LEGAL INFORMATION
Privacy Policy
This policy explains how StrongOrigin Limited trading as Websites In A Day (company number 13580570), whose registered office is 3 Bassfield Manchester Road, Walmersley, Bury, Lancashire, England, BL9 5LY collects and uses personal information when you visit this website, make an enquiry, become a client or communicate with us. StrongOrigin Limited is the controller of the personal information described here.
Last updated:
1. Who we are and how to contact us
Websites In A Day is a trading division of StrongOrigin Limited trading as Websites In A Day (company number 13580570), whose registered office is 3 Bassfield Manchester Road, Walmersley, Bury, Lancashire, England, BL9 5LY.
For privacy questions, rights requests or complaints, email start@websitesinaday.com. Please use “Privacy request” in the subject line. We may ask for information needed to confirm your identity before acting on a request.
2. Information we collect
We collect information you give us, information created while delivering a project and limited technical information generated when you use the website.
- Identity and contact details, including your name, business name, email address, optional telephone number and country or region.
- Enquiry and qualification details, including your industry, current website, required timeframe, goals, requested features, indicative budget and message.
- Project information, such as briefs, content, brand assets, approvals, feedback, access details you choose to provide, contracts, invoices and support correspondence.
- Marketing preferences and records of consent.
- Cookie-consent choices, consent version and timestamp stored in your browser.
- Technical and usage information, such as page visits, device/browser information and approximate location, only where relevant and permitted. Google Analytics is loaded only after analytics consent.
- Information required to prevent fraud, secure our systems, diagnose faults or establish and defend legal claims.
3. How we obtain information
Most information comes directly from you through forms, email, calls, project documents and day-to-day delivery. We may also receive business contact information from a colleague who introduces you, from public professional sources, or from suppliers you authorise us to work with. Where information comes from another source, we use it only where we have a lawful reason and where its use is reasonably expected.
4. Why we use information and our lawful bases
UK data protection law requires a lawful basis for each use. Depending on the circumstances, we rely on the following bases:
- To answer enquiries, assess project fit and take steps requested before a contract: steps before entering a contract and our legitimate interest in operating our business.
- To prepare, manage and deliver website design, development, hosting, maintenance and related services: performance of a contract.
- To manage payments, records, security, service quality and business administration: contract, legal obligation and legitimate interests.
- To keep accounting and tax records and respond to lawful authorities: legal obligation.
- To send marketing email where you have actively opted in: consent. You can withdraw at any time.
- To measure website use through Google Analytics: consent. Analytics remains off until permission is given.
- To prevent abuse, protect systems and establish or defend claims: legitimate interests and, where applicable, legal obligation.
- To use project work in our portfolio: our legitimate interest in showing our work, subject to the contract, confidentiality, applicable rights and any agreed restrictions.
5. When information is required
Fields marked as required are needed to assess or respond to an enquiry. Certain project, identity, billing and access information is required to enter into or perform a contract. If it is not provided, we may be unable to quote, reserve a launch day or deliver the service. Marketing consent is always optional and separate.
6. Who we share information with
We share personal information only where reasonably necessary and with appropriate safeguards. Recipients may include:
- Hosting, infrastructure, backup, monitoring and security providers, including Hostinger where used for this website or a client service.
- Form handling and email providers, including FormSubmit for website enquiries and the relevant email service used to receive and respond.
- Google Analytics, only after analytics consent, to provide aggregated usage measurement.
- Professional advisers such as accountants, legal advisers and insurers.
- Contractors or specialist suppliers engaged for an agreed project and bound by confidentiality and data-protection duties.
- Payment, banking and accounting providers used to administer contracts and invoices.
- Regulators, courts, law-enforcement bodies or other parties where disclosure is required by law or necessary to protect legal rights.
- A buyer, investor or successor if our business or assets are reorganised, subject to confidentiality and lawful processing.
7. International transfers
Some suppliers may process information outside the United Kingdom. Where UK data protection law requires safeguards, we use an applicable adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved contractual clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.
8. How long we keep information
We keep information only for as long as reasonably needed for the stated purpose, legal obligations and potential claims. Our normal starting points are:
- Unsuccessful or inactive enquiries: up to 24 months after the last meaningful contact.
- Client contracts, invoices and core transaction records: generally seven years after the end of the relevant financial period.
- Project files, approvals and support correspondence: for the contract term and normally up to six years afterwards, unless a shorter period is agreed or longer retention is reasonably required for a claim.
- Marketing records: until you unsubscribe or consent is withdrawn, with a minimal suppression record retained to respect the request.
- Analytics data: according to the retention controls configured in Google Analytics; aggregated reports may be retained without directly identifying you.
- Security logs and backups: according to operational rotation schedules, unless needed to investigate an incident or claim.
9. Security
We use proportionate technical and organisational measures designed to protect information, including access controls, secure transmission, least-privilege access, backups and supplier review. No internet transmission or storage system can be guaranteed completely secure. Please do not send passwords through ordinary email; use an agreed secure sharing method for project credentials.
10. Your data-protection rights
Depending on the circumstances and your location, you may have rights to be informed, access your information, correct inaccurate information, request erasure, restrict processing, receive portable data and object to particular uses. Where processing relies on consent, you may withdraw that consent without affecting earlier lawful processing. Rights can contain exemptions, and we will explain any lawful limitation.
You have an absolute right to object to direct marketing. Email start@websitesinaday.com or use the unsubscribe method in a marketing message. We normally respond to valid rights requests within one calendar month.
11. Complaints
Please contact us first so we can investigate. You may also complain to the UK Information Commissioner’s Office at ico.org.uk or by telephone on 0303 123 1113. If you are outside the UK, you may also have a right to contact the regulator responsible for data protection where you live.
12. Children, automated decisions and external links
Our services are intended for businesses and adults, and we do not knowingly collect children’s information through this website. We do not make decisions producing legal or similarly significant effects solely by automated means. We may use AI-assisted tools under human direction during research, drafting, production and quality assurance; we avoid placing confidential or personal client information into such tools unless appropriately assessed and authorised.
Links to other websites are governed by their own privacy practices.
13. Changes to this policy
We may update this policy when our services, suppliers or legal obligations change. The “last updated” date identifies the current version. Material changes will be highlighted where reasonably practical.