Privacy policy

Version 1.0 · last updated 6 August 2026

The two different roles we play

1. Our own contacts: we are the controller. Website visitors, prospects we contact, and our clients. This policy governs that, and you deal with us.

2. Our clients' customers: we are a processor. When a business hires us, we answer calls and messages from their customers on their behalf. For that data the business is the controller and we act only on their written instructions. If you're a customer of one of our clients and want to exercise your rights, contact that business, though if you contact us we'll route it to them promptly and help.

What we collect, why, and on what basis

WhatWhyLawful basisKept for
Business contact details of prospects (name, business email/phone, company, trade, town)To offer a relevant business serviceLegitimate interests (see below)12 months if no response
Free-audit form entries (name, phone, business type)To prepare and deliver the audit you asked forSteps taken at your request prior to a contract24 months
Client account & billing dataTo provide and bill the serviceContract; legal obligation for tax records6 years (tax)
Website analytics, if enabledTo understand what's usefulLegitimate interests (privacy-first, cookie-less)Aggregate only
Suppression records (opt-outs)To make sure we never contact you againLegal obligation / legitimate interest in honouring your objectionPermanently. That's the point

Our legitimate interests, stated plainly: offering a relevant service to a business, at a business address, about its business. We've weighed that against your interests and we think a single, honest, easy-to-stop approach is proportionate. You can ask for our assessment, and you can object at any time.

Where prospect data comes from

Public sources: the UK Companies House register, public business websites, and verified commercial trade directories. We record the source per contact and will tell you yours on request.

Who we share it with

We don't sell data. Ever. We use service providers who process it for us: Maildoso/SMTP for email delivery, Twilio/Vapi for telephony infrastructure, Google Workspace for business communications, and Cloudflare for edge security and hosting. Each is contractually bound to process only on our instructions. Current list on request.

International transfers

Some providers are outside the UK/EEA. Where that happens we rely on European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum and assess each transfer. Details on request.

Your rights

Access, rectification, erasure, restriction, portability, objection (including an absolute right to object to direct marketing), and withdrawal of consent. Email [email protected]; we respond within one month, free of charge.

Complaints

AEPD (Spain) · ICO (UK) · Data Protection Commission (Ireland). You can go to them directly, but we'd rather you told us first so we can fix it.

Security

TLS 1.3 encryption in transit, AES-256 encryption at rest, strict least-privilege role-based access controls, and automated suppression enforcement.

Changes

We version this page and keep prior versions. Material changes get flagged to clients directly.