Data Protection

Privacy

How theglocalpm.com handles your personal data, under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.

The short version

1. Who is responsible

The controller for data processing on this website, within the meaning of Art. 4(7) GDPR, is:

Company
Ventureland OÜ
Registered office
Pärnu mnt 139b, 11317 Tallinn, Estonia
Registry code
17040268 (Estonian Commercial Register)
Represented by
Ali Mahmoud, Member of the Management Board
Contact for data protection
ali@theglocalpm.com

We have not appointed a Data Protection Officer, as the statutory thresholds under Art. 37 GDPR are not met.

2. Your rights

Under the GDPR you have the right to:

To exercise any of these, email ali@theglocalpm.com. We will respond within one month.

Right to complain

You may lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee. You may also complain to the supervisory authority in your own country of residence.

3. Hosting and server logs

This site is hosted on GitHub Pages, a service of GitHub, Inc. (a Microsoft company), 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA.

When you open a page, your browser necessarily transmits technical data to GitHub's servers, which may be logged: your IP address, the requested file, the date and time, the referring page, and your browser and operating system. We do not have access to these logs and do not combine them with other data.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is delivering the website reliably and securely — a site cannot be served without processing the visitor's IP address.

4. Cookies and your consent

On your first visit you are asked to accept or decline analytics. Nothing analytical is stored or transmitted before you choose.

Your choice is remembered in your browser's local storage under the key tgpm_consent. This is strictly necessary to honour your decision, and is not used to track you.

If you accept, Google Analytics and PostHog set cookies as described below. If you decline, Google Analytics is disabled through Google Consent Mode and sets no cookies; PostHog switches to a cookieless mode which counts you as a visitor without storing anything on your device and without identifying you.

You can change your mind at any time using the Cookies link in the footer of every page. Withdrawing is as easy as granting.

5. Google Analytics 4

Only active if you accept. We use Google Analytics 4 to understand which pages and case studies people actually read. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which may transfer data to Google LLC in the USA.

Data processed includes pages viewed, approximate location derived from your IP address, device and browser type, referring source, and interactions such as opening the booking dialog, opening the résumé, or completing a booking. IP anonymisation is applied by default in Google Analytics 4.

Legal basis: Art. 6(1)(a) GDPR — your consent. Withdrawable at any time.

You can additionally install Google's browser opt-out add-on. More at policies.google.com/privacy.

6. PostHog (EU)

We use PostHog for product analytics. Provider: PostHog, Inc. This site uses PostHog's EU Cloud, so event data is stored on servers within the European Union.

If you accept: PostHog sets a first-party cookie (ph_*) to recognise returning visits, and records pages viewed and interactions such as newsletter signups and booking completions.

If you decline: PostHog runs in cookieless mode. No cookies or local storage are used. You are counted using a privacy-preserving hash calculated on PostHog's servers, which is rotated daily and cannot be traced back to you. In this mode no location enrichment is performed and no session recording takes place.

Legal basis: Art. 6(1)(a) GDPR for the cookie-based mode. More at posthog.com/privacy.

7. Newsletter

The newsletter is delivered by Kit (formerly ConvertKit), a service of Kit.com, Inc., USA. When you subscribe, your email address is transmitted to and stored by Kit.

Double opt-in. After you submit the form you receive a confirmation email. Your address is only added to the list once you click the link in that email. Until then nothing is sent to you. This procedure documents that the subscription was genuinely yours.

Kit records whether emails are opened and which links are clicked, which we use to judge whether the writing is worth continuing. If you would rather not be measured this way, simply unsubscribe — every email contains a one-click unsubscribe link.

Legal basis: Art. 6(1)(a) GDPR — your consent, given by confirming the opt-in email.

Retention: until you unsubscribe. Afterwards your address may be retained on a suppression list solely to ensure we do not email you again. Kit's privacy notice: kit.com/privacy.

8. Booking a call (Cal.com)

Appointment booking is provided by Cal.com, Inc., USA. The booking dialog is embedded on this site, which means Cal.com receives your IP address when a page containing it is loaded, and the scheduling script is fetched from Cal.com's servers.

If you book, the details you enter — typically name, email address, chosen time, and any notes — are processed by Cal.com to arrange the meeting.

Legal basis: Art. 6(1)(b) GDPR for booking data, as processing is necessary to take steps at your request before entering into a contract; Art. 6(1)(f) for embedding the scheduling tool. Cal.com's notice: cal.com/privacy.

9. Other resources loaded by this site

For transparency: the following are loaded from third-party servers when a page opens, which means those providers receive your IP address. They set no analytics cookies and are not used to profile you, but they are external requests and you should know about them.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in presenting the site consistently across devices.

10. Transfers outside the EU

Several providers above are based in the United States. Where data is transferred there, it is safeguarded either by the provider's certification under the EU–US Data Privacy Framework, or by Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR.

Despite these safeguards, US authorities may in principle be able to access such data, and it cannot be guaranteed that you would have the same avenues of redress as within the EU. PostHog analytics data is kept in the EU specifically to reduce this exposure.

11. How long data is kept

12. Changes to this policy

We update this notice when the services behind the site change. The date below reflects the current version.

Last updated: 12 August 2026

Imprint