Privacy Policy
Last updated: April 2026
1. Who We Are (Controller)
UI DESIGNS is a freelance web design and managed hosting service operated by Danny Vincent, a sole trader based in Bournemouth, United Kingdom.
Website: uidesigns.co.uk
Email: info@uidesigns.co.uk
Controller Postal Address: [INSERT POSTAL ADDRESS]
For the purposes of UK data protection law, UI DESIGNS acts as the Data Controller for personal data collected through this website and for our own business administration.
Data Controller vs Data Processor
UI DESIGNS acts as the Data Controller for personal data collected directly from you, including when you:
contact us;
request a quote;
subscribe to newsletters; or
become a client.
When we host or maintain a website on behalf of a client and process personal data for that client (such as form submissions, customer data, or Admin Panel content), UI DESIGNS acts as a Data Processor.
In these cases:
the client acts as the Data Controller; and
UI DESIGNS processes data only on the client’s documented instructions.
This relationship is governed by our Service Agreement and Terms of Service.
2. Who This Policy Applies To
This Privacy Policy applies to:
visitors to uidesigns.co.uk;
prospective clients requesting information or quotations;
newsletter subscribers; and
active clients receiving services or using our Admin Panel.
3. Personal Data We Collect
A. Contact & Enquiry Data
We may collect:
name;
email address;
phone number; and
project details submitted via forms or email.
B. Client Services & Account Data
Where applicable, we may collect:
client contact details and communications;
billing and invoice records;
Admin Panel account details;
IP address logs and security/access logs; and
website content or media uploaded by the client.
C. Technical & Usage Data
We may automatically collect:
IP address;
browser type;
device information; and
basic website usage information (subject to cookie preferences).
D. Cookie & Consent Data
We may collect:
cookie identifiers and similar online identifiers; and
cookie consent preferences and consent records.
E. Payment Data Boundary
Payments and subscriptions are processed securely via Stripe.
UI DESIGNS does not store payment card details.
Our contact forms do not support file uploads.
Admin Panel & Client Website Data
Clients on an active Care Plan may receive access to our proprietary Admin Panel.
To provide support and maintenance, authorised UI DESIGNS personnel may access:
Admin Panel data;
analytics and form submissions;
website files and databases; and
hosted content required to deliver services.
We only access client data where necessary to:
provide contracted services;
perform maintenance;
respond to support requests; or
maintain system security.
We do not use client data for unrelated marketing purposes.
4. How We Use Personal Data
We use personal data to:
respond to enquiries and provide quotations;
deliver contracted services and support;
manage hosting, maintenance, and Admin Panel access;
send newsletters and marketing communications;
process payments and subscriptions;
issue invoices and maintain records;
maintain platform security and performance; and
comply with legal, accounting, and tax obligations.
5. Lawful Bases For Processing
Depending on the circumstances, we rely on the following lawful bases under UK GDPR.
Contractual Necessity
To provide requested services or fulfil contractual obligations.
Legitimate Interests
To:
operate and improve our services;
respond to enquiries;
maintain security;
prevent abuse; and
manage our business operations.
Legal Obligation
To comply with legal, accounting, and tax requirements.
Consent
For:
non-essential cookies and analytics; and
marketing communications where consent is required.
6. Marketing & Newsletters
If you subscribe to our newsletter, we may send occasional marketing communications.
We use double opt-in subscription confirmation.
Every marketing email includes an unsubscribe link.
Unsubscribing from marketing communications does not affect essential operational emails sent to active clients.
7. Cookies, Consent & Google Analytics
Cookie Categories
We use the following cookie categories:
Essential Cookies
Required for website functionality and security.
Functional Cookies
Used to support user preferences and website features.
Analytics Cookies
Used to understand website usage and improve performance.
Analytics Provider
We use Google Analytics 4 (GA4).
We do not enable advertising features such as:
Google Signals;
remarketing; or
ads personalisation.
Consent Model
Analytics cookies are only activated after consent is provided via our cookie banner.
We use Google Consent Mode to ensure analytics behaviour respects your consent choices.
Cookie Consent Tool
We use a custom cookie consent manager which records:
consent status;
selected cookie categories; and
consent timestamps.
You may change or withdraw your cookie preferences at any time using the “Cookie Settings” link available on the website.
8. Third-Party Processors
We use trusted third-party providers to operate our services and infrastructure.
Depending on how you interact with us, these providers may process personal data on our behalf.
Key Providers
Stripe
Payment processing and subscription management.
Resend
Email delivery and newsletter communications.
Hosting and infrastructure services.
IONOS
Email, infrastructure, and related technical services.
Google Analytics
Website analytics and usage insights (only after consent).
We may also share data where necessary with professional advisers or where required by law.
Appropriate contracts and safeguards are maintained with relevant providers.
9. International Transfers
Some third-party providers may process personal data outside the United Kingdom, including in the United States.
Where international transfers occur, we implement appropriate safeguards, including:
Standard Contractual Clauses (SCCs); and
other recognised transfer mechanisms where applicable.
You may contact us for further information regarding international transfer safeguards.
10. Data Retention
We retain personal data only for as long as reasonably necessary.
Retention Periods
Data TypeRetention PeriodEnquiry DataUp to 12 monthsMarketing DataUntil unsubscribedEmail CorrespondenceUp to 7 yearsFinancial RecordsMinimum 7 yearsServer & Access LogsApproximately 30 daysClient Project DataDuration of active services
Data Deletion After Service Ends
Following cancellation or termination of hosting services:
website files and databases are typically deleted from live systems within 30 days;
residual copies may temporarily remain within backup systems; and
clients requesting a code transfer will receive an export prior to deletion.
Data may be retained longer where legally required.
11. Your Rights
Under UK GDPR, you may have the right to:
access your personal data;
correct inaccurate data;
request deletion of your data;
restrict or object to processing; and
request data portability where applicable.
To exercise your rights, contact:
We may request identity verification before releasing personal data.
We aim to respond within 30 days.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
12. Security
We implement appropriate technical and organisational measures designed to protect personal data against:
unauthorised access;
loss;
misuse;
alteration; and
unauthorised disclosure.
However, no method of transmission or storage can be guaranteed as completely secure.
13. Children’s Data
Our services are not intended for individuals under the age of 18.
We do not knowingly collect personal data from children.
14. Changes To This Policy
We may update this Privacy Policy from time to time.
The latest version will always be available on this page.
15. Contact
For questions regarding this Privacy Policy or your personal data, contact:
Email: info@uidesigns.co.uk