Privacy Policy
Last updated: 24 August 2026
1. Introduction
This Privacy Policy describes the personal data we collect through our website and our services, how we use and share it, the lawful bases we rely on, how long we keep it, and the rights available to you. It should be read alongside our Terms and Conditions and our Cookie Policy.
We respect your right to privacy and will only process personal data in accordance with the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
2. Who We Are
- Our website address is supradigital.co.uk
- Our company name is Supra Digital Ltd, registered in England and Wales, company number 15189445
- Our registered address is Suites 10–12 The Hive, Bell Lane, Stevenage, Hertfordshire, SG1 3HW
- Our trading address is Kings Court, London Road, Stevenage, Hertfordshire, SG1 2NG
- Our VAT number is GB452322619
- Our nominated representative for data protection is Matthew Woods, contactable at [email protected]
We are the data controller for personal data collected through this website and for data about our own clients and prospective clients. Where we handle personal data on behalf of a client as part of delivering our services, we act as a processor. See section 9.
3. What We Collect
We may collect, use, store and transfer the following kinds of personal data about you:
- Identity Data – first name, last name, job title, company name
- Contact Data – billing address, email address and telephone numbers
- Transaction Data – details of services purchased, invoices, and records of payments made to us
- Technical Data – IP address, browser type and version, time zone, operating system and device information
- Usage Data – information about how you use our website and services
- Communications Data – the content of enquiries, emails and live chat conversations with us
- Marketing Data – your preferences in receiving marketing from us
Payment details. We do not collect or store your card or bank details. Online payments are processed by our payment provider, Stripe, which handles card data directly under its own privacy notice. We receive only a confirmation of payment and limited transaction metadata.
We do not seek to collect any special category data (such as data about race, ethnicity, religious beliefs, health, genetic or biometric data), and we ask that you do not send us such information unless we have specifically asked for it.
4. Lawful Bases for Processing
Under Article 6 of the UK GDPR, we must have a lawful basis for each processing activity. The bases we rely on are set out below.
| What we do | Lawful basis |
|---|---|
| Responding to an enquiry made through our website, email, phone or live chat | Legitimate interests (responding to people who contact us), or steps prior to entering a contract |
| Providing our services and administering our contract with you | Performance of a contract |
| Issuing invoices, taking payment and keeping accounting records | Performance of a contract, and legal obligation for tax and accounting records |
| Sending marketing emails to individuals | Consent, which you may withdraw at any time |
| Sending marketing about similar services to existing business clients | Legitimate interests, subject to your right to opt out at any time |
| Analytics, session recording and improving our website | Consent, given through our cookie banner |
| Website security, fraud prevention and maintaining service availability | Legitimate interests (protecting our business and our users) |
| Keeping records to establish, exercise or defend legal claims | Legitimate interests, and legal obligation where applicable |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms. You can ask us for details of that assessment.
5. Categories of Recipients
We do not sell your personal data. We share it with the categories of recipient below. Most act as processors, handling data only on our instructions and under contract. Some act as controllers in their own right, meaning they decide how they use the data under their own privacy notices. Where that is the case it is noted below.
- Hosting and infrastructure providers – Railway (application and database hosting), Cloudflare (content delivery and security), and 20i (hosting and email). Processors acting on our instructions
- Productivity and document storage – Google (Google Workspace and Google Drive), which holds client and prospect contact details, proposals, contracts and correspondence. Processor acting on our instructions
- Accounting – Sage (Sage Accounting Cloud), which holds accounting records including client contact and transaction data. Processor acting on our instructions
- Analytics providers – Google (Google Analytics) and Microsoft (Clarity), where you have consented. Processors acting on our instructions
- Communication and email providers – Resend, for transactional and notification email. Processor acting on our instructions
- AI service providers – Anthropic, which processes live chat messages to generate responses in our website chat assistant. Processor acting on our instructions
- Payment providers – Stripe, which acts as an independent controller for payment data under its own privacy notice, and GoCardless for Direct Debit collection once live, which likewise acts as an independent controller
- Advertising platforms – Google and Meta, where advertising campaigns are running. These act as controllers in their own right
- Professional advisers – accountants, insurers and lawyers where necessary. These act as independent controllers
- Regulators and authorities – where we are required to disclose information by law. These do not act on our instructions
6. International Transfers
Some of the providers listed above are based outside the United Kingdom, or store data outside the UK, including in the United States and the European Economic Area.
Where personal data is transferred outside the UK, we ensure a similar degree of protection by relying on one of the following safeguards:
- transfer to a country the UK Government has determined provides an adequate level of protection; or
- the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required.
You can request further information about the safeguards applied to a specific transfer by contacting us.
7. How Long We Keep Data
We keep personal data only for as long as we need it for the purposes set out in this policy. In practice:
- Enquiries that do not become clients – up to 24 months from your last contact with us, then deleted
- Client records and contracts – for the life of the relationship and 6 years afterwards, to deal with any legal claims
- Accounting and tax records – 6 years from the end of the relevant accounting period, as required by HMRC
- Marketing preferences and opt-outs – retained indefinitely so we can honour your choice not to be contacted
- Live chat transcripts – up to 24 months
- Analytics data – in line with the retention settings of the relevant provider, usually no more than 14 months
If you ask us to erase your data, we will do so unless we are required or entitled to keep it, for example to comply with our legal obligations to retain accounting records or to establish, exercise or defend a legal claim. Where we cannot erase everything, we will tell you what we are keeping and why, and we will restrict our use of it to that purpose.
8. Data Security
We have put in place appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These include encryption in transit, access controls, and limiting access to those employees, contractors and providers who have a business need to know.
We have procedures to deal with any suspected personal data breach, and will notify you and the ICO where we are legally required to do so.
9. When We Act as a Processor
When we deliver services to clients, for example managing a website, CRM, advertising account or mailing list, we often handle personal data belonging to that client's own customers or contacts. In those circumstances the client is the controller and we act as processor.
As processor we will:
- process personal data only on the client's documented instructions;
- ensure that people authorised to process the data are subject to confidentiality obligations;
- apply appropriate technical and organisational security measures;
- engage sub-processors under a general authorisation, giving the client at least 30 days' notice before a new sub-processor begins processing, and allowing the client to object on reasonable data protection grounds;
- assist the client in responding to data subject rights requests;
- assist with breach notification and data protection impact assessments; and
- delete or return the personal data at the end of the engagement, unless required by law to retain it.
We enter into a written data processing agreement with clients as required by Article 28 of the UK GDPR. A copy, together with our list of sub-processors, is available on request from [email protected].
10. Your Rights
Under data protection law you have the right to:
- be informed about how your personal data is used;
- request access to a copy of your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of your data in certain circumstances;
- request restriction of processing;
- object to processing based on legitimate interests, and to direct marketing at any time;
- request transfer of your data to you or another provider (data portability); and
- withdraw consent at any time, where we rely on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at [email protected]. We will respond within one month. If your request is complex, we may extend that by up to two further months and will tell you if so. There is normally no fee.
11. Complaints
If you are unhappy with how we have handled your personal data, you have the right to complain to us, and we must acknowledge your complaint within 30 days of receiving it and respond without undue delay. Please send complaints to [email protected], marking them as a data protection complaint.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at any time. You do not have to contact us first. The ICO can be reached at ico.org.uk or on 0303 123 1113.
12. Cookies
We use cookies and similar technologies on this website. Full details of the cookies we set, their purposes and durations, and how to manage your preferences, are in our Cookie Policy.
13. Changes to This Policy
If we change this Privacy Policy we will post the updated version on this page with a revised date. Where changes are significant, we will take reasonable steps to bring them to your attention.
14. Governing Law
This Privacy Policy, and any dispute or claim relating to it, is governed by and construed in accordance with the laws of England and Wales.