Legal

Privacy Policy

How XCONS Solutions Ltd. collects, uses and protects your personal data, and the rights you have over it.

Table of Contents

Who we are

XCONS Solutions Ltd (“we”, “us”, “our”) is a digital growth agency registered in England and Wales, company number 16117496, with its registered office at 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ.

We are the data controller for the personal information described in this policy. That means we decide how and why your data is used.

Questions about this policy

What information we collect

When you contact us or request an audit or quote

Your name, email address, phone number, company name, website URL, and anything you choose to tell us in a message or on a call.

When you become a client

The above, plus billing details, business information needed to deliver the work, and access credentials to systems you ask us to work on.

When you visit our website

IP address, browser type and version, device type, pages viewed, time spent, referring source, and how you interact with pages. Collected through cookies and similar technologies — see our Cookie Policy.

When you subscribe to our newsletter

Your email address, and whether you open or click our emails.

Special category data

We do not intentionally collect special category data — health, ethnicity, religious beliefs, biometric data and similar. Please don’t send it to us.

When you request a free audit

To produce an audit we need your website address, and we use publicly available tools to examine that site. We may also ask for read-only access to analytics or Search Console if you want a deeper review — that access is yours to revoke at any time, and we never ask for passwords.

We keep a copy of the audit report for 24 months so we can refer back to it if you get in touch again. After that it’s deleted, unless you’ve become a client, in which case it forms part of your project record.

We may use anonymised, aggregated findings from audits in our own research and marketing — for example, how many of the sites we reviewed had a particular technical problem. Nothing that could identify you, your business or your website is ever included. We rely on legitimate interests for this and you can object at any time by emailing us.

How we use it, and why we're allowed to

What we do with your data and the lawful basis we rely on for each purpose.
What we do Why we’re allowed to
Reply to your enquiry, prepare an audit or quote Legitimate interests — you contacted us and expect a reply
Deliver services you’ve engaged us for Contract — necessary to perform our agreement
Send invoices and keep financial records Legal obligation — UK tax and accounting law
Send marketing emails and newsletters Consent — you opted in, and can opt out any time
Analytics and improving our website Consent — via your cookie preferences
Prevent fraud and secure our systems Legitimate interests — protecting our business and yours

Where we rely on legitimate interests, we’ve considered whether our interest is outweighed by your rights, and concluded it isn’t. You can object at any time — see Your rights below.

Who we share it with

We don’t sell your data. We never have and we won’t.

We do share it with service providers who process data on our behalf, under contracts requiring them to protect it:

  • Website hosting and email:Hostinger (EU-based). Where a client’s own project requires different hosting, we use whatever that project needs.
  • CRM and marketing automation:GoHighLevel (US-based). This is where enquiries, audit requests and client records are held.
  • Analytics:Google Analytics and Google Search Console (Google, US-based), and Microsoft Clarity (Microsoft, US-based).
  • Advertising:Google Ads (US-based). We use this occasionally rather than continuously, and we do not use Meta or any other social advertising platform.
  • Payments and banking:Stripe (US and Ireland) for card payments where you buy a plan directly, and Tide (UK) for business banking and invoicing.
  • Scheduling:Calendly (US-based), if you book a call with us.

We may also disclose information where legally required — to comply with a court order, respond to a lawful request from authorities, or protect our legal rights.

International transfers

Some of our providers are based outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework, depending on the provider.

You can ask us for details of the safeguards applying to any specific transfer.

How long we keep it

Types of data we hold and how long each is retained.
Data Retention
Enquiries that don’t become clients 24 months from last contact
Client records and project files 6 years after the engagement ends
Financial and tax records 6 years, as required by law
Free audit reports 24 months from delivery, then deleted unless you become a client
Marketing subscribers Until you unsubscribe, then a suppression record so we don’t contact you again
Website analytics 14 months

Your rights

Under UK data protection law you have the right to:

  • Access— get a copy of the personal data we hold about you
  • Rectification— have inaccurate data corrected
  • Erasure— have your data deleted, where there’s no overriding reason to keep it
  • Restriction— limit how we use your data
  • Portability— receive your data in a portable format, or have it sent to another provider
  • Object— object to processing based on legitimate interests, including direct marketing
  • Withdraw consent— where we rely on consent, withdraw it at any time

To exercise any of these, email info@xconssolutions.co.uk. We’ll respond within one month. There’s no charge unless a request is clearly unfounded or excessive.

Security

We use appropriate technical and organisational measures to protect your data, including encrypted connections, access controls, and limiting access to those who need it. No system is completely secure, but we take this seriously.

Children

Our services are for businesses. We don’t knowingly collect data from anyone under 18. If you believe we have, contact us and we’ll delete it.

Changes to this policy

We may update this policy from time to time. The date at the top shows when it was last changed. Material changes will be communicated where we have a way to reach you.