Legal
Privacy Policy
How personal data submitted through this website is collected, used and protected, in line with UK GDPR and the Data Protection Act 2018.
Last updated: 4 October 2026
This policy explains how Nadine Benjamin ("I", "me", "my"), an independent Brand & Marketing Strategist trading as a sole trader in London, United Kingdom, collects and uses personal data through this website and in the course of consultancy work. For the purposes of the UK General Data Protection Regulation, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003, I am the data controller.
You can reach me about anything in this policy at [email protected], or by post to a correspondence address, which I will give you by return if you ask for it by email. If you are in the European Economic Area, please also read "Visitors in the EEA" towards the end of this policy.
This policy is written to describe what this website and my records actually do, rather than what they are intended to do. Where a control is still being built, that is said plainly.
Information you give me
When you submit an enquiry or project brief, I collect what you type into the form. Every submission asks for your name, email address, the type of enquiry and your message. A business or working name is generally optional, but is required when applying for the named case-study partnership. Depending on the service selected, the form may also ask for a company website, an estimated budget, a project timeline and links to useful material. The Focus Consultation brief collects a fuller picture of your business: your role, what your business does and for whom, your ideal customer, what makes you different, how customers find you, your closest competitors, the challenge you want addressed, what you have already tried, what a good outcome looks like, the decision waiting on the answer, any constraints, and links to useful material. A telephone number may be supplied voluntarily for project administration. It is used only in connection with your enquiry or engagement, and never for marketing.
If you sign up to the newsletter, through the footer form, the tick box on the enquiry form, or the AI assistant, I collect only your email address.
If you apply for and are selected for the Brand Clarity Audit named case-study partnership, I also collect the business name, website, logo or brand assets, honest and detailed written feedback, a written progress update and the project material needed to prepare the case study. The partnership is only available where the business agrees to public identification: the business name and logo, agreed project context, recommendations, implementation progress, results and accurate attributed extracts from the feedback will be published. The case study will state that a reduced partner rate was provided. Information unrelated to the agreed case-study scope remains confidential.
Please do not send me information about your health, your beliefs, your background or anything else that UK GDPR treats as a special category of personal data, or information about criminal offences. None of my services need it. If you do include something of that kind in a free-text field, it will sit in the message you sent until that record reaches the end of its retention period; tell me and I will remove it sooner.
Optional saved drafts and workbook companion
The free positioning statement generator and project brief normally save only in the browser you are using. If you choose “Continue on another device”, I store the answers currently in that tool, the type of draft, its expiry and a cryptographic hash of the return-link token in my private Cloudflare database. I do not store the raw return-link token. No account or newsletter sign-up is created. Anyone holding the return link can open the uploaded copy, so keep it private; you can delete it from the return-link page. The uploaded copy is deleted automatically after 30 days and is not included in backup snapshots. The lawful basis is my legitimate interests in providing the optional return-link feature you have chosen, while keeping its storage short and under your control (Article 6(1)(f)).
The optional interactive Positioning Workbook companion stores the paid purchaser’s own typed sections and saved versions, together with the purchase email needed to provide access. It does not generate strategy or send an email automatically when a version is sent for review. The working copy is deleted from the live database 180 days after its last save or review request. You can export the current editor text and delete the saved notes sooner; neither action affects the purchased PDF or purchase record. Backup copies follow the normal backup cycle described below. The lawful basis is performance of the contract for the paid workbook (Article 6(1)(b)).
Information collected automatically
My hosting provider, Cloudflare, processes the technical information every website receives in order to serve pages, defend the site and keep it available: your IP address, your browser's user-agent string, the page you requested and approximate location derived from your IP address. This happens at network level, before any code of mine runs, and is described in Cloudflare's own privacy documentation.
Cloudflare Web Analytics is used on this site. This site loads a small measurement script from static.cloudflareinsights.com on its public pages, and it reports page views back to Cloudflare. It is not loaded on the private office or the client area, and it is not loaded in a browser that has been used to sign in to the private office, so my own visits are excluded from my figures. It sets no cookies, stores nothing on your device and does not follow you between websites; Cloudflare processes technical information including your IP address in order to count visits and produce aggregate figures such as which pages are read most and which countries visitors come from. I see only those aggregate figures.
This site also records a small number of its own page-view and progress events so that I can understand how people move through service pages, briefs, forms, the free positioning statement generator and paid products, and where they stop. A random browser-journey identifier in local storage joins measured steps in this browser over time. It is persistent, so it is not a unique-person count or a session count. A separate random identifier in session storage groups measured activity in one browser tab and is replaced after 30 minutes without measured activity. Neither identifier contains information about you, is used for advertising or can follow you to another website. Both are created and used only with analytics consent. The Cookie Notice names them, explains how to stop them and explains how to ask me to delete matching events and linkage.
When you choose to submit a site search or choose one of its results, the matching itself still happens in your browser. I record only a daily aggregate of a small controlled list of strategy terms, or the broad label “Other strategy topic”, the broad theme, whether local search showed a result and which public page was selected. I do not put the raw search-box wording, a cookie value, visitor or session identifier, IP address, user-agent, referrer or device information into these records. Email addresses, phone numbers, web addresses and other high-risk detail are rejected before a report is sent. The daily aggregates are deleted after 180 days. Backup copies follow the existing backup-retention cycle, with the latest successful snapshot kept until a newer successful backup exists.
These measurement technologies sit on different legal footings, and it would be misleading to describe them as though they sat on one. Cloudflare Web Analytics and the anonymous on-site-search aggregate neither store anything on your device nor read anything from it. Cloudflare does process technical information such as your IP address in order to count a visit; the on-site-search aggregate does not place that information in my reporting tables. The lawful basis for these measurements is my legitimate interests in understanding how the site is used and where it can be improved (UK GDPR Article 6(1)(f)). You may object at any time under Article 21; see “Your rights”.
The analytics identifiers are the opposite case. They are written to your browser, and the browser-journey identifier stays there between visits, which is exactly the storage regulation 6 covers. Regulation 6 as amended by the Data (Use and Access) Act 2025 does now contain an exception for storage whose sole purpose is collecting statistical information about how a website is used, and it would probably cover these identifiers, but I do not rely on it. The identifiers are used only with your consent (UK GDPR Article 6(1)(a)): they are not created until you accept analytics, no browser-linked progress event is recorded while your choice is undecided, and declining or later withdrawing removes them from the browser. That is the stricter of the two positions and I would rather be on it. The Cookie Notice names both identifiers, explains how withdrawal clears them from the browser and prevents future linking, and explains how to ask me to erase matching events and linkage already held on the server.
With analytics consent, this site remembers the first and latest recorded source, campaign tags and landing page for this browser. Referrer paths and unrelated query parameters are not retained. This attribution is removed from browser storage when you withdraw consent and is no longer reused after 425 days. Source information can be retained with an enquiry or completed purchase.
With the same analytics consent, an approximate live activity count reports visible public tabs using a separate random token kept only in page memory. It is not joined to an enquiry, purchase or persistent journey identifier. Every 30 seconds while visible, the page reports its public path and a broad source category. The live count uses a 90-second window and temporary server records expire after 120 seconds; no IP address, fingerprint, query string or referrer text is stored in them. Hiding or closing the page or withdrawing consent stops the reports and requests removal. Detected bots, private-office browsers, Do Not Track and Global Privacy Control signals, and the existing EEA geographic exclusion are honoured. The lawful basis is your analytics consent.
If analytics consent is still granted when you submit an enquiry or start a purchase checkout, the random browser-journey and measurement session identifiers may be stored with the resulting enquiry or completed purchase. If an enquiry later leads directly to a client, booking or invoice record, the same identifiers may follow that record. This makes the commercial outcome comparable with the consented browser journey that produced it without using email or another personal detail as the analytics join key. Once stored with a named commercial record, the identifiers are pseudonymous personal data. They and their linkage date are cleared automatically 425 days after the first valid link, or sooner following a verified erasure request; the underlying commercial record then continues under its own retention period. No linkage is created where analytics consent is absent. Withdrawing consent clears the identifiers and attribution from that browser and prevents future linking, but does not by itself erase a record or linkage already submitted to the server.
For a purchase checkout, attribution and the consented identifiers may first be held on this site against an opaque checkout reference for up to 30 days. Stripe receives only that reference, not either browser identifier. If payment completes, the information can be transferred to the purchase record; otherwise the temporary handoff expires.
The website chat and its AI assistant
This website offers a chat, shown as a “Chat with Nadine” button in the corner of the page. When I am online I can read a conversation as it happens and join it myself. At all other times, and until I join, replies come from my AI assistant, which is an artificial intelligence system, not a person. Every reply the assistant writes is labelled “AI assistant”, and every message I write is labelled with my name. The assistant is powered by Anthropic's Claude, with Cloudflare's Workers AI as a fallback if Anthropic is unavailable, and I have set it up to answer questions about the services, help you find a sensible starting point and bring me into the conversation where that is right.
To generate each reply, the AI provider receives up to the twenty most recent messages, the address and title of the page you are viewing, and a short approved summary associated with that page. Controlled additional page detail is included only when you explicitly ask the assistant to explain, summarise or answer a question about the current page; the page's visible text is not copied and sent automatically. The provider also receives whether you have already submitted an enquiry or newsletter sign-up in the conversation, the current London date and time, whether I am online, a list of the site's published services and articles, and, if you have used the chat before on this browser and given your first name, that first name and the fact that you are returning. Content sent to the Anthropic API is not used to train Anthropic's models. Anthropic and Cloudflare act as my processors for this purpose.
Conversations are logged so that I can follow up properly and review the quality of the service. The log holds the transcript, the address of the page the chat began on, your browser's user-agent string and your IP address. An ordinary conversation is deleted seven days after your last message. If the conversation is linked to an enquiry, it is kept while that enquiry is still open and for a further seven days after I close it as won or lost, so, in practice, a conversation attached to an enquiry I have not yet closed is kept until I do close it. The IP address is held to protect the site from abuse and is deleted with the conversation it belongs to.
When I join a conversation. I use a private console that shows me conversations in which you have asked to speak with me, in which you have told the assistant that you are an existing client, or in which the chat has offered you a live conversation with me, together with the transcript, the page the chat began on and the IP address. In each of those cases I am also alerted by email and in the console; the email carries the reason and the page address, not the conversation. When you ask for me, or tell the assistant you are an existing client, the conversation so far is sent to Anthropic to produce a short private summary for me. While I am in a conversation I can ask for suggested replies, which sends the conversation to Anthropic in the same way; what I send you is always written or chosen by me. Everything I write is added to the same conversation log and follows the same retention period, and I can hand the conversation back to the assistant at any time, in which case the chat tells you so. A separate record of these steps (when a conversation was assessed, offered to me, requested, joined, declined or handed back) is kept against the conversation and deleted with it.
Before I join. The assistant puts nobody through to me until it has your name, your email address and a line on what you would like to discuss. Those details are saved with the conversation and in my enquiry records, so I know who I am speaking with and can reply by email if the chat ends. If you tell the assistant you are an existing client, your email address is checked against my client records so I can see whether it matches. While I am in the chat, each of us is shown when the other is typing; only the time you last typed is recorded, never what you type before you send it. If I do not reply within 45 seconds the assistant tells you I am still with you, and if I have not replied within 75 seconds it tells you I have been disconnected, takes the conversation back and offers to take a message for me.
How the chat decides whether to offer you a conversation with me. The assistant keeps a private assessment of each conversation: a likely fit for my services, a possible fit, or not a fit. While I am online, a conversation it rates a likely fit is offered a live chat with me, which you can accept or decline. A conversation it has marked as spam, a sales pitch, time-wasting, suspicious or abusive is never put through to me live. The assessment is stored with the conversation and deleted with it. It decides only whether a live chat is offered: you can ask for me in the chat at any time, and the enquiry form, email and the newsletter remain open to you whatever it says, so it has no legal or similarly significant effect on you.
The chat header shows me as online during my working hours, and at other times when I have my chat console open. It finds out with a request that returns only “online” or “away”, and whether I can join the chat live, and carries no information about you. I can join live only while my console is open; that switches itself off when the console is closed, and in any case at the end of the working day it was switched on for.
Two things are stored in your browser by the assistant: a short session identifier and the active conversation, which are cleared after five minutes without a message from you or the assistant, or when you close the tab; and a small marker recording that you have used the chat before together with your first name if you have given it, which stays until you clear this site's storage. Ending or timing out a conversation prevents its messages being included in a new AI request. It does not erase a server-side conversation log or an enquiry that has already been submitted; those records follow the retention periods below. The Cookie Notice lists the browser storage.
If you give the assistant your name, email address or other contact details during a conversation, those details are recorded in my enquiry records at the point in the conversation when you give them, before you press Send on the in-chat form; the form is a review step over information I already hold. The assistant is also set up to work out your likely company website from a work email address and to note the role you appear to hold, without asking you for either. When you do press Send, the details and a transcript of the conversation reach me in the same way as a website form.
The assistant is instructed not to ask for your name or any personal detail in its opening reply, and not to start collecting details until you show an actual interest in a service, an enquiry, a newsletter sign-up or being put in touch with me. It is instructed to ask only for what the particular service needs.
The assistant can also end a conversation and mark it for my attention where it appears to be spam, a sales pitch, time-wasting, suspicious or abusive. Where that happens, the IP address the conversation came from is recorded automatically and prevents further use of the chat from that address for thirty days. That is an automated step taken on the AI system's own assessment, without my reviewing it first. It affects the chat only: the enquiry form, the newsletter and email to me all remain open to you. If it happens to you and you think it is wrong, email me at [email protected] and I will look at it myself and remove the block if it should not have been applied.
The lawful basis for providing the chat and its assistant, joining conversations live, logging conversations and protecting the site from abuse is my legitimate interests in helping visitors, in understanding and improving the service, in responding to enquiries and in keeping the site secure (UK GDPR Article 6(1)(f)). Newsletter sign-up through the assistant relies on your consent (Article 6(1)(a)).
Other AI processing of your information
Two further AI operations use Anthropic's Claude as my processor. Neither produces a decision about you that is taken solely by a machine and has a legal effect or a similarly significant effect on you; every reply and every decision about whether and how to work with you is mine.
First, when an enquiry arrives, the organisation named, the service asked about, any budget and timeline given, your message and any brief answers, including, for an enquiry made through the chat, the chat transcript, are sent to Anthropic, which returns a suggested priority (high, medium or low), a suggested service tier and a one-line reason. Your name, email address and telephone number are not included. The result is stored on the enquiry record and affects only the order in which enquiries are shown to me on my own dashboard.
Second, I use an AI-generated daily summary of my own workload. The information sent for that purpose includes the names and organisations of people with open enquiries, the email addresses and names of clients with overdue payments or past-due project dates, engagement references, amounts due and due dates, and figures about revenue and system health. It does not include enquiry message text or client email addresses beyond those cases.
The lawful basis for both is my legitimate interests in running the consultancy efficiently and responding to enquiries properly (Article 6(1)(f)). You may object to either at any time under Article 21; see "Your rights".
The client account
If you become a client I may give you an account on this website where you can see the details and progress of your engagement. To provide it, I store your name, email address, a securely hashed version of your password (never the password itself), your organisation, telephone number and website where you have given them, an internal note of my own about the engagement, and the details of your projects: the reference, the engagement, the dates, the stage, the deliverables, progress updates, the onboarding steps, the agreed fee, the scope, the payment terms, and any external folder, task-board or calendar reference. Proposal and billing records hold the service, amount, status, dates and relevant proposal, invoice or payment references. If either of us uploads a project file, the file is held in private Cloudflare storage and its account record includes the project, file name and type, size, version, status, visibility, replacement history and download history. When you review or approve a deliverable, accept or decline a proposal, request changes, or confirm completion, I keep the action, any comment, your account email address, the date and time, the applicable version and a fixed snapshot of the record acted on. Notification emails may tell either of us that an action occurred, but the signed-in account record is the source of truth. A non-disclosure agreement generated for you is not stored as an uploaded file.
Signing in sets one strictly necessary cookie so that you stay signed in securely. It is not used for measurement or advertising, and the Cookie Notice describes it in full. Sessions last seven days and end after twelve hours of inactivity.
The chat can also be used from within the signed-in client area. As described above, the visible text of the page is not sent to the AI provider, so the project details on your screen are not included unless you type them into the chat yourself.
The lawful bases are performance of our contract (Article 6(1)(b)) and my legitimate interests in administering client relationships (Article 6(1)(f)).
How enquiries and newsletter sign-ups are handled
An enquiry is emailed to me so that I can respond, and recorded in my own private database, hosted by Cloudflare, so that I can manage and follow up enquiries in one place. The email is delivered by Resend, my email provider. Enquiries made through the chat reach me the same way, together with the chat transcript. The lawful basis is my legitimate interests in responding to and keeping track of business enquiries (Article 6(1)(f)), and performance of a contract once an engagement is agreed (Article 6(1)(b)).
Newsletter sign-up uses a confirmed two-step opt-in. When you give your email address I send you a confirmation email and add you to the list only if you click the link in it, which expires after three days, so no address can be added without the owner's agreement. Your address is then held by Resend, which sends the newsletter on my behalf. Every newsletter carries an unsubscribe link, and you can also reply to any email from me, or write to [email protected], and I will remove you straight away. So that I can show your consent was properly given, I keep a dated record of the form you signed up from, the version of the wording you were shown, and the moment you clicked the confirmation link. The lawful basis is your consent (Article 6(1)(a)), which you may withdraw at any time.
Who else handles your information
I do not sell personal data and I do not share it for anyone else's marketing. The following organisations process personal data on my instructions, under contract, as my processors: Cloudflare, which hosts this website, its database, its file storage and its network protection; Anthropic, which generates the chat assistant's replies, my private summaries of live-chat conversations, the enquiry priority suggestion and my daily summary; Resend, which sends my email and holds the newsletter list; and Asana, which holds my own task list. I also use Google Search Console, which receives no personal data of yours. My accountant and, where necessary, my professional advisers may see records that contain your information. I will disclose information where the law requires it.
Cloudflare, Anthropic, Resend and Asana are established in, or process data in, the United States. Those transfers are made under the safeguards permitted by Chapter V of the UK GDPR, applying the data protection test introduced by the Data (Use and Access) Act 2025, in practice the UK Addendum to the EU standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it. You may ask me for details of the mechanism relied on for any particular provider.
How long I keep your information
The schedule below is the standard I work to. Where the table shows a period that is applied by hand rather than automatically, that is stated. The automated deletion jobs record and surface failures rather than silently treating an unsuccessful deletion as complete.
| Record | Retention period | How it is applied |
|---|---|---|
| Enquiries that do not lead to an engagement | 12 months from the last contact | By hand |
| Enquiries that lead to an engagement, and client, project, proposal, approval, project-file and billing records, excluding the analytics linkage listed separately below | The engagement, then 6 years from the end of the tax year in which the last invoice falls, for tax and accounting purposes and for the limitation period on contract claims | By hand; unreferenced private upload remnants are removed automatically after 24 hours |
| Chat conversation log, including IP address, user-agent, page, the assistant's private assessment and any messages from me | 7 days from the last message; where linked to an enquiry, until that enquiry is closed as won or lost, plus 7 days | Automatically |
| Chat abuse block against an IP address | 30 days | Automatically |
| Newsletter subscription | Until you unsubscribe or ask me to delete it | By hand, on request |
| Optional cross-device generator and brief drafts | Up to 30 days, or earlier deletion through the return link | Automatically; not included in backup snapshots |
| Interactive Positioning Workbook companion notes and version history | 180 days after the last save or review request; backup copies follow the 35-day backup cycle, with the latest successful snapshot kept until a newer successful backup exists | Automatically from the live database; early deletion is available in the companion |
| Progress events and the browser-journey and measurement session identifiers that link them | Up to 425 days | Automatically |
| Temporary checkout attribution handoff, including the opaque reference, attribution and consented analytics identifiers | Up to 30 days, or earlier after successful transfer to a completed purchase | Automatically |
| Analytics linkage on enquiry, purchase, client, booking and invoice records | Up to 425 days from the first valid linkage; the commercial record then continues under its own retention period without the analytics identifiers | Automatically; only the linkage is cleared |
| Activity and change log, which records client email addresses against actions taken | 6 years, in line with the client records it documents | Not yet applied, see below |
| Sign-in failure counters, which hold an IP address and an email address | Cleared on a successful sign-in | Not yet applied, see below |
| Records of data protection requests and their outcomes | 6 years, as evidence of compliance | By hand |
| Database backups | 35 days, except that the most recent backup is always kept | Automatically |
| Blocked-country counters | Aggregate daily counts only, with no identifier | Kept indefinitely |
Being straightforward about the two rows marked “not yet applied”: those records currently have no automatic deletion, so they persist until I remove them by hand. Automatic deletion for each is being built. If you want either removed sooner in your own case, ask me and I will do it.
Erasure is carried out by me by hand against this schedule. When I complete a request I record what was done, erased in full, anonymised, retained because the law requires it, retained for accounting and tax record-keeping, declined because I could not verify the request, or another outcome that I explain, together with my reason and the lawful basis for anything kept.
Backup copies are kept so that the site and its records can be recovered if something fails. They are held for recovery only. I do not use them for ordinary business processing, and I do not read or search them to answer an enquiry, to contact anyone, or for any other day-to-day purpose. A backup taken before your request is not edited, so for a limited period it may still contain information that has already been deleted from the live system. Backups are kept for up to 35 days and are then deleted automatically, except for the single most recent backup, which is replaced when the next one is taken. If a backup ever has to be restored, the deletion and retention decisions already made are applied again to the restored records automatically, so information you asked me to delete is not brought back into use.
Your rights
Under UK GDPR you have the right to be told what personal data I hold about you and to have a copy of it; to have inaccurate data corrected; to have data erased where there is no good reason for me to keep it; to restrict or object to processing, including profiling; to receive data you gave me in a portable form; and to withdraw consent where I rely on it. You also have the right not to be subject to a decision taken solely by automated means that has a legal or similarly significant effect on you, and to ask for human involvement, to make representations and to contest such a decision.
To exercise any right, email [email protected] with the subject line "Data Protection Request", or use the enquiry form on the contact page and choose the data protection option. If you use the form, you will get an automatic acknowledgement straight away giving you a reference and the date by which I will answer. I will respond within one calendar month. Where a request is complex or there are several, I may extend that by up to two further months and will tell you if I do. Where I genuinely need you to tell me more before I can search for your data, I will ask, and the month runs from your reply. My search will be reasonable and proportionate rather than exhaustive, as the Data Protection Act 2018 now provides. I may ask you to confirm your identity before I disclose anything.
If you have a client account you can download a copy of your account, project, proposal, billing, project-file metadata, decision and data protection request records at any time from the account itself. File bodies that are still visible in your project library can be downloaded separately. You can also ask for your account to be deleted from there; making that request suspends your access while I deal with it. The account-data download does not yet include your original enquiry, your chat conversations, the progress events, analytics linkage, the activity log or the contents of uploaded files; ask me and I will supply those too.
You can switch the browser-linked measurement described above off in one click, in this browser, using the control on the Cookie Notice. Doing that stops future progress events, removes both analytics identifiers and the acquisition storage from this browser immediately, and prevents future linkage from it. It does not by itself erase events or linkage already held on the server. You can ask me to delete matching events and clear the linkage from commercial records; records that must be retained for another lawful reason can remain without the analytics identifiers.
Complaints
If you are unhappy with how I have handled your personal data, please tell me first, so that I have the chance to put it right. Email [email protected] with the subject line "Data Protection Complaint", or use the enquiry form on the contact page and choose the data protection option; either route is a valid complaint and you do not have to use any particular wording. If you use the form you are acknowledged automatically within minutes; in any event I will acknowledge your complaint within 30 days of receiving it, look into it without undue delay, take whatever steps are appropriate, and tell you the outcome. This is the complaints procedure required by section 164A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act 2025.
You also have the right to complain to the Information Commissioner's Office, the UK's independent data protection regulator, at ico.org.uk or on 0303 123 1113. The ICO will normally expect you to have raised the matter with me first.
Visitors in the EEA
My services are offered to visitors in the United Kingdom, Ireland, the rest of Europe, North America and the United Arab Emirates, so if you are in the European Economic Area the EU General Data Protection Regulation applies to your information alongside UK law, and you may complain to your own national supervisory authority as well as to the ICO. Two differences matter in practice. The statistical-measurement exception in regulation 6 described above is a feature of UK law and has no equivalent in the EEA. I do not rely on it in the United Kingdom either: the identifiers are consented to everywhere. As an additional safeguard, no progress event is recorded for visitors whose connection places them in an EEA country, whatever they have accepted. An EEA visitor who has accepted analytics may still have the random identifiers linked to an enquiry or completed purchase they deliberately submit, as described above; neither identifier is sent to Stripe. And the chat's AI assistant is an AI system within the meaning of the EU Artificial Intelligence Act, whose transparency requirements for AI systems that interact with people apply from 2 August 2026; it tells you it is an AI assistant when the conversation starts, each of its replies is labelled as such, and you can always ask for me in the chat or reach me by email instead.
Security
This site is served only over HTTPS, with a strict content security policy, and no third-party script other than Cloudflare's measurement beacon is permitted to run. Passwords are stored only as salted hashes and are rehashed to the current work factor when you sign in. Sign-in attempts are rate-limited by IP address and email address. Administrative access requires a separate credential and, for changes to client records, a second confirmation. Project uploads are held outside the public media library, are limited to PDF, PNG, JPG and plain-text formats up to 10 MB, are checked against the declared file type, and are served only through an authenticated download as an attachment. Database backups are taken to Cloudflare storage that is not publicly readable, verified by reading them back, and tested by restoring them into a separate database. Backup files are not separately encrypted by me beyond the encryption the storage provider applies.
Changes to this policy
I update this policy when the way the site works changes or when the law changes. The date at the top shows when it was last revised. Where a change materially affects you, I will say so in the newsletter or by email.