Skip to content

Privacy Policy

Last updated:

This Privacy Policy explains how [COMPANY NAME] (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you use our website or engage our bespoke web design and development services. We are fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller Identification

For the purposes of the UK GDPR and the Data Protection Act 2018, the Data Controller responsible for your personal information is:

2. Personal Data We Collect

When you contact us, request a project quote, use our interactive cost estimator, or enter into a commercial development agreement, we collect the following personal and commercial information:

  • Identity & Contact Details: Full name, business email address, direct contact telephone number, and company name.
  • Project Specifications: Current website URL, commercial scope, technical requirements, desired launch milestones, and estimated budget ranges.
  • Technical Telemetry: IP address, browser type and version, operating system, and approximate geographical location (anonymised at the edge via Google Consent Mode v2).
  • Billing & Contract Records: Invoicing address, VAT details (where applicable), bank transaction references, and payment histories. We do not store raw debit or credit card credentials.

3. Lawful Basis for Processing

Under Article 6 of the UK GDPR, we only process your personal information when a clear lawful basis exists:

  • Performance of a Contract (Art. 6(1)(b)): Processing necessary to prepare tailored quotations, execute commercial scopes of work, deliver web software, and provide ongoing technical support.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary to protect our infrastructure from malicious automated spam (e.g. Cloudflare Turnstile), troubleshoot server errors, and manage our business operations efficiently.
  • Consent (Art. 6(1)(a)): Processing based on your explicit, affirmative opt-in consent (e.g. subscribing to technical marketing updates or enabling non-essential analytics cookies).
  • Legal Obligation (Art. 6(1)(c)): Processing necessary to maintain commercial tax, accounting, and company audit records in accordance with UK statutory law.

4. How We Use Your Data

We never sell, rent, or lease your personal information to third-party data brokers or marketing agencies. We use your data strictly for:

  • Evaluating technical feasibility and providing accurate, fixed-price project estimates.
  • Communicating directly regarding milestones, staging reviews, and deployment scheduling.
  • Issuing statutory tax invoices and processing bank payments.
  • Fulfilling our post-launch warranty and ongoing care plan commitments.

5. Data Retention Periods

We retain personal data only for as long as strictly necessary to fulfill the purposes for which it was gathered:

  • General Enquiries & Quotations: Contact form submissions and unaccepted project quotes are retained for 24 months from the date of last communication, after which they are securely deleted.
  • Active Client & Project Records: Source code repositories, client correspondence, contracts, and deliverable documentation are retained for the duration of the commercial relationship plus 6 years following project completion to satisfy UK HMRC tax and statutory limitation requirements.
  • Analytics & Web Logs: Anonymised server access logs are retained for 90 days for security triage and bot analysis.

6. Third-Party Data Processors

To operate our studio infrastructure efficiently, we engage vetted sub-processors who adhere to strict data security standards:

  • Cloud Hosting & Edge Delivery: Vercel Inc. (hosting and edge routing with standard contractual clauses).
  • Spam Prevention & Security: Cloudflare Inc. (Turnstile bot verification).
  • Analytics (Optional): Google Analytics 4 (only activated if explicit user consent is granted via our consent banner).
  • Banking & Invoicing: Registered UK clearing banks and certified accounting software for statutory transaction processing.

7. International Data Transfers

Where personal information is transferred outside the United Kingdom or the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as UK International Data Transfer Agreements (IDTAs), European Commission Standard Contractual Clauses (SCCs), or adequacy regulations recognised under UK law.

8. Your UK GDPR Statutory Rights

Under the UK GDPR, you hold specific statutory rights regarding your personal information:

  • Right of Access: You may request a copy of the personal data we hold about you (Subject Access Request).
  • Right to Rectification: You may request the correction of inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): You may request deletion of your personal data where retention is no longer legally necessary.
  • Right to Restrict Processing: You may ask us to suspend processing your data in certain scenarios.
  • Right to Data Portability: You may request your data in a structured, machine-readable format.
  • Right to Object: You may object to data processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please email us directly at lancashirewebdesigners@gmail.com. We respond to all verified requests within one calendar month at zero charge.

9. Right to Lodge a Complaint (ICO)

If you have any concerns regarding our handling of your personal data, we request that you contact us first so we can resolve the matter swiftly. However, you retain the statutory right to lodge a complaint with the UK supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk

Call Us WhatsApp Get a Quote