Who we are
This website is run by Midlands Code Lab Ltd, a company registered in England and Wales (company number 17278808) whose registered office is at 1 Burrough Court, Burrough on the Hill, Melton Mowbray, LE14 2QS. We are registered with the Information Commissioner's Office (registration number ZC177542). For the purposes of UK data protection law, we are the "data controller" of the personal information you submit through this site.
You can contact us about anything in this notice by emailing [email protected].
What personal information we collect
When you fill in our contact form, request a callback, or email us directly, we collect:
- Your name
- Your email address
- Your phone number (only if you give it via the callback widget)
- Anything you write in the brief / message / note field
- Your preferred day and time window for a callback (callback widget only)
If you book a call through our calendar booking link, the calendar provider may also collect your time zone and the meeting time you pick.
If you sign up for our email list, we collect:
- Your first name and email address
- The date and time you signed up, and the IP address you signed up from
- Which page of this site you signed up on
- A reference to the exact wording you agreed to. We keep every version of that wording on file, so we can always show you what you were told on the day
- The date and time you confirmed your subscription by clicking the link in our confirmation email
We keep that signup record because UK data protection law requires us to be able to demonstrate that you agreed, when, and to what. It is not used to profile you.
We do not run analytics that identify individual visitors. We do not use tracking cookies. We do not fingerprint or profile you. Some of our marketing emails include a small tracking pixel that tells us whether the email was opened. We use it to measure how well our emails are working. It records that the email was opened and when, and nothing else about you, we do not use it to build a profile, and we do not use it to target you anywhere else. Our emails never contain click-tracking links: any link in an email we send goes straight to the page it names.
Why we collect it
If you contact us: so we can reply to your enquiry and have a sensible conversation about whatever you got in touch about. Contacting us does not put you on our email list. We will never add you to it because you sent us a message, and we do not share your details with anyone for marketing purposes.
If you sign up for our email list: so we can send you the emails you asked for, and nothing else. You have to actively ask for those, twice. You tick a box, then you click a confirmation link in an email we send you. Until you do the second part, we will not send you anything else.
If you download something from this site: nothing is required. Our guides and PDFs are free to download without giving us any details at all. If a download page also offers you the email list, that offer is separate and optional, and refusing it does not stop you getting the file.
Our lawful basis
Under the UK GDPR, our lawful basis depends on what you did:
- Replying to your enquiry: legitimate interests. Our interest in being able to respond to a message you have actively sent us. You took the active step of contacting us, so this processing is expected and reasonable.
- Sending you marketing emails: consent. You gave it by ticking an unticked box and then confirming by email. You can withdraw it at any time, and it is as easy to withdraw as it was to give.
- Keeping a record that you unsubscribed: legitimate interests. Our interest in making sure we do not email you again by mistake. This is called a suppression record, and the Information Commissioner's Office expects us to keep one.
- Keeping business and tax records: legal obligation. Where UK company and tax law requires it.
Marketing emails are also covered by the Privacy and Electronic Communications Regulations 2003. Every marketing email we send identifies us clearly and carries a one-click unsubscribe link.
Who we share your information with
To receive form submissions and send email, we rely on the following third-party services, each of which acts as our data processor:
- Cloudflare: hosts this website and processes our newsletter signups in transit. Those are handled at Cloudflare's nearest data centre, which for UK visitors is normally in the United Kingdom or the European Union, and are passed straight through rather than stored there. We also use Cloudflare Turnstile on the signup form to keep automated sign-ups out. Turnstile is designed as a privacy-preserving alternative to reCAPTCHA and is not used to track you across other websites, but it does load a script from Cloudflare and may place a short-lived token on your device to remember that you passed the check.
- EmailOctopus (Three Hearts Digital Ltd, a UK company registered in England and Wales, number 09897211): stores our email list and sends our marketing emails. Subscriber data is held on Amazon Web Services servers in Ireland, inside the European Economic Area, and their sending servers are in the EU too.
- Web3Forms: receives submissions from our main contact form, stores them briefly on their servers, and forwards them to our inbox. Their own privacy policy applies to that storage.
- Splitforms: does the same job for the enquiry forms on our local SEO and social media pages.
- Microsoft 365: hosts [email protected] and receives contact form submissions as email. Microsoft Bookings, part of the same service, handles the "Book a free intro call" link and collects the data needed to schedule that meeting.
We are in the process of moving the contact forms onto the same in-house handler our newsletter form uses, which will remove Web3Forms and Splitforms from this list. We will update this notice when that happens.
Beyond these, we do not share your information with anyone else, except where we are required to by law. We have never sold a mailing list and we will not.
Some of these providers store or process data outside the United Kingdom. Ireland and the wider European Economic Area are covered by the UK's adequacy regulations. Where a provider processes data elsewhere, including the United States, we rely on the UK's recognised transfer mechanisms, including the UK International Data Transfer Addendum and Standard Contractual Clauses.
How long we keep your information
- Contact form submissions: these arrive as email in our inbox. We keep them while a conversation is active. After a project ends, or a quote goes cold, we delete the thread within 12 months.
- Email list subscribers: we keep your email address and signup record for as long as you stay subscribed. Every two years we will ask you to confirm you still want the emails, and remove you if you do not reply. Because we do not track opens, that check is a question we ask rather than something we infer from your behaviour.
- Unsubscribe records: if you unsubscribe, we keep your email address on a suppression list indefinitely. That is the only way to guarantee we never email you again by accident. We keep nothing else about you.
- Project records for clients we work with: we keep these for 6 years from the end of the engagement, in line with UK tax record-keeping requirements.
Your rights
Under the UK GDPR you have the right to:
- Ask what data we hold about you
- Ask us to correct it if it is wrong
- Ask us to delete it
- Restrict how we process it
- Ask for a copy in a portable format
- Withdraw your consent to marketing at any time
- Complain to the Information Commissioner's Office
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Your right to object to direct marketing. You can tell us to stop sending you marketing at any time, and we have to stop. There is no exception to this and you do not have to give a reason. Click the unsubscribe link at the bottom of any email we send, or just email [email protected] and say stop. Both work, and both are one step.
Cookies and browser storage
This site does not set tracking cookies. It uses a small amount of browser storage to remember your colour-palette choice in the "Tweaks" panel, if you use it. That preference stays on your device. It is not shared with anyone.
Our newsletter signup form posts directly to this website rather than to an outside provider. The one exception is Cloudflare Turnstile, the spam check described above, which loads a script from Cloudflare and may place a short-lived token on your device. We would rather it were not there, but without it a bot can flood the list. Our contact and enquiry forms currently post to the third-party providers named above and do need JavaScript. Moving them onto the same in-house handler is on our list.
Changes to this notice
If this notice changes in any material way, we will update the "Last updated" date at the top, and flag the change on the homepage for at least 30 days.
How to complain
If you are unhappy with how we have handled your information, please email [email protected] first so we can put it right.
If we cannot, you have the right to complain to the Information Commissioner's Office:
- Web: ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
About this notice: this is a plain-English privacy notice for a small UK limited company. It is not legal advice. If your circumstances are unusual, or if you ever start processing significantly more personal data than is described here, you should review this notice with a solicitor or check the ICO's own privacy notice generator at ico.org.uk/create-your-own-privacy-notice.