Legal
Privacy policy
We collect the details you give us and a little technical data to run the site. We use it to reply to you and to run the business. We never sell it, and you can ask to see, change or delete it at any time.
1. Who we are
Made Digital is the trading name of Made Digital UK Ltd (“we”, “us”, “our”), a limited company registered in England and Wales. We design and build websites for small businesses, tradespeople and growing companies, and we look after them once they’re live. Our registered office and correspondence address is 66 Paul Street, London, EC2A 4NA.
For the purposes of UK data protection law, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Made Digital UK Ltd is the data controller of the personal data described in this policy.
- Company registration number: 17259143, registered in England and Wales.
- ICO registration number: ZC166442. You can check it at ico.org.uk.
This policy covers personal data we collect through this website, through enquiries and client work, and through our business development. For questions about it, or to exercise your rights, email privacy@made-digital.co.uk.
2. The data we collect
- Identity and contact data. Your name, business name, email address and phone number, given through a form on this site, by email or on the phone.
- Enquiry data. What you tell us about the business, the website you’ve got, and what you’re looking for. Each form also records the page it was sent from and the time. If you came from the demo on the Trade Site page, the trade, colour and business name you picked there come with it.
- Communications data. The content of emails, calls and messages between us, including the notes we keep of a call.
- Business contact data, for prospecting. Publicly available business contact details (a name, a role, a business email or phone number) taken from company websites, directories or professional platforms, so that we can get in touch about our services. We collect this at a business level, and don’t target private individuals. Section 5 has the detail.
- Technical data. Your IP address, browser and device, time zone and approximate location, collected automatically by our hosting provider’s server logs, and by cookies where you’ve allowed them.
- Usage data. How you use the site, collected through analytics cookies only where you’ve given consent.
We don’t set out to collect special category data (health, ethnicity, religion and the like). Please don’t put sensitive personal details in an enquiry. Our services are for businesses, and we don’t knowingly collect data from anyone under 18.
3. How we collect it
- From you, when you fill in a form on this site, email us, ring us, or get in touch another way.
- Automatically, as you use the site, through server logs and, with your consent, cookies. The cookie policy lists them.
- From public business sources: company websites, Companies House, business directories, professional networks and public listings, where we’ve identified a business that could use what we do. Business contact information only, never personal details about a private individual. See section 5.
- From a third party, occasionally: a referral or a recommendation from somebody who’s entitled to pass your details on.
4. Why we use it, and the lawful basis
UK GDPR requires a lawful basis for each use of personal data. Ours are:
- Replying to your enquiry and giving you a price. Our legitimate interest in responding to businesses that contact us, and steps taken at your request before a contract.
- Doing the work for clients. Performance of a contract.
- Business development and outreach. Our legitimate interest in telling businesses that are likely to benefit about our services, balanced against their rights. Section 5 explains how.
- Marketing to existing contacts. Your consent, or our legitimate interest under the “soft opt-in” that PECR allows for existing clients. Section 5.
- Analytics cookies. Your consent, as PECR requires.
- Legal and accounting obligations. Compliance with a legal obligation.
- Keeping the site and the business secure. Our legitimate interest in preventing fraud and misuse.
Where we rely on legitimate interests, we’ve weighed the effect on your rights and we don’t use your data in ways you wouldn’t reasonably expect. You can ask us about that assessment at any time.
5. Business development and marketing
Prospecting
As a working web design business we contact other businesses to introduce what we do, where there’s reasonable ground to think it fits. That’s ordinary business-to-business sales, and it’s separate from marketing to consumers.
To do it we may process publicly available business contact information, such as a name and role, a business phone number or a business email address, from sources including:
- company websites and their contact pages;
- Companies House public records;
- online business directories, such as Google Business Profile, Yell or a trade directory;
- professional networking platforms;
- public social media business profiles;
- referrals from existing clients or professional contacts.
We use it only to make first contact, by email or phone, about our website and digital services. The lawful basis is our legitimate interests under UK GDPR, and the business-to-business provisions of PECR for electronic messages. We’ve assessed this against your rights and interests and are satisfied that our outreach is reasonable and proportionate.
If we’ve contacted you and it isn’t relevant to you or your business, we’re sorry. Tell us and we’ll remove your details promptly. You have the absolute right to object to this processing at any time. See section 11.
Marketing to existing contacts
If you’ve enquired about or bought our services, we may occasionally tell you about related services. We do that on the basis of our legitimate interests, under PECR’s soft opt-in. Every message carries a clear way to opt out, and we honour it promptly.
We never sell or rent your contact details, and we never send marketing on behalf of another business.
How to opt out or object
- Reply to any email or message and ask to be removed; or
- email privacy@made-digital.co.uk.
Opting out of marketing doesn’t stop the messages that a live project needs.
6. Cookies and analytics
This site sets one strictly necessary cookie, which remembers your cookie choice. Analytics (Google Analytics and Microsoft Clarity) runs only after you’ve accepted it through our consent sheet, and you can withdraw that from the footer of any page. No marketing cookie is set.
The website also keeps daily totals of taps on its call, email and WhatsApp buttons, and of how far people get through its forms and the Trade Site demo, with no names, nothing typed into a form and no other personal details in them. The cookie policy explains how, and how to opt out.
The cookie policy names every cookie, what it’s for and how long it lasts.
7. Who we share it with
We don’t sell personal data. We share it only with the providers we need to run the business. Where they act as our processors, they do so under a contract that requires them to keep your data secure and use it only on our instructions:
- Our hosting provider, which hosts this website and delivers the emails that its forms send to us.
- Google Analytics, to understand how the site is used, where you’ve consented.
- Microsoft Clarity, a behavioural analytics tool run by Microsoft Corporation (USA) which, with your consent, sets cookies and may record anonymised session replays, heatmaps, clicks and scroll depth. It runs only after you’ve accepted analytics. Microsoft processes the data under its own privacy terms and the UK IDTA.
- Stripe, our payment provider, which takes deposits, balances and monthly plan payments. Card details are entered on Stripe’s own pages and are never held by us.
- Microsoft 365 and OneDrive, where our own business files, including client and enquiry records, are stored and backed up.
- Anthropic, whose software assistant we use to help research businesses, prepare proposals and draft correspondence. Where we do, it may process the business and contact details described above.
- Professional advisers, such as our accountant or a solicitor, where necessary.
- Regulators, law enforcement and other authorities, where the law requires it.
Separately, where we host or maintain a website for a client, any personal data belonging to that client’s own customers is processed by us only on the client’s instructions. In that relationship the client is the controller and we are their processor.
8. International transfers
We aim to keep personal data in the UK. Some of our providers may process it elsewhere. Where they do, an appropriate safeguard is in place: a country covered by UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. Ask us for the detail if you’d like it.
9. How long we keep it
- Enquiries that don’t become projects: up to 12 months from our last contact, then securely deleted or anonymised.
- Client records: for the length of the work and up to 6 years after, for legal, tax and accounting obligations and any dispute.
- Signed agreements and payment records: for the length of the work and at least 6 years after, unaltered, because they are the record of what was agreed and paid and we may need to produce them for HMRC or in a dispute. We review them and delete those no longer needed.
- Marketing preferences: for as long as you’re subscribed, plus a suppression record so that an opt-out stays honoured.
When data is no longer needed, we securely delete or anonymise it.
10. How we protect it
Appropriate technical and organisational measures: encrypted (TLS) connections to the site, access controls, and reputable providers only. No transmission over the internet is completely secure, so we can’t promise absolute security. We have a procedure for a suspected personal data breach, and we’ll notify you and the ICO where the law requires it.
11. Your rights
Under UK data protection law you have these rights, free of charge in most cases:
- Access: a copy of the personal data we hold about you.
- Rectification: inaccurate or incomplete data corrected.
- Erasure: your data deleted where there’s no good reason for us to keep it.
- Restriction: how we use your data limited, in certain circumstances.
- Objection: to processing based on our legitimate interests, and to direct marketing at any time.
- Portability: certain data in a structured, machine-readable format.
- Withdrawing consent: where we rely on consent, at any time, without affecting what was done before.
We don’t carry out automated decision-making or profiling with legal or similarly significant effects. To exercise a right, contact us using section 15. We’ll respond within one month, and may need to confirm your identity first.
12. How to complain
If you’re concerned about how we’ve handled your data, please tell us first; we’d rather put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13. Other websites
This site links to other websites, including the live client sites in our work. This policy applies only to made-digital.co.uk. We’re not responsible for the privacy practices of other sites, and we’d encourage you to read the policy of any site you visit.
14. Changes to this policy
We may update this policy as our practices or the law change. Changes are posted here with a new date at the top. Where a change is significant, we’ll take reasonable steps to bring it to your attention.
15. How to contact us
For questions about this policy, to exercise your rights, or to object to marketing, use our privacy address: privacy@made-digital.co.uk. Or ring 07375 347 947.
Made Digital UK Ltd, 66 Paul Street, London, EC2A 4NA. Company number 17259143, registered in England and Wales.