Web Ventures

Privacy Policy

Effective date: 30 September 2026

Last updated: 30 September 2026

1. Who we are

Web Ventures helps small businesses get found online and generate more customers. We build and manage websites, improve Google visibility through SEO and fresh content, manage social media, create video content and proactively contact potential customers on behalf of our clients.

In this Privacy Policy, "Web Ventures", "we", "us" and "our" mean:

[Full legal entity name] trading as Web Ventures

Email: sam@webventuresuk.co.uk

We are responsible for deciding how and why we use personal data in connection with our own business activities. In those circumstances, we are a data controller.

We may also process personal data on behalf of our clients when delivering services such as website management, enquiry handling, SEO, social media management, content creation and outreach. In those circumstances, our client will usually be the data controller and Web Ventures will usually be a data processor. Further information is provided in section 13.

This Privacy Policy applies to our website, our services and our interactions with customers, prospective customers, suppliers, business contacts and website visitors.

2. The personal data we collect

Depending on how you interact with us, we may collect the following types of personal data:

Information you provide to us

This may include:

  • your name and job title;
  • your business name and business details;
  • your email address, telephone number and other contact details;
  • your business or correspondence address;
  • account, login and service information;
  • billing, invoicing and payment information;
  • information included in website enquiry forms or other forms submitted to us;
  • information contained in correspondence, enquiries, feedback and support requests;
  • your marketing preferences and records of consent or objections; and
  • information you provide when discussing or purchasing our services.

Information provided by our clients

When providing services to a client, we may receive personal data from that client. This may include:

  • contact details of the client's customers, prospects, suppliers or other business contacts;
  • information submitted through a client's website or enquiry forms;
  • website content, images, videos and social media information;
  • customer reviews, testimonials and appointment or enquiry details; and
  • information needed to manage the client's website, SEO, content, social media or outreach campaigns.

Our clients are responsible for ensuring that they have a lawful basis for providing personal data to us and for giving individuals appropriate privacy information where required.

Technical and usage information

When you use our website or services, we may collect:

  • your IP address;
  • browser type and version;
  • device type and operating system;
  • general location information derived from your IP address;
  • time zone and language settings;
  • pages visited, links followed and other website usage information;
  • information about how you interact with emails or online content; and
  • cookie, analytics and similar technology data.

Information from third parties

We may receive information from:

  • connected tools and services, such as Google Analytics and Google Search Console;
  • social media platforms;
  • payment providers;
  • hosting, website and software providers;
  • publicly available business directories, websites and professional networks;
  • referral partners and marketing platforms; and
  • our clients, suppliers and other business contacts.

We may combine information received from different sources where this is necessary for the purposes described in this Privacy Policy.

3. How we collect personal data

We collect personal data:

  • directly from you, for example when you contact us, request information or purchase our services;
  • from client businesses when we provide services to them;
  • through website enquiry forms, contact forms and other online forms;
  • through our website, cookies and similar technologies;
  • through connected tools, including Google Analytics and Google Search Console;
  • through social media platforms;
  • from payment, hosting, email and other service providers;
  • from publicly available sources, such as company websites and professional directories; and
  • from referrals, introductions and other business contacts.

Where we obtain personal data from a source other than the individual, we will provide the required privacy information within the time required by applicable data protection law, unless an exception applies.

4. How we use personal data

We may use personal data for the following purposes:

  • responding to enquiries and requests;
  • providing, administering and supporting our services;
  • building, hosting, maintaining and managing websites;
  • managing website domains, hosting accounts, forms and integrations;
  • providing SEO, Google visibility and fresh content services;
  • managing social media accounts and publishing social media content;
  • creating, editing and managing video content;
  • carrying out outreach and prospecting on behalf of clients;
  • managing client and supplier relationships;
  • processing payments, invoices and accounts;
  • communicating with you about our services;
  • providing customer support;
  • monitoring, maintaining and improving our website, systems and services;
  • understanding website usage and measuring the effectiveness of our services and marketing;
  • preventing fraud, misuse, unauthorised access and other unlawful activity;
  • keeping records and managing our business;
  • complying with legal, regulatory, tax, accounting and insurance requirements;
  • establishing, exercising or defending legal claims; and
  • sending marketing communications where permitted by law.

We will not use personal data for purposes that are incompatible with the purposes described in this Privacy Policy without first providing further information where required.

5. Our lawful bases for using personal data

We rely on one or more of the following lawful bases under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

PurposeLawful basis
Providing services, managing accounts and responding to service requestsProcessing is necessary to perform a contract with you or to take steps at your request before entering into a contract
Processing payments, maintaining business records and complying with legal requirementsProcessing is necessary to comply with a legal obligation
Managing business relationships, improving services, maintaining security and handling general enquiriesOur legitimate interests, provided those interests are not overridden by your rights and interests
Sending certain marketing communicationsYour consent, where required, or our legitimate interests where permitted by applicable law
Using non-essential cookies, analytics or similar technologiesYour consent, where required, by the Privacy and Electronic Communications Regulations ("PECR")
Protecting our business, systems and legal positionOur legitimate interests and, where applicable, compliance with a legal obligation
Any other purpose for which you have clearly given permissionYour consent

Where we rely on legitimate interests, our interests may include operating and promoting our business, providing effective services, communicating with business contacts, improving our website and services, protecting our systems and managing legal and commercial risks.

You may object to processing based on legitimate interests. Further information about your rights is set out in section 14.

6. Website, SEO, content, social media, video and outreach services

Website build and management

When building or managing a website, we may process information needed to:

  • create and update website pages;
  • manage website hosting, domains, forms and integrations;
  • monitor website performance and security;
  • receive and route website enquiries; and
  • provide technical support and maintenance.

Where a website collects personal data from the client's customers or website visitors, the client will generally be the controller of that information. Web Ventures will process it only in accordance with the client's instructions and the applicable client agreement.

SEO and content

We may process website, search and performance information to:

  • assess website visibility and performance;
  • identify search opportunities;
  • create and publish website content;
  • monitor search rankings and traffic; and
  • improve online visibility.

We may use tools such as Google Analytics and Google Search Console for these purposes, subject to the applicable settings, permissions and cookie requirements.

Social media management

When managing social media for a client, we may process account information, comments, messages, posts, images, videos and other information made available through the relevant platform.

Social media platforms have their own privacy policies and terms. We do not control how those platforms process personal data within their own systems.

Video content

When creating video content, we may process names, images, voices, likenesses, business information and other content supplied by a client or an individual appearing in the content.

Clients are responsible for ensuring that they have the necessary permissions and lawful basis to provide content containing personal data to us.

Outreach and prospecting

Where instructed by a client, we may identify and contact prospective business customers on the client's behalf. This may involve using professional contact details and publicly available business information.

We will carry out outreach in accordance with applicable data protection and electronic marketing laws, including PECR. We will provide appropriate information and a straightforward way to object or opt out where required.

We will not use outreach services to make decisions about individuals that produce legal or similarly significant effects.

7. Sharing personal data

We may share personal data with trusted third parties where necessary to provide our services, operate our business or comply with the law. These may include:

  • website hosting, domain and infrastructure providers;
  • website, content management and security providers;
  • analytics and search tools, including Google Analytics and Google Search Console;
  • email, communications and customer relationship management providers;
  • social media platforms;
  • video, design and content production providers;
  • payment processors, banks and accounting providers;
  • professional advisers, including lawyers, accountants and insurers;
  • IT, cybersecurity and technical support providers;
  • regulators, government bodies, law enforcement agencies or courts where required; and
  • a buyer, investor or successor in connection with a business sale, merger, restructuring or similar transaction.

Where a third party processes personal data on our behalf, we will take reasonable steps to ensure that appropriate contractual and security arrangements are in place.

We do not sell personal data.

We may share aggregated or anonymised information that does not identify individuals, for example to understand general website usage or service performance.

8. International transfers

Some of our service providers may process personal data outside the United Kingdom.

Where personal data is transferred outside the UK, we will take appropriate steps to ensure that the transfer is lawful and that the data receives an adequate level of protection. Depending on the circumstances, this may include:

  • transferring data to a country recognised by the UK as providing an adequate level of protection;
  • using the UK International Data Transfer Agreement;
  • using the UK International Data Transfer Addendum to the EU Standard Contractual Clauses;
  • relying on another lawful transfer mechanism under UK data protection law; and
  • carrying out appropriate assessments and implementing supplementary safeguards where necessary.

You may contact us using the details in section 1 if you would like further information about the safeguards used for a particular international transfer.

9. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purposes for which it was collected, including to meet legal, accounting, reporting and dispute-resolution requirements.

The following are our general retention periods:

  • Customer and contract records: for the duration of the relationship and usually for up to seven years after it ends.
  • Invoices, payment records and accounting information: for the period required by tax and accounting laws, normally at least six years after the end of the relevant financial year.
  • Enquiry and correspondence records: usually for up to three years after the last meaningful contact, unless a longer period is reasonably necessary.
  • Marketing preferences and suppression records: for as long as necessary to respect your opt-out or objection.
  • Website and technical logs: usually for a limited period, generally no longer than 12 months, unless needed for security, investigation or legal purposes.
  • Cookies and analytics information: in accordance with the relevant cookie duration and the settings of the applicable analytics provider.
  • Client data processed on behalf of a client: for the period instructed by the client and set out in the applicable agreement. We will return or delete the data when the service ends unless the law requires us to retain it.
  • Legal, regulatory or dispute-related information: for as long as reasonably necessary to establish, exercise or defend legal claims or comply with a legal obligation.

We may retain information for longer where necessary to comply with a legal obligation, protect our legal rights, prevent fraud or resolve a dispute. When personal data is no longer required, we will securely delete it or anonymise it.

10. Data security

We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  • access controls and permissions;
  • secure passwords and authentication measures;
  • encryption or secure transmission where appropriate;
  • secure hosting and software configurations;
  • backups and recovery procedures;
  • malware, firewall and security monitoring measures;
  • staff and contractor confidentiality obligations;
  • data minimisation and access on a need-to-know basis;
  • supplier due diligence and contractual safeguards; and
  • procedures for identifying, investigating and responding to data breaches.

No method of sending or storing information is completely secure. If we become aware of a personal data breach that is likely to create a risk to individuals, we will take the steps required by applicable law.

11. Cookies and similar technologies

Our website and the websites we manage may use cookies, pixels, scripts, tags, local storage and similar technologies.

These technologies may be used for:

  • essential website functions;
  • security and fraud prevention;
  • remembering preferences;
  • measuring website usage and performance;
  • improving website content and services; and
  • marketing or advertising, where applicable.

Strictly necessary technologies may be used without consent where permitted by law. We will request consent before using non-essential cookies or similar technologies where required by PECR.

Analytics technologies, including Google Analytics, may collect information such as IP address, device information, browser information, pages visited and interaction data. Where consent is required, analytics cookies will not be set until you have given consent.

You can manage your cookie preferences through our cookie consent tool, where available. You can also adjust your browser settings. Disabling certain cookies may affect website functionality.

We may update our cookie information from time to time to reflect the technologies actually used on our website. The cookie consent tool or cookie notice should be consulted for details of the specific cookies, providers, purposes and retention periods in use.

12. Marketing communications

We may send information about our services, news, offers and relevant business updates by email or other electronic means where permitted by law.

We will comply with applicable direct marketing requirements, including PECR. Depending on the circumstances, we may rely on consent, an existing customer relationship or legitimate interests. We will obtain consent where the law requires it.

You can opt out of marketing communications at any time by:

  • clicking the unsubscribe link in a marketing email;
  • contacting us at sam@webventuresuk.co.uk; or
  • using any preference or opt-out facility provided in the communication.

You may continue to receive essential service, account, security or administrative communications after opting out of marketing.

If you ask us not to send marketing communications, we may retain limited information on a suppression list so that we can respect your request.

13. Controller and processor roles

When Web Ventures is a controller

We are a controller when we decide how and why personal data is used for our own purposes, including:

  • managing our customers and prospective customers;
  • handling enquiries;
  • operating and improving our website;
  • administering payments and accounts;
  • managing our suppliers and business contacts;
  • sending our own marketing communications; and
  • complying with our legal obligations.

When Web Ventures is a processor

We are generally a processor when we process personal data solely on behalf of a client and according to the client's documented instructions.

For example, this may apply when we:

  • manage a client's website and enquiry forms;
  • process customer enquiries received through a client's website;
  • manage a client's social media accounts;
  • create or publish content containing the client's customer data;
  • carry out outreach on behalf of a client; or
  • use client-provided personal data to deliver a contracted service.

Our client remains responsible for deciding the purposes and lawful basis for that processing. The client is also responsible for providing appropriate privacy information to individuals and responding to rights requests where it is the controller.

Where required, our client agreement or a separate data processing agreement will set out the processing instructions, data categories, security arrangements, sub-processors, retention requirements and procedures for handling individual rights requests and data breaches.

If you believe that your personal data has been processed by us on behalf of one of our clients, you should normally contact that client first. We will assist the client as required under our agreement and applicable law.

14. Your rights

Under the UK GDPR, you may have the following rights:

  • The right to be informed: to understand how your personal data is used.
  • The right of access: to request a copy of your personal data and information about how we use it.
  • The right to rectification: to ask us to correct inaccurate or incomplete personal data.
  • The right to erasure: to ask us to delete personal data where there is no good reason for us to continue using it.
  • The right to restriction: to ask us to limit how we use personal data in certain circumstances.
  • The right to data portability: to receive certain personal data in a structured, commonly used and machine-readable format, or ask us to transfer it to another organisation where technically feasible.
  • The right to object: to object to processing based on legitimate interests, including profiling based on those interests.
  • The right to object to direct marketing: you may object to direct marketing at any time.
  • The right to withdraw consent: where we rely on consent, you may withdraw it at any time. Withdrawal will not affect processing carried out before consent was withdrawn.
  • Rights relating to automated decision-making: you may have rights where decisions are made solely by automated means and produce legal or similarly significant effects.

These rights are not absolute and exceptions may apply. For example, we may need to retain certain information to comply with a legal obligation or establish, exercise or defend a legal claim.

To exercise a right, please contact us at:

Email: sam@webventuresuk.co.uk

Post: [Postal address]

We may ask for information to verify your identity before dealing with your request. This is a security measure designed to ensure that personal data is not disclosed to the wrong person.

We will normally respond to a valid request within one month. If a request is complex or we receive several requests, we may extend this period by up to a further two months where permitted by law. We will explain the reason for any extension.

15. Complaints

If you have concerns about how we use your personal data, please contact us first so that we can try to resolve the issue.

You also have the right to complain to the Information Commissioner's Office ("ICO"), the UK supervisory authority for data protection:

Information Commissioner's OfficeWycliffe HouseWater LaneWilmslowCheshireSK9 5AF

Telephone: 0303 123 1113

Website: https://ico.org.uk/make-a-complaint/

16. Children's data

Our services and website are intended for businesses and adults. We do not knowingly collect personal data from children under the age of 13.

If you believe that a child has provided personal data to us, please contact us at sam@webventuresuk.co.uk. If we become aware that we have collected such information without an appropriate lawful basis, we will take reasonable steps to delete it.

17. Third-party websites and platforms

Our website and services may contain links to third-party websites, applications or platforms. Those third parties operate under their own privacy policies and terms.

We are not responsible for the privacy practices, content or security of third-party websites or platforms. You should review their privacy information before providing them with personal data.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or the way we use personal data.

The latest version will be published on our website with the effective date shown at the beginning of the policy. Where changes are significant, we will take reasonable steps to bring them to your attention.

We recommend checking this Privacy Policy periodically to stay informed about how we use personal data.