1.1 ClickBright Media LTD ("ClickBright", "we", "us", "our") is committed to protecting and respecting the privacy of individuals whose personal data we process.
1.2 This Privacy Policy explains how we collect, use, disclose, retain and protect personal data obtained through our website at clickbright.co.uk (the "Website"), through our enquiry and qualification forms, through our booking and calendar systems, and in the course of providing and marketing our services.
1.3 This Privacy Policy is issued on behalf of ClickBright Media LTD acting as data controller. Where we process personal data on behalf of our clients in the course of delivering our services, we act as a data processor and our processing is governed by the data processing terms contained in the relevant client service agreement rather than by this Privacy Policy.
1.4 Please read this Privacy Policy carefully, together with our Website Terms & Conditions and our Cookie Notice, so that you are fully aware of how and why we are using your personal data.
2. WHO WE ARE
2.1 Data controller: ClickBright Media LTD, a private company limited by shares incorporated in England and Wales (company number [•]).
2.2 Registered office and correspondence address:
Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE, United Kingdom.
2.5 Nature of our business: we are a specialist restaurant and hospitality growth agency providing paid media management (Meta Ads and Google Ads), Google Business Profile optimisation, conversion tracking and analytics implementation, landing page development, lead generation and strategy consulting.
2.6 We are registered with the Information Commissioner's Office under registration reference [•].
2.7 We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the UK GDPR. Responsibility for data protection compliance rests with our director, who may be contacted using the details at clause 24.
3. DEFINITIONS AND INTERPRETATION
3.1 In this Privacy Policy, the following expressions have the following meanings:
Term
Meaning
Data Protection Legislation
the UK GDPR, the Data Protection Act 2018, PECR, and all other legislation and regulatory requirements in force from time to time in the United Kingdom relating to the processing of personal data and privacy, together with any guidance or codes of practice issued by the ICO
ICO
the Information Commissioner's Office, or any successor supervisory authority
PECR
the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended)
Personal Data
has the meaning given to it in Article 4(1) of the UK GDPR
Processing
has the meaning given to it in Article 4(2) of the UK GDPR, and "process" and "processed" are construed accordingly
Services
the advertising, tracking, analytics, lead generation, consulting and related services supplied by ClickBright
Special Category Data
personal data of the categories set out in Article 9(1) of the UK GDPR
UK GDPR
Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018
You
the individual whose personal data we process, including visitors to the Website, prospective clients, clients, supplier contacts and other business contacts
3.2 In this Privacy Policy:
(a) clause headings are for convenience only and do not affect interpretation;
(b) a reference to a statute or statutory provision is a reference to it as amended, extended or re-enacted from time to time, and includes all subordinate legislation made under it;
(c) words in the singular include the plural and vice versa;
(d) any words following the terms "including", "include", "in particular", "for example" or any similar expression are illustrative and do not limit the sense of the words preceding those terms; and
(e) terms which are defined in the UK GDPR but not defined in this Privacy Policy have the meaning given to them in the UK GDPR.
4. SCOPE OF THIS PRIVACY POLICY
4.1 This Privacy Policy applies to personal data we process in our capacity as data controller in relation to:
(a) visitors to and users of the Website;
(b) individuals who submit an enquiry, qualification form, proposal request or contact request;
(c) individuals who book a strategy call or other appointment with us;
(d) contacts at our clients and prospective clients;
(e) contacts at our suppliers and partners; and
(f) recipients of our marketing communications.
4.2 This Privacy Policy does not apply to:
(a) personal data processed by us as a data processor on behalf of a client, for example customer, booking or enquiry data held within a client's own advertising accounts, CRM or booking platform. In those circumstances the client is the data controller and its own privacy notice will apply; or
(b) third party websites, platforms or applications to which the Website may link. We are not responsible for the privacy practices of third parties and encourage you to read their privacy notices.
5. INFORMATION WE COLLECT
5.1 Information you provide to us directly
We collect the following categories of personal data when you complete a form, book a call, email, telephone or message us, or otherwise interact with us:
(a) Identity Data — first name, last name, job title or role, and the name of the business you represent;
(b) Contact Data — email address, telephone number, mobile number, business address and, where provided, social media handles;
(c) Business and Qualification Data — venue type, number of sites, average spend per head, current monthly advertising budget, current booking or ticketing platform, current agency arrangements, growth objectives, and other information provided in response to our qualification questions;
(d) Appointment Data — the date, time and time zone of any strategy call booked, the meeting platform used, and any notes, agenda items or attachments you supply;
(e) Correspondence Data — the content of emails, telephone call notes, SMS messages, WhatsApp messages and messages sent through our CRM, including any attachments;
(f) Contractual and Financial Data — where you become a client, the details necessary to administer the engagement, including billing contact details, bank account details supplied to our payment provider for the purposes of Direct Debit collection, invoice records and payment history. We do not store full bank account details on our own systems; these are held by GoCardless as described at clause 9.4; and
(g) Marketing and Communications Data — your preferences in receiving marketing from us, your consent records, and your engagement with our marketing communications.
5.2 Information collected automatically
When you visit the Website, we and our service providers may automatically collect:
(a) Technical Data — internet protocol (IP) address (which may be truncated or otherwise pseudonymised where the relevant tool supports it), browser type and version, operating system and platform, device type, screen resolution, language settings and time zone setting;
(b) Usage Data — pages viewed, the URL of the page from which you arrived and to which you exit, time and date of visit, time spent on pages, scroll depth, clicks, form interactions, downloads and errors encountered;
(c) Referral and Campaign Data — referring website, search terms where made available by the search engine, and campaign parameters such as UTM tags, Google Click Identifier (GCLID) and Meta Click Identifier (fbclid); and
(d) Identifier Data — cookie identifiers, local storage identifiers, first-party advertising identifiers such as the _fbp browser identifier, and session identifiers.
We collect this information using cookies, pixels, tags, software development kits, local storage and server-side collection methods, as described at clauses 6, 7 and 8. Where the placing or reading of such technologies requires your consent under PECR, we will not deploy them until you have given that consent.
5.3 Information we receive from third parties
We may receive personal data about you from:
(a) advertising and analytics platforms, in aggregated or pseudonymised form, in relation to campaign performance;
(b) our CRM and communication platforms, in relation to message delivery and engagement;
(c) publicly available sources, including the Website of the business you represent, Companies House, Google Business Profile, industry directories and professional networking platforms, where we are assessing whether our Services may be relevant to your business;
(d) referral partners, introducers and existing clients who recommend you to us; and
(e) our payment provider, in relation to the status of mandates and payments.
5.4 Special Category Data and criminal offence data
We do not seek to collect Special Category Data or personal data relating to criminal convictions and offences. Please do not supply such data to us. If you do so unsolicited, we will delete it promptly unless we are required to retain it by law.
6. COOKIES AND SIMILAR TECHNOLOGIES
6.1 A cookie is a small text file placed on your device when you visit a website. We also use related technologies, including tracking pixels, JavaScript tags, browser local storage and session storage (together, "Cookies and Similar Technologies").
6.2 Under regulation 6 of PECR, we may only store information on, or gain access to information stored on, your device where:
(a) the storage or access is strictly necessary for the provision of a service explicitly requested by you; or
(b) you have given your consent.
6.3 We use the following categories:
(a) Strictly necessary — required for the Website to function, to route traffic, to maintain security and to record your cookie preferences. These are deployed without consent in reliance on regulation 6(4) of PECR;
(b) Analytics and performance — used to understand how the Website is used and to improve it. Deployed only with your consent;
(c) Advertising and targeting — used to measure advertising performance, attribute conversions, build audiences and deliver relevant advertising. Deployed only with your consent; and
(d) Functional — used to remember your preferences and enhance functionality. Deployed only with your consent.
6.4 Consent management. On your first visit you will be presented with a consent banner allowing you to accept all, reject all (other than strictly necessary), or select categories individually. Rejecting non-essential categories is as straightforward as accepting them. Your choice is recorded, together with a timestamp and the version of the notice presented, and is retained as evidence of consent. You may withdraw or change your consent at any time via the cookie preferences link in the Website footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6.5 Local storage. Where applicable, we and our service providers use browser local storage and session storage to hold identifiers and preference values. Local storage is treated as equivalent to cookies for consent purposes and is deployed on the same basis as the corresponding cookie category.
6.6 Browser controls. Most browsers allow you to refuse or delete cookies and to clear local storage through their settings. Doing so may impair the functionality of the Website. Guidance on managing cookies is available at aboutcookies.org and allaboutcookies.org.
6.7 Full details of the individual cookies we use, their purpose, provider and duration are set out in our Cookie Notice, available on the Website.
7. ANALYTICS AND ADVERTISING TECHNOLOGIES
7.1 Google Tag Manager. We use Google Tag Manager as a tag management system. Google Tag Manager does not itself set cookies or collect personal data, but it controls the deployment of the tags described below, and does so in accordance with the consent choices you have made under clause 6.
7.2 Google Analytics. We use Google Analytics 4, provided by Google Ireland Limited, to understand how visitors use the Website. Google Analytics sets cookies which generate statistical information about Website use, including pages viewed, session duration, traffic sources and events completed. IP addresses are truncated or otherwise processed so as not to be stored in identifiable form. We use Google Analytics for measurement, validation and diagnostic purposes. Google Analytics is deployed only where you have given consent to analytics cookies. Google Consent Mode is implemented so that, where consent is refused, no analytics or advertising identifiers are set and only aggregated, cookieless signals are transmitted.
7.3 Google Ads. We use Google Ads conversion tracking and remarketing to measure the effectiveness of our advertising and, where you have consented, to deliver advertising to you on Google properties and partner sites. This may involve the collection of a Google Click Identifier (GCLID) and the setting of advertising cookies. Enhanced conversions may be used, whereby a hashed representation of an email address or telephone number submitted in a form is transmitted to Google to improve conversion measurement accuracy. Hashing is applied in the browser or on our server before transmission using the SHA-256 algorithm, and we do not transmit unhashed contact details to Google for this purpose.
7.4 Meta Pixel. We use the Meta Pixel, provided by Meta Platforms Ireland Limited, on the Website. Where you have consented to advertising cookies, the Meta Pixel records page views and defined events such as form submissions and call bookings, and sets first-party cookies including _fbp. This enables us to measure advertising performance, attribute conversions and build audiences.
7.5 Meta Conversions API. We operate the Meta Conversions API, which transmits event data from our server to Meta rather than from your browser. Event data may include the event name, timestamp, page URL, and hashed customer information parameters such as email address, telephone number, first name, last name, city, postcode and country. All customer information parameters are hashed using the SHA-256 algorithm before transmission. Events sent through the Meta Conversions API are deduplicated against corresponding browser events using a shared event identifier so that a single action is not counted twice. Conversions API events are transmitted only where you have consented to advertising technologies.
7.6 Joint controllership with Meta. In respect of the collection and transmission of event data through the Meta Pixel and the Meta Conversions API, and the subsequent use of that data by Meta for the creation of aggregated reporting and analytics, ClickBright and Meta Platforms Ireland Limited act as joint controllers pursuant to Article 26 of the UK GDPR. The essence of the arrangement between us is set out in the Meta Controller Addendum. ClickBright is responsible for providing you with the information set out in Articles 13 and 14 of the UK GDPR and for obtaining any consent required. Meta is responsible for enabling the exercise of your rights in respect of its subsequent processing. You may exercise your rights against either party.
7.7 Server-side tracking. We operate a server-side tagging environment hosted on a subdomain of our own domain. Event data is collected in your browser, transmitted to our server-side container, and then forwarded to the relevant advertising and analytics platforms. Server-side tracking is used to improve data accuracy and resilience, to apply hashing and data minimisation before onward transmission, and to reduce the volume of data sent directly from your browser to third parties. Server-side tracking does not extend the scope of the data we collect beyond the categories described in this Privacy Policy, does not operate where you have declined the relevant consent category, and does not circumvent your consent choices or your browser's privacy settings.
7.8 Data minimisation in advertising. Where technically possible we transmit only the parameters necessary to achieve the measurement purpose, we apply hashing to all direct identifiers before transmission to advertising platforms, and we do not transmit Special Category Data or sensitive contextual parameters.
7.9 Further information about how these providers process personal data is available in their own privacy notices, which we encourage you to review.
8. GOHIGHLEVEL, CRM, CALENDARS AND BOOKINGS
8.1 We use GoHighLevel, provided by HighLevel Inc., as our customer relationship management platform, marketing automation platform and appointment scheduling system. GoHighLevel is engaged by us as a data processor under a written contract satisfying Article 28 of the UK GDPR.
8.2 Personal data held within our CRM includes your Identity Data, Contact Data, Business and Qualification Data, Appointment Data, Correspondence Data and Marketing and Communications Data, together with a record of your interactions with us such as form submissions, calls, messages, pipeline stage, notes made by our team and consent records.
8.3 Forms. Enquiry, contact, qualification and proposal request forms hosted on or embedded within the Website submit data to our CRM. Form submissions may also generate a conversion event which is transmitted to the advertising platforms described at clause 7, subject to your consent.
8.4 Calendars and appointment booking. Where you book a strategy call, we process the information necessary to schedule and hold that call, including your name, email address, telephone number, selected time slot, time zone and any information you provide in the booking form. A calendar invitation will be sent to you and to the relevant member of our team. Automated reminders may be sent by email and, where you have provided a mobile number and consented to do so, by SMS or WhatsApp. Such reminders are service messages relating to an appointment you have requested and are not marketing communications.
8.5 Pipeline and automation. Our CRM applies automated workflows, such as sending confirmations, reminders and follow-up messages, and moving records between pipeline stages. These workflows do not produce legal effects concerning you or similarly significantly affect you, and accordingly do not constitute automated decision-making within the meaning of Article 22 of the UK GDPR. We do not carry out automated decision-making producing legal or similarly significant effects, and we do not use your personal data for profiling other than the limited assessment of whether our Services are likely to be a suitable fit for your business.
9. COMMUNICATIONS AND OTHER SYSTEMS
9.1 Email. We use business email services to correspond with you. Emails and their attachments are retained in accordance with clause 14.
9.2 Telephone. We may contact you by telephone in relation to your enquiry or engagement. Where a call is recorded, we will notify you at the outset of the call and explain the purpose of the recording, and you may object to the recording.
9.3 WhatsApp and SMS. Where you provide a mobile number, we may communicate with you by SMS or WhatsApp. WhatsApp is operated by Meta Platforms Ireland Limited and is subject to its own privacy terms and end-to-end encryption. Message content and metadata relating to business messaging may be synchronised into our CRM for record-keeping purposes. You may ask us to cease contacting you by these channels at any time.
9.4 Payments. We use GoCardless Ltd, an authorised payment institution regulated by the Financial Conduct Authority, to collect payments by Direct Debit. Where you set up a mandate, your bank account details are provided directly to GoCardless and are processed by GoCardless as an independent data controller in accordance with its own privacy notice. We receive from GoCardless only the information necessary to administer your account, such as mandate status, payment status and the last four digits of the account number.
9.5 Accounting and administration. We use accounting software and professional advisers to prepare our statutory accounts, VAT returns and other filings. Personal data contained in invoices and payment records is processed for these purposes.
10. HOW WE USE PERSONAL DATA AND OUR LEGAL BASES
10.1 We will only use your personal data where the law allows us to do so. The table below sets out, for each purpose, the categories of personal data used and the legal basis relied upon under Article 6 of the UK GDPR.
#
Purpose
Categories of data
Legal basis
1
Responding to enquiries, contact requests and proposal requests
Identity, Contact, Business and Qualification, Correspondence
Legitimate interests (responding to a request made of us and pursuing business opportunities); or steps at your request prior to entering into a contract
2
Scheduling, confirming, reminding about and conducting strategy calls
Identity, Contact, Appointment
Steps at your request prior to entering into a contract; legitimate interests (efficient administration of appointments)
3
Qualifying whether our Services are a suitable fit for your business
Identity, Contact, Business and Qualification
Legitimate interests (ensuring we engage only where we can deliver value, and avoiding wasted time for both parties)
4
Preparing and issuing proposals and quotations
Identity, Contact, Business and Qualification
Steps at your request prior to entering into a contract
5
Performing our contract with you or the business you represent, including delivery of the Services, reporting and account management
Identity, Contact, Contractual and Financial, Correspondence
Performance of a contract; legitimate interests (where our contract is with the corporate entity rather than you personally)
6
Collecting payment, issuing invoices and recovering sums due
Identity, Contact, Contractual and Financial
Performance of a contract; legitimate interests (recovery of debts due to us)
7
Sending marketing communications by email or SMS
Identity, Contact, Marketing and Communications
Consent; or legitimate interests where the PECR "soft opt-in" at clause 13.3 applies
8
Sending marketing communications to corporate subscribers
Identity, Contact, Marketing and Communications
Legitimate interests (business development), PECR permitting such communications to corporate subscribers subject to an opt-out
9
Operating and securing the Website, and preventing fraud and abuse
Technical, Usage
Legitimate interests (network and information security, protection of our systems)
10
Website analytics and measurement
Technical, Usage, Identifier
Consent (for the placing and reading of cookies under PECR) and consent under Article 6(1)(a) for the associated processing
11
Advertising, conversion measurement, attribution and audience creation
Technical, Usage, Identifier, hashed Contact
Consent
12
Producing case studies, testimonials and performance reporting
Identity, Business, aggregated performance data
Consent (where you or your business is identifiable); legitimate interests (where fully anonymised)
13
Maintaining business records and complying with legal obligations, including tax, accounting and data protection record-keeping
Identity, Contact, Contractual and Financial, consent records
Compliance with a legal obligation
14
Establishing, exercising or defending legal claims, and handling complaints
All relevant categories
Legitimate interests (protection of our legal position); compliance with a legal obligation
15
Improving our Services, internal training and quality assurance
Correspondence, Usage, Business
Legitimate interests (improvement of our Services)
10.2 We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which permits us to do so.
11. CONSENT
11.1 Where we rely on consent, that consent will be freely given, specific, informed and unambiguous, and will be given by a clear affirmative action. We do not use pre-ticked boxes, silence or inactivity as a means of obtaining consent.
11.2 We maintain records of consent, including what you consented to, when, by what means, and the version of the information presented to you at the time.
11.3 You may withdraw your consent at any time, and it will be as easy to withdraw as it was to give. To withdraw consent to marketing, use the unsubscribe link in any email or reply "STOP" to any SMS. To withdraw consent to cookies and similar technologies, use the cookie preferences link in the Website footer. To withdraw any other consent, contact us using the details at clause 24.
11.4 Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent before its withdrawal.
12. LEGITIMATE INTERESTS
12.1 Where we rely on legitimate interests, we have carried out a balancing assessment to satisfy ourselves that our interests are not overridden by your interests, rights and freedoms. The legitimate interests we pursue are:
(a) responding to enquiries and requests made of us;
(b) identifying, developing and pursuing business opportunities in the hospitality sector;
(c) administering our client relationships and delivering our Services efficiently;
(d) recovering sums properly due to us;
(e) securing our Website, systems and data against unauthorised access and misuse;
(f) improving the quality of our Services; and
(g) protecting our legal position and defending claims.
12.2 In each case we have considered whether the processing is necessary to achieve the interest, whether a less intrusive means is available, the reasonable expectations of the individuals concerned, and the likely impact on those individuals. We do not rely on legitimate interests where the processing would be intrusive or unexpected, and we do not rely on legitimate interests for the deployment of non-essential cookies or for advertising technologies requiring consent.
12.3 You may request further information about any legitimate interests assessment we have conducted by contacting us using the details at clause 24. You have the right to object to processing based on legitimate interests, as set out at clause 18.5.
13. MARKETING COMMUNICATIONS
13.1 We may send you marketing communications by email, SMS, WhatsApp, telephone or post about our Services, case studies, insights and events which we consider will be of interest to your business.
13.2 Consent-based marketing. Where you are an individual subscriber (including a sole trader or an unincorporated partnership in Great Britain), we will send electronic marketing only where you have given your prior consent, or where the exception at clause 13.3 applies.
13.3 Soft opt-in. In accordance with regulation 22(3) of PECR, we may send electronic marketing about our own similar Services where we obtained your contact details in the course of a sale or negotiations for a sale of our Services to you, and you were given a simple means of refusing the use of your details for marketing at the time of collection and in every subsequent message.
13.4 Corporate subscribers. Electronic marketing to corporate subscribers, being limited companies, limited liability partnerships, Scottish partnerships and other corporate bodies, is permitted under PECR without prior consent. We will always identify ourselves, provide a valid address, and honour any objection immediately.
13.5 Live and automated calls. We do not make automated marketing calls. We will not make live marketing calls to any number registered with the Telephone Preference Service or the Corporate Telephone Preference Service unless we hold your specific consent.
13.6 Opting out. You may opt out of marketing at any time by clicking the unsubscribe link in any marketing email, replying "STOP" to any SMS, telling us during any call or exchange of messages, or contacting us using the details at clause 24. We will action your request without undue delay and in any event within 28 days.
13.7 Opting out of marketing will not prevent us from sending you service communications relating to an appointment, an enquiry you have made, or an existing contract between us.
13.8 We do not sell, rent or trade your personal data, and we do not share your contact details with third parties for their own direct marketing purposes.
14. DATA RETENTION
14.1 We will retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory or reporting requirements.
14.2 Our standard retention periods are:
Category
Retention period
Website enquiry and contact form submissions which do not progress
24 months from the date of last meaningful contact
Qualification data and proposals for prospects which do not convert
24 months from the date of last meaningful contact
Booking and appointment records for calls which do not convert
24 months from the date of the appointment
Marketing contact records and consent records
For the duration of the relationship plus 24 months from the date of last engagement, or until consent is withdrawn, whichever is earlier. Suppression list entries are retained indefinitely for the sole purpose of ensuring we do not contact you again
Client records, contracts, correspondence and reporting
6 years from the end of the engagement, reflecting the limitation period under the Limitation Act 1980
Financial records, invoices and payment records
6 complete financial years following the financial year to which they relate, in accordance with HMRC requirements and the Companies Act 2006
Call recordings, where made
6 months, unless required for the resolution of a dispute
Cookie consent records
12 months, after which consent is re-sought
Website server and security logs
12 months
Records relating to a data subject rights request
3 years from the date of the request
14.3 Where we have no ongoing legitimate business need to process your personal data, we will securely delete it or, where deletion is not technically feasible (for example within backup archives), we will securely isolate it and cease active processing until deletion is possible.
14.4 We may retain anonymised information, from which you can no longer be identified, indefinitely for statistical and benchmarking purposes.
15. DATA SECURITY
15.1 We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR, including:
(a) encryption of data in transit using TLS across the Website, our server-side tagging environment and our CRM;
(b) hashing of direct identifiers using the SHA-256 algorithm prior to transmission to advertising platforms;
(c) role-based access controls, with access limited to those personnel and contractors who require it in order to perform their duties;
(d) multi-factor authentication on business-critical systems, including our CRM, email, advertising accounts and hosting;
(e) use of reputable service providers who maintain recognised security certifications;
(f) confidentiality obligations imposed on all personnel and contractors;
(g) segregation of client advertising accounts and tracking configurations; and
(h) regular review of access rights and removal of access on cessation of engagement.
15.2 We have procedures to deal with any suspected personal data breach. We will notify the ICO of a notifiable breach without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
15.3 No method of transmission over the internet or method of electronic storage is entirely secure. While we take appropriate steps to protect your personal data, we cannot guarantee absolute security, and any transmission is at your own risk.
16. DISCLOSURE AND THIRD-PARTY PROCESSORS
16.1 We may disclose your personal data to:
(a) service providers acting as processors, who provide IT, hosting, CRM, communications, analytics and administrative services;
(b) professional advisers, including accountants, auditors, insurers and solicitors, acting as controllers or processors as appropriate;
(c) HM Revenue & Customs, regulators and other authorities, where required by law;
(d) advertising platforms, in the circumstances described at clause 7, where consent has been given; and
(e) a purchaser or prospective purchaser of our business or assets, in which case personal data will be disclosed subject to appropriate confidentiality undertakings and will be used by the purchaser in accordance with this Privacy Policy.
16.2 The principal third parties who process personal data in connection with our business are:
Provider
Role
Purpose
HighLevel Inc. (GoHighLevel)
Processor
CRM, forms, calendars, marketing automation, SMS and messaging
Google Ireland Limited
Processor / joint controller as applicable
Google Analytics, Google Tag Manager, Google Ads, Google Workspace
Meta Platforms Ireland Limited
Joint controller for pixel and Conversions API event data
Advertising measurement, attribution and audiences; WhatsApp Business messaging
GoCardless Ltd
Independent controller
Direct Debit mandate and payment collection
Our server-side tagging host
Processor
Hosting of the server-side container which receives and forwards event data
Our website hosting provider
Processor
Hosting of the Website and associated logs
Our accountants and bookkeepers
Processor
Preparation of accounts and statutory filings
16.3 We require all processors to enter into a written contract containing the provisions required by Article 28 of the UK GDPR, to process personal data only on our documented instructions, to maintain appropriate security measures, to impose confidentiality obligations on their personnel, to obtain our authorisation before engaging sub-processors, and to assist us in responding to data subject rights requests and in meeting our security and breach notification obligations.
16.4 A current list of our processors and sub-processors is available on request.
17. INTERNATIONAL TRANSFERS
17.1 Some of our service providers are established outside the United Kingdom, or process personal data on infrastructure located outside the United Kingdom, principally in the United States and the European Economic Area.
17.2 Transfers to countries in respect of which the Secretary of State has made adequacy regulations under section 17A of the Data Protection Act 2018, including the EEA member states, are made in reliance on those regulations.
17.3 Where personal data is transferred to a country which is not the subject of adequacy regulations, we ensure that an appropriate safeguard under Article 46 of the UK GDPR is in place, being one or more of:
(a) the UK International Data Transfer Agreement;
(b) the European Commission's Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum; or
(c) in respect of transfers to United States organisations which have self-certified to the EU–US Data Privacy Framework and its UK Extension, reliance on the UK Extension to the EU–US Data Privacy Framework.
17.4 Where we rely on a transfer agreement rather than adequacy, we carry out a transfer risk assessment and, where necessary, apply supplementary measures such as encryption in transit, pseudonymisation and hashing of identifiers prior to transfer.
17.5 You may request a copy of the relevant safeguards, redacted as necessary to protect commercially confidential information, by contacting us using the details at clause 24.
18. YOUR RIGHTS
Subject to the conditions and exemptions in the Data Protection Legislation, you have the following rights.
18.1 Right of access (Article 15). You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data together with prescribed information about the processing. We will not charge a fee unless your request is manifestly unfounded or excessive, or is repetitive, in which case we may charge a reasonable fee or refuse to act.
18.2 Right to rectification (Article 16). You have the right to have inaccurate personal data corrected and incomplete personal data completed. We encourage you to notify us of any change to your details so that our records remain accurate.
18.3 Right to erasure (Article 17). You have the right to have your personal data erased where it is no longer necessary for the purpose for which it was collected, where you withdraw consent and no other legal basis applies, where you object and there is no overriding legitimate ground, or where the data has been unlawfully processed. This right is not absolute; we may decline where we are required to retain the data to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
18.4 Right to restriction of processing (Article 18). You have the right to require us to suspend the processing of your personal data in certain circumstances, for example while we verify its accuracy or consider an objection.
18.5 Right to object (Article 21). You have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. Where you exercise this right we will cease processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. You have an absolute right to object to processing for direct marketing purposes, and we will stop such processing immediately on receipt of your objection.
18.6 Right to data portability (Article 20). Where we process your personal data by automated means on the basis of your consent or for the performance of a contract, you have the right to receive that data in a structured, commonly used and machine-readable format and to have it transmitted to another controller where technically feasible.
18.7 Right to withdraw consent (Article 7(3)). Where processing is based on consent, you may withdraw that consent at any time, as described at clause 11.3.
18.8 Rights in relation to automated decision-making (Article 22). We do not carry out solely automated decision-making producing legal effects concerning you or similarly significantly affecting you.
18.9 How to exercise your rights. Please submit your request in writing to [email protected] or to the postal address at clause 2.2, stating clearly which right you wish to exercise and providing sufficient detail for us to locate the relevant data.
18.10 Verification. We may request specific information to verify your identity before acting on a request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
18.11 Timescales. We will respond without undue delay and in any event within one month of receipt of a valid request. That period may be extended by up to a further two months where the request is complex or where we have received a number of requests from you, in which case we will inform you of the extension and the reasons for it within one month.
19. CHILDREN'S PRIVACY
19.1 Our Website and Services are directed at businesses and business professionals. They are not directed at, nor intended for use by, children under the age of 18, and we do not knowingly collect personal data relating to children.
19.2 We do not offer information society services directly to children within the meaning of Article 8 of the UK GDPR.
19.3 If you believe that a child has provided personal data to us, please contact us using the details at clause 24 and we will take steps to delete that data without undue delay.
20. THIRD-PARTY WEBSITES
20.1 The Website may contain links to third-party websites, plug-ins, platforms and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.
20.2 We do not control, and are not responsible for, the privacy practices of third-party websites. When you leave the Website, we encourage you to read the privacy notice of every website you visit.
21. COMPLAINTS
21.1 If you are dissatisfied with how we have handled your personal data or a request you have made, please contact us in the first instance at [email protected]. We take all complaints seriously and will investigate and respond promptly.
21.2 You have the right to lodge a complaint at any time with the Information Commissioner's Office, the United Kingdom supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint
21.3 We would, however, appreciate the opportunity to address your concerns before you approach the ICO.
22. CHANGES TO THIS PRIVACY POLICY
22.1 We keep this Privacy Policy under regular review and may update it from time to time to reflect changes in our practices, the technologies we use, legal requirements or regulatory guidance.
22.2 The date at the top of this Privacy Policy indicates when it was last revised. Any changes take effect from the date of publication on the Website.
22.3 Where changes are material, we will take reasonable steps to bring them to your attention, for example by prominent notice on the Website or by email where we hold a valid address for you.
22.4 We recommend that you review this Privacy Policy periodically to remain informed about how we process personal data.
23. NO CONTRACTUAL EFFECT
23.1 This Privacy Policy does not form part of any contract for the supply of Services and does not confer any contractual rights on you. Our contractual relationship with clients is governed by the applicable client service agreement.
24. CONTACT INFORMATION
24.1 All questions, comments, requests and complaints regarding this Privacy Policy or our processing of personal data should be addressed to:
24.2 This Privacy Policy and any dispute or claim arising out of or in connection with it are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save that nothing in this clause affects your statutory rights or your right to lodge a complaint with the ICO.