Skip to main content

Privacy Policy

Privacy Policy (UK GDPR & Data Protection Act 2018)

Last updated: 19 June 2025


1. Who we are

 

WebCraft NI (“we”, “us”, “our”) is a web-development and digital-marketing studio registered in Northern Ireland. We act as the data controller for the personal data described below.

 

Contact for data matters

  • Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

  • Tel: +44 7708 878 062


2. Personal data we collect

Category

Typical items

How we obtain it

Enquiry & account data

Name, job title, company, email, phone, website URL, project brief, budget band

Directly from you via our “Start Here” form, email, phone or meetings

Marketing preferences

Newsletter opt-in, communication channel choices

Directly from you (checkboxes, profile updates)

Technical data

IP address, device type, browser, operating system, referring site, pages viewed, time on site

Automatically via cookies, server logs, Google Analytics 4

Cookie data

Cookie ID, consent status

Via our consent banner & your device

Client project data

CMS log-in details, design assets, end-user data you lawfully supply to us

From you under a separate data-processing agreement

We do not intentionally collect special-category data (e.g. health, race) or children’s data. Please avoid sending it to us.


3. Why we use your data & lawful bases

Purpose

Lawful basis (UK GDPR Art. 6)

Details

Responding to enquiries & providing a FREE 30-min Digital Growth Audit

Art. 6 (1)(b) Contract

Pre-contractual steps at your request

Delivering client projects & support

Art. 6 (1)(b) Contract

Fulfilling our service agreement

Issuing invoices & maintaining tax records

Art. 6 (1)(c) Legal obligation

HMRC record-keeping (6 years)

Sending service emails (e.g. project status)

Art. 6 (1)(b) Contract

Legitimate operational communication

Email marketing & newsletters

Art. 6 (1)(a) Consent (PECR soft-opt-in where applicable)

You may withdraw consent at any time

Site analytics & performance optimisation

Art. 6 (1)(f) Legitimate interests

Understanding and improving how visitors use our site

Where we rely on legitimate interests, we balance our interests against your rights and expect minimal privacy impact (e.g. anonymous analytics).


4. Cookies & similar technologies

 

We use first-party cookies, Google Analytics 4 and Meta Pixel. On your first visit a banner asks for consent to non-essential cookies; essential cookies are required for site security and core functionality. Full details are in our Cookie Notice.


5. Who we share data with

Recipient

Reason

Safeguards

Website & email hosting providers (Krystal, Google Workspace)

Data storage, email transport

UK/EU servers; UK GDPR-compliant DPA

Analytics vendors (Google Analytics 4)

Aggregate usage statistics

IP-anonymisation; EU-US Data Privacy Framework

Payment processor (Stripe)

Card payments for hosting retainers

PCI-DSS compliance

Sub-contractors & freelancers

Project delivery

Confidentiality & GDPR clauses in contracts

Legal / regulatory bodies (ICO, HMRC)

Compliance with law

Data disclosed only when required

We never sell or lease your personal data.


6. International transfers

 

Some suppliers (e.g. Google LLC, Stripe) store data in the United States. Transfers are protected by:

  • Adequacy regulations (EU-US Data Privacy Framework) or

  • Standard Contractual Clauses (SCCs) + supplementary measures.


7. Data retention

Data type

Retention period

Enquiry leads (no purchase)

24 months after last contact

Client contracts, invoices, project files

7 years after project completion (tax & legal)

Marketing consent records

Until withdrawn + 6 years

Analytics logs

14 months (GA4 default)

We securely delete or anonymise data when it is no longer needed.


8. Security

 

We apply industry-standard controls: TLS-encrypted transport, least-privilege access, MFA on all admin accounts, daily server backups, and annual penetration testing of web assets.


9. Your rights (UK GDPR, Ch. 3)

 

You may exercise:

  1. Access – copy of your data.

  2. Rectification – correct inaccurate data.

  3. Erasure (“right to be forgotten”).

  4. Restriction of processing.

  5. Data portability (machine-readable copy).

  6. Object to processing under legitimate interests or direct marketing.

  7. Not to be subject to automated decision-making producing legal effects.

 

How to make a request

Email This email address is being protected from spambots. You need JavaScript enabled to view it. with proof of identity; we’ll respond within one month.


10. Complaints

 

If you have concerns, please contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO):

  • ico.org.uk | Tel: 0303 123 1113 | Wycliffe House, Wilmslow SK9 5AF.


11. Changes to this policy

 

We update this notice when laws or our practices change. The latest version will always be at webcraftni.com/privacy-policy; significant changes will be highlighted or emailed to clients where required.


Disclaimer: This policy is provided for general information and is not legal advice. For specific obligations, consult a qualified solicitor specialising in UK data-protection law.

  • Hits: 849