Skip to content

Legal

Privacy policy

  • Home
  • Legal
  • Privacy policy

Last updated 5 September 2026

Who we are

OneRee is a digital growth agency working from London and Dubai. The London office covers the United Kingdom and Europe; the Dubai office covers the GCC. OneRee is the controller of personal data collected through this website.

Contact for any privacy matter: hello@1ree.com.

What we collect

  • What you type into a form. Name, work email, company, role, region, budget band, chosen interests, and whatever you write in the message.
  • Technical data attached to that submission. Your IP address, your browser's user-agent string and the time. These are included in the notification email and are used to operate the spam defences — the rate limiter stores only a one-way hash of the IP, never the address itself.
  • Server logs. The web server records requests, IP addresses and user-agents for security and troubleshooting, on our host's normal rotation.
  • Communications. Emails you send us and our replies.

We set no cookies and run no analytics, so we do not know which pages you visited unless you tell us.

The AI Readiness Score, the AI Payback Calculator and the Search Snippet Preview run entirely in your browser: nothing you enter into them is transmitted to us or to anyone else. The Site Health Check is the exception — it is a request form, so the URL, your name and your email are emailed to us like any other enquiry.

Why we use it

PurposeLawful basis
Replying to your enquiryLegitimate interests / steps prior to a contract
Sending the One Thing newsletterConsent
Producing a Site Health Check report you requestedConsent
Delivering services under a contractPerformance of a contract
Operating the spam defences on our formsLegitimate interests — keeping the forms usable
Meeting legal and accounting obligationsLegal obligation

Who we share it with

For this website we use a deliberately short list of processors:

  • Our hosting provider, which serves the site and keeps the server logs described above.
  • Our email provider, which relays form submissions and holds the mailbox they arrive in.
  • Cloudflare, for the anti-spam challenge on our forms, where it is enabled.

Client engagements involve further processors — including the AI model providers named in the relevant contract. Those are listed in the engagement's data handling note before any of your data reaches them. Each processor is bound by a data processing agreement. We do not sell personal data and we do not share it for anyone else's marketing.

International transfers

Some processors are outside the UK and the UAE. Where that is the case, transfers are made under the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision. For client engagements with data residency requirements, in-region processing is available and is specified in the contract.

How long we keep it

  • Enquiries that do not become clients: 24 months, then deleted.
  • Newsletter subscribers: until you unsubscribe, plus a suppression record so we do not re-add you.
  • Client records: for the duration of the engagement plus seven years where accounting rules require it.
  • Analytics: 14 months.

Your rights

Under UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to processing, and ask for it in a portable format. Where processing relies on consent you can withdraw it at any time. Email hello@1ree.com and we will respond within one month.

If you are not satisfied you can complain to the UK Information Commissioner's Office at ico.org.uk. Individuals in the UAE have comparable rights under the UAE Personal Data Protection Law.

Controller or processor

For this website, our newsletter and enquiries, OneRee is the controller — we decide why and how the data is used.

For personal data inside systems we operate on a client's behalf during an engagement, the client is the controller and OneRee is a processor. That relationship is governed by the data processing agreement in the client contract, which sets out the instructions we act on, the subprocessors we use, and what happens to the data when the engagement ends.

How we protect it

  • Everything is transmitted over HTTPS. Form submissions are validated and rate-limited server-side.
  • Access is least-privilege and reviewed whenever the team working on an account changes.
  • Credentials are held in a password manager with two-factor authentication mandatory on every business account.
  • Devices are encrypted at rest and lock automatically.
  • Dependencies are scanned automatically and patched on an agreed cadence.

No system is perfectly secure. We do not claim otherwise, and you send information over the internet at your own risk.

If something goes wrong

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and notify you directly without undue delay where the risk is high.

Security researchers: please see security.txt and email security@1ree.com.

Where you are in the European Union

We offer services to organisations in the European Union, so where we process the personal data of people in the EU, the EU General Data Protection Regulation applies to that processing alongside UK GDPR. The lawful bases, retention periods and rights set out in this policy apply in the same way.

Your EU rights include the right to lodge a complaint with the supervisory authority in the member state where you live or work. If we are required to appoint a representative in the EU under Article 27, the appointment will be published in this section; until then, please raise anything directly with us at hello@1ree.com, which is the fastest route in any case.

Transfers of EU personal data outside the EEA are made under the European Commission's Standard Contractual Clauses or an adequacy decision, as described under International transfers above.

Where you are in the United Arab Emirates

The Dubai entity operates from a UAE free zone. Which data protection regime governs your data depends on that zone: the financial free zones (the DIFC and the ADGM) each have their own data protection law, and elsewhere in the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies. The applicable regime and the licensing free zone are identified in our company details and in the data handling note for any engagement.

Under whichever regime applies you may ask for access to your data, correction, erasure, restriction of processing, and to object to processing or withdraw consent. Contact hello@1ree.com and we will confirm the applicable law and route the request accordingly.

Where an engagement carries a data residency requirement, in-region processing is available and is written into the contract rather than assumed. Cross-border transfers out of the UAE are made only on a basis permitted by the applicable regime.

Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you, or similarly significantly affects you. The AI Readiness Score and the other free tools run entirely in your browser and produce no record we ever see.

Children

This website and our services are directed at businesses, not children. We do not knowingly collect data from anyone under 18. If you believe we hold such data, email hello@1ree.com and we will delete it.

Changes

If we change this policy materially we will say so on this page and, for newsletter subscribers, by email.


Questions about anything on this page: hello@1ree.com.

back top