1. Who we are
Wilderloom Earth is a nature media brand and content-operations application operated by Manybrook Ventures LLC (“Manybrook”, “we”, “us” or “our”). For the processing described in this notice, Manybrook generally acts as the data controller—the organisation deciding why and how personal information is used.
Privacy enquiries and rights requests: admin@kempenterprise.com. Please use the subject “Wilderloom Privacy”. We may ask for proportionate information to verify your identity before completing a rights request.
2. Scope
This notice covers our websites, newsletters, forms, competitions, surveys, customer-support interactions, prospective products, social-media presences, content analytics and our internal AI-assisted content tools, including our Pinterest integration. It also covers information received when someone follows a link to us or voluntarily joins one of our future marketing funnels.
Third-party platforms such as Pinterest, YouTube, Google, Meta, TikTok or an email provider also process information under their own privacy notices. Their independent processing is not controlled by this notice.
3. Information we may collect
- Identity and contact data: name, email address, telephone number, country, account or social-media handle.
- Preference and consent data: topics, channel and contact preferences; the wording, source, date and time of consent; opt-outs and suppression records.
- Interaction and enquiry data: messages, support requests, survey responses, competition entries and correspondence.
- Transaction data: purchases, subscriptions, refunds and limited payment metadata. Full card details are handled by regulated payment providers rather than stored by us.
- Technical and usage data: IP address, device/browser information, timestamps, referring URLs, pages or content viewed, clicks, campaign attribution and cookie identifiers, where permitted.
- Social and platform data: public engagement information and information a platform makes available through an authorised API. Our Pinterest app is designed to access only the authenticated business account's own Pins, Boards and performance data.
- Content and media: material you intentionally submit to us, together with associated permissions and provenance records.
- Inferences: broad interests or audience segments derived from lawful interactions, used to improve relevance. We do not use solely automated decisions that produce legal or similarly significant effects.
We do not intentionally seek special-category data (such as health, biometric, ethnicity, religion, political or sexual-life data) through ordinary marketing funnels. If a specific service genuinely requires it, we will provide additional information and establish an appropriate lawful condition first.
4. How we obtain information
We collect information directly from you; automatically from our sites after any required cookie choice; from connected platforms through authorised APIs; from service providers acting for us; from referrals you have authorised; and from public sources only where collection and later use are fair, lawful and reasonably expected. We will not scrape private profiles, bypass platform controls or add people to electronic-marketing lists merely because their details are public.
5. Purposes and lawful bases
| Purpose | Information | Typical lawful basis |
|---|---|---|
| Operate accounts, forms, services and requested communications | Contact, enquiry, transaction and account data | Contract or steps requested before a contract; legitimate interests; legal obligation |
| Create, schedule and manage operator-approved content on our own accounts | Authorised platform, content and operational data | Legitimate interests in operating our media business; contract where applicable |
| Measure our own Pins, Boards, videos, campaigns and content performance | Aggregated or account-level analytics and usage data | Legitimate interests; consent where cookies or similar technologies require it |
| Send email, text or similar direct marketing | Contact, preference, consent and engagement data | Consent where required by PECR; otherwise a carefully assessed lawful basis and applicable soft opt-in |
| Personalise content and marketing | Preferences, interactions, usage and high-level inferences | Consent where required; otherwise legitimate interests after balancing individuals' rights |
| Process payments, prevent fraud, keep records and meet tax/accounting duties | Identity, transaction and technical data | Contract, legal obligation and legitimate interests |
| Protect systems, investigate misuse and establish or defend legal claims | Technical, account and communication data | Legitimate interests and legal obligation |
| Improve services through AI-assisted tools | Minimised content, operational and analytical data | Legitimate interests or consent/contract where those are more appropriate |
Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact, and use safeguards such as minimisation, access controls and opt-outs. You may ask for more information about a balancing assessment.
6. Direct marketing, funnels and customer databases
Future landing pages and funnels will state who is collecting the data, the intended follow-up and the relevant privacy notice at the point of collection. Electronic-marketing consent will use a clear, separate, unticked choice where required. Consent records will capture the person or identifier, time, source, wording shown and channels agreed.
- We will provide an unsubscribe or equivalent opt-out in marketing messages and honour objections promptly.
- We maintain a minimal suppression record after opt-out so the person is not accidentally re-added.
- We do not buy lists for email, text or automated calling unless due diligence proves valid, specific permission covering Manybrook or the identified brand and the intended channel.
- We do not combine databases across unrelated ventures simply because they share an owner. Any cross-brand promotion requires an appropriate expectation, lawful basis and transparent notice.
- We will not use customer data collected for service delivery for an incompatible new purpose without completing the required assessment and, where necessary, obtaining fresh consent.
7. Cookies and similar technologies
Strictly necessary technologies may operate without consent. Analytics, advertising, profiling or social-media tracking technologies will not be activated for UK/EEA visitors until an appropriate affirmative choice has been recorded, unless an applicable exemption genuinely applies. A deployed site using such technologies will provide a cookie notice and preference control identifying categories, providers, purposes and durations. Merely continuing to browse will not be treated as consent.
8. AI and automation
We may use AI-assisted services for content drafting, classification, analytics, support preparation and operational workflows. We apply human oversight to publishing and material customer decisions. We aim to minimise or pseudonymise personal information sent to AI providers, restrict training use where provider controls allow, apply contractual safeguards, and avoid entering sensitive or unnecessary personal data. We do not permit an AI system to make a solely automated decision that has legal or similarly significant effects on an individual without a valid legal basis, required safeguards and a meaningful route to human review.
9. Sharing and processors
We may share the minimum necessary information with contracted providers of hosting, cloud storage, analytics, email/customer-relationship management, payments, security, professional advice, customer support, content production and platform/API services. We may also disclose information when required by law, to protect rights and safety, or as part of a corporate transaction subject to confidentiality and lawful-use restrictions.
Providers are selected according to need and risk. Where they process information for us, we require appropriate data-processing terms, confidentiality, security, deletion/return commitments and assistance with rights and incidents. We do not give third parties independent permission to market their unrelated products to you unless this was clearly disclosed and lawfully authorised.
10. International transfers
Some providers may process information outside the UK. Before making a restricted transfer, we assess whether the transfer rules apply and use an available lawful mechanism, such as UK adequacy regulations or appropriate safeguards (which may include the UK International Data Transfer Agreement or UK Addendum), together with a transfer-risk assessment and supplementary measures where needed. A limited legal exception will be used only where its conditions genuinely apply.
11. Retention
We retain personal information only for as long as needed for the stated purpose, legal duties, disputes and security. Our operational baseline—subject to a documented reason to shorten or extend it—is:
- unconverted enquiries and prospect records: up to 24 months after the last meaningful interaction;
- marketing consent and preference evidence: while marketing continues and normally up to 6 years afterward to demonstrate compliance;
- suppression records: a minimal identifier for as long as needed to honour the objection;
- customer and transaction records: normally 6 years after the relevant relationship or transaction, subject to tax/legal needs;
- routine analytics: normally up to 26 months, preferably aggregated sooner;
- security logs: normally 12 months unless an incident requires longer preservation;
- API access tokens: until revoked, expired or no longer required; revoked promptly when an integration ends.
Backups roll off according to controlled schedules. Data may be anonymised so it no longer identifies anyone, in which case it may be kept for analytical purposes.
12. Security
We use risk-appropriate controls including least-privilege access, multi-factor authentication where available, encryption in transit, restricted secrets, logging, backups, software updates, vendor review and incident procedures. No internet system is perfectly secure, but we continually review safeguards. If a personal-data breach occurs, we will investigate, mitigate, document and notify regulators or affected people where legally required.
13. Your rights
Depending on applicable law and circumstances, you may have rights to be informed; access a copy; correct inaccuracies; request deletion; restrict processing; object (including an absolute right to object to direct marketing); receive certain data in a portable format; withdraw consent without affecting earlier lawful processing; and request safeguards relating to qualifying automated decisions. You may also complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority. We would welcome the opportunity to address your concern first.
14. Children
Wilderloom Earth content may be enjoyed by families, but our general websites, databases and marketing funnels are not designed to collect personal information directly from children. We do not knowingly profile children for advertising or send them direct marketing. Any future child-directed feature will undergo a specific age-appropriate design and data-protection assessment, use high-privacy defaults and obtain verifiable parental authorisation where required.
15. Pinterest integration
Our Pinterest application supports internal, AI-assisted content operations for Wilderloom Earth. It is intended to create or schedule operator-approved Pins from media we control and to read our authenticated business account's own Pins, Boards and performance data for reporting and optimisation. It is not intended to read another user's private data, collect Pinterest login credentials, use session cookies as authentication, or publish without operator approval. Access uses Pinterest's authorised OAuth process and granted scopes. Tokens are confidential, access-restricted and revoked when no longer needed.
16. Changes and accountability
We review this notice and the processing behind it when services, vendors, laws or purposes materially change. A new purpose is assessed for compatibility and lawful basis before use. Material changes will be highlighted and, where required, communicated directly or supported by fresh consent. The effective date above shows the current version.
We maintain appropriate records of processing, consent, vendors, retention, incidents and relevant assessments. Before launching higher-risk processing—such as large-scale profiling, sensitive data use, systematic monitoring or child-directed services—we will assess whether a data-protection impact assessment and specialist legal review are required.
17. Contact
Email: admin@kempenterprise.com
Subject: Wilderloom Privacy
Controller: Manybrook Ventures LLC
This notice describes our operating commitments and is not a substitute for individual legal advice. Applicable rights and obligations may vary by location and context.