1. Introduction
This Privacy Policy describes how Lomit ("we," "us," or "our"), operating the website lomit.digital and providing professional consulting services under the Dissect-Diagnose-Prognose (DDP) model, collects, uses, discloses, retains, and protects personal information and client business data.
We act as a premium-tier consulting firm that conducts revenue pipeline audits and delivers retainer-based solutions. We are committed to protecting the privacy and confidentiality of website visitors, prospective clients, and engaged clients. We do not sell personal information. This Policy is designed to comply with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state privacy laws.
By accessing our website or engaging our services, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use our website or services.
2. Scope
This Policy applies to:
- Visitors to our website
- Individuals who submit inquiries, contact forms, or book discovery/audit calls
- Prospective and engaged clients (and their representatives) who provide information in connection with Revenue Analysis Audits or retainer engagements
- Any personal information we process in the course of delivering our services
This Policy does not apply to third-party websites or services that may be linked from our site. We are not responsible for the privacy practices of those third parties.
Client confidential business, financial, and operational information provided under engagement is additionally protected by the terms of our engagement agreements, non-disclosure agreements, and professional confidentiality obligations.
3. Information We Collect
We collect only the information reasonably necessary for the purposes described in this Policy.
A. Information You Provide Directly
- Contact and identification details: name, email address, telephone number, company name, job title, and business address.
- Inquiry and engagement information: details submitted via contact forms, email, or discovery calls regarding your business and revenue pipeline.
- Client engagement data: financial, operational, systems, marketing, and performance information provided for Dissection, Diagnosis (Revenue Analysis Audit), and Prognosis (retainer solutions).
- Payment and billing information: processed via third-party payment processors; we do not store full payment card details.
- Communications: records of correspondence, meeting notes, and feedback.
B. Information Collected Automatically
- Device and technical data: IP address, browser type, operating system, device identifiers, referring URLs, and pages visited.
- Usage data: time spent on pages, navigation paths, and interaction with website features.
- Cookies and tracking: see Section 8 for details.
C. Information from Third Parties
- Publicly available business information or data provided by referral sources, with appropriate notice where required.
- Information from service providers (e.g., analytics or CRM tools) solely as necessary for our operations.
We do not intentionally collect special-category data (e.g., health, biometric, or precise geolocation data) unless explicitly required for a specific engagement and with appropriate safeguards and consent or other lawful basis.
4. How We Use Information
We process personal information for the following purposes and on the following legal bases (where GDPR or equivalent applies):
- To respond to inquiries, schedule calls, and provide information about our services (legitimate interests or pre-contractual steps).
- To perform Revenue Analysis Audits and deliver retainer-based solutions under the DDP model (performance of a contract).
- To manage client relationships, billing, and communications (performance of a contract and legitimate interests).
- To improve our website, services, and internal processes through analytics (legitimate interests, with consent where required for non-essential cookies).
- To detect, prevent, and address security incidents or fraud (legitimate interests and legal obligation).
- To comply with legal, regulatory, or professional obligations (legal obligation).
- To send relevant service-related or marketing communications (consent or legitimate interests, with opt-out available at any time).
We do not use personal information for automated decision-making that produces legal or similarly significant effects without appropriate human involvement and disclosure.
5. Disclosure of Information
We do not sell, rent, or trade personal information.
We may disclose information only in the following limited circumstances:
- To service providers and processors: third parties who assist us in operating our business (e.g., website hosting, CRM, email delivery, payment processing, analytics, or secure file storage). These parties are contractually bound to process data only on our instructions, maintain confidentiality, and implement appropriate security measures. Where required, we enter into Data Processing Agreements.
- To professional advisers: legal, accounting, or insurance professionals under strict confidentiality obligations.
- For legal protection: when required by law, court order, or governmental authority, or to protect our rights, property, or safety, or that of our clients or others.
- In business transfers: in connection with a corporate transaction (e.g., merger or acquisition), subject to appropriate confidentiality protections.
- With explicit consent: when you explicitly direct us to share specific details.
Client confidential business data provided during engagements is shared only as necessary to deliver the agreed services and is subject to the confidentiality terms of the engagement agreement.
6. Data Security
We implement appropriate technical and organizational measures designed to protect personal information and client data against unauthorized access, loss, alteration, or disclosure. These measures include access controls, encryption in transit and at rest where appropriate, secure storage practices, staff training on confidentiality, and regular review of our security posture.
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data incident that poses a risk to your rights, we will notify affected individuals and relevant authorities as required by applicable law.
7. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including:
- Inquiry and lead data: for a reasonable period after last contact, or longer if required for legitimate business or legal purposes.
- Client engagement records and audit data: for the duration of the engagement plus a period thereafter as required by contract, professional standards, tax, or legal obligations (typically several years).
- Website analytics data: in accordance with the retention settings of our analytics tools (commonly 14–26 months).
- Marketing communications data: until you opt out or we determine the data is no longer needed.
When retention is no longer required, we securely delete or anonymize the data.
8. Cookies and Tracking Technologies
Our website may use cookies and similar technologies to enable core functionality, analyze usage, and improve user experience. Essential cookies are necessary for the site to function. Non-essential cookies (e.g., analytics or marketing) are used only with your consent where required by law.
You may manage cookie preferences through your browser settings or any cookie consent mechanism we provide. Disabling certain cookies may affect site functionality.
9. International Data Transfers
If you are located outside the country in which we operate, your information may be transferred to and processed in other jurisdictions. Where required, we implement appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission or equivalent mechanisms, to protect the data.
10. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Right to access and receive a copy of your data
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten") under certain conditions
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent at any time (where processing is based on consent)
- Right to opt out of the sale or sharing of personal information (CCPA/CPRA)
- Right to non-discrimination for exercising your rights
- Right to lodge a complaint with a supervisory authority
To exercise these rights, contact us using the details in Section 13. We will respond in accordance with applicable law and may need to verify your identity. Certain rights may be limited where we have overriding legal or contractual obligations, or where the data relates to confidential client engagements.
11. Children's Privacy
Our website and services are directed at business professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be posted on this page with a revised "Last Updated" date. Material changes will be communicated by appropriate means, such as a notice on the website or by email where we have your contact details. Continued use of the website or services after the effective date of changes constitutes acceptance of the updated Policy.
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a concern, please reach out to us directly:
Lomit Revenue Engineering
Direct Email: raaidh@lomit.digital
We respond to legitimate privacy inquiries within the timeframes mandated by applicable data protection laws.