GDPR and your data
Last updated 22 August 2026
This page covers the specific obligations under UK and EU GDPR. The privacy policy explains what we collect. This one explains the legal machinery underneath it.
Who is the controller
For our own website and enquiry form, we are the controller. We decide what is collected and why.
For the CRM, messaging and invoicing we run on your behalf, you are the controller and we are your processor. We act on your documented instructions and nothing else. A written data processing agreement covering this is provided before your account goes live.
Lawful basis
- Replying to your enquiry: legitimate interest, specifically responding to someone who asked us to.
- Running your account: performance of the contract between us.
- Keeping invoices and tax records: legal obligation.
- Marketing messages to your own customers: consent, captured and recorded by the system before any message is sent.
Automated messaging and consent
Missed call text back replies to someone who has just called you. Review requests and any marketing message require a recorded consent, and the system will not send to a contact without one.
Every automated message carries an opt out. Opt outs apply immediately and across every channel, and they cannot be overridden from inside the CRM.
Rights, and how they are handled
If one of your customers exercises a right with you, we give you the tools to satisfy it: export, correction and deletion are all available from the record itself.
If a request reaches us directly for data we hold as your processor, we will forward it to you rather than act on it ourselves, and we will tell you the same day.
Sub processors
We use third parties for hosting, messaging and payments. Each is engaged under terms that meet Article 28. The current list is available on request, and we will give you notice before adding a new one so you can object.
International transfers
Where a supplier processes data outside the UK or EEA, the transfer is covered by an adequacy decision or by standard contractual clauses. We will tell you which applies to which supplier if you ask.
Breach reporting
If we discover a personal data breach affecting your account we will notify you without undue delay and inside seventy two hours of becoming aware of it, with what happened, what data was involved and what we are doing about it.
Data protection contact
Send data protection requests to the contact address below. We will acknowledge within five working days and answer inside one month.