Legal
Privacy Policy
Last updated: 01/05/2026
This Privacy Policy explains how Anchor Digital Ltd collects, uses, stores and shares personal information.
Anchor Digital Ltd trades as Anchor Digital.
By using our website, contacting us, submitting a form, becoming a client, or using our services, you acknowledge that we may process your personal information in line with this Privacy Policy.
Website: https://anchorweb.co.uk
Email: charlie@anchorweb.co.uk
Who we are
Anchor Digital Ltd is a digital services business. We design, build, host and manage websites; build custom software and AI systems; provide SEO, paid advertising and Google Business Profile management; and set up or refer payment services.
For data protection purposes, Anchor Digital Ltd is the controller of personal information we collect for our own business purposes, such as enquiries, client records, invoicing and marketing.
Where we process personal information on behalf of a client, we act as a processor for that client. This includes:
• Form submissions, bookings and enquiries on client websites we manage
• Data flowing through CRM, booking, payment or automation integrations we set up
• Data processed by custom software or AI systems we build, host or support for a client
• Data in advertising, analytics and business profile accounts we manage for a client
Where we act as a processor, the client is the controller and decides why and how the data is used. Our standard Data Processing Agreement applies to that processing and forms part of our Terms and Conditions.
Personal information we collect
We may collect and process:
• Name
• Business name
• Job title
• Email address
• Phone number
• Website URL
• Business address
• Billing details
• Payment status
• Enquiry details
• Project requirements
• Messages, emails and call notes
• Form submissions
• Website content supplied by clients
• Images, videos, logos or brand assets supplied by clients
• Data, documents, records and examples supplied by clients for custom software or AI systems
• Login or access details where needed to provide services
• Advertising, analytics and business profile account data where we manage those accounts
• Technical information such as IP address, browser type, device type and website usage data
• Analytics and performance data
• Marketing preferences
• Any other information you choose to provide
We may also process personal information contained within client-supplied materials, such as staff profiles, testimonials, reviews, blog posts, case studies, customer enquiries, booking details, contact form submissions, customer records, invoices, emails or documents connected to a system we build.
How we collect personal information
We may collect personal information when you:
• Visit our website
• Submit a contact form or enquiry form
• Use a quiz, quote form or project intake form
• Email us
• Message us on social media
• Book a call or meeting
• Become a client
• Pay an invoice or use a payment link
• Provide project materials, data or documents
• Give us access to accounts, websites, systems or tools
• Use a website or system we manage
• Respond to marketing or outreach
• Leave a review
• Interact with our website analytics or tracking tools
We may also receive personal information from third-party platforms used to deliver our services, from public sources (see section 15), and from channel partners or referrers.
Why we use personal information
We use personal information to:
• Respond to enquiries
• Provide quotes and proposals
• Communicate with clients and prospects
• Plan and deliver projects
• Design, build, host and manage websites
• Design, build, host and support custom software and AI systems
• Set up contact forms, booking tools, payment tools and CRM integrations
• Provide SEO, paid advertising, Google Business Profile and review management
• Set up or refer payment services
• Provide support, updates, monitoring and maintenance
• Process payments and manage invoices
• Keep records of work agreed and completed
• Improve our website and services
• Monitor website and system performance and usage
• Troubleshoot technical issues
• Protect the security of our website and systems
• Comply with legal, tax and accounting obligations
• Send relevant business communications where permitted
• Manage reviews, testimonials and portfolio examples
• Use external tools to help deliver client work
Lawful bases for processing
We only use personal information where we have a lawful basis to do so.
Depending on the situation, we may rely on:
Contract: To provide services you have requested, prepare proposals, manage projects, process payments and deliver agreed work.
Legitimate interests: To run and improve our business, respond to enquiries, contact businesses about our services, manage client relationships, maintain records, secure our systems, improve our services and use tools needed to deliver work efficiently.
Consent: Where you have given clear consent, for example to receive certain marketing communications or where a specific tool or feature requires consent.
Legal obligation: Where we need to comply with legal, tax, accounting or regulatory obligations.
Where we act as a processor for a client, the client is responsible for the lawful basis.
External tools and service providers
To run our business and deliver our services, we use external tools, platforms and service providers. We may share or process personal information through these tools where needed.
These may include:
• Website hosting and deployment platforms
• Website builders and development tools
• Domain and DNS providers
• Email providers
• Contact form and transactional email tools
• Payment processors
• Analytics tools
• CRM tools
• Project management tools
• File storage tools
• Design tools
• CMS platforms
• Booking tools
• Automation tools
• SEO and advertising tools
• AI model and API providers
• Communication tools
• Accounting tools
• Outreach and email sequencing tools
Examples of providers we may use include Lovable, Cloudflare, Supabase, 20i, GitHub, Resend, Stripe, Umami, Google, Microsoft, Meta, WordPress, Shopify, Zapier, Make, Instantly, OpenAI, Anthropic, Google Gemini or similar providers.
The exact tools used vary by project. We only share personal information with external providers where reasonably necessary for our business operations or to deliver agreed services. A current list of subprocessors for client data is available on request and is set out in our Data Processing Agreement.
AI tools we use in our work
We may use AI tools to help with parts of our work. This may include:
• Drafting website copy
• Restructuring client-provided content
• Summarising project information
• Generating ideas
• Creating image prompts
• Reviewing website structure
• Preparing SEO or AI visibility materials
• Drafting FAQs
• Analysing public website content
• Writing, reviewing or debugging code
• Analysing data supplied by a client for a project
• Improving internal workflows
Where relevant, information provided by clients may be entered into AI tools to help deliver the service. This may include business information, website copy, service descriptions, project requirements, public website content, brand information, draft content, technical information, and sample data or documents needed to design a system.
We will not intentionally submit highly sensitive personal information, payment card details, passwords or confidential information into AI tools unless it is necessary, appropriate and agreed, or clearly required to provide the service.
AI tools are provided by third parties and process data in line with their own terms and privacy policies. We use business or API accounts where available, which generally do not use submitted data to train models, but we cannot control the providers' policies.
AI systems and custom software we build for clients
We build custom software and AI systems for clients. These systems may process personal information belonging to the client's customers, staff, suppliers or contacts, for example by reading emails, documents, forms, invoices or records, and producing summaries, drafts, classifications, data entries or other outputs.
For these systems:
• The client is the controller and decides what data is connected, what the system does with it, and who sees the outputs.
• We act as processor while we build, host or support the system, under our Data Processing Agreement.
• The system may send data to third-party AI model providers, hosting providers and other tools to operate. Those providers act as subprocessors.
• The client is responsible for telling its own customers and staff about the processing, and for having a lawful basis for it.
• Systems we build are not designed to make automated decisions that have legal or similarly significant effects on individuals. A human review step is expected for outputs that affect money, customers, employment, contracts or legal matters. If a client chooses to configure a system otherwise, the client is responsible for that decision and for complying with data protection law.
• Logs, prompts, inputs and outputs may be stored by the system or its providers for operation, debugging and improvement. Retention is set per system and agreed with the client. After handover, the client controls retention unless we provide an ongoing service.
Client data used in third-party tools
Clients acknowledge that, to provide our services, we may need to use third-party platforms and external tools.
This may include entering or uploading client-provided information, website content, business details, images, form structures, service descriptions, project notes, sample data, documents or technical requirements into external tools.
We will take reasonable steps to use reputable tools and limit information shared to what is reasonably needed.
Where a client has specific restrictions on the use of external tools or AI tools, the client must tell us in writing before work begins.
Marketing services we provide for clients
Where we provide SEO, paid advertising, Google Business Profile or review management for a client:
• We access the client's advertising, analytics, search console and business profile accounts using manager or editor access. The client remains the account owner.
• We may set up conversion tracking, tags, pixels and analytics on the client's website. Visitors to the client's website are then subject to the client's privacy policy and to the policies of the platforms involved (such as Google or Meta).
• We may use subcontractors or channel partners to deliver paid advertising. They will have access to the client's advertising account data for that purpose.
• Review management may involve sending review requests to the client's customers on the client's behalf, using contact details the client provides. The client is responsible for having a lawful basis to contact those customers.
Payment services
Payment Referral. Where we introduce a client to a payment provider or channel partner, we pass the client's business contact details to that provider so they can get in touch. We may receive a commission or referral fee. The provider processes the client's information under its own privacy policy.
Payment Setup. Where we configure a payment platform (such as Stripe) on a client's account, we may see account settings and, during testing, transaction data. We never hold funds, and we never store customer card details. After handover, the client operates the account.
Our own invoices. Payments to us may be processed through third-party payment providers such as Stripe. We do not store full payment card details. We keep records of payments, invoices, receipts and payment status for accounting and legal purposes.
Information we do not want you to send
Please do not send us unnecessary sensitive personal information. This includes:
• Health information
• Financial account details
• Full payment card details
• Government ID documents
• Children's information
• Passwords in plain text
• Special category personal data
• Criminal offence data
If this information is required for a specific reason, for example because a client's business processes it and a system we build needs to handle it, we will agree the safest way to handle it in writing first.
Website analytics
We may use analytics tools to understand how our website is used. This may include: pages visited; time on site; referring websites; device type; browser type; approximate location; campaign links or UTM tracking; clicks or interactions.
We use this to improve our website, track enquiries and understand which marketing activity is working.
We use privacy-friendly, cookieless analytics where possible.
Marketing and outreach
We may contact businesses about our services where permitted by law.
We may use publicly available business contact details to identify relevant businesses. Sources may include business websites, directories, social media, Google Business Profiles, Companies House, and public registers published by regulators (for example, the Care Quality Commission register).
We may use outreach and email tools to send and manage these communications.
If we contact you and you do not want to hear from us again, you can ask us to stop and we will. We keep a suppression record so we do not contact you again.
Contact forms and client website forms
If you submit a form on our website, we will use the information to respond to your enquiry.
If you submit a form on a client website that we manage, the information is sent to the client and may pass through tools we manage, such as hosting, form, email, CRM or automation providers. The client is responsible for deciding how that form data is used, and the client's privacy policy applies.
International transfers
Some of the tools and providers we use, including AI model providers, may process personal information outside the UK.
Where this happens, we take reasonable steps to ensure appropriate safeguards are in place where required. This may include using providers covered by UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or other lawful transfer mechanisms.
Where we build a system for a client, the client decides what data is connected and is responsible for checking that any resulting international transfer is permitted for that data.
How long we keep personal information
We keep personal information only for as long as reasonably needed. Retention depends on the type of information and why we hold it.
We may keep:
• Enquiry records for up to 24 months
• Client project records for up to 7 years
• Invoice and accounting records for up to 7 years
• Email correspondence for as long as needed to manage the client relationship
• Website and system backups for a limited period depending on the platform
• Form submissions for as long as needed to respond, manage the project or support the client
• Logs, inputs and outputs of AI systems we host for the period agreed with the client
• Analytics data according to the settings of the analytics provider
• Marketing suppression records for as long as needed to make sure we do not contact people who have opted out
If we do not have a specific retention period, we decide how long to keep information based on the type of data, the reason it was collected, legal requirements, business need and whether there is any ongoing relationship or dispute.
How we protect personal information
We take reasonable steps to protect personal information. This may include:
• Using reputable service providers
• Limiting access to information
• Using password-protected accounts
• Using two-factor authentication where available
• Keeping systems updated where we control them
• Using secure hosting and SSL where relevant
• Using business or API accounts with AI providers rather than consumer accounts
• Avoiding unnecessary collection of sensitive information
• Deleting information when no longer needed
No system is completely secure, and we cannot guarantee absolute security.
Data breaches
If we become aware of a personal data breach affecting information we hold as controller, we will assess it and, where required, report it to the Information Commissioner's Office and notify affected individuals.
If a breach affects data we process for a client, we will notify the client without undue delay so the client can meet its own obligations.
Your rights
Under data protection law, you may have rights in relation to your personal information. These may include the right to:
• Access your personal information
• Correct inaccurate information
• Request deletion
• Restrict processing
• Object to processing
• Request data portability
• Withdraw consent where processing is based on consent
• Not be subject to solely automated decisions with legal or similarly significant effects
• Complain to the Information Commissioner's Office
If your request relates to data we process on behalf of a client, we may refer you to that client, who is the controller.
Right to object
You have the right to object to certain processing, including processing based on legitimate interests and direct marketing.
If you object to direct marketing, we will stop using your personal information for that purpose.
Withdrawing consent
Where we rely on consent, you can withdraw your consent at any time. Withdrawing consent does not affect processing that happened before withdrawal.
How to exercise your rights
To exercise your rights, contact:
Email: charlie@anchorweb.co.uk
We may need to verify your identity before responding. We aim to respond within one month.
Complaints
If you are unhappy with how we handle your personal information, please contact us first so we can try to resolve it.
You also have the right to complain to the Information Commissioner's Office.
ICO website: https://ico.org.uk
Links to other websites
Our website may link to third-party websites. We are not responsible for the privacy practices, content or security of third-party websites.
Children
Our services are intended for businesses and adults. We do not knowingly collect personal information from children.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
The latest version will be available on our website and will apply from the date shown at the top.
If we make material changes, we may notify clients where reasonable.
Contact
For questions about this Privacy Policy, contact:
Anchor Digital Ltd
Website: https://anchorweb.co.uk
Email: charlie@anchorweb.co.uk
This Privacy Policy is governed by the laws of England and Wales.
© 2026 Anchor Digital Ltd · Company No. 16225031
This Privacy Policy is governed by the laws of England and Wales.
© 2026 Anchor Digital Ltd · Company No. 16225031