The short version. We collect as little as we can. Our website sets no tracking cookies. We use your details to reply to you, make your free preview and do the work our clients pay for. We never sell your data, and we don't put personal data into AI tools. To see, correct or delete your data, email [email protected].
Who we are
Northpin Studio is an independent web design studio run by a self-employed designer, based in Monaco. We decide how and why your personal data is used, so we are the "controller" under UK data protection law. Where the EU GDPR applies to you, we are the controller under that law too.
- Company number: not applicable (not a registered company)
- Privacy questions: [email protected]
- Anything else: [email protected]
- EU representative (Article 27 EU GDPR): none appointed yet. We assess this as we take on clients in the EU and will name a representative here when Article 27 requires one.
This notice covers our website, northpin.studio, in every language, and the way we work with enquirers, clients and the businesses we contact. It doesn't cover the websites we build for clients. Each client has its own privacy notice. When we host a client's website, we act for the client as its "processor" under our Data Processing Addendum.
When you visit our website
Hosting and security
Our website is hosted on Cloudflare Pages. When your browser asks for a page, Cloudflare's servers receive the technical details every website receives: your IP address, the page you asked for, the date and time, the website that sent you (if any), and your browser and device type.
Cloudflare uses these details to deliver the page and to block attacks and abusive bots. We don't use them to find out who you are. If Cloudflare blocks a request as a threat, it may show us details of that request, such as the IP address and time, so we can keep the site safe.
Lawful basis: our legitimate interests in running a website that is safe and works.
Visitor statistics, without cookies
To learn which pages are useful, we may switch on Cloudflare Web Analytics. When it's on, your browser loads a small script from static.cloudflareinsights.com. It records:
- the page you viewed and the website that sent you here
- your browser, operating system and type of device
- your country
- how quickly the page loaded and appeared on your screen
It sets no cookies and saves nothing on your device. Cloudflare says it doesn't fingerprint visitors. We only see totals, such as "120 visits to the pricing page this week", never a profile of a person.
The rules for this kind of counting differ between the UK and EU countries. So if we switch it on, we only load it on our English pages, unless we've checked that the rules where you are allow it without asking you first.
To opt out, block static.cloudflareinsights.com with a content blocker or your browser's tracking protection. The site works exactly the same. There's more detail in our cookie notice.
Lawful basis: our legitimate interests in improving our website.
What stays in your browser
- Fonts. Our fonts are stored on our own server. Your browser never asks Google Fonts or any other font service for them.
- No embeds. We don't embed Google Maps, YouTube, social media feeds, reCAPTCHA or advertising pixels.
- Language suggestion. If your browser is set to another language we offer, a small banner may suggest that version of the page. The check happens only in your browser. Nothing is sent to us or saved.
Our website check tool
Our website check sends the web address you type straight from your browser to Google's PageSpeed Insights service. Google tests that page and sends the results back to your browser. We don't receive or keep the address or the results.
Google receives the address, your IP address and standard browser details. It uses them as an independent controller, under the Google Privacy Policy. Please only enter the address of a public web page, not a private link.
When you ask for a free preview or contact us
What we collect
When you fill in our free preview form, we collect:
- your business name, and your town or a Google Maps link to your business
- the main thing you want your website to do
- whether you have a website, and its address if you do
- the languages you want your website in
- your first name
- how you'd like us to contact you (email, WhatsApp or Telegram), and your phone number or email address
- anything you write in the optional note
- the page you sent the form from, the language of that page and any plan you picked, so we know what you were looking at
We need your business name, your first name and a phone number or email address to reply. Without them, we can't make your preview. Everything else is optional.
If you email or message us, we collect your message, your contact details and anything you choose to send, such as photos or your logo. To make your preview, we also look at public information about your business, such as your Google Business Profile and your current website.
How your form reaches us
Your answers go to a small program that Cloudflare runs for our site (a "Pages Function"). It sends them to our inbox as an email, using Cloudflare Email Routing, and isn't set up to keep a copy. Our mailbox is run by our email provider, Proton AG (Proton Mail). Both are on our sub-processor list.
If we ever move the form to another service, such as Web3Forms or Formspree, we'll add it to that list first.
Why we use it
We use your details to reply to you, make your preview, talk it through with you and, if you want one, send you a proposal. We won't add you to a mailing list.
If you choose WhatsApp, we'll message you there. WhatsApp is run by Meta, which handles your messages under the WhatsApp Privacy Policy.
Lawful basis: taking steps you've asked for before a possible contract (Article 6(1)(b)). If you're writing for a company rather than for yourself, our legitimate interests in answering business enquiries (Article 6(1)(f)).
Your preview
Your preview sits on a private link that tells search engines not to list it. If you don't order, we delete the preview and the materials used for it within 30 days. The free preview terms have the details.
If you are a client
What we collect
- the names, job titles and contact details of the people we deal with
- your business details: business name, billing address and, if you give them, your company or VAT number
- your signed Order Form and its e-signature record (names, email addresses, dates, times and IP addresses, as recorded by the e-signature tool)
- invoices and payment records
- our emails and messages
- the text, photos and other content you send for your website
- login or access details you share with us, for example for your domain. We keep these only in an encrypted password manager.
Payments are handled by Stripe. We never see your full card or bank account number.
Why we use it
We use it to do the work in our contract, bill you, keep our accounts, meet our tax and legal duties, and deal with any complaint or legal claim.
Lawful bases:
- performing our contract with you (Article 6(1)(b))
- our legal obligations, for tax and accounting records (Article 6(1)(c))
- our legitimate interests (Article 6(1)(f)), for keeping records in case of a dispute, for dealing with staff of a client company, and for showing your finished website in our portfolio unless you opt out on your Order Form
Your customers' data
When we host your website or pass on its form messages, we handle your customers' personal data only on your instructions. Our Data Processing Addendum sets out how. Your own privacy notice tells your customers about it.
If we contacted you first
This section is for businesses we contacted without being asked. It tells you what the law says we must tell you when we didn't get your details from you.
Where we got your details
We find local businesses by searching public business listings ourselves, such as Google Business Profile on Google Maps, and by looking at their websites. Before we get in touch, we may check public registers such as Companies House. We don't buy contact lists, and we don't use automated scraping. We never phone anyone: we get in touch in writing or in person.
What we hold
- your business name, address, phone number, email address and website, as they appear publicly
- the name of the owner or a contact, where it's part of the listing (for example, for a sole trader)
- notes about your current website, such as its speed score or what could be better
- where and when we found your details
- our messages to you and any reply
- whether you've asked us not to contact you again
Why we use it
We use it to contact your business about its website, with a specific observation about your current site. Sometimes we include a private concept preview.
We follow the marketing rules of the country you're in. For example, in the UK we don't send unsolicited marketing emails or direct messages to sole traders or partnerships. We write by post or visit in person, and ask before sending anything by email. We never phone anyone. We don't send unsolicited emails to businesses in countries that require consent first, such as Germany and Spain.
If we made a concept preview for your business, it's on a private link that search engines are told not to list. It's labelled as not connected with or endorsed by your business. It doesn't use your photos, photos from Google or your reviews. We delete it within 30 days.
Lawful basis: our legitimate interests in offering our services to local businesses (Article 6(1)(f)). We've weighed our interests against yours in a written assessment, and we keep what we hold to a minimum. You can ask us for a summary of that assessment.
Where the law needs your permission before we email or message you (for example, UK sole traders and partnerships), we only do so with your consent, which is then our lawful basis for those messages (Article 6(1)(a)). You can withdraw it at any time by replying "stop".
You can say no at any time
You have an absolute right to object to direct marketing. Reply "stop" to any message from us, or email [email protected]. We'll stop within 48 hours and delete what we hold about you.
We then keep one short entry on our "do not contact" list: your business name, the email address or phone number, and the date you asked. That's so we never contact you again by mistake.
Why we use your data: purposes and lawful bases
- Delivering our website and keeping it secure: legitimate interests, Art 6(1)(f).
- Counting visits without cookies, if switched on: legitimate interests, Art 6(1)(f).
- Replying to enquiries and making free previews: steps before a contract, at your request, Art 6(1)(b). For staff writing on behalf of a company: legitimate interests, Art 6(1)(f).
- Contacting businesses we found ourselves: legitimate interests, backed by a written assessment, Art 6(1)(f). Where the law needs your permission before we email or message you: consent, Art 6(1)(a).
- Doing and billing the work for clients: contract, Art 6(1)(b).
- Keeping tax and accounting records: legal obligation, Art 6(1)(c).
- Keeping the "do not contact" list, to honour opt-outs: legal obligation and legitimate interests, Art 6(1)(c) and (f).
- Handling complaints and legal claims: legitimate interests, Art 6(1)(f).
- Sending sub-processor update emails you asked for, and publishing testimonials you've agreed to: consent, Art 6(1)(a).
The articles are those of the UK GDPR and, where it applies to you, the EU GDPR. We rely on consent only where we say so in this notice: emails and messages you've agreed to receive, sub-processor update emails and testimonials. You can withdraw your consent at any time.
Who we share it with
We don't sell or rent your data, and we don't share it for advertising.
Service providers. A few companies process data for us under contracts that require them to protect it: hosting and security (Cloudflare), payments (Stripe), and our email, e-signature, accounting, code hosting and backup, password manager and domain registration providers. Our sub-processor list names each one, says where it handles data and explains how transfers are protected.
Freelancers. If a freelancer helps with your project, for example a translator, they work under a written contract with confidentiality and data protection terms.
Organisations that decide for themselves how they use data. These include Google, when you use our website check; WhatsApp, if you choose to talk to us there; Stripe, for its own fraud checks and legal duties; our bank; and our accountant, solicitor or insurer when we need them.
When the law requires it. For example, to HMRC, or to protect our legal rights.
If our business changes. If the business, or part of it, moves to a new company that we control, or is sold, your data moves with it. The new owner must use it as this notice describes. We'll update this notice with the new company's details, and tell our clients by email before it happens.
Sending data outside the UK
We're based in the UK. If you're in the EU, the European Commission has decided that the UK protects personal data to EU standards. That decision was renewed in December 2025 and runs until 27 December 2031, so your data can come to us without extra paperwork.
Some of our providers, such as Cloudflare and Stripe, handle data in the United States and other countries. When they do, we rely on one of these safeguards:
- the UK Extension to the EU–US Data Privacy Framework, for UK data, and the EU–US Data Privacy Framework, for EU data, where the provider is certified
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, for UK data
- the EU Standard Contractual Clauses, for EU data
Email [email protected] if you'd like a copy of the safeguards for a provider.
How long we keep it
- Enquiries that don't lead to an order: 12 months after our last contact, then deleted.
- Free previews and the materials used for them: deleted within 30 days of sending you the preview (or the tweaked version, if later), if you don't order.
- Records of businesses we contacted first: 12 months after our last contact, then deleted.
- "Do not contact" list: kept indefinitely, with the minimum data, so we never contact you again.
- Contracts and project emails, including signed Order Forms and their e-signature records: 6 years after the contract ends.
- Complaints: 6 years after the complaint is closed.
- Requests to use your data protection rights: a record of each request for 3 years after it's closed.
- Testimonials: the testimonial, your permission and our evidence, for as long as the testimonial is shown.
- Sub-processor update emails: your email address, until you ask us to stop.
- Accounting records: at least 5 years after the 31 January tax-return deadline if we trade as a sole trader, or 6 years from the end of the financial year if we trade as a limited company.
- Backups: overwritten on a rolling 30-day cycle.
After these periods, we delete the data or make it anonymous.
Your rights
You have the right to:
- access your data: get a copy of what we hold about you
- correct it, if it's wrong or incomplete
- delete it
- restrict it: ask us to pause using it
- object to how we use it where we rely on legitimate interests. For direct marketing, this right is absolute: we will always stop.
- move it: get the data you gave us in a common digital format, or have it sent to another organisation, where we use it under a contract or with your consent
- withdraw consent at any time, where we rely on it
Some rights have limits. For example, tax law says we must keep invoices even if you ask us to delete them.
How to use your rights. Email [email protected]. It's free. We'll reply within one month. If a request is complex, or you send several, we may take up to two more months. If so, we'll tell you why within the first month. We may ask for information to confirm who you are. The month starts once we have it. We'll search for your data in a reasonable and proportionate way, as the law allows.
Complaints
If you're unhappy with how we've handled your data, please tell us first so we can put it right. Email [email protected] with "Complaint" in the subject line. We'll acknowledge it within 30 days, look into it without undue delay and tell you the outcome.
You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. If you live in the EU, you can complain to the data protection authority in your country. The European Data Protection Board keeps a list of EU authorities.
Other things you should know
- No automated decisions. We don't make decisions about you by automated means alone, and we don't profile you.
- AI tools. We use AI tools in our work, for example to draft text, translations and code. We don't put your personal data into them: when we use one to help draft text, we use placeholders instead of names, contact details and other personal details, and we don't give them your customers' data.
- Children. Our services are for businesses. This website isn't intended for anyone under 18, and we don't knowingly collect children's data.
- Security. We protect data with two-step sign-in on our accounts, encryption, a password manager, and access only for people who need it. If a breach puts you at high risk, we'll tell you. Where the law requires it, we'll report a breach to the ICO within 72 hours.
- Other websites. Links to other sites, such as Google Maps, take you to services with their own privacy notices.
Changes to this notice
We'll update this notice when the way we use data changes, and change the date at the top of this page. If a change affects our clients in a significant way, we'll tell them by email.
Questions? Email [email protected].