Privacy policy
Version 1.0 · last updated 6 August 2026
The two different roles we play
1. Our own contacts: we are the controller. Website visitors, prospects we contact, and our clients. This policy governs that, and you deal with us.
2. Our clients' customers: we are a processor. When a business hires us, we answer calls and messages from their customers on their behalf. For that data the business is the controller and we act only on their written instructions. If you're a customer of one of our clients and want to exercise your rights, contact that business, though if you contact us we'll route it to them promptly and help.
What we collect, why, and on what basis
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Business contact details of prospects (name, business email/phone, company, trade, town) | To offer a relevant business service | Legitimate interests (see below) | 12 months if no response |
| Free-audit form entries (name, phone, business type) | To prepare and deliver the audit you asked for | Steps taken at your request prior to a contract | 24 months |
| Client account & billing data | To provide and bill the service | Contract; legal obligation for tax records | 6 years (tax) |
| Website analytics, if enabled | To understand what's useful | Legitimate interests (privacy-first, cookie-less) | Aggregate only |
| Suppression records (opt-outs) | To make sure we never contact you again | Legal obligation / legitimate interest in honouring your objection | Permanently. That's the point |
Our legitimate interests, stated plainly: offering a relevant service to a business, at a business address, about its business. We've weighed that against your interests and we think a single, honest, easy-to-stop approach is proportionate. You can ask for our assessment, and you can object at any time.
Where prospect data comes from
Public sources: the UK Companies House register, public business websites, and verified commercial trade directories. We record the source per contact and will tell you yours on request.
Who we share it with
We don't sell data. Ever. We use service providers who process it for us: Maildoso/SMTP for email delivery, Twilio/Vapi for telephony infrastructure, Google Workspace for business communications, and Cloudflare for edge security and hosting. Each is contractually bound to process only on our instructions. Current list on request.
International transfers
Some providers are outside the UK/EEA. Where that happens we rely on European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum and assess each transfer. Details on request.
Your rights
Access, rectification, erasure, restriction, portability, objection (including an absolute right to object to direct marketing), and withdrawal of consent. Email [email protected]; we respond within one month, free of charge.
Complaints
AEPD (Spain) · ICO (UK) · Data Protection Commission (Ireland). You can go to them directly, but we'd rather you told us first so we can fix it.
Security
TLS 1.3 encryption in transit, AES-256 encryption at rest, strict least-privilege role-based access controls, and automated suppression enforcement.
Changes
We version this page and keep prior versions. Material changes get flagged to clients directly.