ThisWebDesignBack to app
PrivacyCookiesTermsAcceptable UseData ProcessingSub-processors

Privacy Policy

ThisWebDesign Ltd · Effective 28 June 2026

This Privacy Policy explains how ThisWebDesign Ltd (“we”, “us”, “our”) collects, uses and protects personal data when you use TWD Platform (the “platform”) and when you deal with us. It applies to the people who hold an account on the platform, who buy our services, or who contact us. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Controller and processor: which applies to you

The platform is used by many separate organisations (“workspaces”). The role we play depends on whose data it is:

  • You as an account holder. For personal data about you as a user of the platform (your account, how you sign in, billing, support and security), we are the controller, and this policy governs.
  • Data a workspace processes about its own contacts. When a workspace uploads or manages personal data about its own customers, clients or contacts through the platform, that workspace is the controller and we act only as its processor under our Data Processing Agreement. If you are a contact of a workspace, their own privacy notice governs that data, so please contact them in the first instance.

Who we are

ThisWebDesign Ltd is a company registered in England and Wales. We are the controller of the personal data described in this policy and are responsible for it under UK data protection law. Our registration and contact details are set out below.

Legal entity
ThisWebDesign Ltd
Registered in
England and Wales
Company number
12565907
Registered office
10 Sunflower Close, Littlehampton, West Sussex, United Kingdom, BN17 6UY
VAT
Not VAT registered
Data protection contact
privacy@thiswebdesign.co.uk
General enquiries
support@thiswebdesign.co.uk

The personal data we collect

  • Account and identity data: your name, email address, profile photo, job title, the language and time zone you choose, and the credentials used to authenticate you (your password is stored only as a salted hash by our identity provider; we never see it).
  • Workspace and permission data: the workspaces you belong to and the role and access rights you hold within them.
  • Billing data: if you purchase a paid plan, your billing name, billing address, VAT or tax identifiers, the plan you hold and your transaction history. Card details are entered directly with our payment processor (Stripe) and are never stored on the platform.
  • Communications: the content of messages, emails, calls and chats you exchange with our support team, and our records of them.
  • Usage, device and security data: your IP address, device and browser type, sign-in events, the actions you take in the app, and audit and security logs we keep to protect the service. We may infer an approximate location from your IP address for security and sanctions-screening purposes.
  • Cookies and similar technologies: see our Cookie Policy.

How we collect it

We collect personal data directly from you when you register, configure your account, buy a plan or contact us; automatically as you use the platform; from a workspace administrator who may create an account for you; and from our sub-processors (for example, billing status from Stripe).

Why we use your data and our lawful basis

PurposeLawful basis (UK GDPR)
Provide, operate and maintain the platform and your accountPerformance of a contract; our legitimate interests where you use it under your organisation’s contract
Authenticate you and keep the service secure, fraud and abuse prevention, audit loggingLegitimate interests (security of the service); legal obligation
Take payment and administer billingPerformance of a contract; legal obligation (tax and accounting)
Provide support and respond to your requestsPerformance of a contract; legitimate interests
Send service messages, security alerts, billing notices, material changesPerformance of a contract; legitimate interests
Send marketing about our own products and featuresConsent, where required; otherwise legitimate interests. You can opt out at any time
Improve, troubleshoot and develop the serviceLegitimate interests
Comply with law, enforce our terms, and screen against sanctions and export controlsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can ask us for that assessment by contacting privacy@thiswebdesign.co.uk.

Marketing

We will only send you marketing where we are permitted to. Every marketing message includes an unsubscribe link, and you can opt out at any time by contacting us. Opting out of marketing does not stop service messages that are necessary to operate your account. We do not sell your personal data.

Special category data

We do not intentionally collect special category data (such as health, ethnicity or political opinions) about platform account holders. Where a workspace chooses to process such data about its own contacts through the platform, it does so as controller under the Data Processing Agreement, and is responsible for the lawful basis and any additional condition for that processing.

Who we share your data with

  • Sub-processors who help us run the service. The current list, what each does and where it operates is published at our sub-processors page.
  • Professional advisers: lawyers, accountants, auditors and insurers, bound by confidentiality.
  • Authorities and regulators where we are required to disclose by law, or to establish, exercise or defend legal claims.
  • A successor organisation in connection with a merger, acquisition or reorganisation, subject to the protections in this policy.

Every processor we use is bound by a written contract requiring it to protect personal data and to process it only on our instructions.

Where your data is stored and international transfers

Your personal data is stored in the United Kingdom, in the Amazon Web Services Europe (London) Region (eu-west-2). This covers our application databases, uploaded files and documents, search and cache stores, outbound email processing and account identity records.

United Kingdom and the EEA

The United Kingdom benefits from a European Commission adequacy decision, and the UK recognises the EEA as providing adequate protection. Personal data therefore flows freely between the UK and the EEA without additional safeguards.

United States and the rest of the world

Where a sub-processor processes personal data outside the UK (for example payment or communications providers operating in the United States), that transfer is made under the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with the provider’s own data processing agreement and technical safeguards such as encryption in transit and at rest.

Wherever a user or contact is located, their personal data is stored in the United Kingdom region described above; we do not move primary storage to a user’s own country.

How long we keep your data

  • Account data: for as long as your account is active. After your account is closed we delete or anonymise it within a defined period, save where we must retain it for the reasons below or back-ups are rotating out.
  • Billing and tax records: retained for six years to meet UK tax and accounting requirements.
  • Support communications: kept only as long as needed to handle your request and for a reasonable period afterwards.
  • Security and audit logs: kept for a limited period to detect and investigate security events.

Your rights

Under UK data protection law you have the right to:

  • be informed about how we use your data (this policy);
  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to our processing in certain circumstances;
  • data portability, receive your data in a portable format; and
  • withdraw consent at any time, where we rely on consent.

To exercise any of these rights, contact privacy@thiswebdesign.co.uk. We will respond within one month. There is normally no charge, and we may need to verify your identity before we act.

Automated decision-making

We do not make decisions that produce legal effects, or similarly significant effects, about you based solely on automated processing.

How we keep your data secure

We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access controls on a least-privilege basis, audit logging, and regular review of our security. No method of transmission or storage is completely secure; where we are required to, we will notify you and the ICO of a personal data breach.

Children

The platform is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “last updated” date above and, where the change is material, take reasonable steps to tell you.

How to contact us and how to complain

For any privacy question or to exercise your rights, contact privacy@thiswebdesign.co.uk.

If you are unhappy with how we have handled your personal data you can complain to the Information Commissioner's Office (the UK supervisory authority). You can reach the ICO on 0303 123 1113 or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We would, however, appreciate the chance to address your concerns first, so please contact privacy@thiswebdesign.co.uk before you approach the ICO.

Questions about these documents? Contact us at privacy@thiswebdesign.co.uk.