Privacy Policy
Privacy Policy (UK GDPR & Data Protection Act 2018)
Last updated: 19 June 2025
1. Who we are
WebCraft NI (“we”, “us”, “our”) is a web-development and digital-marketing studio registered in Northern Ireland. We act as the data controller for the personal data described below.
Contact for data matters
-
Email:
This email address is being protected from spambots. You need JavaScript enabled to view it. -
Tel: +44 7708 878 062
2. Personal data we collect
|
Category |
Typical items |
How we obtain it |
|---|---|---|
|
Enquiry & account data |
Name, job title, company, email, phone, website URL, project brief, budget band |
Directly from you via our “Start Here” form, email, phone or meetings |
|
Marketing preferences |
Newsletter opt-in, communication channel choices |
Directly from you (checkboxes, profile updates) |
|
Technical data |
IP address, device type, browser, operating system, referring site, pages viewed, time on site |
Automatically via cookies, server logs, Google Analytics 4 |
|
Cookie data |
Cookie ID, consent status |
Via our consent banner & your device |
|
Client project data |
CMS log-in details, design assets, end-user data you lawfully supply to us |
From you under a separate data-processing agreement |
We do not intentionally collect special-category data (e.g. health, race) or children’s data. Please avoid sending it to us.
3. Why we use your data & lawful bases
|
Purpose |
Lawful basis (UK GDPR Art. 6) |
Details |
|---|---|---|
|
Responding to enquiries & providing a FREE 30-min Digital Growth Audit |
Art. 6 (1)(b) Contract |
Pre-contractual steps at your request |
|
Delivering client projects & support |
Art. 6 (1)(b) Contract |
Fulfilling our service agreement |
|
Issuing invoices & maintaining tax records |
Art. 6 (1)(c) Legal obligation |
HMRC record-keeping (6 years) |
|
Sending service emails (e.g. project status) |
Art. 6 (1)(b) Contract |
Legitimate operational communication |
|
Email marketing & newsletters |
Art. 6 (1)(a) Consent (PECR soft-opt-in where applicable) |
You may withdraw consent at any time |
|
Site analytics & performance optimisation |
Art. 6 (1)(f) Legitimate interests |
Understanding and improving how visitors use our site |
Where we rely on legitimate interests, we balance our interests against your rights and expect minimal privacy impact (e.g. anonymous analytics).
4. Cookies & similar technologies
We use first-party cookies, Google Analytics 4 and Meta Pixel. On your first visit a banner asks for consent to non-essential cookies; essential cookies are required for site security and core functionality. Full details are in our Cookie Notice.
5. Who we share data with
|
Recipient |
Reason |
Safeguards |
|---|---|---|
|
Website & email hosting providers (Krystal, Google Workspace) |
Data storage, email transport |
UK/EU servers; UK GDPR-compliant DPA |
|
Analytics vendors (Google Analytics 4) |
Aggregate usage statistics |
IP-anonymisation; EU-US Data Privacy Framework |
|
Payment processor (Stripe) |
Card payments for hosting retainers |
PCI-DSS compliance |
|
Sub-contractors & freelancers |
Project delivery |
Confidentiality & GDPR clauses in contracts |
|
Legal / regulatory bodies (ICO, HMRC) |
Compliance with law |
Data disclosed only when required |
We never sell or lease your personal data.
6. International transfers
Some suppliers (e.g. Google LLC, Stripe) store data in the United States. Transfers are protected by:
-
Adequacy regulations (EU-US Data Privacy Framework) or
-
Standard Contractual Clauses (SCCs) + supplementary measures.
7. Data retention
|
Data type |
Retention period |
|---|---|
|
Enquiry leads (no purchase) |
24 months after last contact |
|
Client contracts, invoices, project files |
7 years after project completion (tax & legal) |
|
Marketing consent records |
Until withdrawn + 6 years |
|
Analytics logs |
14 months (GA4 default) |
We securely delete or anonymise data when it is no longer needed.
8. Security
We apply industry-standard controls: TLS-encrypted transport, least-privilege access, MFA on all admin accounts, daily server backups, and annual penetration testing of web assets.
9. Your rights (UK GDPR, Ch. 3)
You may exercise:
-
Access – copy of your data.
-
Rectification – correct inaccurate data.
-
Erasure (“right to be forgotten”).
-
Restriction of processing.
-
Data portability (machine-readable copy).
-
Object to processing under legitimate interests or direct marketing.
-
Not to be subject to automated decision-making producing legal effects.
How to make a request
Email
10. Complaints
If you have concerns, please contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO):
-
ico.org.uk | Tel: 0303 123 1113 | Wycliffe House, Wilmslow SK9 5AF.
11. Changes to this policy
We update this notice when laws or our practices change. The latest version will always be at webcraftni.com/privacy-policy; significant changes will be highlighted or emailed to clients where required.
Disclaimer: This policy is provided for general information and is not legal advice. For specific obligations, consult a qualified solicitor specialising in UK data-protection law.
- Hits: 849



