1. Information We Collect
We collect personal and business details voluntarily submitted via our interactive project brief builder, contact forms, booking system, or payment checkout:
- Contact & Identity Data: Full name, email address, phone number, business name, and current website URL.
- Project Briefs & Uploads: Requirements, target audience, budget ranges, timelines, billing preferences, and uploaded inspiration images/assets.
- Messaging & Enquiry Data: Preferred contact channel (email or direct message), messaging handles, project topics, and the messages you send us. All project communication is handled by email or direct messaging.
- Transaction Data: Billing details and payment records processed securely via external payment providers (raw card details are never stored).
- Technical & Usage Data: IP address, browser type, device information, and interaction metrics collected via functional cookies.
2. Legal Basis & How We Use Your Information
Under UK GDPR, we process personal data under the following lawful bases:
- Performance of a Contract: Processing project briefs, generating quotes, completing website builds, and managing hosting/maintenance.
- Legitimate Interests: Responding to project inquiries, optimizing site performance, preventing fraud, and operating our studio efficiently.
- Legal Obligations: Complying with HMRC tax regulations, accounting standards, and network security laws.
- Consent: Sending promotional updates or portfolio highlights where explicitly requested (consent can be withdrawn at any time).
3. Data Storage, Security & Retention
- Security: Data submitted via form workflows is encrypted in transit (TLS/SSL) and stored securely in restricted-access cloud infrastructure (e.g., Supabase / Encrypted DBs). Access is limited strictly to authorized team members.
- Retention: Non-converting project inquiries are purged or anonymized within 12 months. Client project, contract, and accounting records are retained for up to 6 years following contract termination to comply with UK HMRC obligations.
4. Third-Party Service Processors
We share necessary data with trusted third-party data processors operating in compliance with UK GDPR standards:
- Hosting & Infrastructure: Vercel / Netlify / AWS (website hosting and asset delivery).
- Database Services: Supabase (secure form records and project brief management).
- Payment Processing: Stripe (PCI-DSS Level 1 compliant checkout and billing).
- Email Delivery: Postmark / Resend / SendGrid (transactional notifications and automated brief confirmations).
We do not sell, rent, or trade personal data to third parties for marketing purposes.
5. Your Legal Rights Under UK Law
Under the UK Data Protection Act 2018 and UK GDPR, you have the right to request access to, rectification of, or erasure of your personal data; restrict or object to processing; and request data portability. To exercise these rights, contact our Data Lead. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
6. Contact Details
For privacy requests or data enquiries, contact:
Data Protection Lead — Harvey Designs
harveyddesigns@gmail.com