Website: tudorsgroup.com (the "Site")
Version: 2 October 2026
Last updated: 2 October 2026
Prevailing language: English. Translations are provided for convenience; in case of discrepancy, this English version prevails.
1. Definitions
1.1 "T&T", "we", "us" means, jointly, T&T Consulting Business, LLC and Tudor & Tudor, LLC, Florida limited liability companies, 13575 58th St N, Suite 200, Clearwater, Florida 33760, United States, acting as joint controllers. "T&T" is the trade name of the group. The activity of the Site is directed from Split, Croatia.
1.2 "Terminal equipment" or "device" means the computer, phone, tablet or other device, including its browser, through which you access the Site.
1.3 "Storage and access technology" means any technique by which information is stored on, or read from, your device, including HTTP cookies, the Web Storage API (localStorage and sessionStorage), IndexedDB, cache storage, scripts that instruct the browser to transmit information held on the device, tracking pixels and device fingerprinting. In this Policy, "cookie" is used for convenience to cover all of them.
1.4 "Strictly necessary" means storage or access without which a service you have explicitly requested cannot be provided, or which is required solely to carry out the transmission of a communication.
1.5 "Consent" means a freely given, specific, informed and unambiguous indication of your wishes, given by a clear affirmative act (Article 4(11) GDPR).
1.6 "Opt-out preference signal" means a browser-level signal such as Global Privacy Control ("GPC") that communicates a request not to have personal information sold or shared, or not to be tracked.
1.7 "Personal data" has the meaning given in Article 4(1) GDPR and, for other jurisdictions, the equivalent term in the law cited in Section 4.
2. Scope
2.1 This Policy describes every storage and access technology used on the Site, the legal basis on which each is used, and how you control it.
2.2 It applies only to the Site. It does not apply to services operated by third parties to which the Site sends you (Section 8).
2.3 How we process personal data you submit through forms is described in our Global Privacy Policy, available at /privacy.
3. Summary
3.1 The Site sets no first-party cookies. It uses one Web Storage entry, tt-consent, which records your choice and contains no personal data or identifier.
3.2 Our own visit counter sets no cookie, stores nothing on your device, keeps no identifier and does not record IP addresses. Our server adds each page it serves to daily totals; the script that confirms that a person, and not an automated program, viewed the page runs only if you accept the Analytics category (Section 6).
3.3 We use no advertising, social media, retargeting, session-recording or third-party analytics technology. The Marketing category exists but is empty.
3.4 On the consultation booking page, once you choose a time to pay for, Stripe's payment form is loaded from Stripe and may set Stripe's own cookies, which are strictly necessary for the payment you request (Section 5).
3.5 Nothing that is not strictly necessary runs until you choose, and refusing is as easy as accepting. Your choice is valid for 12 months.
4. Legal framework
4.1 European Union
4.1.1 Directive 2002/58/EC (ePrivacy Directive), Article 5(3), as amended by Directive 2009/136/EC, requires prior consent, given on the basis of clear and comprehensive information in accordance with the GDPR, for the storing of information, or the gaining of access to information already stored, in the terminal equipment of a user. The only exceptions are storage or access (a) for the sole purpose of carrying out the transmission of a communication, or (b) strictly necessary to provide an information society service explicitly requested by the user.
4.1.2 Article 5(3) is technology neutral and does not depend on whether the information is personal data. It applies equally to localStorage, sessionStorage and scripts that read information from the device. The European Data Protection Board confirmed this in Guidelines 2/2023 on the Technical Scope of Art. 5(3) of the ePrivacy Directive (version 2, adopted 7 October 2024), which state that the information covered is not limited to personal data and which, in their analysis of the notion of "gaining of access", treat as access any situation in which the entity instructs the browser, by code it distributes, to send information stored on or generated by the device.
4.1.3 Where consent is required, it must meet the GDPR standard: Articles 4(11) and 7 GDPR, interpreted by EDPB Guidelines 05/2020 on consent (version 1.1, 4 May 2020), which hold among other things that access to a service may not be conditioned on accepting cookies ("cookie walls", paragraphs 39 to 41) and that scrolling or continued browsing is not consent (paragraph 86). The Court of Justice held in Planet49 (C-673/17, 1 October 2019) that a pre-ticked box is not valid consent and that the user must be told the duration of cookies and whether third parties have access to them.
4.1.4 Where storage or access leads to processing of personal data, that processing also needs a legal basis under Article 6 GDPR.
4.1.5 EU law contains no general exemption from consent for audience measurement. The European Commission's "Digital Omnibus" proposal of 19 November 2025 would introduce rules on this subject in the GDPR, but it had not been adopted at the date of this Policy. If it is adopted, we will review this Policy; until then we apply Article 5(3) as described above.
4.2 Croatia
4.2.1 Article 5(3) is transposed in Croatia by Article 43(4) of the Zakon o elektroničkim komunikacijama (Electronic Communications Act, Narodne novine 76/22, 14/24 and 45/26), which permits the use of electronic communications networks to store information in, or to gain access to information already stored in, the terminal equipment of a subscriber or user only where that subscriber or user has given consent on the basis of clear and comprehensive information, subject to the two exceptions in 4.1.1. The 2026 amendment (Narodne novine 45/26) did not amend Article 43.
4.2.2 The competent authority for personal data is the Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, https://azop.hr.
4.3 United Kingdom
4.3.1 The Site is not directed at the United Kingdom. Visitors connecting from the United Kingdom receive the same treatment as all other visitors (4.10.1).
4.4 United States
4.4.1 California. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq., "CCPA"), regulates the "sale" and "sharing" (disclosure for cross-context behavioral advertising, §1798.140(ah)) of personal information, including through cookies. Cal. Code Regs. tit. 11, §7025 requires a business to treat an opt-out preference signal such as GPC as a valid request to opt out of sale and sharing, for the browser and, where known, the consumer. We do not sell or share personal information. We nonetheless honour GPC as described in Section 10. The CCPA applies to a "business" that meets one of the thresholds in §1798.140(d) (annual gross revenue above the amount adjusted by the California Privacy Protection Agency, USD 26,625,000 from 1 January 2025, or the volume tests set out there). We do not state that T&T meets any of those thresholds; we apply the standard described in this Policy voluntarily. Authorities: California Privacy Protection Agency, https://cppa.ca.gov, and the California Attorney General, https://oag.ca.gov/privacy.
4.4.2 Other states. Several state privacy laws (for example Colorado, Connecticut, Texas, Oregon) require recognition of universal opt-out mechanisms. Our treatment of GPC satisfies these requirements to the extent they apply.
4.5 Brazil
4.5.1 Under the Lei Geral de Proteção de Dados (Lei 13.709/2018, "LGPD"), cookies that process personal data require a legal basis under Article 7 (consent, Article 7(I) and Article 8, or legitimate interest, Articles 7(IX) and 10), with transparent information (Article 9). The ANPD guidance "Guia Orientativo: Cookies e Proteção de Dados Pessoais" (October 2022) accepts legitimate interest for strictly necessary cookies and expects consent for non-necessary ones in most cases. Authority: Autoridade Nacional de Proteção de Dados, https://www.gov.br/anpd.
4.6 Colombia
4.6.1 Ley Estatutaria 1581 de 2012 requires prior, express and informed authorisation for processing personal data (Article 9) and information to the data subject (Article 12), implemented by Decreto 1074 de 2015 (Chapter 25, which incorporates Decreto 1377 de 2013). Colombian law contains no cookie-specific rule. The Superintendencia de Industria y Comercio has stated (Concepto 16-172268 of 2016) that where personal data are collected through cookies, the controller must comply with Ley 1581 de 2012 and its principles. The aggregated counter collects no personal data. Authority: Superintendencia de Industria y Comercio (SIC), https://www.sic.gov.co.
4.7 Mexico
4.7.1 The Ley Federal de Protección de Datos Personales en Posesión de los Particulares published in the Diario Oficial de la Federación on 20 March 2025 ("LFPDPPP 2025") governs consent (Article 7) and the privacy notice (Article 15). Mexican data protection rules require the privacy notice to inform data subjects of the use of remote or local electronic mechanisms that collect personal data automatically (such as cookies and web beacons) and of how to disable them. This Policy provides that information for the Site. Authority: Secretaría Anticorrupción y Buen Gobierno, https://www.gob.mx/buengobierno.
4.8 South Africa
4.8.1 The Protection of Personal Information Act 4 of 2013 (POPIA) treats online identifiers as personal information (section 1) and requires a lawful justification (section 11) and notification to the data subject (section 18). POPIA has no cookie-specific rule. Authority: Information Regulator, https://inforegulator.org.za.
4.9 Canada
4.9.1 Under the Personal Information Protection and Electronic Documents Act (PIPEDA), Schedule 1, Principle 4.3, knowledge and consent are required for the collection of personal information, and the Office of the Privacy Commissioner's Guidelines for obtaining meaningful consent (2018) and its policy position on online behavioural advertising apply to tracking technologies. In Québec, section 8.1 of the Act respecting the protection of personal information in the private sector requires that any technology allowing a person to be identified, located or profiled be deactivated by default. Under Canada's Anti-Spam Legislation (CASL), section 8 regulates the installation of computer programs in the course of commercial activity, and section 10(8) deems express consent to be given for the installation of a cookie, HTML code or JavaScript where the person's conduct makes it reasonable to believe that they consent to it. Authority: Office of the Privacy Commissioner of Canada, https://www.priv.gc.ca.
4.10 Other jurisdictions
4.10.1 For visitors from any other jurisdiction we apply the same rule: prior opt-in consent for anything that is not strictly necessary.
5. Technical inventory
| Name | Storage type | Provider | Purpose | EU legal basis and exemption | Duration | Data held |
|---|---|---|---|---|---|---|
tt-consent | localStorage (first party) | T&T | Records your choice so the banner is not shown again and only accepted categories run | Strictly necessary (Art. 5(3), second sentence): recording consent is required to comply with Art. 7(1) GDPR. Holds no personal data, so Art. 6 GDPR is not engaged | Your choice is valid for 12 months; the banner asks again after 12 months, when the Policy version changes, or if you clear site data | Categories accepted or refused, date and time of the choice, Policy version |
| Visit counter: browser confirmation (script, no storage) | Script access to device information and transmission via navigator.sendBeacon | T&T, on Cloudflare Workers and D1 | Confirms that a person viewed the page, to separate people from automated traffic in the aggregated counts | Consent (Art. 5(3)); Art. 6(1)(a) GDPR for the transient processing described in 6.5 | No storage on the device; aggregates kept 400 days | Page path, referring source, country (derived server-side); no identifier, no IP address stored |
Stripe payment form (Stripe.js) and Stripe cookies, such as __stripe_mid and __stripe_sid | Third-party script and HTTP cookies, loaded only on the consultation booking page after you choose a time | Stripe, Inc. | Secure entry of card details and fraud prevention for the payment you request | Strictly necessary for the payment you explicitly request (Art. 5(3)); Art. 6(1)(b) and (f) GDPR. Stripe acts as an independent controller for fraud prevention | According to Stripe: __stripe_mid one year, __stripe_sid 30 minutes | Data about your device and browser, and Stripe's own identifiers, under https://stripe.com/privacy |
5.1 No other storage and access technology is used. In particular, apart from Stripe's payment form on the booking page, the Site uses no third-party cookies, IndexedDB, fingerprinting, tracking pixels, advertising identifiers, session replay or embedded third-party content, and loads no fonts, scripts, maps, videos or verification challenges from third-party domains. Our forms and the booking page send what you submit to our own form handler, which runs on Cloudflare Workers at a workers.dev address operated by us.
6. The visit counter
6.1 Server totals. When our server delivers a page, it adds one to the daily totals for that page, the country and network (autonomous system number) that Cloudflare derives from the connection, and the type of traffic (for example, a declared search engine crawler). Nothing is read from or stored on your device, and no IP address or identifier is recorded, so this step needs no consent under Article 5(3); the transient processing that produces the totals relies on our legitimate interest (Art. 6(1)(f) GDPR). For automated programs that do not identify themselves clearly, the browser identification string, shortened to 120 characters, is kept for 90 days to classify them. The steps below describe the separate browser confirmation.
6.2 Activation. The confirmation script runs only if tt-consent records a valid acceptance of Analytics and no opt-out preference signal is present. Otherwise the script does nothing and no request is sent.
6.3 Trigger. When a page has been visible on screen for two continuous seconds (measured with the Page Visibility API), the script sends one request to our own endpoint on tudorsgroup.com using navigator.sendBeacon. Pages opened in background tabs and closed before becoming visible are not counted.
6.4 Content of the request. The request contains the page path, the domain of the referring site (without path or query string) and, if the link you followed carried one, its utm_source tag. On receipt, the referring domain is reduced to one of a fixed list of sources (for example "google" or "linkedin") and the rest is discarded. It contains no cookie, no identifier, no user-agent string beyond what the browser sends with every request, and no data stored on your device.
6.5 Server-side processing. On receipt, our Worker reads the country code that Cloudflare derives from the connection, adds one to the daily total for the combination of page, country and referring source in a Cloudflare D1 database, and discards the request. The IP address is processed only transiently by Cloudflare to route the connection and derive the country; it is not written to the database or to any log controlled by T&T.
6.6 Anti-falsification quota. To prevent inflated counts, the endpoint applies a limit on accepted requests that does not use IP addresses, identifiers or data stored on your device: a confirmation is accepted only if the same page was delivered to the same country and network in the previous 30 minutes, and never from data-centre networks or from other sites. The record that makes this check possible (time slot, country, network and page) is deleted after 30 minutes.
6.7 Retention. Daily aggregates are deleted after 400 days.
6.8 Why consent is still required in the EU. Although the counter stores nothing and the aggregates are not personal data, the confirmation script reads information from the device (visibility state and referrer) and instructs the browser to transmit it. Under Article 5(3) and Guidelines 2/2023 this is "gaining of access", and measuring audiences is not strictly necessary for a service you requested. Consent is therefore required regardless of the absence of cookies.
7. Marketing category
7.1 The Marketing category appears in the consent settings so that the structure of your choice remains stable. It is empty: no marketing, advertising or social-media technology is loaded, whether you accept or refuse it.
7.2 Before any technology is added to Marketing, we will update this Policy, increase its version number and ask for your consent again. Acceptance given while the category was empty will not be treated as consent to any later technology.
8. Third-party services outside the Site
8.1 Stripe Checkout. For payments other than consultations, you are redirected to a payment page hosted by Stripe on its own domain. T&T never receives your card details. Stripe sets its own cookies there under its policy (https://stripe.com/privacy and https://stripe.com/cookie-settings). Stripe's payment form on our booking page is described in Section 5.
8.2 Google Meet. Consultations take place on meet.google.com, where Google sets its own cookies under its policy (https://policies.google.com/technologies/cookies).
8.3 Those technologies are set on third-party domains, under those parties' responsibility, and are outside the scope of this Policy and of our consent banner.
9. Consent mechanism
9.1 Prior consent. On your first visit a banner offers three choices at the same level: "Accept all", "Reject all" and "Settings". Until you choose, only the items marked strictly necessary in Section 5 are active.
9.2 Equal prominence. "Reject all" is presented with the same size, colour weight and position as "Accept all", consistent with the EDPB Cookie Banner Taskforce report (January 2023).
9.3 Granularity. Under "Settings" you may accept or refuse Analytics and Marketing separately. No box is pre-ticked.
9.4 No cookie wall. All content and forms are available whether you accept or refuse.
9.5 Proof. Your choice, its date and time and the Policy version are recorded in tt-consent. Because the Site assigns no identifier, no copy is kept on our servers. We keep an archive of every version of the banner text and of this Policy with its dates of use, so that the information shown at the time of any recorded choice can be demonstrated (Article 7(1) GDPR).
9.6 Withdrawal. "Cookie settings" is permanently available in the footer of every page. Withdrawal is as easy as giving consent (Article 7(3) GDPR) and takes effect immediately; it does not affect counts already aggregated, which contain no data about you.
9.7 Expiry and renewal. Your choice, whether acceptance or refusal, expires 12 months after the date recorded in tt-consent. After that date the Site treats every category other than strictly necessary as refused and shows the banner again. We also ask again, before 12 months have passed, when the version of this Policy changes because what we store or measure has changed.
10. Global Privacy Control
10.1 If your browser sends the Sec-GPC: 1 header or exposes navigator.globalPrivacyControl = true, the Site treats it as a refusal of Analytics and Marketing, in every jurisdiction, and the banner states "Opt-out request honored" and explains that analytics and marketing are switched off.
10.2 Under Cal. Code Regs. tit. 11, §7025, the signal is also processed as a request to opt out of sale and sharing. We do neither.
11. Deleting stored data from your browser
11.1 You can delete everything the Site has stored at any time. The Site will continue to work and the banner will appear again. Menu names may change between browser versions.
| Browser | Steps |
|---|---|
| Chrome (desktop) | Click the icon to the left of the address bar, then "Site settings", then "Delete data"; or Settings, Privacy and security, Site settings, "View permissions and data stored across sites", search tudorsgroup.com, delete |
| Chrome (Android) | Settings, Site settings, All sites, tudorsgroup.com, "Delete & reset" |
| Edge | Settings, Cookies and site permissions, "Manage and delete cookies and site data", "See all cookies and site data", search tudorsgroup.com, delete |
| Firefox | Click the padlock in the address bar, then "Clear cookies and site data"; or Settings, Privacy & Security, Cookies and Site Data, "Manage Data" |
| Safari (macOS) | Safari, Settings, Privacy, "Manage Website Data", search tudorsgroup.com, Remove |
| Safari (iPhone, iPad) | Settings, Apps, Safari, Advanced, Website Data, search tudorsgroup.com, swipe to delete |
12. Changes to this Policy
12.1 We will update this Policy before deploying any change to the technologies in Section 5. Each change that affects what is stored or measured increases the version number and triggers a new request for consent (9.7). Earlier versions are available on request.
13. Contact and complaints
13.1 Questions about this Policy: Dinko Anton Tudor, Managing Member, legal@tudorsgroup.com.
13.2 You may also complain to the supervisory authority of your country, including AZOP (Croatia), the CPPA (California), the ANPD (Brazil), the SIC (Colombia), the Secretaría Anticorrupción y Buen Gobierno (Mexico), the Information Regulator (South Africa) or the Office of the Privacy Commissioner (Canada), at the addresses given in Section 4.