Legal
Privacy Policy
How XCONS Solutions Ltd. collects, uses and protects your personal data, and the rights you have over it.
- Last updated 27 August 2026
Table of Contents
Who we are
XCONS Solutions Ltd (“we”, “us”, “our”) is a digital growth agency registered in England and Wales, company number 16117496, with its registered office at 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ.
We are the data controller for the personal information described in this policy. That means we decide how and why your data is used.
Questions about this policy
Contact us at info@xconssolutions.co.uk or +44 7366 355562.
What information we collect
When you contact us or request an audit or quote
Your name, email address, phone number, company name, website URL, and anything you choose to tell us in a message or on a call.
When you become a client
The above, plus billing details, business information needed to deliver the work, and access credentials to systems you ask us to work on.
When you visit our website
IP address, browser type and version, device type, pages viewed, time spent, referring source, and how you interact with pages. Collected through cookies and similar technologies — see our Cookie Policy.
When you subscribe to our newsletter
Your email address, and whether you open or click our emails.
Special category data
We do not intentionally collect special category data — health, ethnicity, religious beliefs, biometric data and similar. Please don’t send it to us.
When you request a free audit
To produce an audit we need your website address, and we use publicly available tools to examine that site. We may also ask for read-only access to analytics or Search Console if you want a deeper review — that access is yours to revoke at any time, and we never ask for passwords.
We keep a copy of the audit report for 24 months so we can refer back to it if you get in touch again. After that it’s deleted, unless you’ve become a client, in which case it forms part of your project record.
We may use anonymised, aggregated findings from audits in our own research and marketing — for example, how many of the sites we reviewed had a particular technical problem. Nothing that could identify you, your business or your website is ever included. We rely on legitimate interests for this and you can object at any time by emailing us.
How we use it, and why we're allowed to
Swipe to see full detail
| What we do | Why we’re allowed to |
|---|---|
| Reply to your enquiry, prepare an audit or quote | Legitimate interests — you contacted us and expect a reply |
| Deliver services you’ve engaged us for | Contract — necessary to perform our agreement |
| Send invoices and keep financial records | Legal obligation — UK tax and accounting law |
| Send marketing emails and newsletters | Consent — you opted in, and can opt out any time |
| Analytics and improving our website | Consent — via your cookie preferences |
| Prevent fraud and secure our systems | Legitimate interests — protecting our business and yours |
Where we rely on legitimate interests, we’ve considered whether our interest is outweighed by your rights, and concluded it isn’t. You can object at any time — see Your rights below.
Who we share it with
We don’t sell your data. We never have and we won’t.
We do share it with service providers who process data on our behalf, under contracts requiring them to protect it:
- Website hosting and email:Hostinger (EU-based). Where a client’s own project requires different hosting, we use whatever that project needs.
- CRM and marketing automation:GoHighLevel (US-based). This is where enquiries, audit requests and client records are held.
- Analytics:Google Analytics and Google Search Console (Google, US-based), and Microsoft Clarity (Microsoft, US-based).
- Advertising:Google Ads (US-based). We use this occasionally rather than continuously, and we do not use Meta or any other social advertising platform.
- Payments and banking:Stripe (US and Ireland) for card payments where you buy a plan directly, and Tide (UK) for business banking and invoicing.
- Scheduling:Calendly (US-based), if you book a call with us.
We may also disclose information where legally required — to comply with a court order, respond to a lawful request from authorities, or protect our legal rights.
International transfers
Some of our providers are based outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework, depending on the provider.
You can ask us for details of the safeguards applying to any specific transfer.
How long we keep it
Swipe to see full detail
| Data | Retention |
|---|---|
| Enquiries that don’t become clients | 24 months from last contact |
| Client records and project files | 6 years after the engagement ends |
| Financial and tax records | 6 years, as required by law |
| Free audit reports | 24 months from delivery, then deleted unless you become a client |
| Marketing subscribers | Until you unsubscribe, then a suppression record so we don’t contact you again |
| Website analytics | 14 months |
Your rights
Under UK data protection law you have the right to:
- Access— get a copy of the personal data we hold about you
- Rectification— have inaccurate data corrected
- Erasure— have your data deleted, where there’s no overriding reason to keep it
- Restriction— limit how we use your data
- Portability— receive your data in a portable format, or have it sent to another provider
- Object— object to processing based on legitimate interests, including direct marketing
- Withdraw consent— where we rely on consent, withdraw it at any time
To exercise any of these, email info@xconssolutions.co.uk. We’ll respond within one month. There’s no charge unless a request is clearly unfounded or excessive.
Security
We use appropriate technical and organisational measures to protect your data, including encrypted connections, access controls, and limiting access to those who need it. No system is completely secure, but we take this seriously.
Children
Our services are for businesses. We don’t knowingly collect data from anyone under 18. If you believe we have, contact us and we’ll delete it.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed. Material changes will be communicated where we have a way to reach you.
