Privacy policy
Last updated: 2026-08-25
This page explains what happens to your information when you use this website. It covers the contact form, the cookies the site sets, and the suppliers who help us run it.
It is written to be read. If anything here is unclear, or you want something corrected or deleted, write to us and we will handle it.
- Company
- IHLAB GROUP OÜ
- Registered address
- Narva mnt 5, 10117 Tallinn, Estonia
- sam@twofiveone.eu
- Contact for privacy questions
- Samuel G. Villegas, Founder
Who is responsible
Two Five One is the brand. The company behind it is the one named above, and it is the data controller for everything described on this page. That means it decides why your information is handled and how.
We have not appointed a formal Data Protection Officer, because the law does not require one for a company of this size and this kind of work. The person named above answers privacy questions directly.
What we collect
There is one form on this site. When you send it, we receive what you typed:
- Your name, your work email address, the company you work for, and your telephone number with its country code.
- Your department, if you fill that field in. Pages written for a particular role fill it in for you, and you can change it.
- Your message.
- Which page you sent the form from, which language you were reading, and the date and time.
What we do not collect
We do not store the network address of your device alongside your enquiry. The site checks it in memory for up to fifteen minutes to stop the same sender flooding the form, and then it is gone. There is no column for it in our database.
The web server keeps ordinary access logs, which do contain network addresses and the pages requested. Those exist to keep the site available and to investigate abuse. They are not connected to your enquiry.
We do not buy contact lists, we do not build profiles of visitors, and we do not use automated decision-making of any kind.
How we measure the site
We count visits ourselves instead of handing that job to an analytics company. The measurement runs on this site, writes to our own database, and sends nothing to anyone else.
It sets no cookies and stores nothing at all on your device. That is why it is not one of the choices in the cookie banner: there is nothing on your equipment to ask about. To tell one visit apart from another within a single day, our server makes a one-way fingerprint out of your network address, what your browser says about itself, and today's date, mixed with a secret only we hold. It cannot be turned back into you, and because the date is part of it, it changes every night. We have no way to recognise you tomorrow.
Each visit records the page, the language, where you arrived from, any campaign details carried in the link you followed, how long the page was open, and how far down it was read. Your country is worked out from the timezone your browser reports, not from your network address, which is never written down.
Why we handle it, and on what basis
European data protection law requires us to name a lawful basis for each purpose. Ours are:
- To answer your enquiry and prepare a possible engagement. Basis: taking steps at your request before entering a contract, and our legitimate interest in responding to a business enquiry.
- To keep the site working and safe: rate limits, server logs, backups. Basis: our legitimate interest in running a service that stays available and is not abused.
- To remember the language you chose. Basis: our legitimate interest in showing you the site in the language you picked. This is also strictly necessary for the feature to work at all.
- To understand how the site is used and whether our advertising is working. Basis: our legitimate interest in knowing which pages and which campaigns produce enquiries. This measurement is our own, stores nothing on your device, and shares nothing.
- To measure whether our advertising on Meta produces enquiries. Basis: your consent, given through the cookie banner, and withdrawable at any time.
Cookies
A cookie is a small file a site stores in your browser. This site sets four, and only one of them needs your permission.
- The first two are strictly necessary. One holds a preference you set yourself; the other exists so the site can stop asking you this question. Neither tells anyone outside this site anything about you, and neither is offered as a choice.
- The last two belong to the Meta advertising pixel. If you decline, the pixel is never loaded and neither cookie is written, wherever you are. If you accept, it is. If you have not answered, it depends where you are: in the European Economic Area, the United Kingdom and Switzerland we ask first and load nothing until you reply. Elsewhere, where that requirement does not apply, the pixel loads and you can still turn it off at any time with the cookie settings link in the footer.
| Cookie | What it does | How long it lasts | Set by |
|---|---|---|---|
| tfo_locale | Remembers the language you chose, so an address without /es still opens in it | 1 year | This site |
| tfo_consent | Records your answer to the cookie banner, so you are not asked again | 6 months | This site |
| _fbp | Identifies your browser to Meta, so an advertisement can be connected to a form you later sent | 3 months | Meta |
| _fbc | Stores the click identifier from a Meta advertisement you arrived from, for the same purpose | 3 months | Meta |
Changing your mind
Accepting and declining are the same click, on the same banner, with equally sized buttons. Declining does not limit any part of this site.
You can change your answer whenever you like. Use the cookie settings link in the footer of any page: it clears your recorded answer and brings the banner back. Withdrawing consent stops any further measurement. It cannot undo what was already sent to Meta before you withdrew.
Who else sees it
We do not sell your information and we do not share it for anyone else's marketing. These suppliers process it on our instructions so the site can work:
- Resend, our email provider, which delivers your confirmation message and the notification we receive. It handles the contents of the form.
- Meta Platforms Ireland Limited, which receives the advertising events described above, and only if you accepted. It is told which page produced an enquiry and in which language. It is never told your name, your email address, or your telephone number.
- Our hosting provider, which operates the server this site and its database run on.
Information that leaves Europe
Some of those suppliers are established in the United States or process information there. Where that happens, the transfer relies on the European Commission's standard contractual clauses, or on its adequacy decision for the EU–US Data Privacy Framework where the supplier is certified under it.
You can ask us which safeguard applies to a particular supplier and we will tell you.
How long we keep it
We keep an enquiry for twenty-four months after our last contact about it, so that a conversation picked up again later still has its history. If the enquiry becomes an engagement, the records that belong to that engagement are kept for as long as accounting and tax law requires.
Measurement records are kept for twelve months and then deleted. Server logs are kept for a short period and then rotated away. Cookies expire on the schedule in the table above. If you ask us to delete your enquiry sooner, we will, unless the law requires us to keep a specific record.
Your rights
Under European data protection law you can ask us to:
- Give you a copy of what we hold about you.
- Correct anything that is wrong.
- Delete it.
- Restrict what we do with it, or object to our handling it on the basis of legitimate interest.
- Send it to you, or to someone else, in a portable form.
- Withdraw a consent you gave, at any time, without that affecting what was lawful before you withdrew it.
Exercising them, and complaining
Write to the email address at the top of this page. We will answer within one month. We will not charge you, and we will not ask you to explain why.
If you are not satisfied with our answer, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), which supervises us. If you live or work in the European Union, you can complain to your own country's data protection authority instead.
How it is protected
The site is served over an encrypted connection. The database accepts no connections from the public internet at all. Only the site itself can reach it, over a private network on the same machine. Access to the server is limited to people who need it. Backups are taken nightly and kept for thirty days.
No system is perfect. If a breach ever put your rights at risk, we would tell the supervisory authority and, where the law requires it, you.
Children
This site sells business services and is not directed at children. We do not knowingly collect information from anyone under sixteen. If you believe a child has sent us something, tell us and we will delete it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how we handle information you have already given us, we will do more than change the date: we will tell you.
