Privacy
Privacy policy
What personal data we hold, why we hold it, how long for, and what you can do about it.
Last updated: on publication. This policy is written as a working document and should be reviewed by a solicitor or a data protection adviser before you rely on it.
1. Who is responsible for your data
The controller is FJP CONSULTANCY, a private limited company registered in England and Wales under number TO BE COMPLETED, registered office 54 Leathermarket Court, London SE1 3HS, United Kingdom.
For anything about your data, email hello@fjp-consultancy.com. We have not appointed a data protection officer, as we are not required to; enquiries go to the address above and are handled directly.
2. What we collect and why
When you place an order
We collect your company name, your name, email address, phone number, billing address, VAT number if you give one, the website you want promoted, your brief, and the details of what you ordered.
Why: to form and perform the contract with you — confirming the engagement, delivering the work, invoicing and keeping accounting records.
Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)) for the engagement itself, and legal obligation (Article 6(1)(c)) for the accounting and tax records we are required to keep.
When you pay
Payment is taken on a page hosted by SumUp. We never see, receive or store your card details. We receive the payment outcome, the amount and our own order reference so we can reconcile it.
Lawful basis: performance of a contract, and our legitimate interest in preventing fraud and reconciling payments.
When you email or call us
We keep the message, your contact details and our reply, so that we can answer and so that we have a record of what was agreed.
Lawful basis: our legitimate interest in responding to enquiries and keeping a record of business correspondence (Article 6(1)(f)), or steps taken at your request before entering a contract.
Your cart
What you put in the configurator is stored in your own browser's local storage until you order or clear it. It stays on your device and is not transmitted to us until you submit an order. It contains your selections only — never a price, and never payment details.
Data we process on your behalf as a client
While delivering an engagement we may be given access to personal data in your systems — advertising account data, customer lists you upload for audience matching, analytics data. There we act as a processor on your documented instructions, and you remain the controller. We process it only to deliver the engagement, keep it confidential, and delete or return it at the end. You are responsible for having a lawful basis for any personal data you ask us to use in advertising, and for the transparency information given to your own customers.
3. What we do not do
- We do not sell personal data. Ever, to anyone.
- We do not use your details for marketing unrelated to your enquiry or engagement without asking you first.
- We do not use advertising or analytics cookies on this site.
- We do not make automated decisions producing legal or similarly significant effects, and we do not profile you.
4. Cookies and similar technologies
This site sets no advertising or analytics cookies and runs no third-party tracking scripts. The only client-side storage used is:
- Local storage — holds your cart between pages, on your device only.
- Session storage — briefly holds your order reference between checkout and the payment screen, cleared when you close the tab.
Both are strictly necessary to provide the service you asked for, so no consent banner is required under the Privacy and Electronic Communications Regulations. SumUp may set its own cookies on its own payment page, governed by its privacy notice.
5. Who else sees your data
We share personal data only with providers who need it to run the service, each under a contract restricting what they may do with it:
- Vercel Inc. — hosting and server logging for this site.
- SumUp — payment processing. They are the controller of the card data you enter on their page.
- Our order notification system — where configured, new orders are forwarded to an internal system so we see them promptly.
- Advertising and analytics platforms — only where delivering your engagement requires it, and only as your processor.
- Our accountant and professional advisers — where needed for our own legal and accounting obligations.
We may also disclose data where required by law, or to establish or defend legal claims.
6. Transfers outside the UK
Some providers are based outside the UK, including in the United States. Where personal data is transferred outside the UK we rely on the safeguards permitted by UK data protection law — an adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable. Ask us and we will tell you which applies to a particular provider.
7. How long we keep it
- Order and invoice records: six years after the end of the accounting period, as required for UK tax purposes.
- Enquiries that do not become engagements: up to 24 months, then deleted.
- Engagement working files and reporting: up to 24 months after the engagement ends, unless you ask us to delete them sooner.
- Client personal data processed on your behalf: deleted or returned within 30 days of the engagement ending, on your instruction.
- Server logs: retained by our host for a short technical period and not used to build any profile of you.
8. Your rights
Under the UK GDPR you have the right to:
- be told what we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no overriding obligation to keep it;
- restrict how we use it while a question is resolved;
- receive data you gave us in a portable, machine-readable form;
- object to processing we base on legitimate interests, including any direct marketing;
- withdraw consent at any time, where consent is the basis we rely on.
Email hello@fjp-consultancy.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity first.
9. Security
The site is served over HTTPS. Order data is transmitted encrypted, and card details never reach our systems at all. Access to order records is limited to the people who need it. No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you where the law requires it.
10. Complaints
Raise it with us first — email hello@fjp-consultancy.com and we will look into it.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk — telephone 0303 123 1113.
11. Changes to this policy
If we change how we handle personal data we will update this page and change the date at the top. Material changes affecting an existing engagement will be notified to you by email.
12. Related pages
See also the terms of business and the legal information page.