Owner and Data Controller

AVIDD Design Ltd

Company number: 11134451

Contact email: studio@avidd-design.co.uk

Types of Data Collected

Our website collects the following types of personal data, either directly from users or through third-party services:

  • Cookies
  • Usage Data (e.g., pages visited, time spent)
  • Name and Email address

Personal data may be freely provided by users, or in the case of usage data, collected automatically when using the website.

Cookies

This website uses the following cookies:

  • _ga (Google Analytics)
  • _gat (Google Analytics)
  • _gid (Google Analytics)

Cookies are used to enhance website functionality and monitor usage. You can adjust your browser settings to block or delete cookies if you prefer.

We use Google Tag Manager to manage website analytics and marketing scripts. This may collect anonymized data. You can opt out via your browser settings

Processing and Security of Data

Methods of Processing

The Data Controller processes personal data securely using computers and IT-enabled tools in accordance with organisational procedures. Personal data may be accessed by employees or appointed service providers (e.g., hosting, IT support, marketing, legal services) only as necessary to provide services. A list of third-party processors is available on request.

Place of Processing

Personal data is processed at AVIDD Design Ltd’s offices or at locations of authorised personnel or third-party service providers. For more information, contact the Data Controller.

Retention of Data

We retain your contact form submissions for 12 months to respond to inquiries and for legal compliance. Newsletter subscriptions are kept until you unsubscribe.

Purpose of Collected Data

We collect your name and email to respond to your inquiries (legal basis: legitimate interest). If you sign up for our newsletter, we process your email based on your consent.

  • Analytics
  • Communication with users
  • Interaction with website services (e.g., support, inquiries)

International Data Transfer

Some of our service providers (e.g., Google) may process your data outside the UK/EU/EEA.

Website Hosting

Our hosting is provided by 20i. Their GDPR compliance includes:

  • Processing personal data only for communication, authentication, and billing purposes
  • Not sharing personal data with third parties unnecessarily
  • Deleting irrelevant personal data promptly
  • Performing privacy impact assessments
  • Managing consent for communication
  • Handling requests for deletion and compliance with the right to be forgotten
  • Reporting and managing data breaches in accordance with GDPR
  • Appointing a Data Protection Officer (contact details available on request)

Legal Use of Data

Personal data may be disclosed for legal purposes, including in court proceedings or if required by public authorities.

Statutory / Contractual & Consequences

Providing your email is necessary to respond to your inquiry. Without it, we cannot reply.

Additional Information

Further information on the collection or processing of personal data may be requested from the Data Controller.

System Logs and Maintenance

For maintenance and security purposes, system logs and other personal data (e.g., IP addresses) may be collected. This is necessary for website operation and to prevent abuse.

Rights of Users

Users have the right to:

  • Access their personal data
  • Correct inaccuracies
  • Request deletion or restriction
  • Receive data in a portable format
  • Object to processing
  • Raise a complaint with the Information Commissioner

Requests should be submitted to the Data Controller at the contact information above.

Changes to This Privacy Policy

The Data Controller may update this privacy policy at any time. Users are encouraged to review this page regularly. Significant changes will be highlighted. Continued use of the website after changes implies acceptance of the updated policy. Users may request deletion of their data if they do not agree with updates.


Note: This version is simplified for clarity and readability while ensuring coverage of mandatory UK GDPR elements such as data controller identity, data collection, purpose, retention, processing methods, user rights, cookies, and legal disclosures.