How 3DH uses your details when we email you
Last updated: 7 October 2026
If you received an email from Pedro Bandeira at 3DH Consulting about your business's website, this page explains where your details came from, what we keep, and how to make it stop. It sits alongside our main privacy policy.
1. Who we are
Pedro Bandeira Duarte dos Santos, trading as 3DH Consulting, a sole proprietorship registered in Poland (CEIDG) and based in Warsaw. NIP PL5213562807, REGON 142346889. We are the data controller for everything this page describes. Contact: pedro@3dhconsulting.com.
2. What we hold about you
- Your name, your role at the business, and the business email address we wrote to.
- Whether that address could receive mail when we checked it.
- The business's name, location and website.
- Facts about the business's public website, for example whether it takes bookings online, has a contact form, works well on a phone or uses a secure connection, and how that compares with the public websites of other businesses of the same kind in the same area.
- The page where we found your address, and the date we read it.
- The emails we sent you, and your reply if you send one.
- If you open the link to our website in one of our emails: that the link from that email was opened, and which pages of our site were then viewed and for how long. The link carries a short random code that tells us which email it came from and nothing about you. We use it only to learn which of our emails are useful, never to write to you about your visit.
Nothing else. No sensitive data, and nothing bought from a list.
3. Where it came from
From your business's own public website. We use a name and an address only when the website publishes them; we never guess an address or build one from a name. The list of businesses comes from OpenStreetMap, a public map, and the age of the website's domain from the public domain registry.
4. Why, and on what legal basis
To offer a website service to businesses whose public website shows something we can help with. The legal basis is our legitimate interest in offering our services to businesses (GDPR Art 6(1)(f)). We weighed that interest against yours: we use only a business address that was published for business contact, we write only about your business's own public website, we send at most three emails, every email lets you stop them, and if you do not reply we delete our research notes about you within 90 days. If any of that stops being true, so does our reason to hold your details.
5. Your right to object
You can object at any time, free of charge, to our use of your details for direct marketing (GDPR Art 21). Reply "no" to any of our emails, or use the link in it. It takes effect the same day, and we will not contact you again from any address or for any reason other than answering you. To make sure of that we keep a one-way scrambled copy (a hash) of your email address, which cannot be turned back into the address.
6. How many emails
At most three: a first email and two short reminders. We stop after the third, or as soon as you reply, object, or an email bounces, and your address then goes on our do-not-contact list for good.
7. How long we keep it
If you do not reply, the research notes we made about you are deleted 90 days after our last email, and only the hash in section 5 remains. From then on, a visit through one of our links can no longer be connected to you. Our emails to you, your reply if you send one, and the short record of them in our customer relationship system are kept as business correspondence for 24 months after the last contact, as in our main privacy policy, unless we end up working together. Research on businesses we never contacted is deleted after 180 days.
8. Who else processes it
- Zoho Corporation B.V. (the Netherlands), our email provider, which sends our emails and stores them, with any reply, in its EU data centres.
- Our customer relationship system, which we host ourselves.
- Vercel Inc. and Supabase Inc., which host our website and its visit records, as described in our main privacy policy.
- Bouncer Sp. z o.o. (Wrocław, Poland), which checks, before we write, that the business email address can receive mail. It receives the address only, processes it in the EU (Frankfurt) and deletes it within 60 days.
- Anthropic (its EU customers contract with Anthropic Ireland, Limited), whose AI model helps us read your business's public website and draft our email. It sees the public pages of that website, as any visitor would, and the facts we noted about the business; we add your name and address to the email ourselves. It processes data in the United States under the EU Standard Contractual Clauses and, under its commercial terms, does not use it to train its models.
We do not sell your details or share them with anyone else, unless the law requires it.
9. Automated decisions
We use software to compare public websites and choose which businesses to write to. It makes no decision that has legal or similarly significant effects on you.
10. Your other rights
You can ask for access to your data, for its correction or erasure, or for its use to be restricted. Write to pedro@3dhconsulting.com. You also have the right to complain to the Polish supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.