Privacy-Aware Digital Services

GDPR & privacy.

Responsible data handling should be part of how digital experiences are designed and managed.

Fawkes Digital Marketing supports privacy-aware practices across websites, forms, hosting, analytics, SEO, and connected digital services.

Website Design

Privacy Foundation

Privacy should be part of the foundation.

The General Data Protection Regulation gives individuals important rights relating to their personal data. We work to support responsible collection practices, understandable disclosures, privacy-aware forms, secure website practices, and reasonable handling of privacy-related requests.

Last updated: October 14, 2025

Data Minimization

Forms and digital workflows should collect only the information reasonably needed for the intended business purpose.

Privacy-Aware Forms

Contact forms, quote requests, lead forms, and similar experiences should clearly communicate what information is being requested and why.

Data Protection

Website and service data should be handled using appropriate transport security, access controls, storage practices, and trusted service providers.

Analytics Awareness

Analytics, search, advertising, and measurement tools should be evaluated with privacy, disclosure, visitor preferences, and applicable requirements in mind.

Retention Awareness

Personal information should not be retained indefinitely without a legitimate operational, contractual, legal, or business need.

Third-Party Awareness

Plugins, analytics platforms, CRMs, payment systems, embedded content, and other providers may independently collect or process information and should be considered when evaluating privacy obligations.

Privacy Requests

A clear channel for privacy-related questions.

Visitors, customers, and authorized representatives may contact Fawkes regarding personal information associated with our websites or digital services.

Depending on the circumstances and applicable law, requests may involve access, correction, deletion, restriction, objection, or other privacy-related concerns.

Our Role

We support responsible digital implementation.

Fawkes can help customers review website forms, analytics, hosting settings, integrations, plugins, cookies, and other digital components that may affect how personal information is collected or processed.

The exact responsibilities involved depend on the service, the data being processed, the relationship between the parties, and applicable law.

Customer Responsibility

Customers remain responsible for their own data practices.

Customers are responsible for determining the lawful basis, notices, permissions, retention practices, disclosures, and other requirements applicable to personal data collected through their own websites, forms, email lists, and business processes.

Fawkes provides technology and digital support but does not replace a customer's legal, regulatory, or privacy obligations.

Privacy Support Areas

Practical support for responsible data handling.

Access Requests

We can help identify information associated with our own systems or services when a valid privacy request applies.

Correction Requests

Personal information under our control may be reviewed for correction when appropriate and reasonably verifiable.

Deletion Questions

Requests involving deletion may be reviewed subject to applicable legal, contractual, operational, security, and retention requirements.

Website Forms

We can help customers review what their forms collect, where submissions are sent, and which connected services may process that information.

Analytics & Cookies

Analytics tools, cookies, tracking technologies, and embedded services can be reviewed as part of a broader privacy-aware website configuration.

Vendor Awareness

Third-party processors and service providers may have independent terms, privacy practices, storage locations, and processing responsibilities.

GDPR & Privacy Questions

Frequently asked questions.

Review common questions about privacy, personal data, and the digital services supported by Fawkes.

What is GDPR?

The EU's General Data Protection Regulation (GDPR) is a comprehensive law that governs how personal data of EU residents is collected, stored, and processed. Introduced in 2016 to modernize outdated data protection rules, GDPR ensures individuals have greater control over their personal information in an increasingly digital world.

Who does it apply to?

GDPR applies to any organization handling the personal data of EU residents, regardless of where the organization is based. It establishes clear obligations for data controllers and processors.

Where does GDPR apply?

GDPR has global reach. Any organization worldwide that processes personal data of EU residents falls under its jurisdiction.

Penalties for Non-Compliance

Violating GDPR can result in severe penalties:

  • Up to 4% of the organization's annual global turnover, or
  • €20 million, whichever is higher.
Key Stakeholders
  • Data Subject: Any natural person residing in the EU whose personal data is being processed.
  • Data Controller: Determines the purpose and methods of processing personal data.
  • Data Processor: Processes data on behalf of the controller.
  • Supervisory Authorities: Public authorities that monitor GDPR compliance and investigate breaches.
What is Personal Data or Personally Identifiable Information (PII)?

Personal data is any information that identifies or can identify a natural person. It can be:

  • Direct identifiers: Name, email, phone number, etc.
  • Indirect identifiers: Date of birth, gender, location, and other characteristics.
Key Changes from Previous Regulations

GDPR introduces enhanced rights for data subjects and stricter obligations for organizations:

  • Explicit Consent: Individuals must be informed and give clear permission for their data to be processed, with the ability to withdraw consent easily.
  • Right to Access: Data subjects can request details of personal data being held.
  • Right to Be Forgotten: Individuals can request deletion of their personal data.
  • Processor Obligations: Processors must demonstrate GDPR compliance and follow controller instructions.
  • Data Protection Officer (DPO): Organizations may need a DPO to oversee GDPR compliance.
  • Privacy Impact Assessments (PIA): Large-scale processing requires assessments to minimize risks.
  • Breach Notification: Controllers must notify authorities and affected individuals within 72 hours of a breach.
  • Data Portability: Individuals can receive their data in a machine-readable format and transfer it to another controller.
Lawful Bases for Processing Data

Controllers can process personal data under six lawful bases:

  • Contract: Processing necessary to fulfill contractual obligations or customer requests.
  • Legal Obligation: Processing required by law or regulatory authority.
  • Vital Interests: Processing needed to protect life or health.
  • Public Task: Processing carried out by public authorities for official duties.
  • Legitimate Interests: Processing for business or societal interests, documented through a Legitimate Interests Assessment (LIA).
  • Consent: Freely given, specific, informed, and unambiguous permission from the data subject.
What is a Legitimate Interests Assessment (LIA)?

An LIA evaluates whether the organization has a valid reason to process personal data. It includes:

  • Assessment of the legitimate interest
  • Determining necessity for processing
  • Balancing test to ensure rights of data subjects are protected
Additional GDPR Resources

For more information, refer to the following:

Note: Brilliance One is not responsible for the content of these external pages and does not endorse them.

Privacy Support

Have a privacy or data-protection question?

Contact us regarding privacy concerns, personal-data questions, website data requests, or privacy-related support involving Fawkes digital services.

Brilliance One 1013 Fuller St SW
Cullman, AL 35055
Privacy Support sales@brillianceone.com
256-258-8593

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.

The session has been paused.