The Strategic Idea

Privacy Policy

The Strategic Idea

Version 1.1, effective September 25, 2026

This policy explains what personal data The Strategic Idea collects on thestrategicidea.com, why, who we share it with, how long we keep it and how you can exercise your rights.

It is written to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR, and we follow the same principles for visitors from anywhere else. People in Brazil have a dedicated Portuguese version under Brazil's data protection law (LGPD).

1. Who is responsible for your data

The Strategic Idea is a brand for strategic design, cases, automation and knowledge, founded and led by Marja Amim. The controller, meaning who decides how and why your data is processed, is:

2. What we collect and why

Browsing the site does not require an account. We collect personal data in the situations below.

2.1 Research quiz for women entrepreneurs

At /pt/empreendedoras there is a short quiz, in Portuguese, that is part of an exploratory study of women entrepreneurs in Brazil. It collects:

The card is a reflection based on your three choices. It is not a diagnosis and does not assess personality, ability, health or potential. We make no decisions about you based on it, and there is no automated decision-making with legal or similarly significant effects.

If you take part again with the same email, the new answers replace the old ones.

We do not publish your card, answers or contact details. If we share research results, they will be aggregated and will not identify participants.

2.2 Free downloads and content emails

When you request a free download, such as the "Presentation ideas bank", we collect:

The download link arrives by email. That step confirms the address is yours (double opt-in). If you do not confirm, you are not added to the content list.

Consent text on the form:

"I want to receive the material and content from The Strategic Idea by email. I can unsubscribe at any time. I have read the Privacy Policy."

Separate option, only for people who enter a WhatsApp number:

"I agree to receive content from The Strategic Idea on WhatsApp. I can unsubscribe at any time."

Every content email has a one-click unsubscribe link.

2.3 Emails you send us

If you write to an @thestrategicidea.com address, we receive your name, email address and message. We use them only to reply and follow up.

2.4 Form security

To prevent abuse, the server uses the IP address of whoever submits a form to limit attempts per minute. This check lives only in server memory for about a minute and is not saved.

2.5 Admin area

The admin area at /admin is used only by the site administrator. Visitors have no access to it.

3. Legal bases (GDPR and UK GDPR)

You can withdraw consent at any time by writing to the contact in section 12. Withdrawal does not affect processing that happened before it.

4. Cookies and analytics

The site does not use analytics tools, advertising pixels or third-party cookies. Fonts are served by the site itself.

The only cookie is the admin session cookie, set only for someone who logs in at /admin. Visitors do not receive it, so the site shows no cookie banner.

If this changes, we will update this policy first.

5. Who we share data with

We do not sell or rent your data. We do not "sell" or "share" personal information as those terms are defined in the California Consumer Privacy Act, and we do not use it for cross-context behavioural advertising.

Data only passes through providers the site needs to run:

We may also disclose data when required by law or by a competent authority.

6. International transfers

The Strategic Idea is based in Brazil, and the server and email services are mainly in the United States. If you are in the EU or UK, your data is transferred outside the European Economic Area and the UK.

Oracle, which hosts the site and database, includes the European Commission's Standard Contractual Clauses in its data processing terms.

7. How long we keep data

Backups. The database is backed up daily. Deleted data may remain in backups for up to about 60 days, until newer copies replace them. Backups are not used for any other purpose.

8. How we protect your data

No system is immune to failure. If a personal data breach is likely to put your rights at risk, we will notify the relevant authority and, where required, you.

9. Your rights

Under the GDPR and UK GDPR you have the right to:

Write to marja@thestrategicidea.com. We reply within one month.

You can also complain to your local data protection authority. In the UK, that is the Information Commissioner's Office (ico.org.uk). In the EU, you can find your authority through the European Data Protection Board (edpb.europa.eu).

10. Other places

We apply the same practices to visitors wherever they are. If you live somewhere with its own privacy law, such as a US state with a consumer privacy law, you can make the requests described in section 9, and we will not treat you differently for doing so.

11. Children

The site is meant for professionals and business owners. We do not knowingly collect data from anyone under 16. If that happens, we will delete it as soon as we find out.

12. Contact

Privacy contact: marja@thestrategicidea.com

Requests are handled by Marja Amim, founder and CEO. We have not appointed a data protection officer: the GDPR only requires one for large-scale monitoring or large-scale processing of special category data, and Brazilian rules exempt small businesses from appointing one as long as they keep a contact channel.

13. Changes to this policy

When this policy changes, we will update the date and version at the top of the page. New forms only go live after this policy is updated to describe them. If a change affects the purpose of processing based on consent, we will ask for your consent again.