Privacy policy

A template. Have it reviewed against the laws that apply where your clients are before publishing.

This is a placeholder. You serve clients across several jurisdictions, which means GDPR and UK GDPR for European clients, state privacy laws for US clients, and PIPEDA in Canada. Have a lawyer review this before it goes live — a generic policy copied from another site is a genuine liability, not a formality.

What this policy should cover

What we collect. Contact details submitted through forms, analytics data, cookies and any information shared during an engagement.

Why we collect it. Responding to enquiries, delivering services, improving the site, and legal or accounting obligations.

Legal basis. Required under GDPR for European visitors — consent, contract or legitimate interest, stated per purpose.

Who we share it with. Named processors: analytics, email, CRM, hosting. Including any transfers outside the visitor's own jurisdiction.

How long we keep it. Specific retention periods, not “as long as necessary.”

Your rights. Access, correction, deletion, portability and objection, plus how to exercise them and how to complain to a regulator.

Cookies. What is set, by whom, for what, and how to refuse non-essential ones.

Contact. A working address for privacy requests.

Questions about how we handle data?

Ask us directly. We will tell you exactly what we store and where.

Contact us