Who is responsible for your information
EasyStepDigital is the controller responsible for the personal information described in this notice. References to “we”, “us” and “our” mean EasyStepDigital.
For privacy questions, rights requests or complaints, email hello@easystepdigital.com.
Information we may collect
- Your name, business name and role.
- Your email address, telephone number and communication preferences.
- Enquiry details, including the service, budget, timing and project information you choose to provide.
- Correspondence, proposals, contracts, invoices and project records.
- Basic technical and security information, such as IP address, browser type, requested pages, timestamps and server logs.
- Cookie choices and analytics information, if optional analytics is introduced.
Please do not include special-category information—such as health, ethnicity, religion or biometric information—in an enquiry unless it is genuinely necessary.
Why we use information and our lawful bases
- To respond to enquiries and prepare proposals: steps requested before entering a contract and our legitimate interest in developing our business.
- To deliver and manage agreed services: performance of a contract.
- To administer payments and business records: performance of a contract and compliance with legal obligations.
- To secure and improve the website: our legitimate interests in operating a reliable, secure and useful service.
- To use optional analytics or send marketing: your consent where consent is legally required. You may withdraw it at any time.
- To establish or defend legal claims: our legitimate interests and compliance with legal obligations.
Submitting an enquiry does not add you to a general marketing list. If we plan to use your information for a new incompatible purpose, we will explain that purpose and identify the applicable lawful basis first.
Who we share information with
We may share relevant information with carefully selected recipients, including:
- website hosting, form, database, email, cloud-storage and IT support providers;
- payment, accounting and professional-advisory providers;
- contractors working on your project under appropriate confidentiality terms;
- regulators, courts, law-enforcement bodies or other parties where legally required;
- a buyer or successor if all or part of the business is reorganised or transferred.
Providers may only use personal information for the agreed service and must protect it appropriately. We do not sell personal information.
International transfers
Some technology providers may process information outside the United Kingdom. Where UK data protection law requires safeguards, we rely on a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism. You may contact us for information about the safeguard relevant to your data.
How long we keep information
- General enquiries that do not become projects: normally up to 12 months.
- Client, contract, payment and project records: normally six years after the relationship ends, unless law or a dispute requires longer.
- Security and diagnostic logs: normally no longer than 12 months.
- Consent records: while the consent is relied upon and as needed to evidence it.
We may keep anonymised information that can no longer identify an individual. Retention may be shortened or extended where necessary because of legal, regulatory, security or dispute-resolution requirements.
How we protect information
We use proportionate technical and organisational measures intended to prevent accidental loss, unauthorised access, alteration or disclosure. Access is limited to people and providers who need the information for an authorised purpose. No internet service can be guaranteed completely secure, so please avoid sending unnecessary confidential material through the initial enquiry form.
Your data protection rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal information;
- ask us to correct incomplete or inaccurate information;
- ask us to erase information in certain circumstances;
- ask us to restrict how information is used;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent;
- object to processing based on legitimate interests or direct marketing;
- complain about how your information has been handled.
Email us to exercise a right. We may need to confirm your identity and clarify your request. We normally respond within one month. Rights can be subject to legal limitations and exemptions.
Complaints
Please contact us first so we can investigate your concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.
Children and automated decisions
Our services are intended for businesses and are not directed at children. We do not knowingly collect children’s information through this website. We do not make solely automated decisions about website visitors that produce legal or similarly significant effects.
Cookies, other websites and changes
Read our cookie notice for information about cookies and similar technology. Links to third-party websites are provided for convenience; their operators are responsible for their own privacy practices.
We may update this notice when our services, providers or legal obligations change. The latest version will be published here with a revised update date.