Who we are
JMJ Web Design Limited (company number 08668431), registered in England and Wales, is the data controller for the personal data collected through this website (wpcarepros.co.uk) and our services. We are registered with the Information Commissioner's Office (ICO registration number A8313464).
You can contact us about data matters at: hello@wpcarepros.co.uk
What we collect
We collect personal data in the following situations:
- When you submit our contact or application form: name, email address, phone number, website URL, and any information you choose to include in free-text fields.
- When you become a client: billing name and address, payment method details (processed and stored by our payment processor โ we never see your card number), and information about your WordPress site(s).
- When you contact us by email: your email address and the contents of your message.
- Automatically when you visit the website: IP address, browser type and version, pages visited, time and date of visit โ via analytics software.
We do not knowingly collect data from children under 16.
How we use it
We use the personal data we collect for the following purposes:
- To respond to enquiries and process applications for our services.
- To provide and manage the services you have subscribed to.
- To send you service updates, monthly reports, and billing communications.
- To improve our website and understand how visitors use it.
- To comply with legal obligations.
We do not sell your personal data. We do not use it for automated profiling or decision-making that has a legal or similarly significant effect on you.
Lawful basis for processing
We rely on the following lawful bases under UK GDPR:
- Contract: processing necessary to provide the services you've signed up for, or to take steps at your request before entering a contract.
- Legitimate interests: responding to enquiries, improving our website, and keeping our services secure โ where these interests are not overridden by your rights.
- Legal obligation: where we are required to retain or share data by law (e.g. financial records for HMRC).
- Consent: if you have opted in to receive marketing communications from us. You can withdraw consent at any time.
Third parties we share data with
We use a small number of third-party services to run our business. Each is bound by its own privacy policy and, where required, a data processing agreement with us:
- Stripe โ payment processing. Your card details go directly to Stripe and are never stored by us.
- Google Analytics โ website analytics, using anonymised IP addresses.
- Postmark / Amazon SES โ transactional email delivery.
- Our hosting infrastructure โ servers located in the United Kingdom and European Economic Area.
We do not transfer your personal data outside the UK/EEA without appropriate safeguards in place.
How long we keep it
- Enquiry data (not converted to client): 12 months, then deleted.
- Client data (active): retained for the duration of the contract.
- Client data (after contract ends): 6 years, to comply with HMRC record-keeping requirements.
- Website analytics: 26 months, then automatically purged by our analytics provider.
Your rights
Under UK GDPR, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate data.
- Erasure: ask us to delete your data, where we have no legal obligation to retain it.
- Restriction: ask us to limit how we use your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email us at hello@wpcarepros.co.uk. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Cookies
We use a small number of cookies on this website:
- Essential cookies: required for the site to function (e.g. WordPress session cookies). These cannot be disabled.
- Analytics cookies: set by Google Analytics to help us understand how the site is used. These use anonymised IP addresses and can be disabled via your browser settings or by opting out of Google Analytics.
We do not use advertising, tracking, or social media cookies.
Security
We take reasonable technical and organisational measures to protect your personal data โ including encrypted connections (HTTPS), access controls, and regular security reviews. No transmission over the internet can be guaranteed to be 100% secure, but we do everything we reasonably can.