Skip to content
Build Bros Ltd logo Build Bros

Legal

Privacy Policy

How Build Bros Ltd collects, uses and protects your personal data under UK GDPR, including your rights and how to contact us. Version 1.0.

1. Who we are

Build Bros Ltd ("we", "us", "our") is a web design and development company registered in England and Wales.

  • Company name: Build Bros Ltd
  • Company registration number: 17443193
  • Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
  • Website: build-bros.co.uk
  • Email: hello@build-bros.co.uk
  • Phone: 020 8064 3071

We are the data controller for the personal data described in this policy. We are also a data processor for some personal data belonging to our clients' own website visitors, which is covered in section 10.

This policy explains what personal data we collect, why we collect it, how long we keep it and what rights you have. It applies to build-bros.co.uk and to our dealings with enquirers, clients and suppliers.

2. What personal data we collect

2.1 When you send us an enquiry

Through our contact form or by email we collect your name, your email address, your phone number (optional), your company name (optional), your indicated budget range (optional), which package you are interested in (optional), the content of your message, the date and time of the enquiry, and your IP address and browser user agent, collected for spam prevention and security.

2.2 When you book a consultation

Through our booking page we collect your name, your email address, your phone number (optional), your company name (optional), which package you are interested in (optional), any notes you provide about your enquiry, the date and time slot you select, your IP address for spam prevention and rate limiting, and confirmation that you verified your email address, and when.

2.3 When you have a customer portal account

If you become a client we create an account for you. We hold:

  • Your name, email address, phone number and business name
  • Your password, stored only as a secure one-way hash which we cannot read
  • Any passkey credential you choose to register, and, if you sign in with Google, the Google account identifier and email address associated with it
  • Your responses to our onboarding questionnaire about your business, goals, customers, competitors, style preferences, existing assets and domain or hosting details
  • A record of your acceptance of our Terms of Business, including the version accepted, the date and time, your IP address and your browser user agent
  • Messages, files and images you upload to your project workspace
  • Approval decisions and comments you make, together with the date, time and IP address
  • Your orders, invoices and payment status
  • Login records and security events

2.4 When you pay us

Card payments are processed by Stripe and PayPal. We do not receive or store your full card number, expiry date or security code. We receive and store a payment reference, the amount, the currency, the payment status and, where the payment provider supplies it, the last four digits and card type, plus your billing name and address.

2.5 When you visit our website

  • Essential technical data, including your IP address, browser type and pages requested, processed in our hosting provider's server logs to keep the site running and protected.
  • No analytics: we do not currently use analytics or tracking tools on our website. See our Cookie Policy.

2.6 Data we do not collect

We do not knowingly collect data from children. We do not collect special category data (such as health, ethnicity, religious belief or biometric data) and ask that you do not send it to us. We do not buy marketing lists.

3. Why we use your data, and our lawful basis

What we doData usedLawful basis under UK GDPR
Reply to your enquiryContact form and email dataLegitimate interests (Art. 6(1)(f)): responding to a request you made of us
Take and manage a consultation bookingBooking dataSteps taken at your request prior to entering a contract (Art. 6(1)(b))
Verify your email before holding a slotEmail address, IP, timestampLegitimate interests: preventing fraudulent and abusive bookings
Prevent spam and abuseIP address, user agent, submission timingLegitimate interests: security and service integrity
Provide our services and run your projectAccount, questionnaire, project workspace dataPerformance of a contract (Art. 6(1)(b))
Record acceptance of our Terms of BusinessUser, version, timestamp, IP, user agentLegal obligation (Art. 6(1)(c)) and legitimate interests: evidencing agreement
Issue and collect invoices, take paymentOrder, invoice and payment dataPerformance of a contract, and legal obligation for tax records
Keep accounting and tax recordsInvoice and payment dataLegal obligation (Art. 6(1)(c))
Send service emails about your projectAccount and project dataPerformance of a contract
Send marketing emails, if we offer themName and email addressConsent, or the soft opt-in for existing clients under PECR, with an unsubscribe link in every message
Defend or bring a legal claimAny relevant dataLegitimate interests: establishing, exercising or defending legal claims

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and concluded they are not, because the processing is what you would reasonably expect and is limited to what is necessary. You can ask us for details of that assessment.

4. Who we share your data with

We do not sell your personal data and we never will. We share it only with service providers who help us run the business, and only as far as needed.

ProviderWhat they doData involvedWhere
Alpha Internet Limited (Zume)Hosts our website, database and filesAll data stored by the siteUnited Kingdom
Cloudflare, Inc.Spam protection (Turnstile) on our contact and booking formsIP address and browser data used for the spam checkGlobal network, including the UK, EU and USA
Stripe Payments Europe, Ltd.Card payments and subscription billingName, email, billing address, payment dataEU and USA
PayPal (Europe) S.à r.l. et Cie, S.C.A.One-off payments by PayPalName, email, payment dataEU and USA
Google (sign-in), where usedOptional account sign-inEmail address, Google account identifierEU and USA
Alpha Internet Limited (Zume)Runs the mail server that sends and receives our emailsName, email address, message contentUnited Kingdom

We may also disclose data where we are legally required to, for example to HMRC, a regulator, or a court.

International transfers

Some providers process data outside the UK. Where that happens, transfers are protected by UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards. You can ask us which mechanism applies to a particular provider.

5. How long we keep your data

DataRetention period
Enquiries that do not become clients24 months from the last contact, then deleted
Consultation bookings that do not become clients24 months from the booking date
Unverified bookingsDeleted automatically once the verification link expires and the record is cleared
Client account and project recordsFor the duration of the relationship and 6 years after the final invoice
Invoices, payments and accounting records6 years from the end of the accounting period, as required by UK tax law
Terms of Business acceptance records6 years after the relationship ends, as evidence of agreement
Project chat messages and uploaded filesFor the duration of the relationship and 12 months after project completion, unless you ask us to delete them sooner
Approval audit records6 years, because they evidence what was agreed
Server and security logs14 days, then deleted automatically
Marketing consent recordsUntil you withdraw consent, plus 24 months to evidence the withdrawal

When a retention period ends we delete the data or anonymise it so it can no longer identify you.

6. How we protect your data

  • All traffic to and from our website is encrypted with HTTPS.
  • Passwords are stored as salted one-way hashes and are never readable by us.
  • Administrator accounts require two-factor authentication.
  • Two-factor secrets and recovery codes are encrypted at rest.
  • Access to client data is limited to the people who need it to do the work.
  • Backups are taken regularly and stored securely.
  • We patch our systems and monitor for security issues.

No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.

7. Cookies

We use a small number of essential cookies to make the site work. We do not currently use analytics cookies, and if we ever introduce them, nothing will load unless you agree. Full details are in our Cookie Policy.

8. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data, which is what this policy is for.
  • Access a copy of the personal data we hold about you.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data where there is no continuing lawful reason for us to hold it.
  • Restrict processing in certain circumstances, for example while a dispute about accuracy is resolved.
  • Data portability, receiving data you provided to us in a common machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time, which we will always honour.
  • Withdraw consent at any time where we rely on consent, without affecting processing carried out before you withdrew it.
  • Not be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not carry out such processing.

To exercise any of these rights, email hello@build-bros.co.uk. We will respond within one month. There is normally no charge. We may ask you to confirm your identity before we release personal data, which protects you as much as us.

9. Complaints

If you are unhappy with how we have handled your personal data, please tell us first at hello@build-bros.co.uk so we can try to put it right.

You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk

10. Data we process on behalf of our clients

Where we build or maintain a website for a client, that client is the data controller for their own website visitors' data and we act as their data processor. In that role we:

  • process personal data only on the client's documented instructions;
  • ensure that anyone with access is bound by confidentiality;
  • apply appropriate technical and organisational security measures;
  • do not engage a sub-processor without the client's general or specific authorisation;
  • assist the client with data subject requests, breach notification and impact assessments so far as we reasonably can;
  • delete or return the personal data at the end of the engagement, unless we are legally required to keep it.

These obligations are set out in full in our Terms of Business.

If you are a visitor to a website we built for someone else, that business is responsible for your data and you should contact them directly.

11. Changes to this policy

We may update this policy as our services or the law change. The version number and "last updated" date at the top will always tell you which version you are reading. If a change materially affects how we use your data, we will tell affected clients directly.

12. Contact us

Email: hello@build-bros.co.uk
Post: Build Bros Ltd, 128 City Road, London, United Kingdom, EC1V 2NX
Phone: 020 8064 3071

Questions about this page? Email hello@build-bros.co.uk.

Questions about your data?

Ask us. We will give you a straight answer in plain English, the same as we do about everything else.

We use optional analytics cookies to understand how visitors use our site. No analytics run unless you accept. See our Cookie Policy for details.