Back to home

Legal

Website Privacy Policy

This policy covers the personal data I handle when you browse this site, enquire about website design, book a call, pay an invoice, or use my client portal.

Last updated 31 August 2026. This document sets out my own position as the supplier. It is written to be clear rather than clever, but it is not legal advice to you. If a clause matters to your business, take independent advice before you sign.

Simgela Ltd, London, United Kingdom. Company No. 16450664 · VAT GB 494367155 · hello@simgela.com

UK 0333 090 8164 · International +44 (0) 208 064 2172

1. Who I am

Simgela Ltd, trading as Simgela Studio, is the data controller for the personal data described in this policy. I am registered in England and Wales, company number 16450664, VAT number GB 494367155, at London, United Kingdom.

This policy explains how I handle personal data when you browse this website, enquire about website design, book a call with me, or use my client portal. For anything in this policy, or to exercise your rights, contact me at hello@simgela.com.

2. The personal data I collect

I keep data collection to what I genuinely need to quote for work, deliver it, bill for it, and support it afterwards.

  • Enquiry and booking data: your name, email address, business name, the details you type into the booking form, and the date and time slot you choose for a call.
  • Client account data: the information held in your client portal, including project tasks, time records, invoices, support hours used, and correspondence with me.
  • Payment data: billing name, address, invoice history, and the card references created when you pay me. Full card details are captured and stored by Stripe, not by me.
  • Website and analytics data: IP address, device and browser type, referring page, pages viewed, and interactions with the site, collected through cookies and similar technologies.
  • Content you supply: copy, images, logos, and access credentials you send me so I can build or update your website.

3. How and why I use it

  • To respond to enquiries, prepare quotes, and hold booked calls.
  • To design, build, host, and support your website under your contract with me.
  • To raise invoices, collect payment from your card on file, and keep accounting records.
  • To operate and secure the client portal, including tracking time and support hours.
  • To measure how the website performs and improve the pages people actually use.
  • To meet legal obligations, including tax, accounting, and record keeping duties.

4. My lawful bases under UK GDPR

  • Performance of a contract: delivering and supporting your website, running your portal account, and invoicing you.
  • Legitimate interests: replying to enquiries, protecting my systems from misuse, keeping records of work delivered, and defending legal claims. I balance these against your interests and only rely on them where the impact on you is limited.
  • Consent: non-essential analytics cookies. You can withdraw consent at any time through your browser settings or my cookie controls.
  • Legal obligation: keeping financial records and responding to lawful requests.

5. Cookies, analytics and session insight

Essential cookies keep the site and the client portal working, for example by holding your sign in session and protecting forms against abuse. These cannot be switched off without breaking the service.

I use Google Analytics to see which pages bring in enquiries, and Microsoft Clarity to see heatmaps and session recordings of how people move through the pages. Clarity recordings capture clicks, scrolling, mouse movement and page content, with text input fields masked so I do not see what you type. Neither tool is used to build advertising profiles.

Both Google Analytics and Microsoft Clarity are only loaded where I have your consent. You can withdraw consent at any time by clearing and blocking cookies in your browser, using your browser's do not track or tracking prevention settings, or by installing the Google Analytics opt-out browser add-on. Blocking them does not affect your ability to use the site or the portal.

6. Who I share data with, and their privacy policies

I do not sell your personal data and I do not share it for advertising. I use a small, deliberately short list of suppliers, each under written terms, and each with access limited to what their role needs. These are the third parties who may handle personal data connected to my services, what they are used for, where they process data, and where to read their own privacy policy.

Stripe

Card payments, invoice checkout and payment records. Card details are entered directly with Stripe; I never see or store your full card number.

Processes data in Ireland and USA

Read their privacy policy

Google Workspace (Gmail, Calendar, Meet)

Email correspondence, booked call invitations and video meetings.

Processes data in USA and EU

Read their privacy policy

Lovable

The platform this website and the client portal are designed, built, hosted and supported on, including the database behind your portal account.

Processes data in EU and USA

Read their privacy policy

Google Analytics

Aggregated website traffic and page performance reporting.

Processes data in USA

Read their privacy policy

Microsoft Clarity

Heatmaps and masked session insight so I can see where pages confuse people and fix them.

Processes data in USA

Read their privacy policy

Discord

Project communication about live work, which can include your business name, project details and the content you send me.

Processes data in USA

Read their privacy policy
  • Stripe acts as an independent controller for its own payment, fraud prevention and regulatory duties, as well as processing payments on my instructions.
  • My accountants and, where genuinely necessary, my professional advisers.
  • Authorities, regulators or courts where I am legally required to disclose information.

7. Credentials and access you give me

To build, host or support your website I often need access to domains, hosting, email, analytics, social accounts or a content management system. I store those credentials in access controlled systems and never use them for anything outside the work you have asked for.

At the end of an engagement, or at your request at any time, I will hand back or confirm removal of my access. I recommend you rotate any password you have shared with me once my work is complete.

8. My role when I work on your website

I am the controller for my own client, enquiry and billing records. Where I build, host or support a website that collects personal data from your own customers, you are the controller for that data and I act as your processor, handling it only on your instructions and only for as long as I support the site.

That means you are responsible for your own privacy notice, your own cookie consent banner, and the lawful basis for anything your site collects, including forms, bookings, newsletters and tracking you ask me to install. I will tell you when something you have requested creates a compliance duty for you, but I cannot accept that duty on your behalf. This mirrors the data protection clause in my terms of service.

9. International transfers

Several of the providers listed above, including Stripe, Google, Lovable, Microsoft and Discord, process data in the USA or other countries outside the UK. Where that happens I rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with additional safeguards such as encryption in transit and at rest, and data minimisation, where appropriate.

10. How long I keep it

  • Enquiries and booked calls that do not become projects: up to 12 months from my last contact.
  • Client project and portal records: for the life of the contract and then 6 years, to cover my accounting and legal obligations.
  • Invoices, mandates and payment records: 6 years after the end of the relevant financial year.
  • Email and internal project discussion, including Discord messages: up to 24 months after the project or support period ends.
  • Analytics and session insight data: retained in aggregated or pseudonymised form, up to 26 months for Google Analytics and up to 13 months for Microsoft Clarity.
  • Credentials you share with me: deleted once the engagement ends or the access is no longer needed.

11. How I protect it

I use encrypted connections, access controls, least privilege accounts, reputable managed platforms and regular updates. Card and bank details are handled by PCI compliant payment providers so that I never store them. No system is completely secure, so I also limit what I collect and how long I keep it.

Only I have access to your data, and every supplier I use is bound by written terms that restrict what they may do with it.

12. Data breaches

If a security incident affects your personal data, or personal data I process on your behalf, I will tell you without undue delay, explain what I know, and cooperate with any reporting you need to make to the Information Commissioner's Office or to your own customers. Where I am the controller and the risk requires it, I will report to the ICO within 72 hours of becoming aware.

13. Marketing

I do not sell or rent your details, and I do not run advertising profiles. I email existing clients about their own project, invoices and support. Anything wider, such as occasional notes about services or website advice, is only sent where you have opted in, and every message includes a one click unsubscribe.

14. Your rights

Under UK data protection law you have the right to access your data, to have inaccurate data corrected, to ask for erasure, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent where I rely on it.

To make a request, email hello@simgela.com. I will respond within one month and may ask you to confirm your identity first. If you are unhappy with my response you can complain to the Information Commissioner's Office at ico.org.uk, though I would appreciate the chance to put things right first.

15. Children

My services are aimed at businesses and I do not knowingly collect personal data from children under 13. If you believe a child has given me their data, contact me and I will delete it.

16. Changes to this policy

I review this policy whenever my services or suppliers change, and at least annually. The date at the top of this page shows the current version. Material changes affecting existing clients, including any change to the third parties listed above, will be notified by email.