Privacy policy

Privacy Policy
Last updated: 4 September 2026

Who we are
This website is operated by Daria Makhno, trading as MD4, based in Sweden.

Daria Makhno is the data controller responsible for the personal data described in this Privacy Policy.

Email: [email protected]

What information we collect and why
We process only the information reasonably necessary to operate the website, respond to enquiries and provide our services.

When you contact us or request a mini-audit, we may collect your name, email address, company details, website or social media link, and the information included in your message. We use this information to respond to you, understand your request and discuss or prepare our services. The legal basis is taking steps before entering into a contract or, for business-to-business communication, our legitimate interest in responding to relevant enquiries.

When you become a client, we may process your contact details, business information, communications, project materials, agreements and invoicing information. We use this data to deliver the agreed services, manage our working relationship and meet accounting or other legal obligations. The legal bases are performance of a contract and compliance with legal obligations.

When you request the Offer Builder or subscribe to emails, we may collect your name, company name, email address, subscription status and a record of your consent. We use your email to provide the requested resource. Marketing emails are sent only with your consent. You can unsubscribe at any time by using the link in an email or contacting us.

When you visit the website, technical information such as your IP address, browser and device type, requested pages, date and time, referrer and security-related information may be processed automatically. This is used to operate and protect the website, prevent spam or misuse and understand its general performance. The legal basis is our legitimate interest in maintaining a secure and reliable website.

Please do not send sensitive personal information through the website unless we have specifically agreed that it is necessary.

Service providers and international transfers
We use trusted service providers to operate the website and communicate with visitors, including:

Durable for website hosting and website functionality;
Brevo for the embedded subscription form and email communications;
Google for reCAPTCHA protection and email services;
Cloudflare for website security, performance and privacy-focused analytics.
These providers process information only as necessary to provide their services and are subject to contractual or legal data-protection obligations. Some providers may process information outside the European Economic Area. Where required, transfers are protected by an adequacy decision, Standard Contractual Clauses or another legally recognised safeguard.

We may also disclose information to accountants, professional advisers or public authorities where necessary or legally required.

We do not sell personal data.

Provider policies: Durable, Brevo, Google and Cloudflare.

Cookies and similar technologies
Cloudflare Web Analytics provides aggregated website statistics without using cookies, local storage or individual visitor profiling.

Google reCAPTCHA and the embedded Brevo form may process technical information or use their own cookies when their services are loaded. These technologies help protect forms, deliver requested functionality and prevent abuse. You can control or delete cookies through your browser settings.

If we introduce non-essential analytics or advertising cookies in the future, we will request consent before using them.

How long we keep information
We keep personal information only for as long as necessary:

enquiries that do not become client engagements: normally up to 12 months after the last communication;
newsletter information: until you unsubscribe; afterwards, we may retain a minimal suppression record to respect your request;
client and project information: during the engagement and normally for up to 3 years afterwards;
information needed for legal claims: for as long as reasonably necessary, potentially up to 10 years;
invoices and accounting records: for the period required by Swedish law, normally 7 years.
Information may be deleted earlier when it is no longer needed, unless retention is required by law or necessary to protect legal rights.

Your rights
Under the GDPR, you may have the right to:

access your personal data;
correct inaccurate information;
request deletion or restriction of processing;
receive certain information in a portable format;
object to processing based on legitimate interests or direct marketing;
withdraw consent at any time.
Withdrawing consent does not affect processing that took place before the withdrawal.

To exercise your rights, email [email protected]. We may need to verify your identity before completing a request.

You may also lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), at imy.se.

We do not use personal data to make solely automated decisions that have legal or similarly significant effects.

Changes to this policy
We may update this Privacy Policy when our services, providers or legal obligations change. The latest version will always be published on this page with its revision date.