Legal
Privacy policy
Drafted to the EU standard with an Australian annex, because that is the strictest of the three regimes we operate under - European Economic Area, United Kingdom, Australia.
This document is not finished
It still contains 70 placeholders, highlighted below. Each one needs a real value - the legal entity, the registered address, the appointed EU and UK representatives, and the named processors.
It has not been reviewed by a lawyer. It is well-researched and cited, but it must be checked by an EU/EEA data-protection practitioner and Australian privacy counsel before the site goes anywhere public. The specific questions to put to them are in legal/privacy-research-notes.md.
[LEGAL_ENTITY_NAME]
Effective date: [EFFECTIVE_DATE]
Last updated: [LAST_UPDATED]
Version: [VERSION]
1. Introduction and who we are
1.1. This Privacy Policy explains how [LEGAL_ENTITY_NAME] ("we", "us", "our") collects, uses, shares, stores and protects personal data when you visit [WEBSITE_URL], create an account, price a basket, complete a specification, approve a quote, pay for and receive a website build, view a private preview, take one of our courses, or otherwise interact with us.
1.2. We are the data controller of the personal data described in this Policy. "Controller" means we decide why and how your personal data is processed. Where we use service providers who process personal data on our instructions, they act as our processors and are bound by written contracts.
1.3. Our details:
- Legal entity: [LEGAL_ENTITY_NAME]
- Company registration number: [COMPANY_REGISTRATION_NUMBER]
- Registered address: [REGISTERED_ADDRESS]
- Email: [CONTACT_EMAIL]
- Telephone: [CONTACT_PHONE]
- Privacy contact: [PRIVACY_CONTACT_EMAIL]
1.4. Data Protection Officer. [*Select one:*] We have appointed a Data Protection Officer, who can be reached at [DPO_CONTACT]. / We have assessed our processing against Article 37 of the GDPR and concluded that we are not required to appoint a Data Protection Officer. Our privacy contact point is [PRIVACY_CONTACT_EMAIL]. *(See the gaps list - this assessment must be documented, not merely asserted.)*
1.5. Our EU representative (GDPR Article 27). Because we are established outside the European Economic Area but offer services to individuals in the EEA, we have appointed the following representative in the Union under Article 27 of the GDPR. You may contact our representative on any matter relating to our processing of your personal data, in addition to or instead of contacting us:
[EU_REPRESENTATIVE_NAME], [EU_REPRESENTATIVE_ADDRESS] (member state: [EU_REP_MEMBER_STATE]), [EU_REPRESENTATIVE_EMAIL]
1.6. Our UK representative (UK GDPR Article 27). Because we are established outside the United Kingdom but offer services to individuals in the UK, we have appointed the following UK representative:
[UK_REPRESENTATIVE_NAME], [UK_REPRESENTATIVE_ADDRESS], [UK_REPRESENTATIVE_EMAIL]
1.7. Australia. We handle personal information about individuals in Australia. This Policy is also our APP privacy policy for the purposes of Australian Privacy Principle 1. Section 13 sets out the additional information required under Australian law.
2. Scope of this Policy
2.1. This Policy applies to:
(a) our public website, design library, showcase and journal at [WEBSITE_URL];
(b) our account registration, login and client account area;
(c) the basket, the specification form, the quote and the order;
(d) payment by bank transfer, and the invoicing and tax records that follow it;
(e) the private preview of a build, and any sharing link you create for it;
(f) the delivery of files, connection guides and other deliverables;
(g) our courses and any learning material we grant you access to;
(h) our email list and email sequences;
(i) our social media pages and any email or phone contact with us.
2.2. This Policy does not apply to third-party websites we link to, and it does not apply to the website we build for you once it is yours. Two boundaries matter here:
(a) Your project content. If the words, images or data you send us for the build contain other people's personal data - a photograph of a member of staff, a customer list, a testimonial - you are the controller of that content and we act as your processor, on your instructions, under a separate data processing agreement. Ask at [PRIVACY_CONTACT_EMAIL].
(b) The site after handover. We do not deploy, host, connect or operate the sites we build. Once the files are yours, everything the live site collects from its visitors is yours to govern, and this Policy has nothing to say about it. You will need your own privacy notice and, where the site sets non-essential cookies, your own consent banner.
2.3. Legal frameworks. Depending on where you are, your personal data is protected by: the EU General Data Protection Regulation (Regulation (EU) 2016/679) and national ePrivacy laws implementing Directive 2002/58/EC; the UK GDPR and the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) together with the Privacy and Electronic Communications Regulations 2003; and the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Spam Act 2003 (Cth).
3. Summary - the short version
*This summary is for convenience only. It does not replace the full Policy below.*
- We collect what you give us (registration details, specification answers, order and payment details, messages) and what your device gives us (IP address, device and browsing data, cookies).
- We use it to run your account, quote for and build what you ordered, take and reconcile your payment, give you a private preview and your files, answer you, market to you where you have agreed or where the law permits, keep the site secure, and meet our tax and legal duties.
- We do not sell your personal data.
- We share it with a defined set of service providers - hosting, email, accounting and a small number of tools - and nobody else, except where the law requires.
- Your data may be transferred outside your country, protected by the safeguards in section 10.
- You can access, correct, delete, port and object; you can withdraw consent and unsubscribe at any time; and you can complain to your regulator.
4. Personal data we collect
We collect the following categories. Not every category applies to every person.
4.1. Data you give us directly
A. Account and registration data. Name, email address, password (stored only as a salted hash, never in readable form), telephone number where you give one, country and time zone. From the registration and login forms.
B. Subscription data. Name and email address where you ask to hear from us. From the email sign-up.
C. Basket and specification data. The package and add-ons you priced, the design you chose, and your answers to the specification: what the site is for, what goes on each page, what you are supplying, what it needs to do, your business name and registration number where you buy as a business, and the country you are buying from. Free-text answers are about the project, not about you. From the basket and the specification form.
D. Declarations and acknowledgements. The exact wording of every statement you ticked, the version of that wording, and the time you ticked it. This includes the two cancellation acknowledgements, which we must be able to reproduce as they appeared on your screen. From the specification and the checkout.
E. Order and delivery data. Your quote and its snapshot of what was bought, the order reference and status, the delivery promise and the date the clock started, revision requests and how each was classified, sign-off or deemed acceptance, cancellation and refund records, and correspondence about the build. From running your order.
F. Payment data. The amount, currency and date, your bank transfer reference, the account name and details shown on the transfer, billing name and address, VAT or GST identifiers, the invoice, and refund records. See 4.4. From your bank transfer and our reconciliation of it.
G. Project content you send us. Words, images, logos, video, fonts, product data and documents for the build. This may contain other people's personal data, in which case section 2.2(a) applies. We do not ask for and will not accept passwords to your domain, hosting, bank or any other account.
H. Preview and deliverable access data. Which sharing links you created for your preview, when each was last used and how many times, when the preview was viewed, and when each deliverable was downloaded. From the preview and your account.
I. Course and learning data. Which courses you have been granted, who granted them and why, lessons started and completed, and progress. From the learning area.
J. Communications data. Emails, contact-form messages and support correspondence. From direct contact. We do not run discovery calls, we do not record calls and we do not keep session notes.
K. Testimonial content. Your name, role, business name and words, where you have given them to us in writing and agreed to us publishing them. From a written testimonial release. Nothing is published without that release on file.
4.2. Data collected automatically
L. Technical and device data. IP address, browser type and version, operating system, device type, screen size, language, referring URL, and approximate location derived from IP at country or city level.
M. Usage data. Pages viewed, time on page, clicks, entry and exit pages, session duration.
N. Email engagement data. Whether an email was delivered and opened, which links were clicked, and unsubscribe events.
O. Cookies and similar technologies. Cookies, pixels, local storage and similar identifiers. See section 9.
P. Security and audit logs. Login timestamps and outcomes, IP addresses used to sign in, password-reset events, and a record of every administrative action taken on your order or account, including who took it.
4.3. Data from third parties
- Advertising and social platforms ([ADS_PLATFORM]): aggregate campaign performance, and, where you have consented on those platforms, matched-audience and conversion data.
- Referrals: your name and email where a partner refers you and confirms they had a lawful basis to pass it on.
- Publicly available business sources: for business prospecting only, business contact details from company websites or business registries. *(See gaps - this needs a documented legitimate-interests assessment and a source-disclosure process under APP 7.6(c).)*
- Your bank, through ours: the account name and reference that arrive with your transfer. We do not choose what your bank sends us.
4.4. Payment data - what a bank transfer means for your data
4.4.1. We are paid by bank transfer, in full, before work starts. There is no card processor in the flow. That has a consequence worth stating plainly rather than leaving you to work out: we see and hold your payment details ourselves. Nobody stands between us and them.
4.4.2. What we hold: the amount, currency and date, the reference you quoted, the account name that appeared on the transfer and whatever account identifiers your bank passed to ours, the billing name and address needed for the invoice, any VAT or GST number, and the record of which member of our team confirmed the payment against our statement and when.
4.4.3. We do not accept card details, and we will never ask for them. If anyone asks you for a card number, a CVV or a card expiry date in our name, it is not us. Tell us at [PRIVACY_CONTACT_EMAIL].
4.4.4. Payment records are kept for the tax and accounting periods in section 11. They are held in the accounting systems listed in section 8 and are not used for marketing, profiling or any other purpose.
4.5. Sensitive data
4.5.1. We do not collect sensitive information and none of our forms asks for it. We build websites. Nothing in the specification asks about your health, your beliefs, your politics, your union membership, your racial or ethnic origin, your sex life or sexual orientation, or your criminal record, and there is no free-text field that invites any of it.
4.5.2. Under the GDPR and UK GDPR such data is special category data (Article 9). Under the Australian Privacy Act it is sensitive information (s 6(1)). Both regimes require a higher standard, and the cleanest way to meet it is not to hold the data at all.
4.5.3. Please do not send it to us, in a form, in an email or inside your project content. If you do, we will delete it unless we cannot lawfully do so, and we will not use it for anything.
4.5.4. If your project itself involves sensitive information - a site for a clinic, a charity, a support service - tell us before you order. That is a conversation about scope and about a data processing agreement, not something to put into a form field.
4.6. Data we do not collect
We do not knowingly collect: government identification numbers (other than a tax identifier where legally required for invoicing), biometric data, genetic data, criminal-offence data, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, or data concerning sex life or sexual orientation. Please do not send us such data.
5. Why we use your data, and our lawful basis
Under the GDPR and UK GDPR we must have a lawful basis under Article 6 for every purpose, and an additional condition under Article 9 for special category data, which we do not collect. Each purpose below gives the data it uses, by the letters in section 4, the EU and UK lawful basis, and the corresponding position under the Australian Privacy Principles.
1. Create and operate your account, and authenticate you. Data A, P. EU/UK: Art. 6(1)(b), performance of a contract with you. Australia: APP 3 collection necessary for our functions, APP 6 primary purpose.
2. Price a basket, take your specification and issue a quote. Data C. EU/UK: Art. 6(1)(b), steps taken at your request before a contract. Australia: APP 3, APP 6.
3. Record the declarations and cancellation acknowledgements you gave. Data D. EU/UK: Art. 6(1)(c), legal obligation, because consumer law requires us to be able to demonstrate what you were shown and when. Australia: APP 6(2)(b), required or authorised by law.
4. Build, preview and deliver what you ordered, and run the revision and acceptance process. Data C, E, G, H. EU/UK: Art. 6(1)(b). Australia: APP 6 primary purpose.
5. Take and reconcile your payment, issue the invoice, handle refunds. Data F. EU/UK: Art. 6(1)(b), and Art. 6(1)(c) for tax, accounting and consumer-law records. Australia: APP 6, APP 3.
6. Control access to your private preview and your files. Data A, H, P. EU/UK: Art. 6(1)(b), and Art. 6(1)(f), our legitimate interest in making sure an unfinished build is seen only by the people you chose. Australia: APP 6, APP 11.
7. Give you access to a course and record your progress. Data A, I. EU/UK: Art. 6(1)(b). Australia: APP 6.
8. Answer your enquiries and provide support. Data J. EU/UK: Art. 6(1)(b) where you are a client, Art. 6(1)(f) where you are not, our legitimate interest in answering people who write to us. Australia: APP 6.
9. Send marketing emails and offers. Data A, B, N. EU/UK: Art. 6(1)(a), your consent, in the EEA and by default everywhere. In the UK only, where you previously bought or negotiated to buy from us and we are marketing similar services, we may rely on Art. 6(1)(f) together with the PECR reg. 22(3) soft opt-in, with an unsubscribe in every message. Australia: APP 7.2 where you gave us the data and would reasonably expect it, with a simple opt-out in every message, plus Spam Act 2003 express or inferred consent.
10. Improve the designs, the specification form and the site. Data C, M. EU/UK: Art. 6(1)(f), our legitimate interest in improving what we sell, balanced against your rights *(LIA required - see gaps)*, and consent where analytics cookies are involved. Australia: APP 6, secondary purpose within reasonable expectations.
11. Website analytics, conversion measurement, advertising and remarketing. Data L, M, O. EU/UK: Art. 6(1)(a), consent through our cookie banner, plus prior consent under Art. 5(3) of the ePrivacy Directive and PECR reg. 6 for the storage or access itself. Australia: APP 6, and APP 7 where it amounts to direct marketing.
12. Publish a testimonial or show work in our portfolio. Data K. EU/UK: Art. 6(1)(a), your consent, given in a written release. Australia: APP 6 with consent.
13. Keep the site, accounts, previews and files secure, and prevent fraud and abuse. Data L, P, F. EU/UK: Art. 6(1)(f), our legitimate interest in the security of the service and its users, and Art. 6(1)(c) where security is legally required. Australia: APP 11, APP 6(2)(e).
14. Meet legal obligations - tax, accounting, consumer protection, regulatory requests, court orders. Data D, E, F, J. EU/UK: Art. 6(1)(c). Australia: APP 6(2)(b).
15. Establish, exercise or defend legal claims, and handle disputes, refunds and complaints. All data. EU/UK: Art. 6(1)(f), our legitimate interest in defending claims. Australia: APP 6(2)(b).
16. Transfer of business - merger, acquisition or sale of assets. All data. EU/UK: Art. 6(1)(f). Australia: APP 6(2), with notice.
17. Process the personal data inside your project content. Data G. Here we are not the controller. We act on your written instructions as your processor, under a data processing agreement, and section 2.2(a) governs it rather than this table.
Note on legitimate interests. Where we rely on Article 6(1)(f), we have balanced our interest against your rights and freedoms. You may ask us for a summary of that assessment at [PRIVACY_CONTACT_EMAIL], and you have the right to object under Article 21 (see section 11).
6. Marketing communications
6.1. How you get on the list. You will only receive marketing emails from us if you (a) actively opted in, by ticking an unticked box or otherwise agreeing; or (b) are an existing or former client being marketed similar services under the soft opt-in described in 6.4, where that applies to you.
6.2. No pre-ticked boxes. No bundled consent. We do not use pre-ticked boxes, and we do not make an account, a quote or a purchase conditional on agreeing to marketing. Consent to marketing is always a separate, optional choice, and it is never bundled into acceptance of the terms or into a cancellation acknowledgement.
6.3. Double opt-in. We use a double opt-in: after you subscribe, we email you a confirmation link, and you are only added to the list once you click it. We keep a record of the date, time, IP address, form and wording you consented to. *(See the gaps list - this must actually be switched on in [EMAIL_PLATFORM].)*
6.4. UK soft opt-in. If you are in the UK and you bought - or negotiated to buy - services from us, we may email you about our own similar services on the basis of PECR reg. 22(3), provided we gave you a simple way to refuse when we collected your address and give you one in every message. You can stop this at any time.
6.5. Australia. Under the Spam Act 2003 (Cth) we send commercial electronic messages only with your express or inferred consent; every message identifies [LEGAL_ENTITY_NAME], gives accurate contact details that remain accurate for at least 30 days after sending, and contains a functional unsubscribe facility that stays live for at least 30 days. We action unsubscribes within 5 business days. Under APP 7 you may also ask us at any time to stop using or disclosing your personal information for direct marketing, and to tell you where we obtained it.
6.6. How to unsubscribe.
(a) Click "Unsubscribe" at the foot of any marketing email - one click, no login, no password, no explanation required, no charge.
(b) Or email [PRIVACY_CONTACT_EMAIL] with "Unsubscribe" in the subject line.
(c) We action unsubscribe requests within 5 business days and in any event within a reasonable period.
6.7. What continues after you unsubscribe. Unsubscribing stops marketing. We will still send you service messages you cannot opt out of while you have an account or a live order: quotes, order confirmations, the two cancellation acknowledgements repeated back to you, bank transfer instructions, receipts and invoices, preview and delivery notices, revision and acceptance deadlines, course access details, security and password notices, changes to the terms, and legally required notices.
6.8. Suppression list. When you unsubscribe we keep your email address on a suppression list indefinitely. This is the only way we can guarantee we never email you again; it is not used for any other purpose.
6.9. Withdrawing consent is as easy as giving it, and has no effect on the lawfulness of processing before you withdrew.
7. The specification, the quote, the preview and your files
7.1. What the specification asks. The specification asks about the website you want: what it is for, what goes on each page, what you are supplying, what it must do, and how you are buying (as an individual or as a business). It is the document your finished build is judged against, which is why we keep it for as long as we keep the order.
7.2. Consequence of not answering. Where a question is required we cannot quote without it, and the form says so on the screen. Where a question is optional, leaving it blank costs you nothing except a less precise build. *(This satisfies GDPR Art. 13(2)(e) and APP 5.2(e).)*
7.3. We do not score or grade you. There is no lead scoring, no ranking, no assessment of your creditworthiness and no automated accept or decline. The price comes from the published catalogue and the options you chose, and a person issues the quote. See section 15.
7.4. Declarations are kept verbatim. When you tick a statement - that your content is yours to publish, that you understand a package stores nothing, that you expressly ask us to begin work inside the cancellation period, that you understand what beginning costs you - we store the exact words you were shown, the version of those words and the moment you ticked. We do this because a record that merely points at a document proves nothing: the document can be edited afterwards, and what was on your screen that day cannot be reconstructed from it. These records are evidence in your favour as much as ours.
7.5. The private preview. Before handover your build sits at a private address. It is visible to you when you are signed in, and to anyone you deliberately give a sharing link to. We record when a sharing link is used and how often, so that you can see who has seen it and revoke a link that has travelled further than you meant. The preview is not indexed by search engines. It is taken down 60 days after sign-off.
7.6. Your files. Deliverables sit in your account for the period in section 11 and we record when each one is downloaded. Download them and keep your own copy; we are not your archive.
7.7. We do not hold your credentials. We do not deploy, host or connect anything, so we never ask for and will not accept passwords or access tokens for your domain, your hosting, your bank or any other account. If you send one anyway, we will delete it and ask you to change it.
8. Who we share your data with
8.1. We do not sell your personal data, and we do not share it with third parties for their own independent marketing.
8.2. We share personal data with the following categories of recipient, all of which are bound by written contracts meeting the requirements of GDPR Article 28 (and equivalent obligations under APP 8 and s 16C of the Privacy Act):
- Website hosting and infrastructure ([HOSTING]): hosts the site, the database, the private previews and the deliverable files, and takes backups. Potentially all data at rest.
- Transactional email ([TRANSACTIONAL_EMAIL]): sends quotes, order confirmations, acknowledgement copies, delivery notices, password resets. Data A, D, E, J. Kept on separate infrastructure from marketing email, so that a password reset never depends on the deliverability of a campaign.
- Email marketing platform ([EMAIL_PLATFORM]): sends broadcasts and stores subscriber records and engagement. Data A, B, N.
- Banking and payment reconciliation ([BANK]): receives your transfer and shows it on our statement. Data F. Your bank and ours act as controllers in their own right for their own regulatory purposes.
- Accounting, bookkeeping and tax ([ACCOUNTANT]): statutory books and tax filings. Data F.
- Analytics ([ANALYTICS]): measures site usage. Data L, M, O.
- Advertising and social platforms ([ADS_PLATFORM]): ad delivery, conversion measurement, remarketing audiences. Data L, M, O.
- Customer support ([SUPPORT_TOOL]): manages messages and tickets. Data A, J.
- AI and large-language-model providers ([AI_VENDOR]): only as described in 8.4.
- Contractors ([CONTRACTORS]): designers and developers who work on builds under confidentiality and data-processing terms, and who assign their intellectual property before they start. Data C, E, G.
- Professional advisers: lawyers, insurers and auditors, where needed.
We do not use a CRM, a calendar or booking tool, a video conferencing tool or a third-party course platform, because nothing in this business books a call, holds a meeting or hosts a course anywhere but here. If that changes, this list changes first.
8.3. Other disclosures. We may also disclose personal data:
(a) where required by law, a court order, a regulator or a law-enforcement request that we have satisfied ourselves is valid;
(b) to establish, exercise or defend legal claims;
(c) to prevent or investigate fraud, security incidents or serious threats to life or health;
(d) to a buyer or successor in the event of a merger, acquisition, restructuring or sale of assets - in which case we will notify you and this Policy will continue to apply until the acquirer publishes its own.
8.4. AI tools. Where we use AI or large-language-model services - for example to help draft the build from your specification, to write a first pass of a connection guide, or to draft a reply - we use them under business or enterprise terms that contractually prohibit the provider from using your data to train its models. *(See gaps - this must be verified per vendor, in writing.)*
8.5. There is no community area. We do not run a forum, comments or a group, so there is nowhere on our site where one client can see another client's information.
9. Cookies and similar technologies
9.1. What we use. We use cookies, pixels, tags, local storage and similar technologies. Where the law refers to "cookies", the same rules apply to pixels, SDKs, fingerprinting techniques and equivalent tracking - the EDPB confirmed this scope in its Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive.
9.2. Categories.
- Strictly necessary. Sign-in and session, security and CSRF tokens, your basket, your guest basket token, remembering your cookie choices, and access control on a private preview. No consent needed - these are exempt.
- Functional and preferences. Language, time zone, reduced-motion and other display preferences, saved position in a course. Consent needed in the EU/EEA.
- Analytics and statistics. Understanding traffic and which pages people leave from. Consent needed in the EU/EEA. In the UK, certain statistical and appearance cookies are exempt from consent under the Data (Use and Access) Act 2025 provided you are given clear information and a means to opt out. We still ask, and we honour a refusal.
- Marketing and advertising. Advertising pixels, conversion tracking, remarketing audiences. Consent needed, always.
9.3. How our banner works. In the EU/EEA and UK:
(a) No non-essential cookie or pixel fires before you make a choice. Scripts are blocked until then.
(b) The first layer offers "Accept all" and "Reject all" as equally prominent buttons at the same level, plus "Manage preferences".
(c) Rejecting is exactly as easy as accepting - one click, same layer, same visual weight. We do not use pre-ticked boxes, colour or size to nudge you, or bury "Reject" behind extra clicks.
(d) You can consent per category; consent is not all-or-nothing.
(e) We do not operate a cookie wall. Refusing non-essential cookies does not block access to the site, to your account, to your preview or to anything you have purchased.
(f) You can change or withdraw your choices at any time via "Cookie settings" in the footer, as easily as you gave them.
(g) We re-ask for consent every [6 / 12] months [verify], and record the date, time, version of the banner and the choice you made.
9.4. Do Not Track and Global Privacy Control. [*Select:*] We honour Global Privacy Control signals as an opt-out where applicable. / Our site does not currently respond to browser Do Not Track signals, because there is no agreed standard. *(Decide - see gaps.)*
9.5. Full cookie list. A current, itemised list of every cookie and tracker - name, provider, purpose, type, duration and whether it is first- or third-party - is available at [COOKIE_POLICY_URL]. *(This list is a legal requirement in the EU/UK and must be kept accurate - see gaps.)*
10. International transfers of personal data
10.1. We are based in [COUNTRY_OF_INCORPORATION], and many of our service providers are located in [LIST: e.g. the United States, the United Kingdom, the European Union, Australia, Canada]. Your personal data will therefore be transferred to, stored in and accessed from countries outside your own.
10.2. From the EEA. Transfers out of the EEA are made under one or more of the following Chapter V mechanisms:
(a) an adequacy decision of the European Commission, where the destination country benefits from one (currently including the UK, Switzerland, Canada (commercial organisations), New Zealand, Japan, South Korea, Israel, Argentina and others);
(b) for transfers to the United States, the EU-US Data Privacy Framework, where the recipient is on the active DPF list - and, as a fallback, Standard Contractual Clauses, because the DPF adequacy decision is under appeal to the Court of Justice (Case C-703/25 P) following the General Court's judgment of 3 September 2025 upholding it;
(c) the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a documented transfer impact assessment and supplementary technical measures such as encryption in transit and at rest;
(d) a derogation under Article 49 - for example your explicit consent, or necessity for the performance of a contract with you - used only occasionally and never for systematic transfers.
10.3. From the UK. Transfers out of the UK are made under UK adequacy regulations, the International Data Transfer Agreement (IDTA) or the UK International Data Transfer Addendum to the EU SCCs, subject to the "data protection test" introduced by the Data (Use and Access) Act 2025.
10.4. From Australia. Before disclosing personal information to an overseas recipient we take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles (APP 8.1) - principally by binding the recipient contractually to APP-equivalent obligations, restricting purposes, requiring equivalent flow-down terms on sub-processors, and requiring breach notification. You should be aware that under section 16C of the Privacy Act 1988 we remain accountable for the acts of our overseas recipients as if we had done them ourselves; we do not ask you to waive that protection under APP 8.2(b).
10.5. Countries where recipients are likely to be located (APP 1.4(g), APP 5.2(j)): [COUNTRY_LIST - e.g. United States, United Kingdom, Ireland, Germany, Netherlands, Australia, Canada] [verify against your actual vendor list].
10.6. You may request a copy of the relevant safeguards by emailing [PRIVACY_CONTACT_EMAIL].
11. How long we keep your data
11.1. We keep personal data only as long as necessary for the purposes in section 5, plus any period required by law or needed to defend legal claims. Our default periods are below. All periods marked `[verify]` must be confirmed against the tax, accounting and limitation rules of the company's country of establishment and of each market - these vary materially (for example Germany 8-10 years, Ireland 6 years, Australia 5 years for tax records).
- Account and profile data. Life of the account plus 24 months
[verify], from account closure or last sign-in. - Abandoned baskets and incomplete specifications. 12 months
[verify]from the last change, then deleted. - Order records: specification, quote, snapshot of what was bought, delivery dates, revision requests and how each was classified, acceptance or deemed acceptance, cancellation and refund records. 6 years
[verify]from the end of the order, which is the limitation period for a contract claim in most of our markets. - Declarations and cancellation acknowledgements, with the wording as displayed and its version. 6 years
[verify]from the end of the order. These are the evidence that a consumer was told what they were agreeing to, and they are useless if they do not outlive the period in which the question can be asked. - Payment, invoice and tax records, including bank transfer references and the account details that arrived with the transfer. 7 years
[verify]from the end of the tax year of the transaction. - Your project content: the words, images and files you sent for the build. Life of the order plus 12 months
[verify], then deleted. Ask us and we will delete it sooner, once the build is accepted. - Deliverables held for you to download. [FILE_RETENTION_PERIOD] after delivery, then removed. This must match clause 15.4 of the Terms of Use.
- Private preview. Taken down 60 days after sign-off. Sharing links and their access records go with it.
- Course access and progress. Life of the account plus 24 months
[verify]. - Marketing subscribers who never engage. 24 months from the last open or click
[verify], then deleted. - Marketing consent records, as proof of opt-in. Duration of the subscription plus 5 years after withdrawal
[verify]. - Unsubscribe and suppression list. Indefinitely, holding the minimum data needed, so that a list re-import can never resurrect you.
- Support emails and messages. 3 years
[verify]from closure. - Testimonials published with consent. Until you withdraw consent, then removed from our own channels within 30 days.
- Server, access and security logs. 12 months
[verify]. - Administrative audit log: who did what to an order or an account. 6 years
[verify], for the same reason as the order records. - Analytics data. 14 months, the platform maximum.
- Cookie consent records. [12 / 24] months
[verify]. - Backups. Rolling 35 days
[verify], after which they are overwritten. - Records relating to a live or threatened dispute. Until final resolution plus 6 years
[verify].
11.2. Backups. When you ask us to delete data, we remove it from live systems promptly and it is then purged from backups within the backup cycle above. Between those points it is isolated and not used.
11.3. Anonymisation. Instead of deleting, we may irreversibly anonymise data so it can no longer identify you, and retain it for statistics and service improvement. Anonymised data is no longer personal data.
12. Your rights
12.1. If you are in the EEA or the UK
Under the GDPR / UK GDPR you have the right to:
- Access (Art. 15): confirmation that we process your data, a copy of it, and the information in this Policy.
- Rectification (Art. 16): have inaccurate data corrected and incomplete data completed.
- Erasure, the "right to be forgotten" (Art. 17): have data deleted where it is no longer needed, where you withdraw consent, or where you successfully object.
- Restriction (Art. 18): have us pause processing while a dispute about accuracy or about our legitimate interests is resolved.
- Data portability (Art. 20): receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where that is technically feasible.
- Object (Art. 21): object to processing based on legitimate interests. For direct marketing your objection is absolute: we must stop, and there is no balancing test.
- Not to be subject to solely automated decisions (Art. 22): see section 15.
- Withdraw consent (Art. 7(3)): at any time, as easily as you gave it, without affecting the lawfulness of what came before.
- Complain to a supervisory authority (Art. 77): see 12.4.
One limit worth stating plainly. Some records we are required to keep even if you ask us to delete them: your invoice and tax records, and the record of the declarations and cancellation acknowledgements you gave. Erasing those would remove the evidence that you were told what you were agreeing to, which is a protection for you as much as for us. We will tell you which records we have kept and why.
Our response time. We respond within one month of receiving your request (Art. 12(3)). We may extend by up to two further months for complex or numerous requests, and we will tell you within the first month if we do, with reasons. Requests are free unless manifestly unfounded or excessive.
Identity verification. To protect you, we may ask for information to confirm your identity before acting. We will ask for the minimum necessary and will not use it for anything else.
12.2. If you are in Australia
Under the Australian Privacy Principles you have the right to:
(a) Access your personal information (APP 12). We will respond within 30 days. Access is free, though we may charge a reasonable, non-excessive fee for giving access (never for making the request).
(b) Correct your personal information (APP 13), and to ask us to notify anyone we have disclosed it to of the correction. If we refuse, we will give you written reasons and you may ask us to attach a statement of your view to the record.
(c) Opt out of direct marketing at any time, ask us to stop disclosing your information to others for their direct marketing, and ask us to tell you the source of your information (APP 7.6). We will action this within a reasonable period and free of charge.
(d) Deal with us anonymously or by pseudonym where lawful and practicable (APP 2) - for example when browsing the design library, the journal or the pricing page, or when asking a general question. This is not practicable for creating an account, approving a quote, paying by bank transfer or receiving a build.
(e) Complain - see 12.4.
*Australian law does not currently give a general right to erasure or portability. As a matter of policy we will honour deletion requests from Australian users on the same terms as EEA/UK users, subject to our legal retention obligations.*
12.3. How to exercise your rights
Choose whichever is easiest:
- Email: [PRIVACY_CONTACT_EMAIL], with the right you want in the subject line.
- Self-service: sign in and use the privacy and data controls in your account to download, correct or delete your data. [build this - see gaps]
- Unsubscribe link: at the foot of any marketing email, for marketing objections.
- Cookie settings: in the footer of every page, for cookie consent.
- Post: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS].
- EU representative: [EU_REPRESENTATIVE_EMAIL]. EEA residents may contact our Art. 27 representative instead of us.
- UK representative: [UK_REPRESENTATIVE_EMAIL].
Please tell us which right you are exercising and enough detail to find your records.
12.4. Complaints
12.4.1. Complain to us first if you can. Email [PRIVACY_CONTACT_EMAIL]. We will acknowledge within [5] business days, investigate, and give you a written outcome within 30 days. *(From 19 June 2026 the Data (Use and Access) Act 2025 makes a complaints procedure a formal requirement for UK controllers, with acknowledgement within 30 days.)*
12.4.2. You can also complain to a regulator, and you do not have to come to us first:
- EEA: the supervisory authority of your country of residence, your place of work, or the place of the alleged infringement. A full list is at edpb.europa.eu/about-edpb/board/membersen. Our EU representative is located in **[EUREPMEMBERSTATE]**.
- United Kingdom: the Information Commissioner's Office, ico.org.uk/make-a-complaint, 0303 123 1113.
- Australia: the Office of the Australian Information Commissioner, oaic.gov.au/privacy/privacy-complaints, 1300 363 992. The OAIC generally expects you to complain to us first and to give us 30 days to respond.
13. Additional information for Australian individuals
*This section, together with sections 4, 5, 8, 10, 11 and 12.2, forms our APP privacy policy under APP 1.3-1.4.*
13.1. Kinds of personal information we collect and hold (APP 1.4(a)) - see section 4.
13.2. How we collect and hold it (APP 1.4(b)) - see sections 4 and 14.
13.3. Purposes of collection, holding, use and disclosure (APP 1.4(c)) - see section 5.
13.4. Access and correction (APP 1.4(d)) - see section 12.2 and 12.3.
13.5. How to complain and how we handle complaints (APP 1.4(e)) - see section 12.4.
13.6. Overseas disclosure (APP 1.4(f)-(g)) - yes, we are likely to disclose personal information to overseas recipients. The countries in which they are likely to be located are listed at 10.5.
13.7. Notification at collection (APP 5). Separately from this Policy, we give a short collection notice at each point where we collect personal information - the registration form, the email sign-up, the specification form and the checkout - covering our identity and contact details, the purposes, the consequences of not providing the information, our usual disclosures, that this Policy explains access, correction and complaints, and that we are likely to disclose overseas and to which countries. *(See gaps - these notices must be built into the forms; the Policy alone does not satisfy APP 5.)*
13.8. Unsolicited personal information (APP 4). If we receive personal information we did not ask for and could not have collected under APP 3, we will destroy or de-identify it as soon as practicable, if lawful to do so.
13.9. Government identifiers (APP 9). We do not adopt, use or disclose government-related identifiers (such as a Tax File Number or Medicare number) as our own identifier for you.
13.10. Data quality (APP 10). We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant. Please tell us if your details change.
13.11. Notifiable Data Breaches. If we suffer an eligible data breach likely to result in serious harm, we will notify the OAIC and affected individuals as soon as practicable, as required by Part IIIC of the Privacy Act 1988.
13.12. Automated decision-making disclosure. From 10 December 2026, APP 1.7-1.8 require us to disclose the kinds of personal information used in computer programs that make, or substantially help make, decisions that could reasonably be expected to significantly affect your rights or interests. See section 15. [Review and update this section before 10 December 2026.]
14. How we protect your data
14.1. We maintain technical and organisational measures appropriate to the risk, including:
(a) Encryption in transit (TLS 1.2 or better across the whole site, including every form, the client account area and every private preview) and encryption at rest for databases and backups;
(b) Passwords stored only as salted hashes - we never store, and cannot read, your password;
(c) Multi-factor authentication on the back office, the hosting account, the email platform and the bank [verify - must be enforced, not optional];
(d) Role-based access control and least privilege - staff and contractors get only the access their role requires, reviewed at least every 6 months and revoked on the day someone leaves;
(e) Sharing links are stored hashed, never in the clear, given an expiry date, and revocable by you at any time - the same treatment as a session token, because a preview link is a credential;
(f) Audit logging of every administrative action on an order or account, and of login events;
(g) Written confidentiality and data-protection terms with every employee, contractor and vendor, signed before they touch a project;
(h) Vendor due diligence and signed data processing agreements before any vendor touches personal data;
(i) Regular patching and dependency updates of the site and its infrastructure;
(j) Backups taken [daily], encrypted, stored separately, and restore-tested at least annually;
(k) Payment separation - we take no card data at all (see 4.4), and bank details are held in the accounting records rather than in the website database;
(l) A documented incident response plan with named owners and defined timelines.
14.2. No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your password confidential, using a unique password, and telling us immediately at [PRIVACY_CONTACT_EMAIL] if you suspect unauthorised access to your account.
14.3. Data breaches. If a personal data breach occurs:
(a) EEA / UK: we will notify the competent supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms (GDPR Arts. 33), and we will notify you without undue delay where the breach is likely to result in a high risk to you (Art. 34).
(b) Australia: we will assess within 30 days and, if it is an eligible data breach, notify the OAIC and affected individuals as soon as practicable.
15. Automated decision-making and profiling
15.1. We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing.
15.2. We do use automation in limited ways:
(a) Pricing. Your basket total, the delivery promise in working days and the revision rounds are calculated from the published catalogue and the options you chose. It is arithmetic on a published price list, not a judgement about you, and the figures are shown to you before anything is committed;
(b) Quotes above a published figure are confirmed by a person before any money moves, which is a human check added to the automation rather than one removed by it;
(c) Payment confirmation is entirely manual. A person matches your transfer against our bank statement and is recorded as having done so. Nothing about your money is decided by software;
(d) Email segmentation - which email you receive next may depend on what you clicked;
(e) Analytics and advertising audience building, based on the cookie consent you gave;
(f) Fraud and abuse detection - automated rules may flag a login or an order for human review.
15.2.1. There is no lead scoring, no ranking of clients and no automated accept or decline. The previous version of this policy described one, for a different business. It does not exist here.
15.3. Your rights. If you believe a decision about you was made solely by automated means and significantly affects you, you have the right under Article 22 GDPR / UK GDPR to obtain human intervention, to express your point of view, to receive an explanation, and to contest the decision. Contact [PRIVACY_CONTACT_EMAIL].
15.4. Australia. See 13.12 - this section will be expanded before 10 December 2026 to meet APP 1.7-1.8.
16. Children and young people
16.1. Our services are intended for adults. You must be at least [16] years old to create an account, and at least 18 to approve a quote, pay for a build or enter into a contract with us.
16.2. EU/EEA. Where we rely on consent to offer information-society services directly to a child, GDPR Article 8 sets the age of valid consent at 16, but permits member states to lower it to as low as 13. Because the age varies by country (for example 13 in Denmark and Sweden, 14 in Austria and Italy, 15 in France, 16 in Germany, Ireland and the Netherlands), we apply a 16+ floor across the EEA rather than tracking each national rule. [verify - confirm this is acceptable for the countries actually targeted]
16.3. UK. The age of consent for information-society services is 13, but the ICO's Age Appropriate Design Code applies to services likely to be accessed by children. We do not design for or market to under-18s. [verify whether the AADC applies - see gaps]
16.4. Australia. There is no fixed statutory age; capacity to consent is assessed individually, and the OAIC's guidance is that an individual aged 15 or over is generally presumed capable. A Children's Online Privacy Code is being developed by the OAIC under the Privacy and Other Legislation Amendment Act 2024 and is expected by December 2026. [Review this section when the Code is registered.]
16.5. We do not knowingly collect personal data from anyone below the applicable age. If we learn we have, we will delete it promptly. If you are a parent or guardian and believe your child has given us personal data, contact [PRIVACY_CONTACT_EMAIL] and we will delete it.
17. Third-party links, social media and testimonials
17.1. Our website and emails contain links to third-party sites - vendor sites, social media, payment pages, resources we recommend. We are not responsible for their privacy practices. Read their policies.
17.2. Embedded content (videos, chat widgets, social feeds, map frames) may set cookies and collect data as if you had visited that site directly. These are blocked until you consent under section 9. The same is true of anything embedded in a site we build for you, which is why we tell you about it in the connection guide rather than leaving you to find it.
17.3. Our social media pages are hosted by the relevant platform, which may act as a joint controller with us for page insights. Your interactions there are governed by that platform's privacy policy as well as this one.
17.4. Testimonials. We publish testimonials, results and case studies only with a signed release. You may withdraw consent at any time by emailing [PRIVACY_CONTACT_EMAIL]; we will remove the testimonial from our own channels within 30 days. We cannot guarantee removal from third-party caches, archives or screenshots already taken.
18. Changes to this Policy
18.1. We may update this Policy to reflect changes in our services, our vendors or the law.
18.2. Minor changes take effect when we post the updated Policy, with a new "Last updated" date.
18.3. Material changes - for example a new purpose, a new category of recipient, a new lawful basis or a shorter route to your data leaving the region - will be notified to registered users by email at least [14] days before they take effect. Where a change requires your consent under the GDPR, we will ask for fresh consent and will not rely on your silence.
18.4. We keep an archive of previous versions, available on request at [PRIVACY_CONTACT_EMAIL].
19. Other jurisdictions
19.1. California (CCPA/CPRA). We do not currently target California residents. If we begin to, and we meet the applicable thresholds, we will add a California notice covering the categories of personal information collected and disclosed, the right to know, delete, correct and limit, the "Do Not Sell or Share My Personal Information" link, and the non-discrimination guarantee. We do not sell personal information as defined by the CCPA. Note that use of third-party advertising cookies can constitute a "sale" or "share" under the CCPA even where no money changes hands.
19.2. Canada (PIPEDA). We do not currently target Canada. If we begin to, we will add a PIPEDA notice, designate a privacy officer, and address meaningful consent, breach reporting to the Privacy Commissioner of Canada, and Canada's Anti-Spam Legislation (CASL) - which is stricter than the Spam Act 2003 and requires express opt-in with a two-year limit on implied consent, backed by penalties of up to CAD 10 million.
20. Contact
- Controller: [LEGAL_ENTITY_NAME] ([COMPANY_REGISTRATION_NUMBER])
- Address: [REGISTERED_ADDRESS]
- General email: [CONTACT_EMAIL]
- Privacy email: [PRIVACY_CONTACT_EMAIL]
- Telephone: [CONTACT_PHONE]
- Data Protection Officer, if appointed: [DPO_CONTACT]
- EU representative (Art. 27): [EU_REPRESENTATIVE_NAME], [EU_REPRESENTATIVE_ADDRESS], [EU_REPRESENTATIVE_EMAIL]
- UK representative (Art. 27): [UK_REPRESENTATIVE_NAME], [UK_REPRESENTATIVE_ADDRESS], [UK_REPRESENTATIVE_EMAIL]
---
---