Legal

PRIVACY POLICY

Last updated:

This policy explains what personal data Sell with Marketing collects, why we collect it, who we share it with, and the rights you have over it. It is written to the standard of the EU General Data Protection Regulation (GDPR) — the strictest framework we are subject to — and applied worldwide, with additional sections for specific jurisdictions.

1. Who we are

Sell with Marketing ("SWM", "we", "us") is a B2B marketing agency. For the purposes of the GDPR and equivalent laws, we act as the data controller for the personal data described in this policy — that is, we decide why and how it is processed.

We operate from four locations. Our German office is our establishment in the European Union for GDPR purposes:

  • Mexico (headquarters): Av. Tepeyac 5048, Jardines del Tepeyac, 45030 Zapopan, Jalisco, Mexico
  • United States: 723, 1007 Orange St, Wilmington, DE 19801, United States
  • Germany (EU establishment): Seenbachweg 7, 35325 Mücke, Hessen, Germany
  • Venezuela: Torre Kyra, Av. Principal de La Carlota, Caracas 1071, Venezuela

For any question or request about this policy, or to exercise your rights, write to [email protected]. We answer privacy requests within 30 days.

2. What this policy covers

This policy covers sellwithmarketing.com and its subdomains, the forms on this site, our email and LinkedIn outreach, and the CRM records we keep about prospects, clients and contacts. It does not cover third-party websites we link to, or the systems our clients operate themselves.

When we process personal data on behalf of a client — for example, running campaigns inside their advertising or CRM accounts — the client is the controller and we act as a processor under a separate data processing agreement.

3. What we collect

We collect only what we need. There is no obligation to give us any of it, but some of it is required for us to answer you.

CategoryDataWhere it comes from
Contact dataFirst name, last name, work email, phone number, company nameThe form on this site, or your reply to our outreach
Qualification dataAnnual revenue band, the message you write us, the market and language you operate inThe form on this site
Professional dataJob title, employer, public professional profile, company size and sectorPublic sources and B2B databases, for prospecting (see section 6)
Technical dataIP address, approximate country, browser and device type, pages viewed, referring page, timestampsAutomatically, when you browse the site
Interaction dataWhich pages you visited, which forms you started or submitted, clicks, session recordings of interface events (not of your screen contents)Analytics tools, only where you have consented
Transaction dataPurchase amount, currency, product bought, and the email and phone given at checkoutStripe, when you buy a productised service such as NAIMED

We do not knowingly collect special category data (health, political opinions, religion, biometrics, trade union membership, sexual orientation) and we ask you not to send it to us. We do not sell personal data.

4. Why we use it, and our legal basis

Under the GDPR we must have a lawful basis for every use. These are ours:

PurposeLegal basis
Answering your enquiry and delivering the free brand audit you requestedSteps taken at your request before entering a contract (Art. 6(1)(b))
Providing our services and administering the client relationshipPerformance of a contract (Art. 6(1)(b))
B2B prospecting: contacting professionals at companies that match our ideal client profileLegitimate interest in promoting our services to relevant businesses (Art. 6(1)(f)). You can object at any time and we stop
Analytics, advertising measurement, retargeting and non-essential cookiesYour consent (Art. 6(1)(a)), given through our cookie banner and withdrawable at any time
Keeping the site secure, preventing abuse and fixing faultsLegitimate interest in operating a secure service (Art. 6(1)(f))
Invoicing, accounting and tax recordsLegal obligation (Art. 6(1)(c))
Defending or bringing legal claimsLegitimate interest in protecting our rights (Art. 6(1)(f))

Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms. You can ask us for that assessment.

5. Cookies and tracking

Essential cookies keep the site working and your consent choice remembered; they load without consent because the site cannot function without them. Everything else — analytics and advertising — loads only after you accept it in the banner.

  • Consent record: we store your choice in your browser under "swm_consent_v1". Clearing your browser storage resets it and the banner appears again.
  • Google Tag Manager and Google Analytics 4: how the site is used, in aggregate. Consent-gated, and loaded with Google Consent Mode defaults set to denied.
  • Meta Pixel: measures whether our advertising leads anywhere. Loads only with advertising consent.
  • Meta Conversions API: when you complete a purchase, our server sends Meta the event together with your email and phone number hashed with SHA-256 — that is, converted into an irreversible fingerprint, not sent in readable form.
  • UserMaven: product analytics, including automatic capture of interface interactions and form activity. Consent-gated.
  • HubSpot: sets a "hubspotutk" cookie that links a form submission to the browsing session that produced it.
  • Cloudflare: our host. Determines the approximate country from your IP address so we can show the correct consent banner in the EU and EEA.

You can change or withdraw your consent at any time using the cookie settings on this site, and you can block cookies in your browser. Withdrawing consent does not affect processing that already happened.

6. B2B prospecting

We contact professionals at companies that fit our ideal client profile — industrial manufacturers and adjacent sectors. We use business contact details from public sources and B2B databases, we contact you in your professional capacity, and we say who we are and why we are writing in the first message.

Every message includes a way to opt out. If you tell us to stop, we stop, and we keep the minimum record needed to make sure we do not contact you again. To be removed immediately, write to [email protected] with the subject "Do not contact".

7. Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We do share it with the providers that run parts of our operation, each bound by a contract that limits them to our instructions:

ProviderWhat forWhere
HubSpotCRM and form handlingUnited States
ClayB2B prospect research and enrichmentUnited States
InstantlyOutbound email sequencing and deliveryUnited States
Google (Tag Manager, Analytics 4)Website analyticsUnited States
Meta PlatformsAdvertising measurement and retargetingUnited States
UserMavenProduct analyticsEuropean Union
CloudflareHosting, CDN and securityGlobal edge network
SanityContent management and image deliveryUnited States / European Union
StripePayment processingUnited States
Google WorkspaceEmail and internal documentsUnited States

We also disclose data where the law requires it, to our professional advisers under confidentiality, and to a buyer if the business is ever sold — in which case this policy continues to apply until you are told otherwise.

8. International transfers

We operate across Mexico, the United States, Germany and Venezuela, and several of our providers are in the United States. That means your data may be processed outside your country, including outside the EEA.

Where a transfer leaves the EEA, the United Kingdom or Switzerland, we put the appropriate safeguards in place with the provider or office receiving the data. To ask which safeguards apply to your data specifically, write to [email protected].

9. How long we keep it

  • Enquiries that do not become clients: 24 months from the last contact, then deleted.
  • Client records: for the duration of the relationship and 6 years afterwards, to cover contractual and tax obligations.
  • Invoicing and accounting records: as required by Mexican, US and German tax law, generally 6 to 10 years.
  • Analytics data: up to 14 months in aggregate form.
  • Opt-out records: kept indefinitely, because deleting them would mean contacting you again by mistake.

10. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, send it to another provider, or object to our use of it. You can also withdraw consent at any time. We do not charge for this and we do not treat you differently for asking.

If you are in the EEA, the UK or Switzerland, these are your rights under Articles 15 to 22 of the GDPR, and you may complain to your national supervisory authority. Ours is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Postfach 3163, 65021 Wiesbaden, Germany.

If you are in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to delete it, to correct it, to opt out of "sale" or "sharing" — we do neither — and to limit the use of sensitive information, which we do not collect. We will not discriminate against you for exercising these rights.

If you are in Mexico, the Federal Law on the Protection of Personal Data Held by Private Parties gives you ARCO rights — access, rectification, cancellation and opposition — and the right to revoke consent. You may complain to the competent national authority.

If you are in Brazil, the LGPD gives you equivalent rights, including confirmation of processing, anonymisation and portability. Residents of Canada, Australia, Japan, South Korea and other jurisdictions where we operate have the rights granted by their local law, and we apply the standard in this policy as a floor everywhere.

To exercise any of this, write to [email protected]. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.

11. Security

The site is served over HTTPS. Access to our CRM and internal systems is restricted to the people who need it, protected by multi-factor authentication and reviewed periodically. Data sent to Meta through the Conversions API is hashed before it leaves our server. No system is perfectly secure, and if a breach ever affects your rights we will notify you and the relevant authority within the legal deadline — 72 hours under the GDPR.

12. Automated decisions and AI

We use AI tools to help produce and analyse content and to prioritise prospecting. We do not make decisions with legal or similarly significant effects about you by automated means alone. Scoring that ranks accounts for outreach is always reviewed by a person before anyone is contacted, and we do not feed the personal data of our site visitors into public AI models for training.

13. Children

This is a business service and it is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

14. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we use your data, we will tell you directly where we have your contact details, before it takes effect.

Questions, complaints or requests: [email protected]. We answer within 30 days.

A COMPANY WITHOUT A BRAND IS A COMPANY WAITING TO DISAPPEAR. SWM BUILDS THE SUIT. sellwithmarketing.com