DRAFT — not approved for production

Draft Privacy Policy

This page is a working content framework only. It is not legal advice, is not an approved privacy policy, and must not be presented as final. Publication is blocked until Nexxen Solutions confirms the operating legal entity, privacy contact, actual data practices, service providers, retention periods, and applicable legal requirements, and obtains appropriate legal review.

Private-preview draft

This page is intentionally blocked from production approval until the legal entity, privacy contact, operating facts, and legal review are supplied.

1. Identity and privacy contact — confirmation required

The final policy must state the full legal name of the organization responsible for personal information, its business contact details, the effective date, and a monitored privacy contact. These facts have not been approved for this draft.

2. Information collected — inventory required

The final policy should describe only information the production site actually collects. This may include inquiry details, booking information, communications, and limited technical or usage data, but each category must be verified against the deployed forms, calendar, analytics, logs, and consent controls.

3. Purposes and legal basis — review required

The approved version must explain why each category is used, such as responding to an inquiry, arranging a meeting, delivering requested services, maintaining security, or measuring the site where permitted. Applicable consent and other legal-basis language requires jurisdiction-specific review.

4. Providers, transfers, and disclosure — verification required

Every provider that receives personal information must be identified or accurately categorized, including hosting, scheduling, CRM, forms, analytics, email, and security services. The final policy must address processing locations, cross-border handling, and disclosure circumstances that actually apply.

5. Cookies and analytics — configuration required

Cookie, tag, and analytics disclosures must match the production configuration and consent mechanism. Optional analytics or advertising technology must not be described as active unless it is actually enabled and lawfully configured.

6. Retention and safeguards — facts required

The final policy must state defensible retention criteria and describe safeguards without making absolute security promises. Retention periods and deletion procedures have not been supplied for this draft.

7. Access, correction, deletion, and complaints — legal review required

The approved policy should explain how an individual can make a privacy request or complaint and identify rights that apply to the relevant person and jurisdiction. Response procedures, identity verification, exceptions, and regulator information require confirmation.

8. Changes and effective date — approval required

The production policy must include an effective date and a practical process for communicating material changes. No effective date should be inserted until the policy and underlying practices are approved.