Legal
Privacy Policy
A plain description of what this website collects, what stays on your device, which third parties are involved, and how you stay in control.
Last updated 27 August 2026
This document describes the website as it is currently implemented. It is technically accurate to the build and is provided for owner and legal review — it is not a statement of certification or compliance under any specific privacy law.
01
Scope of this policy
This policy describes how information is handled on the Nolmark website at nolmark.co, operated by Nolmark Creative & Digital Marketing Agency (“Nolmark”, “we”).
It covers this marketing and knowledge website only. It does not cover ARRIYIA — Personal Intelligence Platform, built on NoVA, whose application is hosted separately at arriyia.nolmark.co. The ARRIYIA application is a distinct product environment with its own account system; any terms and privacy documentation governing it are provided within that application. Nothing in this policy should be read as describing data practices inside ARRIYIA.
02
Information you submit
The website only receives information you actively provide. There is no account system, no login and no user profile on nolmark.co.
- Enquiry and contact details. The “Start Your Project” enquiry flow and the contact page collect the details you type — such as name, company, industry, services of interest, goals, timeline and budget indication, and the email or phone number you choose to share.
- Marketing audit and growth path inputs. The free marketing audit and “Find My Growth Path” flows collect the business context you enter so a response or recommendation can be prepared.
- Delivery method. These forms are designed to hand your completed brief to a channel you choose — email to hello@nolmark.co or WhatsApp to +255 745 900 440. When you send via WhatsApp, the message is transmitted through WhatsApp’s own service.
Please do not submit sensitive personal information, credentials, or confidential third-party data through these forms.
03
Business Growth Toolkit information
The Business Growth Toolkit (assessments, budget planner, ROI calculator, competitor snapshot, proposal builder and related tools) runs in your browser. The business figures and answers you enter are used to produce your on-screen result.
- Tool inputs and generated results are held in your browser for the duration of your use so results, categories and progress persist as you navigate.
- Interaction events (for example: a tool being started, a step completed, or a result generated) are recorded as product-analytics events together with a randomly generated identifier stored in your browser. These events describe how tools are used.
- Nothing in the Toolkit requires you to identify yourself. If you choose to send a result or brief onward, it is delivered through the channel you select.
04
Intelligence Assistant information and journey context
The Nolmark Intelligence Assistant takes the business goal or challenge you describe and returns a diagnosis, recommended resources, priorities, a roadmap and an action plan.
- Your prompt. The goal text you submit is sent to our server-side function, which calls a third-party AI model gateway (see third-party services) to help classify and interpret it. Please avoid including personal or confidential details in your prompt.
- Journey memory. Your assistant run, selected recommendations, roadmap and action progress are stored in your browser’s session storage so you can resume within the same browsing session. Closing the browser tab or session clears it.
- Journey context on enquiry. If you continue from the assistant into an enquiry or the contact form, a short summary of your journey context may be attached to the message you send, so the response can be relevant. You can see and edit the message before sending it.
- Funnel milestones. Non-identifying milestones (for example: assistant opened, brief generated, roadmap viewed) are recorded as analytics events to understand which parts of the journey are useful.
05
Technical information
As with any website, requests to nolmark.co involve standard technical information necessary to serve pages — such as your IP address, browser and device characteristics, the page requested and the referring page. This is handled by our hosting and content delivery infrastructure as part of serving and securing the site.
We also record lightweight, non-identifying interaction signals in your browser (for example which sections you have viewed) to adapt on-page recommendations and calls to action. These signals stay in your browser session unless an analytics event is permitted.
06
Browser storage (localStorage and sessionStorage)
Most of what nolmark.co stores is not a cookie. It is browser storage held on your own device: localStorage (persists until cleared) and sessionStorage (cleared when the browsing session ends).
The Cookie Policy lists every storage key we set, what it holds and how long it lasts. You can clear all of it at any time from your browser’s site-data settings.
07
Analytics, Google Tag Manager and consent
The site loads Google Tag Manager (container GTM-TQ8CBPKB) as a tag-management layer. Google Tag Manager itself is a container; it does not perform analytics on its own.
- Google Consent Mode v2 defaults are set to denied before the container loads. Analytics storage, ad storage, ad user data, ad personalisation and personalisation storage all start denied.
- Only security storage and functionality storage — the technologies needed for the site to work — are treated as granted.
- Your choice is applied as a Consent Mode update and recorded in a versioned consent record in your browser. If our consent policy version changes, we ask again.
- Consent choices are also pushed to the site's data layer so any tag configured in the container respects them.
- At the date of this policy no Google Analytics 4, Google Ads, Meta or other marketing tags are installed in the page source; the consent framework is in place so that any such tag can only fire with your permission.
You can change or withdraw your choice at any time using , also available in the site footer.
08
Third-party services
These are the third-party services present in the website implementation:
- Google Tag Manager (Google) — tag container, loaded from googletagmanager.com.
- Google Fonts (Google) — the IBM Plex Sans, IBM Plex Mono and Newsreader typefaces are loaded from Google’s font hosts.
- AI model gateway — the Intelligence Assistant calls an AI gateway from our server to interpret your submitted goal. Your prompt text is processed by that service to return a response.
- WhatsApp (Meta) — used only when you choose to send an enquiry or start a chat via WhatsApp.
- Email — enquiries sent by email are handled by our email provider and reach hello@nolmark.co.
- Social platforms — outbound links to LinkedIn (linkedin.com/company/nolmark), Instagram (@nolmarkcdma) and X (@nolmarkcdma). Visiting them is governed by their own policies.
- Hosting and delivery infrastructure — the platform that serves this website and runs its server functions.
We do not sell information, and we do not operate an advertising data exchange on this website.
09
Why we process information
- To respond to your enquiry, prepare a proposal, or deliver the audit or recommendation you requested.
- To generate the Toolkit or Intelligence output you asked for.
- To keep the website functional, secure and available.
- To understand — in aggregate and where you have allowed analytics — which content and tools are useful, so we can improve them.
- To adapt on-page recommendations and calls to action to the journey you are on.
11
Retention
We do not currently publish a fixed retention schedule for this website. As a general principle:
- Enquiry and audit correspondence is kept for as long as needed to respond, to progress or maintain the client relationship, and to keep normal business records.
- Toolkit and Intelligence data held in browser storage stays on your device until your session ends or you clear site data — we do not need to delete it for you.
- Analytics events are retained for as long as they remain useful for product and content improvement.
A formal, documented retention schedule is pending owner and legal confirmation.
12
Security
The site is served over HTTPS. Server-side keys and credentials are held as server environment secrets and are never exposed to the browser. Optional tracking technologies stay denied until you allow them.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security of information sent over the internet or through third-party messaging channels.
13
Your choices and rights
Depending on where you are, applicable privacy law may give you rights to:
- ask what information we hold about you and request a copy;
- ask us to correct information that is inaccurate;
- ask us to delete information we no longer need;
- object to or restrict certain processing; and
- withdraw consent for optional technologies at any time.
To make a request, email hello@nolmark.co. We will respond within a reasonable period. Because there are no accounts on this website, we may need additional information to locate records relating to you.
14
Withdrawing consent
Use to change your analytics and marketing choices. Changes apply immediately as a Consent Mode update. To remove locally stored data, clear site data for nolmark.co in your browser.
15
International visitors
Nolmark operates from Tanzania and serves clients across East Africa. The third-party services listed above are operated internationally, so information handled through them may be processed outside your country. If you access this website from elsewhere, you do so on that basis.
16
Updates to this policy
We may update this policy as the website and its technologies change. The “last updated” date at the top reflects the current version. Material changes to consent categories are handled by a consent version bump, which asks you to choose again.
17
Contact
Privacy questions, requests and corrections: hello@nolmark.co. General enquiries can also reach us on WhatsApp at +255 745 900 440.
Company registration details, a registered office address and a named data-protection contact are not published here and require owner confirmation before being added.
Related documents
Questions about this document? hello@nolmark.co
