Privacy Policy
Last updated: 2026-08-23
This legal document is provided in English only.
1. Who we are (data controller)
This website is operated by RRR FI LP ("RRR FI", "we", "us", or "our").
- Registration number: SL034272 (a Scottish Limited Partnership registration format, consistent with the registered office below)
- Jurisdiction of registration: United Kingdom (confirmed by owner, 23 August 2026); RRR FI LP is registered specifically as a Scottish Limited Partnership, with its registered office in Scotland (see below)
- Registered office address: 5 South Charlotte Street, Edinburgh, United Kingdom, EH2 4AN (confirmed by owner, 23 August 2026)
- General Partner: not separately identified in this document — owner has confirmed this detail is not required for these Terms/Policy
- Contact email for privacy-related enquiries: [email protected]
As the data controller, RRR FI LP is subject to UK data protection law (the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018) because RRR FI LP itself is established and registered in the United Kingdom — this applies regardless of where any individual visitor to the Site is located (see Section 5).
2. Scope of this Policy
This Policy describes, factually and only, what happens to personal data in connection with your visit to rrr-fi.com. It does not describe:
- any product or service referenced on the site (Lexensus, Polydirection, LoanCryptoBank, or any other related company or product), each of which is a separate entity/product with its own data practices, if any;
- any future functionality not yet implemented (see Section 4 in particular).
3. What personal data we collect
3.1 Information you submit voluntarily via the contact form
If you choose to use the contact form on this site, we collect the following fields, which you enter yourself:
- Name
- Company
- Email address
- Industry / area
- Project description
We do not require you to submit any of this information to browse the site. It is only collected if you actively choose to fill in and submit the contact form.
The contact form also contains a hidden field used solely for automated spam detection ("honeypot"). This field is not intended to be filled in by a human visitor and does not collect any information about you as a visitor; it is a technical anti-abuse measure, not a data collection mechanism directed at you.
3.2 Information collected automatically
IP address. When you visit the site, your IP address is recorded automatically in two separate, limited ways:
- Web server access logs. Every request to the site is logged by our web server, including your IP address, timestamp, the page requested, the response status, referrer, and browser/user-agent string. These logs are shared infrastructure logs (not specific to this site alone) and are automatically rotated and deleted; log files are kept for approximately 14 days on a rolling basis, after which they are permanently removed through automated housekeeping. We do not manually extract, compile, or analyze this data for any purpose beyond routine technical operation and security of the server.
- Temporary rate-limiting. When you submit the contact form, your IP address is also checked against a short-term, in-memory rate limit (used only to prevent abuse of the contact form — for example, automated spam submissions). This IP address is held only in the temporary working memory of the running application, is never written to a file or database, is automatically cleared after a short time window (approximately 10 minutes) or immediately whenever the application restarts, and is used for no other purpose.
We do not use your IP address for advertising, profiling, analytics, or any purpose beyond the two narrow technical uses described above.
3.3 What we do NOT collect
For clarity and to avoid any doubt:
- We do not use cookies of any kind. This site does not set session cookies, preference cookies, advertising cookies, or consent-management cookies. There is accordingly no cookie banner on this site, because there is nothing to consent to.
- We do not use any analytics or tracking tool. No Google Analytics, no Google Tag Manager, no Meta/Facebook Pixel, no Yandex Metrica, or any comparable service is present on this site.
- We do not load any third-party script in your browser. Even the fonts used on this site are bundled and served directly from our own server at build time; your browser does not make requests to Google Fonts or any other third-party font service when you visit.
- We do not embed third-party widgets such as chat tools, maps, video players, or social-media share buttons.
- We do not maintain user accounts, and there is no login or authentication system on this site.
- We do not currently store contact form submissions in any database. This site does not use a database at all as of the date of this draft.
4. What happens to the information you submit via the contact form
This section describes what happens today, factually, as verified in the site's technical operation as of 23 August 2026.
- When you submit the contact form, the information is validated and technically sanitized on our server (to remove formatting/code that could be malicious), and then a success confirmation is shown to you.
- The contact form is not currently connected to any email delivery. Submissions are, at present, only written to a private, internal server log used for technical operation and debugging purposes, and are not automatically forwarded to any mailbox, CRM, spreadsheet, or third-party service.
- We do not currently store your submission in a database or any other persistent storage. Your submission exists transiently in server-side technical logs, which are automatically deleted after a maximum of 7 days under our server's log retention configuration (see Section 8).
- No third party or external service receives your contact form submission today. No CRM, no email-marketing platform, no external form-processing service, and no advertising network has access to what you submit.
- We anticipate that in the future, once operational arrangements are finalized, submissions made via the contact form may be used to respond to your enquiry directly (for example, by a member of our team emailing you back). This is a planned, not yet implemented, capability. We will update this Policy to reflect this accurately once it becomes operational, and — where the applicable law requires it — before it becomes operational.
If you choose to contact us via the contact form, please do not include information you consider sensitive or confidential beyond what is necessary for us to understand and respond to your enquiry.
5. Legal basis for processing
The Site is intended for a global audience — we do not restrict or target the Site to any particular country or region, and visitors may access it from anywhere in the world. Because RRR FI LP, the data controller, is established and registered in the United Kingdom, UK data protection law (UK GDPR and the Data Protection Act 2018) applies to our processing of personal data as the controller, regardless of the country from which a particular visitor accesses the Site. This is because the applicable law is determined by where the controller is established, not by the visitor's own location.
Our legal bases for processing under UK GDPR are:
- Consent (UK GDPR Article 6(1)(a)): where you voluntarily submit information through the contact form, your submission is treated as consent to our processing of that information for the purpose of responding to your enquiry, as described in Section 4.
- Legitimate interests (UK GDPR Article 6(1)(f)): we rely on our legitimate interest in operating, maintaining, and securing the Site for (a) web server access logging (Section 3.2) and (b) rate-limiting/anti-abuse measures on the contact form (Section 3.2, Section 5 of the Terms of Use). We consider these interests are not overridden by your own interests or fundamental rights, given the limited, short-retention, narrowly purposed nature of this processing (Section 8).
If you are located outside the United Kingdom (for example, in the European Union or elsewhere), your own local data protection law may also grant you additional or different rights in relation to your own data, independently of UK GDPR. This Policy describes our obligations as controller under UK law; it does not limit any separate rights you may have under your own local law, which you would need to confirm with reference to that law directly.
6. Who we share information with
As of the date of this draft, the only parties that have any technical access to data associated with your visit are the infrastructure providers necessary to operate the site:
- Hosting provider (Hostinger) — as the operator of the physical/virtual server on which the site runs, it necessarily has access to server logs and any data passing through the server as part of providing hosting infrastructure.
- DNS and CDN/reverse-proxy provider (Cloudflare) — Cloudflare provides DNS resolution for the domain and also operates as a reverse-proxy/CDN in front of our origin server: visitor traffic passes through Cloudflare's network before reaching our server. As a result, Cloudflare sees traffic metadata such as IP addresses, requested URLs, and other HTTP request metadata for connections to the Site, and acts as a data processor/subprocessor in relation to that traffic. Cloudflare's own privacy and data processing terms govern its handling of this data in that role.
- Certificate authority (Let's Encrypt) — issues the TLS/SSL certificate that secures the connection to this site. Let's Encrypt does not see or process visitor traffic; its role is limited to certificate issuance.
We do not sell personal data. We do not share personal data with advertisers, data brokers, or any marketing or analytics third party, because no such party has any technical integration with this site as of the date of this draft.
7. International data transfers
The Site is intended for a global audience (Section 5), so visitors may access it, and personal data may be processed, from and in many different countries. As controller, RRR FI LP is subject to UK GDPR (Section 5), which imposes specific requirements where personal data is transferred outside the UK.
Our origin server (operated by our hosting provider, Hostinger) is physically located in the United Kingdom, the same jurisdiction in which RRR FI LP is established. Because Cloudflare operates as a reverse-proxy/CDN in front of that origin server (Section 6), visitor traffic is also routed through Cloudflare's global network before reaching our server; depending on where a given visitor is located, Cloudflare may process traffic metadata (such as IP addresses) at a data center outside the UK as part of its global anycast infrastructure, even though our own origin server remains in the UK. To the extent this involves a transfer of personal data outside the UK, we rely on Cloudflare's own compliance with UK-GDPR-recognized transfer mechanisms (such as the UK's International Data Transfer Addendum, standard contractual clauses, or adequacy regulations, as applicable under Cloudflare's data processing terms) as the relevant safeguard for that specific leg of processing.
We do not otherwise transfer personal data to any third country ourselves.
8. Data retention
- Contact form submissions: not currently stored in any persistent system. They exist only transiently in internal server logs, which are automatically deleted after a maximum of 7 days (our server's log retention is configured with a maximum retention period of 7 days).
- Web server access logs (including IP addresses): retained on a rolling basis for approximately 14 days, after which they are automatically deleted.
- Rate-limiting data (including IP addresses): held only in temporary application memory; cleared automatically after approximately 10 minutes, or immediately on any server restart.
We do not currently retain any personal data for longer than the technical periods described above.
9. Your rights
As RRR FI LP is established in the United Kingdom, we process personal data as controller subject to UK GDPR and the Data Protection Act 2018. Subject to the conditions and exemptions set out in that law, you have the following rights in relation to your personal data:
- Right of access — to ask us to confirm what personal data we hold about you and to provide you with a copy of it.
- Right to rectification — to ask us to correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten") — to ask us to delete your personal data in certain circumstances.
- Right to restrict processing — to ask us to limit how we use your personal data in certain circumstances.
- Right to object — to object to our processing of your personal data where we rely on legitimate interests as our legal basis (Section 5).
- Right to lodge a complaint — you have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO), if you believe our processing of your personal data does not comply with UK data protection law. The ICO can be contacted via ico.org.uk.
Given the very limited nature of the personal data we currently process (Section 3) and the fact that most of it (contact form submissions, rate-limiting IP data) is not stored persistently at all (Section 8), several of the above rights may have little or no practical operation in relation to that specific data. They remain available to you in full in relation to any personal data we do hold, including web server access logs during their retention period (Section 8).
If you are located outside the United Kingdom, you may separately have equivalent or additional rights under your own local data protection law (for example, under the EU GDPR if you are in the European Union), which would need to be exercised in accordance with that law and, where applicable, with your own local supervisory authority; this is independent of, and additional to, the UK-law rights described above.
If you wish to ask a question about your data or exercise any right described above, you can contact us at: [email protected].
10. Children's privacy
This site is a corporate/business informational website and is not directed at children. We do not knowingly collect personal data from children.
11. Changes to this Policy
We may update this Privacy Policy from time to time, in particular as the site's functionality changes (for example, if contact form email delivery is implemented, if Cloudflare's configuration changes further, or if analytics or cookies are introduced in the future — none of the latter two are currently the case). The "Last drafted" / effective date at the top of this document will be updated accordingly. Material changes affecting how personal data is processed will be reflected here before they take effect operationally, where required by applicable law.
12. Contact
For any question about this Privacy Policy or about how your data is handled, please contact:
Registered office: 5 South Charlotte Street, Edinburgh, United Kingdom, EH2 4AN