Legal
Privacy Policy
How Build Bros Ltd collects, uses and protects your personal data under UK GDPR, including your rights and how to contact us. Version 1.0.
1. Who we are
Build Bros Ltd ("we", "us", "our") is a web design and development company registered in England and Wales.
- Company name: Build Bros Ltd
- Company registration number: 17443193
- Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
- Website: build-bros.co.uk
- Email: hello@build-bros.co.uk
- Phone: 020 8064 3071
We are the data controller for the personal data described in this policy. We are also a data processor for some personal data belonging to our clients' own website visitors, which is covered in section 10.
This policy explains what personal data we collect, why we collect it, how long we keep it and what rights you have. It applies to build-bros.co.uk and to our dealings with enquirers, clients and suppliers.
2. What personal data we collect
2.1 When you send us an enquiry
Through our contact form or by email we collect your name, your email address, your phone number (optional), your company name (optional), your indicated budget range (optional), which package you are interested in (optional), the content of your message, the date and time of the enquiry, and your IP address and browser user agent, collected for spam prevention and security.
2.2 When you book a consultation
Through our booking page we collect your name, your email address, your phone number (optional), your company name (optional), which package you are interested in (optional), any notes you provide about your enquiry, the date and time slot you select, your IP address for spam prevention and rate limiting, and confirmation that you verified your email address, and when.
2.3 When you have a customer portal account
If you become a client we create an account for you. We hold:
- Your name, email address, phone number and business name
- Your password, stored only as a secure one-way hash which we cannot read
- Any passkey credential you choose to register, and, if you sign in with Google, the Google account identifier and email address associated with it
- Your responses to our onboarding questionnaire about your business, goals, customers, competitors, style preferences, existing assets and domain or hosting details
- A record of your acceptance of our Terms of Business, including the version accepted, the date and time, your IP address and your browser user agent
- Messages, files and images you upload to your project workspace
- Approval decisions and comments you make, together with the date, time and IP address
- Your orders, invoices and payment status
- Login records and security events
2.4 When you pay us
Card payments are processed by Stripe and PayPal. We do not receive or store your full card number, expiry date or security code. We receive and store a payment reference, the amount, the currency, the payment status and, where the payment provider supplies it, the last four digits and card type, plus your billing name and address.
2.5 When you visit our website
- Essential technical data, including your IP address, browser type and pages requested, processed in our hosting provider's server logs to keep the site running and protected.
- No analytics: we do not currently use analytics or tracking tools on our website. See our Cookie Policy.
2.6 Data we do not collect
We do not knowingly collect data from children. We do not collect special category data (such as health, ethnicity, religious belief or biometric data) and ask that you do not send it to us. We do not buy marketing lists.
3. Why we use your data, and our lawful basis
| What we do | Data used | Lawful basis under UK GDPR |
|---|---|---|
| Reply to your enquiry | Contact form and email data | Legitimate interests (Art. 6(1)(f)): responding to a request you made of us |
| Take and manage a consultation booking | Booking data | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Verify your email before holding a slot | Email address, IP, timestamp | Legitimate interests: preventing fraudulent and abusive bookings |
| Prevent spam and abuse | IP address, user agent, submission timing | Legitimate interests: security and service integrity |
| Provide our services and run your project | Account, questionnaire, project workspace data | Performance of a contract (Art. 6(1)(b)) |
| Record acceptance of our Terms of Business | User, version, timestamp, IP, user agent | Legal obligation (Art. 6(1)(c)) and legitimate interests: evidencing agreement |
| Issue and collect invoices, take payment | Order, invoice and payment data | Performance of a contract, and legal obligation for tax records |
| Keep accounting and tax records | Invoice and payment data | Legal obligation (Art. 6(1)(c)) |
| Send service emails about your project | Account and project data | Performance of a contract |
| Send marketing emails, if we offer them | Name and email address | Consent, or the soft opt-in for existing clients under PECR, with an unsubscribe link in every message |
| Defend or bring a legal claim | Any relevant data | Legitimate interests: establishing, exercising or defending legal claims |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and concluded they are not, because the processing is what you would reasonably expect and is limited to what is necessary. You can ask us for details of that assessment.
4. Who we share your data with
We do not sell your personal data and we never will. We share it only with service providers who help us run the business, and only as far as needed.
| Provider | What they do | Data involved | Where |
|---|---|---|---|
| Alpha Internet Limited (Zume) | Hosts our website, database and files | All data stored by the site | United Kingdom |
| Cloudflare, Inc. | Spam protection (Turnstile) on our contact and booking forms | IP address and browser data used for the spam check | Global network, including the UK, EU and USA |
| Stripe Payments Europe, Ltd. | Card payments and subscription billing | Name, email, billing address, payment data | EU and USA |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | One-off payments by PayPal | Name, email, payment data | EU and USA |
| Google (sign-in), where used | Optional account sign-in | Email address, Google account identifier | EU and USA |
| Alpha Internet Limited (Zume) | Runs the mail server that sends and receives our emails | Name, email address, message content | United Kingdom |
We may also disclose data where we are legally required to, for example to HMRC, a regulator, or a court.
International transfers
Some providers process data outside the UK. Where that happens, transfers are protected by UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards. You can ask us which mechanism applies to a particular provider.
5. How long we keep your data
| Data | Retention period |
|---|---|
| Enquiries that do not become clients | 24 months from the last contact, then deleted |
| Consultation bookings that do not become clients | 24 months from the booking date |
| Unverified bookings | Deleted automatically once the verification link expires and the record is cleared |
| Client account and project records | For the duration of the relationship and 6 years after the final invoice |
| Invoices, payments and accounting records | 6 years from the end of the accounting period, as required by UK tax law |
| Terms of Business acceptance records | 6 years after the relationship ends, as evidence of agreement |
| Project chat messages and uploaded files | For the duration of the relationship and 12 months after project completion, unless you ask us to delete them sooner |
| Approval audit records | 6 years, because they evidence what was agreed |
| Server and security logs | 14 days, then deleted automatically |
| Marketing consent records | Until you withdraw consent, plus 24 months to evidence the withdrawal |
When a retention period ends we delete the data or anonymise it so it can no longer identify you.
6. How we protect your data
- All traffic to and from our website is encrypted with HTTPS.
- Passwords are stored as salted one-way hashes and are never readable by us.
- Administrator accounts require two-factor authentication.
- Two-factor secrets and recovery codes are encrypted at rest.
- Access to client data is limited to the people who need it to do the work.
- Backups are taken regularly and stored securely.
- We patch our systems and monitor for security issues.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.
7. Cookies
We use a small number of essential cookies to make the site work. We do not currently use analytics cookies, and if we ever introduce them, nothing will load unless you agree. Full details are in our Cookie Policy.
8. Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data, which is what this policy is for.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data where there is no continuing lawful reason for us to hold it.
- Restrict processing in certain circumstances, for example while a dispute about accuracy is resolved.
- Data portability, receiving data you provided to us in a common machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time, which we will always honour.
- Withdraw consent at any time where we rely on consent, without affecting processing carried out before you withdrew it.
- Not be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not carry out such processing.
To exercise any of these rights, email hello@build-bros.co.uk. We will respond within one month. There is normally no charge. We may ask you to confirm your identity before we release personal data, which protects you as much as us.
9. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at hello@build-bros.co.uk so we can try to put it right.
You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
10. Data we process on behalf of our clients
Where we build or maintain a website for a client, that client is the data controller for their own website visitors' data and we act as their data processor. In that role we:
- process personal data only on the client's documented instructions;
- ensure that anyone with access is bound by confidentiality;
- apply appropriate technical and organisational security measures;
- do not engage a sub-processor without the client's general or specific authorisation;
- assist the client with data subject requests, breach notification and impact assessments so far as we reasonably can;
- delete or return the personal data at the end of the engagement, unless we are legally required to keep it.
These obligations are set out in full in our Terms of Business.
If you are a visitor to a website we built for someone else, that business is responsible for your data and you should contact them directly.
11. Changes to this policy
We may update this policy as our services or the law change. The version number and "last updated" date at the top will always tell you which version you are reading. If a change materially affects how we use your data, we will tell affected clients directly.
12. Contact us
Email: hello@build-bros.co.uk
Post: Build Bros Ltd, 128 City Road, London, United Kingdom, EC1V 2NX
Phone: 020 8064 3071
Questions about this page? Email hello@build-bros.co.uk.
Questions about your data?
Ask us. We will give you a straight answer in plain English, the same as we do about everything else.