The short version
- I am the only person who reads your enquiry. It is never sold, and there is no mailing list to add you to.
- What you tell me about your company stays between us, whether or not we end up working together.
- No analytics, no pixels, no session recording. Even the fonts are served from this site rather than from Google.
- Enquiries are deleted automatically after twenty-four months, or sooner if you ask.
What I collect
Only what you type into one of the two forms. The engagement form takes your name, your organization’s email address, what the organization needs, how soon, and how much time you have in mind. The coaching form takes your name, your email address, the companies and level you are targeting, and a link to your profile. Both record which page you opened the form from, and when it arrived.
I use it to work out whether I am the right person, and to arrive at the call already knowing your situation — steps taken at your request before a contract, which is the lawful basis under the GDPR. Not consent, so there is nothing here for you to grant or withdraw.
If you are a candidate: I do not pass candidates to companies and I do not take referral fees. The list of firms you are interviewing with goes nowhere — not to an employer, not to a recruiter, not to anyone.
Confidentiality
Most of what a founder writes in that box is not really personal data. It is the roadmap, the architecture, what the last hire got wrong, which of two directors is not working out. Larger firms cover that with an agreement signed before anyone says anything useful. At the enquiry stage there is no such agreement between us, so this is the assurance instead.
I do not repeat it — not to another client, not to an investor, not to someone asking how your company is doing. I do not write it up as a case study, a talk, or an anonymised anecdote, and I do not name you as a client anywhere, including this site, unless you have told me I can. An enquiry that goes nowhere is still confidential: deciding not to work together releases me from none of this.
What the site does by itself
Your IP address and browser are not recorded against your enquiry. If a page breaks or is not found, the server writes one log line holding a truncated address with the last part removed, plus your browser, language and a coarse location — enough to fix the site, not enough to identify a device. Both forms are rate limited, which keeps an address in memory for up to an hour and never writes it down. Nothing about you is bought, enriched or looked up from any other source.
Part of the fractional page sits behind a box asking for a company email address. That check is by domain only: the address is used for one lookup and discarded, never stored, with no record of who tried. Unlocking sets this site’s single cookie, ec_fractional_access — thirty days, readable only by the server, scoped to that one page, holding your company’s domain and nothing else. It exists solely to deliver something you asked for, which is why this site has no consent banner rather than having forgotten one.
Who else sees it
| Vercel | Hosts the site and holds those error logs. |
|---|---|
| Supabase | The database your enquiry is stored in, locked so that only this site’s server can read it. |
| cal.com | Runs the calendar you pick a time from. Submitting either form passes your name, email address and free-text answer to cal.com as part of the booking link — at the moment you press the button, before the calendar appears. |
That is the complete list. Each is bound by its own contract to use the data only to provide that service, and where this means data leaves the UK or the EEA, standard contractual clauses cover the transfer. The only other case would be a legal obligation I cannot refuse, and there has never been one.
How long I keep it, and how to have it gone
Enquiries are deleted twenty-four months after they arrive, by a scheduled job in the database rather than by me remembering. Error logs last as long as the host keeps them and are copied nowhere. The cookie expires after thirty days, or whenever you clear it.
Write to privacy@exechord.com for a copy of what I hold, a correction, a deletion, or a portable export. Replying from the address you wrote to me from is proof enough, and you will have an answer within thirty days. These are rights under the GDPR if you are in the UK or the EU, and I will honour the same request from anyone anywhere, because keeping two standards is more work than keeping one. If I get it wrong, you can also complain to your data protection authority.
Who I am
Exechord is the practice of Madhuri Mukerjee, in San Francisco, and I am the data controller for everything above. The date at the top of this page is the date it last changed; if something material changes I will say what changed rather than quietly reissue the page.