009 Agency (“009 Agency”, “we”) operates 009.agency. This policy covers this website only. Work delivered to clients is governed by the agreement signed for that engagement.
who is responsible
009 Agency decides what is collected on this site and why. For anything in this policy — access, correction, deletion, objection — write to hello@009.agency and a person will answer.
what we collect
What you send when booking the audit call. Booking runs on Calendly, the scheduling service we use: your name, email, your job title, your company name, website and size, and the slot you pick. Calendly processes this as our scheduling provider under its own privacy policy; we receive the booking details. That is the whole list; we do not ask for anything else and we do not buy data about you from anyone.
What you send through the audit request form. The site also takes audit requests through a form (“request audit” in the header): your name, the company website, your email, an optional note, your answer to “how did you hear about us”, and how you reached the site (the campaign link, the referring site and any ad click identifier in the address; if you accepted cookies, also the first page you arrived on after accepting, your most recent campaign link and your PostHog visitor identifier). The submission is emailed to us, posted to our private team chat in Telegram, and kept in a database on our own server, together with the IP address and browser signature of the request, which we use to filter automated spam. A record that a request was made (your name, email, company domain and how you reached the site) is also sent to PostHog, the analytics service we use to see which channels bring requests. PostHog stores it in the EU. Your cookie choice is recorded with the request. None of this is sold, and a note to hello@009.agency deletes it everywhere.
What your browser reports. Nothing is measured until you choose in the cookie banner. If you accept, we run Google Tag Manager with Google Analytics 4, PostHog (hosted in the EU) and the LinkedIn Insight Tag. They set cookies and record standard usage data: pages viewed, referring source, the campaign link you arrived through, approximate location derived from IP, device and browser type, and in PostHog how the page was used (clicks, scrolling and, when enabled, a replay of the visit with typed text masked). If you decline, Google and LinkedIn are not loaded and no analytics cookies are set; PostHog still records page views and clicks, but without an identifier that follows you from visit to visit and with ad click and email campaign identifiers removed from the page address.
Server logs. Our hosting provider records request logs, including IP addresses, for security and diagnostics.
why we use it
- To answer you. Booking details are used to hold the call, prepare and run the GEO audit, and follow up about it. Nothing else.
- To keep the site working and honest. Analytics and logs tell us which pages are read and whether anything is broken.
- To defend against abuse. Logs exist to keep the site usable and abuse out.
- To see which channels work. Campaign links, ad click identifiers and your answer to “how did you hear about us” tell us where requests come from. If you accepted cookies, Google and LinkedIn also use their tags to measure their ads and, in LinkedIn’s case, to show our ads to people who visited this site.
We do not sell your data, we do not rent it, and we do not use the booking details for unrelated marketing. If you never hear from us again after a reply, that is the intended behaviour.
who else sees it
Only the services that make the site run: our hosting provider, Google (Tag Manager and Analytics 4) as the analytics processor and LinkedIn for ad measurement, both only if you accept cookies, PostHog (analytics, hosted in the EU), and Telegram (the private team chat where new requests arrive). Each acts under its own terms and only for the purposes above. We will disclose data if a valid legal order requires it, and we will say so unless the order forbids it.
Google and LinkedIn may process data outside your country, including in the United States, under the safeguards published in their own terms.
how long we keep it
Audit requests are kept while the conversation is live and for up to 24 months after the last contact, so we can pick a thread back up. Analytics data follows Google Analytics 4 retention, set to 14 months. PostHog keeps analytics data for up to 12 months. Server logs are kept for the period our host applies. Ask us to delete your request earlier and we will.
cookies
Analytics and advertising cookies are set by Google Tag Manager, Google Analytics 4, PostHog and the LinkedIn Insight Tag, and only after you accept them. LinkedIn uses its tag to measure visits that come from its ads and to show our ads to people who visited this site. You can change your cookie choice at any time, and your browser can block or clear cookies; the site works without them. If you change from accept to decline, we remove the analytics cookies and stored identifiers we can reach on this site. What stays on your device either way: your light or dark theme, and your cookie choice (our record of it and PostHog’s own record of it). If you accepted, the campaign links you first and last arrived through are also kept on your device so they can be sent with an audit request. The theme never leaves your browser; the cookie choice is sent with an audit request.
your rights
Depending on where you live, you may have the right to see the data we hold about you, correct it, have it deleted, restrict or object to its use, or receive a copy in portable form. Ask at hello@009.agency. We answer within 30 days and we do not charge for it. If you are in the EEA or the UK you also have the right to complain to your local data protection authority.
children
This site is for business audiences and is not directed at children. We do not knowingly collect data from anyone under 16.
security
The site is served over HTTPS, and access to request data is limited to the people who need it to reply to you. No transmission over the internet is perfectly secure, so we do not claim it is.
changes
If this policy changes we update the effective date at the top of this page. Material changes will be described here rather than slipped in quietly. Oct 1, 2026: a cookie banner was added, analytics now load only after your choice, and PostHog, LinkedIn and Telegram are named as services that receive data.