Legal
Privacy Notice
Last updated: 17 September 2026
This Notice explains what personal data Totomoko collects when you use totomoko.com, contact us, or deal with us as a business contact; why we collect it; who else processes it; how long we keep it; and the rights you have over it. It is written to meet Articles 13 and 14 of the GDPR and the UK GDPR, and the notice requirements of United States state privacy laws.
1. Controller
1.1 Identity
The controller of the personal data described in this Notice is Hyper Viral LLC, a limited liability company formed in the State of Wyoming, United States, trading as Totomoko (“Totomoko”, “we”, “us”).
1.2 Contact
For anything concerning this Notice or your personal data: privacy@totomoko.com.
1.3 Data protection officer and representative
Privacy requests may be addressed directly to us at the address in Clause 1.2.
2. Scope
2.1 What this Notice covers
This Notice covers personal data we process as a controller: when you visit the Site; when you contact us, book a conversation, or subscribe to the newsletter; when we research and contact organizations that may benefit from our services; and when you interact with our social-media pages.
2.2 What it does not cover
Personal data we process on a client’s instructions inside a paid engagement is governed by the signed agreement for that engagement and its data processing terms, under which we act as processor. If you are an employee, customer, or contact of a client and have a question about data we process for that client, contact the client, who is the controller. Third-party sites we link to have their own notices.
3. Personal data we collect and where it comes from
3.1 When you visit the Site
Our hosting provider records standard server and security logs for every request: IP address, browser and device type, operating system, the page requested, the referring page, and the time. We also run cookieless aggregate analytics (Cloudflare Web Analytics), and Google Analytics 4 and Microsoft Clarity if you accept them (Clause 5). Source: your browser.
3.2 When you email us
Your email address, your name if you give it, your organization if you give it, and the content of your message. Source: you.
3.3 When you book a conversation
Booking is handled by Cal.com on its own site. Cal.com passes to us the name, email address, time zone, and any notes you enter, and confirms the appointment to both of us. What Cal.com collects on its own pages is governed by Cal.com’s privacy policy. Source: you, via Cal.com.
3.4 When we discuss working together
If a conversation continues, we keep the records needed to follow it up: your name, role, organization, contact details, and notes of what was discussed and agreed. Source: you and your colleagues.
3.5 When you subscribe to the newsletter
Your email address, the date you subscribed, and the fact that you have unsubscribed if you do; if you have also contacted us, the name, organization and country from that form. Whether a newsletter email was opened and which links in it were clicked (open and click tracking, Clause 4.5). Source: you; the tracking, our email provider.
3.6 Business contacts we identify ourselves
We research organizations that may benefit from our services and may contact people in a relevant role at those organizations. For those people we hold: name, job title, organization, business email address, and the public source the information came from. Sources: the organization’s own website, professional networking profiles you have made public, published job advertisements, and business directories.
3.7 Social media
If you interact with our pages on X, LinkedIn, Instagram, or GitHub, we see the profile information and content you make available on that platform. The platform is an independent controller, or in some cases a joint controller with us for page statistics, under its own privacy policy. Source: you, via the platform.
3.8 What we do not collect
We do not collect payment details, government identifiers, precise location, biometric data, or special categories of personal data (such as health, religion, or political opinions) through the Site or in the course of business development. We do not knowingly collect personal data from anyone under 18.
4. Purposes and lawful bases
4.1 Operating and securing the Site
Purpose: to serve pages and to detect, prevent, and block abuse. Data: Clause 3.1. Lawful basis: our legitimate interest in running a secure, available website (Article 6(1)(f) GDPR).
4.2 Responding to you
Purpose: to answer your message or hold the conversation you booked. Data: Clauses 3.2 and 3.3. Lawful basis: steps taken at your request before entering a contract (Article 6(1)(b)), and our legitimate interest in responding to people who contact us (Article 6(1)(f)).
4.3 Pursuing a business relationship
Purpose: to keep track of a live conversation about working together, to prepare proposals, and to follow up. Data: Clause 3.4. Lawful basis: steps taken at your request before entering a contract (Article 6(1)(b)), and our legitimate interest in developing our business (Article 6(1)(f)).
4.4 Contacting organizations that may benefit from our services
Purpose: to send relevant messages to people in a professional role at organizations we have identified, and to keep a record so we do not contact anyone who has asked us not to. Data: Clause 3.6. Lawful basis: our legitimate interest in business-to-business marketing (Article 6(1)(f)), which we have assessed against your interests: we contact business roles only, about matters relevant to that role, and we stop on request. Where the law of your country requires consent for such messages, we do not send them without it. We tell you where your details came from, and point you to this Notice, in the first message we send you, which is always within one month of recording your details.
4.5 Sending the newsletter
Purpose: to send you the newsletter you asked for, and to see whether it is read: newsletter emails carry open and click tracking, so we know whether an email was opened and which links were followed. Data: Clause 3.5. Lawful basis: your consent (Article 6(1)(a)), which you may withdraw at any time by unsubscribing.
4.6 Honouring opt-outs
Purpose: to keep a minimal record of people who have unsubscribed or objected, so that we do not contact them again. Data: email address and the date of the request. Lawful basis: our legal obligation to honor objections and withdrawals of consent (Article 6(1)(c)).
4.7 Legal obligations and claims
Purpose: to comply with law, respond to lawful requests from authorities, and establish, exercise, or defend legal claims. Data: whatever is relevant. Lawful basis: legal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f)).
4.8 No other purpose
We do not use personal data for any purpose not listed in this Article. We do not sell it, share it for anyone else’s marketing, use it to build profiles, or subject you to decisions based solely on automated processing that produce legal or similarly significant effects.
4.9 Legitimate-interest assessments
Where we rely on legitimate interest, we have balanced that interest against your rights and reasonable expectations. You may request a summary of the assessment for any purpose above at privacy@totomoko.com.
5. Cookies and tracking
5.1 Analytics, only with your consent
The Site shows a cookie banner on your first visit. If you accept, we load Google Analytics 4 (Google LLC, United States) and Microsoft Clarity (Microsoft Corporation, United States) to see how the Site is used. Clarity records how you move through pages (clicks, scrolling, mouse movement) as session recordings and heatmaps; text typed into form fields is masked, and recordings are kept for 30 days. Microsoft also uses Clarity data for its own purposes, including advertising, as its privacy disclosure describes. If you decline, neither loads, and you can change your choice at any time from the "Cookie settings" link in the footer. We also run Cloudflare Web Analytics, a cookieless, aggregate measurement that does not identify individual visitors and needs no consent.
5.2 No advertising
The Site runs no advertising, retargeting, or social-media tracking pixel.
5.3 Fonts and scripts
Fonts are served from our own domain. Google Analytics and Microsoft Clarity load only after consent; every other script on the Site is ours.
5.4 Do Not Track and Global Privacy Control
Analytics stays off by default and is enabled only by your Accept choice. If your browser sends a Global Privacy Control signal, we treat it as Decline automatically and do not show the banner. We treat a Do Not Track signal as an opt-out in any event.
5.5 Details
What the Site stores in your browser is set out in full in the Cookies Notice.
6. Recipients and sub-processors
6.1 Processors
The following providers process personal data on our behalf to make the Site and our correspondence work, each under its own data processing terms. Each has access only to the data described.
| Provider | Role | Data | Location |
|---|---|---|---|
| Cal.com, Inc. | Scheduling the first conversation | Booking details (Clause 3.3) | United States |
| Cloudflare, Inc. | Hosting, content delivery, and security for the Site; cookieless aggregate analytics (Cloudflare Web Analytics) | Server and security logs (Clause 3.1); page views and performance metrics, not tied to an individual | United States and the European Union |
| Google LLC | Website usage analytics (Google Analytics 4), only after you accept the cookie banner | Pages viewed, device and browser type, approximate location from IP, and the _ga cookies described in the Cookies Notice |
United States |
| Microsoft Corporation | Session recordings and heatmaps (Microsoft Clarity), only after you accept the cookie banner; Microsoft also uses this data for its own purposes, including advertising | Clicks, scrolling and mouse movement with form input masked, device and browser type, approximate location from IP, and the _clck/_clsk cookies described in the Cookies Notice; recordings kept 30 days |
United States |
| HubSpot, Inc. (HubSpot Ireland Ltd for EU accounts) | CRM: contact and ticket records from the site forms | Name, email, organization, role and message from the contact and newsletter forms; country from the request | European Union |
| Purelymail LLC | Email hosting for our mailboxes | Email you send us and we send you (Clauses 3.2, 3.4, 3.6) | United States |
| Resend, Inc. | Email delivery for the newsletter and automated sequences, sent from news.totomoko.com, with open and click tracking | Email, name, country, organization, and open and click events | United States; sending from the European Union. DPA, sub-processors |
| Stripe, Inc. | Invoicing and payment processing for client engagements | Billing name, address, email and invoice records; card details go to Stripe and never reach us | United States |
6.2 Business records
Records of business contacts and conversations (Clauses 3.4 and 3.6) are held only in our mailboxes and our CRM (Clause 6.1). They are not stored in documents, spreadsheets, or files outside those systems.
6.3 AI providers
We do not use personal data held under this Notice to train any artificial-intelligence model, and we do not opt it into any provider’s training program. Where an AI tool assists us in reading, sorting, or drafting correspondence, it runs under a provider whose terms prohibit training on the data and limit its retention, and the tool is not a recipient of the data for any other purpose. Inside a paid engagement, any AI provider that will process personal data is named in that engagement’s data processing terms before any data moves.
6.4 Professional advisers
We may share personal data with our lawyers and accountants where necessary to obtain their advice or services, under duties of confidentiality.
6.5 Disclosure required by law
We will disclose personal data where the law requires it, in response to a valid legal process, or where necessary to establish, exercise, or defend legal claims or to protect the rights, property, or safety of any person. Where we are permitted to tell you, we will.
6.6 Business transfers
If Totomoko is sold, merges with another business, or transfers substantially all of its assets, personal data may be transferred to the successor, who will be bound by this Notice.
6.7 Changes to processors
If we add or replace a processor for the Site or our correspondence, we will update Clause 6.1 before the change takes effect.
7. International transfers
7.1 Where data is processed
Totomoko is in the United States. The providers in Article 6 process data in the United States and, for Cloudflare, also in the European Union. If you are in the European Economic Area, the United Kingdom, or Switzerland, some of your personal data is transferred outside those territories.
7.2 Safeguards
Transfers to the United States rely on a mechanism recognized by Chapter V GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection: certification under the EU–US Data Privacy Framework, its UK Extension, and the Swiss–US Data Privacy Framework where the provider holds it, and otherwise the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum. Transfers to the United Kingdom from the European Union, and to the European Union from the United Kingdom, rely on the adequacy decisions in force between them.
7.3 Copies
You may request details of the safeguard applying to a particular provider at privacy@totomoko.com.
8. Retention
8.1 Periods
| Data | Retained for |
|---|---|
| Server and security logs (Clause 3.1) | The provider’s standard window, not exceeding 30 days |
| Emails and bookings that do not lead to further contact (Clauses 3.2, 3.3) | 12 months from the last message, then deleted |
| Records of a live business conversation (Clause 3.4) | For as long as the conversation is live, then 12 months |
| Business contacts we identified (Clause 3.6) | 12 months from the date we recorded them, then deleted unless a conversation has begun, in which case Clause 3.4 applies |
| Anything that becomes part of a signed engagement | Governed by that engagement’s agreement |
| Newsletter subscription (Clause 3.5) | Until you unsubscribe |
| Opt-out record (Clause 4.6) | Indefinitely, limited to your email address and the date, so that the opt-out can be honoured |
| Records needed to establish, exercise, or defend legal claims | For the applicable limitation period |
8.2 Earlier deletion
If you ask us to delete your data sooner, we will, unless we are required by law to keep it or it is needed for an ongoing legal claim.
8.3 Backups
Data deleted from live systems is removed from backups on the next backup rotation.
9. Your rights
9.1 Rights under the GDPR and UK GDPR
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- access the personal data we hold about you and receive a copy of it, together with the information in this Notice;
- have inaccurate or incomplete data corrected;
- have your data erased, where one of the grounds in Article 17 applies;
- restrict how we process it while a dispute about accuracy or lawfulness is resolved;
- receive the data you provided to us in a structured, commonly used, machine-readable form, and have it transmitted to another controller where technically feasible;
- object at any time to processing based on legitimate interest, including the business development in Clauses 4.3 and 4.4, which then stops unless we demonstrate compelling legitimate grounds;
- object at any time to direct marketing, which stops without exception;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
9.2 Rights under United States state law
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy statute, you have the right to know what personal data we collect and how we use and disclose it; to access it; to correct it; to delete it; to obtain a portable copy; and not to be discriminated against for exercising these rights. We do not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or process sensitive personal data, so there is nothing to opt out of. You may authorize an agent to make a request on your behalf; we will ask the agent for proof of authorization. If we decline a request, we will say why, and you may appeal by replying to our decision; we will respond to the appeal within forty-five (45) days and, if it is refused, tell you how to contact your state’s attorney general.
9.3 Categories collected, for United States residents
In the preceding twelve months we have collected the following categories of personal data: identifiers (name, email address, IP address); professional or employment-related information (job title, organization); and internet activity (server logs). Purposes are those in Article 4. We disclosed them to the providers in Article 6 for business purposes only. We did not sell or share any category.
9.4 How to exercise your rights
Write to privacy@totomoko.com. We will respond within thirty (30) days, or within the shorter period the applicable law requires, and will tell you if we need longer for a complex request. We will not charge you unless a request is manifestly unfounded or excessive. We may ask for enough information to confirm that a request comes from you or from someone authorized to act for you.
9.5 Complaints
You may lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner’s Office (ico.org.uk, telephone 0303 123 1113); in the European Union, the data protection authority of the member state where you live, work, or where the alleged infringement occurred; in Switzerland, the Federal Data Protection and Information Commissioner. We would prefer that you raise the matter with us first, but that is your right and it is not conditional on doing so.
10. Security
10.1 Measures
Traffic to the Site is encrypted in transit. Personal data is held only in the systems of the providers named in Article 6, reached through accounts protected by multi-factor authentication, with credentials held in a password manager. Access is limited to the people who need it. The Security and Compliance page describes our practices in more detail.
10.2 No absolute guarantee
No method of transmission or storage is completely secure. We take the measures above and review them, but we cannot guarantee absolute security.
10.3 Breach notification
If a personal data breach is likely to result in a high risk to you, we will inform you without undue delay. We will notify the competent supervisory authority within 72 hours of becoming aware of a breach, where the law requires it.
11. Children
11.1 Not directed at children
The Site is for people acting in a business or professional capacity. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact privacy@totomoko.com and we will delete it.
12. Third-party sites
12.1 Links
The Site links to third-party websites and services. This Notice does not apply to them. Read the privacy notice of any site you visit.
13. Changes to this Notice
13.1 Updates
We may update this Notice from time to time. The version on this page is the one that applies, and the date at the top shows when it last changed.
13.2 Material changes
If a change is material and we hold your contact details, we will tell you directly rather than relying on you to re-read this page.
14. Related documents
14.1 Where this Notice sits
This Notice forms part of the Terms of Service. It is read with the Cookies Notice, which sets out what the Site stores in your browser, and the Security and Compliance page, which describes how data is protected. All of them, with the Responsible AI statement, are collected in the Trust Center.
15. Contact
15.1 Privacy
15.2 Controller
Hyper Viral LLC, trading as Totomoko, a Wyoming limited liability company. Totomoko operates remotely; correspondence is by email.