How we handle the information you give us.
Last updated: August 25, 2026
The short version
Moative, Inc. runs moative.com. When you submit a form, download the Book of Theses, register for a session, or email us, we collect what you give us and nothing more. We do not sell your personal information. We do not share it for cross-context behavioural advertising. We run no advertising trackers.
The one non-essential technology on this site is Google Analytics, and it stays switched off until you turn it on. The rest of this notice is the detail behind those sentences, written so you can hold us to them.
Who we are
Moative, Inc. is the controller of the personal information described here. You can reach us at hub@moative.com, or by post at 2626 S Loop West, Suite 130, #1015, Houston, TX 77054.
Your use of this site is also governed by our terms of use.
Our people work from Houston, Chennai, and Bangalore. We have no establishment in the European Economic Area or the United Kingdom, and we do not direct our services at people there. Where a visitor from those regions does contact us, we apply the rights set out in the EEA, UK, and Swiss section below.
What we collect
Information you give us
Three forms on this site collect personal information: the contact form, the case study and Book of Theses download form, and the session registration form. Between them they ask for your first and last name, work email address, company, industry, and whatever you write in the message field. Each submission also records which page you sent it from, so a reply lands in context.
If you write to us directly, we hold that correspondence and anything you choose to put in it.
Information collected automatically
Our host records standard server logs for every request: IP address, user agent, the URL requested, referring URL, and a timestamp. These exist so the site can be operated and defended against abuse.
If you consent to analytics, Google Analytics 4 records your visit with IP anonymisation enabled. Without that consent, the Google tag is never loaded and no analytics identifier is created.
What we do not collect
This site has no accounts, no login, and no payment processing. We do not ask for government identifiers, financial account details, biometric data, precise geolocation, or health information, and we do not want you to send them. We do not host user-generated content, and we run no session-replay tooling.
Cookies and similar technologies
A separate cookie notice lists every cookie and storage key by name, says who sets it and why, and explains how to change your choice at any time. Your decision is recorded in your browser and honoured on every page you visit afterwards.
How we use your information
- To answer you. A principal reads every inbound submission and replies to it.
- To deliver what you asked for. Sending the thesis, the case study, or the session link you requested.
- To continue a conversation that both sides want to continue, and to run the engagements that follow from it.
- To operate and secure the site, including diagnosing faults, blocking abuse, and keeping backups.
- To understand what gets read, where you have consented to analytics, so we can decide what to publish next.
- To meet legal obligations and to establish, exercise, or defend legal claims.
We do not enrich your submission against third-party data brokers, feed it to automated outbound sequencing, or build advertising profiles from it. No decision producing legal or similarly significant effects about you is made by automated means.
Our legal bases for processing
Where the GDPR or UK GDPR applies to a visitor, we rely on the following bases.
- Consent for analytics cookies. You may withdraw it at any time through the cookie preferences link in the footer, without affecting processing carried out before you withdrew it.
- Legitimate interests for replying to your enquiry, running and securing the site, and pursuing business correspondence you started. We balance those interests against your rights each time we rely on this basis.
- Performance of a contract, or steps taken at your request before entering one, where your enquiry leads to an engagement.
- Legal obligation, where retention or disclosure is required of us by law.
How we share your information
We share personal information with a short list of service providers who process it on our instructions and are contractually barred from using it for their own purposes.
| Provider | What it handles | Why |
|---|---|---|
| Netlify | Site hosting, form submissions, server logs | Serves the site and delivers form submissions to our inbox |
| Google Analytics | Consented analytics events | Tells us which pages get read. Never loaded without consent |
| Ghost | The blog at /blog/ | Publishes and serves blog content under our domain |
| Google Workspace | Email correspondence | Where your message arrives and where our reply comes from |
Beyond those providers, we may disclose personal information when the law requires it, when we need to establish or defend a legal claim, or in connection with a merger, acquisition, financing, or sale of assets, in which case the receiving party remains bound by this notice or gives you notice before anything changes.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the twelve months preceding the date at the top of this page.
Where your information goes
We are a United States company with colleagues in India, so information you send us is processed in the United States and may be accessed by our team in Chennai and Bangalore.
If you are in the EEA, the UK, or Switzerland, that is a transfer outside your home jurisdiction. Where such a transfer occurs we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies. Write to us at hub@moative.com and we will describe the safeguards in place for your data.
How long we keep it
Form submissions and correspondence stay in our systems while the conversation or engagement they relate to is live, and for a reasonable period afterwards so we can answer questions about work we did. Server logs are retained on a short rolling window by our host. Consented analytics data is retained on Google Analytics' standard retention setting.
Ask us to delete your record and we will, except where we are required to keep something to meet a legal obligation or to defend a claim. We will tell you if that exception applies to you.
How we protect it
The site is served over HTTPS with HSTS, a content security policy, and frame-denial headers. Access to form submissions and correspondence is limited to the people who need it. No system is perfectly secure, and we do not claim otherwise, but we would rather tell you what we run than describe our security in adjectives.
Your choices
- Analytics. Choose in the banner on your first visit, and change it whenever you like through the cookie preferences link in the footer.
- Correspondence. Tell us to stop writing and we stop. Every email we send is a reply from a person, so replying to it reaches one.
- Browser controls. Your browser can block or delete cookies independently of anything on this site, and can send a Global Privacy Control signal, which we treat as a valid opt-out request where state law requires it.
Your rights
Wherever you live, you can ask us to tell you what personal information we hold about you, correct it if it is wrong, delete it, or give you a copy in a portable format. You can also object to what we are doing with it.
Write to hub@moative.com and we will act on the request. We aim to reply within a few business days and will not take longer than the period your law allows. We may need to confirm your identity before we act, which we do by corresponding with the address the information is held against. Exercising these rights costs nothing and we will not treat you differently for it.
You may use an authorised agent to make a request on your behalf, provided the agent gives us written proof of your authorisation.
United States state privacy rights
This section is the notice at collection required by the California Consumer Privacy Act as amended, and describes rights under comparable laws in Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah, and other states with comprehensive privacy statutes.
Categories we collect
| Category | Examples on this site | Purpose |
|---|---|---|
| Identifiers | Name, work email address, IP address | Replying to you, operating and securing the site |
| Commercial or professional information | Company, industry, message contents | Understanding your enquiry and continuing the conversation |
| Internet activity | Pages requested, referring URL, consented analytics events | Operating the site and, with consent, measuring readership |
We collect these categories from you directly and from the automatic sources described above. We retain each category for the periods set out under how long we keep it. We do not collect sensitive personal information, and we do not use or disclose any information for purposes that would require an opt-out of sensitive-data processing.
What you can ask for
You may request to know the categories and specific pieces of personal information we have collected, the sources, the purpose, and the categories of parties we disclosed it to. You may request correction or deletion, and you may request a portable copy. Because we neither sell personal information nor share it for cross-context behavioural advertising, there is nothing to opt out of on that front, but the Global Privacy Control signal is honoured regardless.
Requests go to hub@moative.com. If we decline a request, you may appeal by replying to our decision, and we will respond to the appeal within the period your state's law allows and explain your route to the state attorney general if we still decline.
Nevada
Nevada residents may direct us not to sell covered information under Nevada Revised Statutes Chapter 603A. We do not sell it, and a request to that effect will be recorded.
EEA, UK, and Swiss rights
If the GDPR, UK GDPR, or the Swiss Federal Act on Data Protection applies to you, you hold the rights of access, rectification, erasure, restriction of processing, data portability, and objection, together with the right to withdraw consent at any time.
You also have the right to lodge a complaint with a supervisory authority: your local data protection authority in the EEA, the Information Commissioner's Office in the UK, or the Federal Data Protection and Information Commissioner in Switzerland. We would rather you came to us first at hub@moative.com, but the right stands either way.
We have not appointed an Article 27 representative, because we are not established in the EEA or the UK and do not offer goods or services to, or monitor the behaviour of, people located there.
Children
This site is built for people doing their jobs. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us something, write to hub@moative.com and we will delete it.
Other sites, and our blog
Links from this site to somewhere else are not endorsements, and the other site's privacy practices govern once you arrive. Our blog at /blog/ is published under our domain but served by a third-party publishing platform that loads its own scripts and fonts. The cookie notice sets out what that means in practice.
Changes to this notice
When we change something material here, we change the date at the top of the page and, where the change affects how we handle information you already gave us, we tell you directly. Checking this page occasionally is worth doing.
Questions and complaints
Write to hub@moative.com, or to Moative, Inc., 2626 S Loop West, Suite 130, #1015, Houston, TX 77054. A real person reads it, and you will get a real answer rather than a ticket number.