Privacy Policy
SlingshotEdge Ltd ("SlingshotEdge", "we", "us" or "our") runs proves.io, the marketing website for the PROVES buyer-confidence sales methodology. SlingshotEdge will respect any personal data you share with us, and will keep it safe.
This notice explains what personal data we collect through this website, which in practice means the details you send us through our "Contact Us" form, how we use it, who we share it with, and the rights you have under the UK GDPR. SlingshotEdge is the data controller responsible for that personal data.
Who we are
SlingshotEdge is the business behind PROVES and is responsible for how your personal data is handled under this notice. Our details are:
- Legal name: SlingshotEdge Ltd
- Website / trading name: PROVES (proves.io)
- Registered and contact address: 23 Mitchell St, Leith, Edinburgh EH6 7BD, United Kingdom
- Email: info@slingshotedge.com
- Phone: +44 7584 632777
Data-protection contact and DPO
If you have any questions about this notice, or about how we look after your personal data, please email info@slingshotedge.com and mark your message for the attention of our Data Protection Lead. We are not required to appoint a Data Protection Officer (DPO) under Article 37 of the UK GDPR and have not appointed one; your query will be handled by our Data Protection Lead and the SlingshotEdge team responsible for data protection. As an organisation established in the UK, we are not required to appoint a UK representative. Because we do not offer goods or services to, or monitor the behaviour of, individuals located in the EU, we do not currently appoint an EU representative under Article 27 of the EU GDPR; we keep this position under review and will appoint one if that changes.
What we collect
When you fill in our Contact Us form, we collect the information you choose to give us. That typically includes:
- your name;
- your email address;
- your phone number;
- your company or organisation name; and
- the content of your message and anything else you include in it.
The form fields are the only personal data this site is designed to collect. Please only share what is needed to answer your enquiry. In particular, please don't include sensitive ("special category") information, such as details about your health, race, religion, political opinions or similar, in the free-text message box. We do not ask for special category data. If you voluntarily include it, we process it only where necessary to respond to you, on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR (which you give by choosing to send it to us), or where another Article 9 condition applies. You can withdraw that consent at any time, and we will otherwise delete such information. Please leave it out where you can.
How we use it
We use the information from your Contact Us submission to:
- respond to your enquiry and provide the information or assistance you asked for;
- follow up with you about your enquiry and any related conversation;
- where relevant, discuss how PROVES could help you or your organisation (business development);
- keep a record of our correspondence so we can manage the relationship and refer back to it if you contact us again; and
- protect our website and our business, for example against misuse of the form.
Our lawful bases
Under Article 6 of the UK GDPR we must have a lawful basis for using your personal data. Depending on the situation we rely on:
- Legitimate interests: responding to enquiries you send us, following up, keeping a sensible record of our dealings, and carrying out ordinary business development are all in our legitimate interests as a business. We have balanced those interests against your rights and freedoms, and when you contact us you would reasonably expect us to reply and to hold a record of the exchange.
- Legitimate interests (security): keeping our website, systems and business secure and preventing, detecting and investigating misuse of the Contact Us form is in our legitimate interest in the security and integrity of our services.
- Consent: where we ask for your consent (for example, to send you marketing you have opted in to, or where you include special category data in your message), we rely on that consent, and you can withdraw it at any time.
Special category data: we do not ask for it, but if you choose to include it in your message we rely on your explicit consent under Article 9(2)(a) of the UK GDPR to process it as part of responding to you, see "What we collect" above.
Where we rely on legitimate interests, you have the right to object, see "Your rights" below.
Do you have to provide it?
Providing your details through the Contact Us form is completely voluntary, it is not a statutory or contractual requirement, and you are not obliged to give us anything to enter into a contract. However, if you don't give us at least a way to reach you and some idea of what you need, we won't be able to respond to your enquiry.
Who we share it with
Our CRM and contact-form provider
Our Contact Us form is embedded from GoHighLevel, a platform operated by HighLevel, Inc. and its affiliate LeadConnector LLC (the embedded form is served from LeadConnector infrastructure at leadconnectorhq.com). GoHighLevel is our customer-relationship management (CRM) system, and when you submit the form your details are captured and stored in GoHighLevel so that we can receive, respond to and manage your enquiry.
HighLevel, Inc. (together with its LeadConnector affiliate) acts as our data processor for this information, it processes contact-form data only on our instructions and on our behalf, under HighLevel's Data Processing Agreement, which governs its processing of data on our behalf. HighLevel maintains its own DPA, published sub-processor list and compliance measures (including recognised security certifications), which it makes available at gohighlevel.com/data-processing-agreement and gohighlevel.com/sub-processors. To provide the platform, HighLevel in turn uses its own vetted sub-processors, such as cloud hosting providers.
Other recipients
We may also share your data with our own trusted service providers who help us run our website and business (for example IT and hosting providers), and we may disclose data where we are required to do so by law, or otherwise only with your consent. We do not sell your personal data.
International data transfers
GoHighLevel's core infrastructure is located in the United States, so when your Contact Us submission is stored and processed in GoHighLevel, your personal data is transferred outside the UK to the US, where GoHighLevel's core infrastructure is located, and it may also be accessed or processed by HighLevel and its sub-processors in other countries.
Wherever personal data leaves the UK, we make sure appropriate safeguards are in place so that it remains protected to UK standards. For these transfers, and for any onward transfers to HighLevel's sub-processors, those safeguards include the EU Standard Contractual Clauses as supplemented by the UK Addendum, which are incorporated into HighLevel's Data Processing Agreement, and, where HighLevel maintains it, HighLevel's self-certification under the UK Extension to the EU-U.S. Data Privacy Framework, a self-certification that is renewed annually and whose current status can be checked on the Data Privacy Framework list at dataprivacyframework.gov. You can ask us for more information about these safeguards, or for a copy of the relevant documents, by emailing info@slingshotedge.com; the underlying terms are also available on GoHighLevel's DPA page linked above.
How long we keep it
We keep your Contact Us information only for as long as we genuinely need it. In practice that means:
- for as long as it takes to deal with your enquiry and any follow-up; and
- for a reasonable period afterwards, so we have a record of our dealings and can pick up the conversation again if you come back to us.
As a general rule, we will delete or anonymise contact-form enquiry data within about 24 months of our last meaningful contact with you, unless we still have a genuine reason to keep it (for example an ongoing conversation, or a legal, tax or accounting obligation) or you ask us to delete it sooner. You can ask us to erase your data at any time, see "Your rights".
How we keep your data safe
Access to contact-form data is restricted to authorised SlingshotEdge staff who need it to respond to you. Within GoHighLevel, access is protected by account controls and credentials, and HighLevel applies its own technical and organisational security measures to the platform. We may disclose data if required by law, and otherwise only with your explicit consent.
Cookies and similar technologies
This section is our cookie notice. Cookies are small files that a website can place on your device. The same rules under the Privacy and Electronic Communications Regulations (PECR) also cover similar technologies, such as information stored in your browser's local storage, so we describe both here.
We keep this to a minimum. We do not use analytics, advertising, or social media tracking on proves.io. There is no Google Analytics, no advertising pixel, and no cross-site tracking of any kind on this website.
What this site stores on your device
- Your theme choice. If you switch the site between light and dark, that preference is saved in your own browser's local storage so the site looks the same next time. It is never sent to us and is not used to identify or track you. Under PECR this counts as strictly necessary to provide something you asked for, so it does not require your consent.
- The Contact Us form. Our form on the Contact page is embedded from GoHighLevel, and it may set its own cookies in order to work, for example to keep your session and to protect against spam and abuse. These are set only on the Contact page, and only because the form is the service you came to that page to use.
That is the complete list. We set no cookies of our own.
How to control it
Because we do not use analytics or advertising cookies, there is currently no consent banner on this site. You remain in full control through your browser: every major browser lets you block or delete cookies for a site, either generally or for proves.io specifically, and you can clear cookies and site data at any time. Blocking cookies on the Contact page may stop the form working, in which case you can always email or call us using the details below instead.
If that changes, we will ask first. If we ever add analytics, advertising, or any other non-essential cookies or tracking, we will put a consent banner in place and obtain your consent before any of them are set, in line with PECR. We would not rely on your browser settings alone, or on you simply continuing to browse, as consent, and you would be able to withdraw it as easily as you gave it. We will update this notice at the same time.
Third parties that serve parts of this site
Some files are delivered from other companies' networks, which means those companies necessarily receive your IP address and basic technical information in order to send the file:
- Google Fonts serves the typefaces used across the site. It does not set cookies.
- A content delivery network serves part of the styling on our home page. It does not set cookies.
- GoHighLevel serves the Contact Us form, as described above.
Direct marketing
We will only send you marketing messages (for example about PROVES) where you have agreed to receive them, or where we are otherwise permitted to under the direct-marketing rules. Every marketing message will give you a simple way to opt out, and you can tell us to stop at any time by emailing info@slingshotedge.com. Asking us to stop marketing won't affect us replying to any enquiry you have sent us.
Automated decision-making
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects on you. Our CRM (GoHighLevel) organises and stores your contact record so that we can manage your enquiry, but we do not use it to make automated decisions about you.
Children's data
proves.io and our Contact Us form are aimed at businesses and professionals, not children. We do not intend to collect personal data from anyone under 18, and if you are under 18 please don't use the form to send us your details. If we learn that we have collected a child's data without appropriate consent, we will delete it.
Your rights
Under the UK GDPR you have a number of rights over your personal data. You can ask us to:
- access the personal data we hold about you;
- rectify it if it is inaccurate or incomplete;
- erase it (the "right to be forgotten");
- restrict how we process it;
- port it, receive it, or have it sent to another provider, in a structured, commonly used format, where that right applies; and
- object to us processing it, including where we rely on legitimate interests.
Where our processing is based on your consent, you also have the right to withdraw that consent at any time, without affecting anything we did before you withdrew it.
To exercise any of these rights, just email us at info@slingshotedge.com. In normal circumstances there is no charge, and we'll respond within the time limits set by the UK GDPR (usually one month).
Complaints
We'd always like the chance to put things right, so please come to us first. You also have the right to complain to the UK's data-protection regulator, the Information Commissioner's Office (ICO), if you're unhappy with how we've handled your personal data. You can reach the ICO at:
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
- Helpline: 0303 123 1113
- Online: ico.org.uk/make-a-complaint
Contact us
If you have any questions about this notice, or want to exercise any of your rights, please get in touch:
- Email: info@slingshotedge.com
- Phone: +44 7584 632777
- Post: SlingshotEdge Ltd, 23 Mitchell St, Leith, Edinburgh EH6 7BD, United Kingdom
Changes to this notice
We may update this notice from time to time, for example if we change how the Contact Us form works or start using new tools. When we do, we'll post the updated version on this page, update the version number and change the "Last updated" date at the top. If the changes are significant, we'll take reasonable steps to bring them to your attention. This version (Version 1.1) is effective from 24 July 2026 and was last updated on 31 July 2026.