Privacy Policy
The Strategic Idea
Version 1.1, effective September 25, 2026
This policy explains what personal data The Strategic Idea collects on thestrategicidea.com, why, who we share it with, how long we keep it and how you can exercise your rights.
It is written to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR, and we follow the same principles for visitors from anywhere else. People in Brazil have a dedicated Portuguese version under Brazil's data protection law (LGPD).
1. Who is responsible for your data
The Strategic Idea is a brand for strategic design, cases, automation and knowledge, founded and led by Marja Amim. The controller, meaning who decides how and why your data is processed, is:
- Legal name: Marja Francis Amim de Azevedo Ltda.
- Company registration number (CNPJ): 23.825.381/0001-43
- Registered in: Porto Alegre, RS, Brazil
- Privacy contact: marja@thestrategicidea.com
2. What we collect and why
Browsing the site does not require an account. We collect personal data in the situations below.
2.1 Research quiz for women entrepreneurs
At /pt/empreendedoras there is a short quiz, in Portuguese, that is part of an exploratory study of women entrepreneurs in Brazil. It collects:
- Email (required): to identify your participation.
- Three multiple-choice answers and the result, the "card" (required): for research analysis.
- Opt-in to be invited to a 20-minute research interview (optional): to send the invitation.
- Opt-in to be contacted about future tests or related services (optional): to contact you about tests and services.
- How you reached the quiz, when provided (optional): to understand where participants come from.
- Version of the consent text (automatic): to prove what you agreed to.
The card is a reflection based on your three choices. It is not a diagnosis and does not assess personality, ability, health or potential. We make no decisions about you based on it, and there is no automated decision-making with legal or similarly significant effects.
If you take part again with the same email, the new answers replace the old ones.
We do not publish your card, answers or contact details. If we share research results, they will be aggregated and will not identify participants.
2.2 Free downloads and content emails
When you request a free download, such as the "Presentation ideas bank", we collect:
- Email (required): to send the download link and, with your consent, content from The Strategic Idea.
- Consent text version, the download you signed up through, and the date and time of sign-up and confirmation (automatic): to prove what you agreed to.
- WhatsApp number (optional): to send content by WhatsApp, only if you tick the separate option for it. Without that tick, the number is not stored.
The download link arrives by email. That step confirms the address is yours (double opt-in). If you do not confirm, you are not added to the content list.
Consent text on the form:
"I want to receive the material and content from The Strategic Idea by email. I can unsubscribe at any time. I have read the Privacy Policy."
Separate option, only for people who enter a WhatsApp number:
"I agree to receive content from The Strategic Idea on WhatsApp. I can unsubscribe at any time."
Every content email has a one-click unsubscribe link.
2.3 Emails you send us
If you write to an @thestrategicidea.com address, we receive your name, email address and message. We use them only to reply and follow up.
2.4 Form security
To prevent abuse, the server uses the IP address of whoever submits a form to limit attempts per minute. This check lives only in server memory for about a minute and is not saved.
2.5 Admin area
The admin area at /admin is used only by the site administrator. Visitors have no access to it.
3. Legal bases (GDPR and UK GDPR)
- Free downloads and content emails: consent, Art. 6(1)(a).
- Content by WhatsApp: separate, optional consent, Art. 6(1)(a).
- Taking part in the research quiz: consent, Art. 6(1)(a).
- Interview invitation and contact about tests or services: separate, optional consent, Art. 6(1)(a).
- Replying to emails you send us: legitimate interests, Art. 6(1)(f), to answer your message.
- Form security: legitimate interests, Art. 6(1)(f), to prevent fraud and abuse.
You can withdraw consent at any time by writing to the contact in section 12. Withdrawal does not affect processing that happened before it.
4. Cookies and analytics
The site does not use analytics tools, advertising pixels or third-party cookies. Fonts are served by the site itself.
The only cookie is the admin session cookie, set only for someone who logs in at /admin. Visitors do not receive it, so the site shows no cookie banner.
If this changes, we will update this policy first.
5. Who we share data with
We do not sell or rent your data. We do not "sell" or "share" personal information as those terms are defined in the California Consumer Privacy Act, and we do not use it for cross-context behavioural advertising.
Data only passes through providers the site needs to run:
- Oracle Cloud Infrastructure (United States): hosting for the site and database.
- Oracle Email Delivery (United States): sending the emails we send from the brand's domain, including download links and content list emails.
- name.com (United States): domain and forwarding of incoming email.
- Google, Gmail (United States and other countries): inbox where we read incoming email.
- Technical maintainer of the server (Brazil): site maintenance and a daily backup copy.
We may also disclose data when required by law or by a competent authority.
6. International transfers
The Strategic Idea is based in Brazil, and the server and email services are mainly in the United States. If you are in the EU or UK, your data is transferred outside the European Economic Area and the UK.
Oracle, which hosts the site and database, includes the European Commission's Standard Contractual Clauses in its data processing terms.
7. How long we keep data
- Content list sign-up: while you are subscribed. When you unsubscribe, we keep only your email on a suppression list so we never email you again.
- Unconfirmed download sign-up: 30 days.
- Research quiz data: up to 12 months after the study ends, or until you ask us to delete it.
- Consent record: for as long as the related data and, for the content list, up to 5 years after you unsubscribe.
- Emails you send us: as long as needed to reply and follow up.
Backups. The database is backed up daily. Deleted data may remain in backups for up to about 60 days, until newer copies replace them. Backups are not used for any other purpose.
8. How we protect your data
- The site only runs over an encrypted connection (HTTPS).
- The database is not exposed to the internet.
- Quiz data can only be read by the administrator, logged into the admin area.
- Email sent from the brand's domain is authenticated (SPF, DKIM and DMARC).
- Forms have rate limits and protection against automated submissions.
No system is immune to failure. If a personal data breach is likely to put your rights at risk, we will notify the relevant authority and, where required, you.
9. Your rights
Under the GDPR and UK GDPR you have the right to:
- access your data;
- correct inaccurate or incomplete data;
- have your data erased;
- restrict processing;
- receive your data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time.
Write to marja@thestrategicidea.com. We reply within one month.
You can also complain to your local data protection authority. In the UK, that is the Information Commissioner's Office (ico.org.uk). In the EU, you can find your authority through the European Data Protection Board (edpb.europa.eu).
10. Other places
We apply the same practices to visitors wherever they are. If you live somewhere with its own privacy law, such as a US state with a consumer privacy law, you can make the requests described in section 9, and we will not treat you differently for doing so.
11. Children
The site is meant for professionals and business owners. We do not knowingly collect data from anyone under 16. If that happens, we will delete it as soon as we find out.
12. Contact
Privacy contact: marja@thestrategicidea.com
Requests are handled by Marja Amim, founder and CEO. We have not appointed a data protection officer: the GDPR only requires one for large-scale monitoring or large-scale processing of special category data, and Brazilian rules exempt small businesses from appointing one as long as they keep a contact channel.
13. Changes to this policy
When this policy changes, we will update the date and version at the top of the page. New forms only go live after this policy is updated to describe them. If a change affects the purpose of processing based on consent, we will ask for your consent again.