
Effective date: 30/12/25
Version: 1.0
This Privacy Notice explains how HYO (“we”, “us”, “our”) collects and uses your personal information when you request our free PDF and when we contact you by email about HYO services.
We follow the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1) Who we are (Controller)
Controller: Helping You Out Ltd trading as HYO
Registered office/business address: Helping You Out Ltd, 48 King St, King's Lynn, PE30 1HE
General contact Email (privacy enquiries): helpingyououtltd@gmail.com
Company number: 8708794
If you have questions about this notice or how we use your data, contact us using the details above.
2) What personal data do we collect?
When you sign up to receive the HYO self-employment PDF, we collect:
First name
Email address
Subscription and consent records (e.g., when you signed up, what you were told at sign-up, whether you confirmed your email)
Email engagement data (e.g., delivery, opens/clicks if enabled in our email platform)
We do not intentionally collect special category data (e.g., health information). Please do not submit it to us.
3) How do we collect your data?
We collect your data when you:
Complete our sign-up form on our Systeme.io landing page
Click confirmation links (if we use double opt-in)
Receive and interact with our emails
Book an initial Discovery Call via video call or 1-on-1 session via video call (if/when you choose to do so)
4) Why we use your data (purposes)
We use your data to:
Deliver what you asked for: send you the free HYO self-employment PDF and any essential service emails linked to that request.
Send our nurture sequence (e.g., a short set of emails explaining HYO and inviting you to book a Discovery Call and/or a paid 1-on-1 meeting).
Send newsletters/updates (when we launch our newsletter).
Operate and improve our landing page, email deliverability, and communications (e.g., managing bounces, unsubscribes, list hygiene, and basic performance reporting).
Handle enquiries and protect our service from misuse (security, fraud prevention).
5) Our lawful bases (UK GDPR) and marketing rules (PECR)
A) Delivering the PDF you requested
Lawful basis: Performance of a contract/steps at your request before entering a contract (to send the resource you asked for).
B) Nurture sequence and newsletters (marketing emails)
PECR rule: Marketing emails to individuals generally require prior consent (unless the “soft opt-in” applies, which typically relates to existing customers). Information Commissioner's Office+1UK GDPR lawful basis for marketing: Consent.
Important: If you have not consented to marketing, we will limit emails to what is necessary to deliver the PDF and administer your request.
C) Withdraw consent at any time
You can withdraw marketing consent at any time by using the unsubscribe link in any marketing email. Withdrawing consent does not affect the lawfulness of processing that took place before you withdrew it.
6) Who we share your data with (processors)
We use trusted service providers to operate our landing page and email delivery. These providers act as processors under UK GDPR.
We use Systeme.io to host our landing page, collect sign-ups, and send emails. Systeme states its servers are hosted by Amazon Web Services in Ireland, and that data is not transferred outside the European Union. Systeme.io
Systeme.io also provides a double opt-in feature; its help guidance states that if a contact does not confirm within 24 hours, they may be automatically deleted (where configured). help.systeme.io
Other tools (only if used)
If we use additional tools (for example, a scheduling platform for calls, payment processing, or analytics), we will list them here and explain what data they receive.
Current additional tools used:
None
7) International transfers
We intend to keep personal data processed within the UK/EU where possible. Systeme.io states that data is not transferred outside the EU. systeme.io
If we add a provider that involves international transfers in the future, we will update this notice and ensure appropriate safeguards are in place.
8) How long do we keep your data (retention)?
We keep your data only as long as needed for the purposes above:
Unconfirmed sign-ups (if double opt-in is enabled): deleted after 24 hours (or as configured). help.systeme.io
Confirmed subscribers who remain engaged: kept while you remain subscribed and for 6 months after your last interaction, then deleted or anonymised.
Unsubscribed contacts: we keep a minimal record to ensure we respect your opt-out (suppression), unless you ask for deletion, and we can do so without risking re-contact.
Enquiries and booking records (if applicable): kept for 6 years for administration and record-keeping.
Default recommendation (you can adjust): 24 months inactivity rule for prospects, reviewed quarterly.
9) Your rights
You may have the right to:
Access your personal data
Correct inaccurate data
Request deletion (in certain circumstances)
Restrict or object to processing (in certain circumstances)
Data portability (where applicable)
Withdraw consent (where we rely on consent)
To exercise your rights, contact: helpingyououtltd@gmail.com
10) Complaints
If you’re unhappy with how we handle your information, you can complain to us first, and you also have the right to complain to the Information Commissioner’s Office (ICO) (UK). Information Commissioner's Office+1
11) Security
We take appropriate technical and organisational measures to protect your information, including access controls and secure cloud-based processing.
12) Cookies and tracking on the landing page
Our landing page may use essential cookies required for it to function. If we use non-essential cookies (e.g., analytics/advertising pixels), we will provide appropriate cookie information and obtain consent where required.
13) Updates to this Privacy Notice
We may update this notice occasionally. We will post the latest version on our landing page and update the effective date at the top.