consent are required; the rest are optional |
| Newsletter subscription | Email address, subscription date, confirmation status | Email address only |
| Client engagement | Billing contact details, company name, tax identifiers where legally required, project materials and credentials you choose to share | As needed to deliver and invoice the work |
| Correspondence | The content of emails and messages you send us, and our replies | Whatever you choose to write |
3.2 Information collected automatically
Our server writes a standard access log entry for each request. It contains the truncated IP address (the final octet is discarded before the entry is written), the timestamp, the page requested, the HTTP status, the referring page where the browser supplies one, and the user-agent string. We use these for aggregate traffic counts, security investigation and debugging — not to build a profile of you.
The site also stores a small number of preferences in your browser’s local storage, such as your cookie choice and whether you have dismissed the announcement bar. These never leave your device and are described in the Cookie Policy.
3.3 Information we deliberately do not collect
- Advertising or cross-site tracking identifiers of any kind.
- Session recordings, heat maps or mouse-movement capture.
- Precise location data.
- Special category data — health, biometrics, political opinions, religious beliefs, sexual orientation, trade union membership.
- Payment card numbers. Card payments are handled entirely by our payment processor; we see only the last four digits and the transaction reference.
- Data purchased or licensed from brokers, or appended from enrichment services.
There is no third-party JavaScript on this site. That means no advertising pixel, no social tracking tag and no cross-site identifier — not because we configured them carefully, but because they are not present at all. You can verify this yourself by opening your browser’s network inspector on any page here.
4. Why we process it, and our lawful basis
Where the GDPR or a comparable law applies, we must have a lawful basis for each processing purpose. Ours are set out below.
| Purpose | Categories used | Lawful basis |
|---|---|---|
| Replying to an enquiry | Contact form data, correspondence | Consent, and legitimate interest in responding to messages addressed to us |
| Sending the newsletter | Email address, subscription status | Consent, withdrawable at any time |
| Delivering client work | Engagement data, correspondence, project materials | Performance of a contract |
| Invoicing and accounting | Billing details, transaction records | Legal obligation (tax and company law) |
| Aggregate traffic measurement | Truncated access logs | Legitimate interest in understanding which articles are read |
| Security, abuse prevention, debugging | Access logs, error logs | Legitimate interest in keeping the service available and secure |
| Defending or bringing legal claims | Whatever is relevant to the claim | Legitimate interest, or legal obligation |
Where we rely on legitimate interests we have carried out a balancing assessment and concluded that the processing is limited, expected and does not override your rights. You may object to any of it — see section 10.
5. Cookies and similar technologies
This site sets no advertising cookies and no analytics cookies. What it does store is a small set of strictly necessary preferences on your own device. The full inventory, with names, purposes and lifetimes, is maintained in the separate Cookie Policy, which is updated whenever anything changes.
6. Who we share information with
We share the minimum necessary, with a short list of processors who act only on our instructions under a written data-processing agreement.
| Category of recipient | What they receive | Why |
|---|---|---|
| Hosting provider | Everything transmitted to the site, including access logs | To serve the website |
| Email delivery provider | Subscriber email addresses and delivery metadata | To send the newsletter |
| Payment processor | Billing name, email, amount; card details go directly to them and never to us | To take payment |
| Accountant | Invoices and transaction records | Statutory bookkeeping and tax filing |
| Professional advisers | Only what is relevant to the matter | Legal or insurance advice when required |
| Public authorities | Only what a valid, binding request compels | Legal obligation |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the California Consumer Privacy Act as amended, we have not sold or shared personal information in the preceding twelve months and have no plans to.
If we ever receive a government or law-enforcement request, we will require that it be valid and properly served, will disclose only what is strictly compelled, and will notify you unless legally prohibited from doing so.
7. International transfers
We are based in the United States and some of our processors operate in the United States and the European Union. Where personal data originating in the EEA or the United Kingdom is transferred outside those areas, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), supplemented by technical measures including encryption in transit and at rest.
You may request a copy of the relevant transfer mechanism by writing to [email protected]. We will provide it, with commercially confidential terms redacted.
8. How long we keep things
| Category | Retention period | What happens then |
|---|---|---|
| Contact form submissions | 24 months from last contact | Deleted |
| Newsletter subscription | Until you unsubscribe, plus 30 days | Deleted, not suppressed |
| Client project records | 7 years from final invoice | Deleted; required for tax and limitation periods |
| Invoices and accounting records | 7 years | Deleted |
| Truncated access logs | 90 days | Deleted; aggregate counts retained without identifiers |
| Security incident records | 24 months | Deleted unless part of an ongoing matter |
| Privacy request register | 3 years | Deleted; kept to demonstrate compliance |
Where a retention period has expired but data is subject to a legal hold, we retain only what the hold requires and delete the rest.
When we delete something it is removed from live systems immediately, but encrypted backups may retain a copy for up to 35 days until that backup rotates out. Restored data is re-checked against deletion records so that deleted information is not silently reinstated. We think it is more honest to say this than to claim instantaneous erasure everywhere.
9. How we protect information
No system is perfectly secure, and any policy that claims otherwise is selling something. What we can tell you is what we actually do:
- TLS on every connection to the site, with modern cipher suites and HSTS enabled.
- Encryption at rest for databases and backups.
- Multi-factor authentication on every administrative account, using app-based codes or hardware keys rather than SMS.
- Least-privilege access. Team members have access only to the systems their role requires, reviewed quarterly.
- Separate staging and production environments, with production credentials never present in staging.
- Dependency and infrastructure patching on a defined schedule, with security patches applied out of band.
- Off-site, versioned backups with quarterly restore drills.
- An incident response plan that is written down and rehearsed annually.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will notify affected individuals directly without undue delay where the risk is high. Our notification will describe what happened, what data was involved, what we have done and what you should do.
10. Your rights
Depending on where you live, some or all of the following apply. We extend them to everyone who asks, regardless of location, because maintaining two standards is more work than maintaining one.
- Access — a copy of the personal data we hold about you, and information about how it is processed.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion, where we have no overriding legal obligation to keep it.
- Restriction — a pause on processing while a dispute about accuracy or legitimacy is resolved.
- Portability — a machine-readable copy of data you provided, where processing is based on consent or contract.
- Objection — to processing based on legitimate interests, and absolutely to direct marketing.
- Withdraw consent — at any time, without affecting processing that already took place.
- Complain — to your local supervisory authority. We would rather you came to us first, but it is your right either way.
California residents additionally have the right to know the categories of personal information collected, disclosed and sold or shared; the right to delete; the right to correct; the right to opt out of sale or sharing (we do neither); and the right not to be discriminated against for exercising any of these. We do not offer financial incentives in exchange for personal information.
11. How to exercise your rights
Email [email protected] with the word “Privacy request” in the subject line, or write to the postal address in section 2. Tell us what you want and give us enough detail to find your records — usually the email address you used.
- We acknowledge within five working days.
- We may ask for proof of identity where the request concerns sensitive records. We ask for the minimum needed and delete it once the request is closed.
- We respond substantively within thirty calendar days. Where a request is complex we may extend by up to sixty further days and will tell you why within the first thirty.
- There is no charge, unless a request is manifestly unfounded or excessive — in which case we will explain the reason before charging anything.
- If we refuse a request in whole or in part, we will tell you exactly why and how to challenge it.
An authorised agent may act for you if you provide written authorisation we can verify.
12. Children’s privacy
This site is intended for a general adult audience and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, write to [email protected] and we will delete it promptly and confirm that we have done so.
13. Automated decisions and profiling
We make no decisions about you by automated means, and we do not profile visitors. Nothing on this site scores, segments or ranks you, and no automated process produces legal or similarly significant effects concerning you.
14. Third-party links and embedded content
Articles link to external websites. Once you follow a link, that site’s own policies govern what happens, and we have no control over and accept no responsibility for their practices. We recommend reading the policy of any site you share information with.
We deliberately avoid embedded third-party content — no video embeds that load tracking scripts, no social widgets, no externally hosted fonts. Where we want to show something hosted elsewhere, we use a static image that links out instead. This is a privacy decision as much as a performance one.
15. Changes to this policy
We review this policy at least every six months and whenever we change how information is handled. When we make a material change we will update the effective date, summarise the change in a dated note at the foot of this page, and — where the change affects how we use information you have already given us — tell subscribers by email before it takes effect.
Previous versions are archived and available on request. We do not make material changes retroactive.
How to reach us about this document
Questions, complaints and requests relating to this policy should go to our legal contact rather than the general inbox, so they are logged and tracked properly:
- Email: [email protected]
- Post: PC MAW Media, 44 Kestrel Lane, Suite 12, Syracuse, NY 13202, United States
- Response time: five working days for acknowledgement, thirty days for substantive resolution
You can also use the contact form and select the closest topic. Related documents: Privacy Policy, Terms of Use, Cookie Policy, Disclaimer and DMCA Notice.