Last updated 8 August 2026
Privacy policy
This policy explains what personal data Climax Digital Ltd collects, why we collect it, how long we keep it, who else sees it, and what you can require us to do about it. It covers this website and the personal data we handle when you enquire, when we quote, and when we carry out work.
We are a data controller for that data, and we handle it under the UK General Data Protection Regulation and the Data Protection Act 2018. Where we act instead as a processor, for example when we are given access to a client's own systems in order to do a piece of work, that client remains the controller and their own policy governs the data.
The policy is written to be read, not to be waved at. Where a term has a legal meaning we have named the Article or the statute so that you can check it.
1. Who we are and how to contact us
Climax Digital Ltd is a private company limited by shares, registered in England and Wales under company number 17388266, and incorporated on 7 August 2026. Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom.
For anything to do with this policy or with the personal data we hold, including a request to exercise your rights, email [email protected]. You may also write to us at the registered office above, although email reaches us faster and gives us a record of the request.
We are not required to appoint a statutory Data Protection Officer under Article 37 of the UK GDPR, and we have not appointed one. Responsibility for data protection sits with the company at the contact details above.
This site is aimed at businesses, charities and other organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 13. Websites we build for clients are controlled by those clients and are covered by their own privacy policies, not by this one.
2. What personal data we collect, and how we collect it
We collect what we need in order to reply to you, to quote, to do the work, and to keep proper business records. Nothing on this site collects data silently in the background.
- Enquiry and project forms. When you submit a form on this site we receive the details you type into it, which will normally be your name, your email address, your organisation, and a description of what you need. Some forms also ask about budget range and timescale. Fields not marked as required can be left blank, and a form only sends when you submit it.
- Email and other correspondence. When you email, reply to us, or send a message through another channel we publish, we hold that correspondence, any attachments, and the contact details in your signature. We treat the thread as the record of what was agreed.
- Information needed to carry out work. If you engage us, we hold what the work requires. That can include the names, roles and contact details of your staff or contractors, access to accounts or systems you choose to grant, billing contact and billing address, and the content you send us to publish, which may itself contain other people's personal data.
- Server logs. The server that hosts this site records technical information about each request: the IP address making it, the date and time, the page or file requested, the response status code, the referring page where the browser sends one, and the browser user-agent string. These records are generated automatically by the web server and are used for security and diagnostics, not to build a profile of you.
- Information you volunteer. Anything else you choose to tell us, for example in a call or a meeting, that we then write down in project notes.
- Connection data. Requests to this site pass through Cloudflare and then our web server, and both record the connecting IP address, the time, the page requested and the browser's user-agent string. That is how a web request works; it is not analytics, it is not linked to anything else we hold, and it is not used to build a profile of you.
We do not collect special category data as defined by Article 9 of the UK GDPR, we do not ask for it, and you should not send it to us. We do not buy or rent contact lists, we do not scrape contact details, and we do not use profiling or automated decision-making of any kind.
3. Why we use your data, and our lawful basis for each purpose
Article 6(1) of the UK GDPR requires a lawful basis for every purpose. Each purpose below names the basis we rely on for it.
- Replying to your enquiry and preparing a quotation or proposal. Article 6(1)(b), because these are steps taken at your request before entering into a contract. Where you enquire on behalf of an organisation rather than in a personal capacity, we rely instead on Article 6(1)(f), our legitimate interest in answering a business enquiry that was addressed to us.
- Carrying out work you have engaged us for, including project management, correspondence, testing, handover and support within an agreed period. Article 6(1)(b), performance of our contract with you.
- Invoicing, taking payment, and keeping accounting and tax records. Article 6(1)(c), compliance with our legal obligations under the Companies Act 2006 and tax legislation. Where we chase an unpaid invoice or take advice on a dispute, we rely on Article 6(1)(f), our legitimate interest in recovering money owed to us.
- Keeping this site and our own systems secure and available, which includes reviewing server logs, applying updates, and investigating errors, abuse or attempted intrusion. Article 6(1)(f), our legitimate interest in the security of systems we are responsible for.
- Keeping a record of what was agreed, what we advised, and what we delivered, for as long as a claim could be brought about it. Article 6(1)(f), our legitimate interest in being able to establish or defend our position.
- Complying with a legal or regulatory obligation, including a valid request from a court, HMRC or a regulator. Article 6(1)(c).
We do not operate a marketing mailing list, and we do not send marketing email. If that changes, this policy will be updated first, we will rely on your consent under Article 6(1)(a) where consent is required, and every message will carry a working unsubscribe link. Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that the processing is proportionate to the purpose. You may object at any time under Article 21, and we explain how in section 7.
4. How long we keep your data
We do not keep personal data indefinitely. These are the periods we work to, measured from the event named in each case.
- Enquiries that do not become work: 12 months from our last exchange with you, then deleted. Enquiries commonly resume after a delay, which is why the period is not shorter.
- Proposals and quotations that are not accepted: 12 months from the date we issued them.
- Project files, contracts and project correspondence: 6 years from the end of the contract. That matches the period in which a contractual claim can normally be brought under the Limitation Act 1980, so it is the period in which we may need the records to defend our position.
- Invoices, receipts and accounting records: 6 years from the end of the accounting period to which they relate, which is the period required for tax purposes.
- Access credentials and access rights you granted us: removed at handover. We ask you to revoke our access to your accounts as part of the closing checklist, and we delete any credential we hold at the same time.
- Server logs: retained for 30 days on a rolling basis and then overwritten, unless a specific entry is preserved because it forms part of a security investigation.
- Backups: copies of email and files may persist in backups for up to 90 days after deletion from the live system, after which they are cycled out automatically.
If you ask us to delete data before these periods expire, we will do so unless we are required to keep it or need it to defend a claim. In that case we will tell you which records we are retaining, on what basis, and when they will be deleted.
6. Transfers of data outside the United Kingdom
Some of the providers in section 5 process data outside the United Kingdom, which is normal for email and for internet infrastructure. Where a transfer leaves the UK, we rely on one of the mechanisms permitted by Chapter V of the UK GDPR.
- Adequacy regulations. Transfers to a country the UK Government has found to provide adequate protection, which includes the European Economic Area, rely on those regulations and need no additional safeguard.
- The International Data Transfer Agreement. Transfers to a country without adequacy rely on the IDTA, or on the UK Addendum to the European Commission's standard contractual clauses, supported by a transfer risk assessment for that provider.
You may ask which mechanism applies to a particular provider, and we will tell you. We do not agree to a transfer that has no lawful mechanism behind it, and where a provider cannot evidence one we use a different provider.
7. Your rights, and how to exercise them
The UK GDPR gives you the following rights over your personal data. Most are qualified rather than absolute, and where we cannot act on a request in full we will explain which exception applies.
- Access, Article 15. A copy of the personal data we hold about you, together with information about the purposes, the recipients and the retention period.
- Rectification, Article 16. Correction of data that is inaccurate, and completion of data that is incomplete.
- Erasure, Article 17. Deletion where we no longer have a lawful reason to hold the data. This does not extend to records we are legally required to keep, such as invoices, or records we need in order to defend a claim.
- Restriction, Article 18. A pause on our use of the data, for example while a dispute about its accuracy is resolved.
- Portability, Article 20. A copy of the data you provided to us, in a structured, commonly used and machine-readable format, where we process it by automated means on the basis of consent or of a contract with you.
- Objection, Article 21. An objection to processing we base on legitimate interests, which we must then stop unless we can show compelling grounds that override your rights. Objection to direct marketing is absolute, and we would stop immediately.
- Automated decision-making, Article 22. A right not to be subject to a decision made solely by automated means that has legal or similarly significant effects. We do not make decisions of that kind.
- Withdrawal of consent, Article 7(3), where consent is the basis we relied on. Withdrawal is free and takes effect for the future; it does not make earlier processing unlawful.
To exercise any of these rights, email [email protected] with enough detail for us to identify the data, for example the address you contacted us from and roughly when. We may ask for information to satisfy ourselves of your identity, because the greater risk is disclosing your data to somebody else. We will respond within one month of receiving the request. Where a request is complex, or where you have made a number of requests, we may extend that by up to two further months, and we will tell you inside the first month if we do, with the reason. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will tell you what the fee is and why before doing any work.
8. Cookies, analytics and tracking
This site does not track you. Nothing we build or deploy contains analytics, a tag manager, advertising or conversion pixels, or tracking cookies of any kind — see the note on Cloudflare at the end of this section for the one tag we do not control, which is blocked and does not run. There is no Google Analytics property, no Google Tag Manager container, no Meta pixel, and no LinkedIn, X or TikTok tag.
It also sets no cookies of its own. Because nothing is written to your device for analytics, advertising or measurement, there is nothing here that requires consent under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, and that is why you are not shown a cookie banner. The absence of a banner is a consequence of the build, not an omission from it.
Typefaces are self-hosted and served from this domain, so loading a page makes no request to Google Fonts or to any other third-party font service. There are no embedded videos, maps, chat widgets or social feeds, which are the components that most often introduce third-party cookies.
What remains is the web server log described in section 2, which the host records in order to serve pages and to detect abuse. A server log is not a cookie, it is not linked to any identifier we hold about you, and it is not used to profile you.
One thing we do not control is worth stating plainly. Cloudflare, which serves this site, inserts a small performance-measurement script into the page as it passes through its network. We did not add it and we cannot remove it from the dashboard. This site's Content-Security-Policy blocks it, so on a standards-compliant browser it never loads, never runs and collects nothing — but you should know the tag is in the page rather than discover it in your browser's console. If that ever changes, this section changes with it.
If we add analytics or any other measurement tool in future, we will update this policy before the change goes live, name the tool and what it collects, and provide a consent mechanism where the law requires one. We will not describe tracking that is not running, and we will not apply a new description retrospectively to a period in which nothing was collected.
9. How we keep data secure
This site is served over HTTPS, so traffic between your browser and the server is encrypted in transit. Accounts we control use multi-factor authentication where the provider offers it, and access to project data is limited to those who need it in order to do the work.
Where we need access to your systems, we ask for a named account with the least privilege the task requires, rather than a shared password, so that access can be audited and withdrawn cleanly at handover.
No transmission over the internet and no system connected to it can be made completely secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, as Article 33 requires, and we will inform the people affected where Article 34 requires it.
10. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at [email protected], so that we have the opportunity to put it right and to explain what happened. You are not obliged to come to us first.
You have the right to complain to the Information Commissioner's Office, which is the UK supervisory authority for data protection, at any time.
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Website: ico.org.uk
- Helpline: 0303 123 1113
Complaining to the ICO does not affect your right to seek a remedy through the courts under Article 79 of the UK GDPR, or to claim compensation under Article 82.
11. Changes to this policy
We revise this policy when what we do changes, and when the law changes. The date shown at the top of the page is the date of the current version, and it is the date to quote if you are asking us about something this policy says.
Where a revision materially affects how we use personal data we already hold, we will contact the people affected rather than rely on the updated page alone. Routine changes, such as replacing one hosting or email provider with another, will appear here at the next revision.