Privacy Policy

Last Updated On 10-Sept-2026

This notice explains what personal information we collect, why we use it, who we share it with, how long we keep it and the rights you have. It applies to website visitors, subscribers, prospective clients, clients and other people who interact with our business.

We use artificial intelligence tools in parts of our work, but we do not use solely automated decision-making that produces legal or similarly significant effects about you. Human judgement remains part of our work. More detailed information about our use of AI is available in our AI and Data Use Notice, available through our website or on request.

1. Who is responsible for your information?

RedRite is the controller responsible for the personal information described in this notice.

Contact details

Email: hello@redrite.co.uk
Postal address: Office 5 & 7, Kirkfields Business Centre, Kirk Lane, Leeds, West Yorkshire LS19 7LX
Phone: 0113 815 1989
ICO registration number: ZA158872

Please tell us if your contact information changes so that we can keep our records accurate.

2. The information we collect and why we use it

The information collected depends on how you interact with us. We only collect information that is relevant to the activity concerned.

Enquiries and communications
Information: Your name, contact details, the content of messages, social media communications and relevant background information you choose to provide.

Purpose: To respond to you, keep appropriate records, provide requested information and establish, exercise or defend legal claims.

Lawful basis: Legitimate interests, namely operating our business, responding to communications and protecting our legal position. Steps requested before entering into a contract may also apply.

Bookings and calls Information: Your name, email address, organisation, booking details and information you share during a call, collected through Microsoft Bookings.

Purpose: To arrange and deliver calls, understand your requirements and prepare follow-up actions.

Lawful basis: Steps requested before entering into a contract; performance of a contract; and legitimate interests in administering meetings and maintaining accurate business records.

Meeting recordings and transcripts
Information: Audio, video, transcripts, summaries, attendance information and meeting notes created through Google Meet and Fathom.

Purpose: To create accurate notes, deliver agreed follow-up, support client work and avoid relying solely on handwritten notes.

Lawful basis: Legitimate interests, where recording is necessary and proportionate, and consent where required. Participants are notified that Fathom is present and can raise concerns or request an alternative.

Client and project information
Information: Contact and identity information, contracts, project briefs, documents, business systems information, correspondence, deliverables and information needed to deliver the service.

Purpose: To enter into and perform contracts, deliver tech operations management and support services, build or configure automated workflows, manage projects and protect legal rights.

Lawful basis: Performance of a contract; steps before a contract; legitimate interests; and legal obligation where relevant.

Payments and financial administration
Information: Billing details, invoices, transaction references, payment status, and limited payment information received from payment providers (Stripe for card payments, GoCardless for direct debit, or bank transfer). We do not receive or store your full card number or bank account details ourselves – these are held by the relevant payment provider.

Purpose: To take payment, issue invoices, maintain accounting records via QuickFile, manage refunds and comply with tax and accounting duties.

Lawful basis: Performance of a contract and legal obligation.

Newsletter and direct marketing

Information: Your name, email address, business information, marketing preferences, sign-up source, consent record and engagement with messages, managed through MailerLite.

Purpose: To send requested newsletters, resources, service information and relevant marketing, and to understand whether communications are useful.

Lawful basis: Consent for newsletter sign-ups and individual subscribers; legitimate interests where permitted for existing customers and corporate business contacts. The Privacy and Electronic Communications Regulations also apply.

Website and analytics
Information: IP address, device and browser information, approximate location, pages visited, referral source, interaction data, identifiers and cookie choices, collected via Google Analytics and the Meta Pixel.

Purpose: To operate and secure the website, understand use, improve content, measure campaigns and, where you consent, deliver or measure advertising.

Lawful basis: Legitimate interests for essential security and administration; consent for non-essential analytics and advertising technologies unless a lawful exception applies.

Testimonials and reviews
Information: Your name, business, testimonial, review or image, where you’ve agreed to this.

Purpose: To demonstrate experience and promote services, sometimes shared on the website or social media.

Lawful basis: Consent, obtained before a testimonial or review is published.

Complaints and rights requests
Information: Identity and contact information, complaint or request details, supporting evidence, correspondence and the outcome.

Purpose: To investigate and respond, verify identity where necessary, demonstrate compliance and protect legal rights.

Lawful basis: Legal obligation and legitimate interests.

3. Special category information

Some personal information receives additional legal protection. This includes information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric identification data, sex life and sexual orientation.

Our services do not normally require this information. However, a person may occasionally mention it during a call, include it in correspondence or provide it within a document. Please avoid sharing special category information unless it is genuinely relevant.

If it is provided unexpectedly and is not needed, we will, where practicable, minimise, redact or delete it. If it must be retained or used, we will identify an appropriate condition under Article 9 of the UK GDPR, which may include obtaining explicit consent or relying on necessity for the establishment, exercise or defence of legal claims.

4. Information about other people

Please do not give us personal information about another person unless you are authorised to do so and it is necessary for the relevant work. If client material contains information about third parties (for example, a client’s own customers or team members), the client remains responsible for ensuring they have a lawful basis to provide that information.

5. How we collect information

We may collect personal information:

  • directly from you when you contact us, book a call, subscribe, buy a service or work with us;
  • through Microsoft Bookings, Google Meet, Fathom, MailerLite and other services used to arrange and deliver business activities;
  • automatically through cookies and similar technologies when you use the website;
  • from Stripe, GoCardless and QuickFile in connection with payments and financial administration;
  • from organisations that introduce or commission work; and
  • from public professional sources such as business websites, LinkedIn and Companies House, where reasonable and relevant to business communication or due diligence.

6. AI-assisted processing

We may use AI services, including Claude (Anthropic) and Google Gemini, to assist with drafting, analysis, research and the configuration of automated workflows for client tech operations work.

We apply data minimisation and avoid entering personal information into an AI service when it is not needed. Where client information is required for agreed work, we use suitable account controls and service settings, consider the sensitivity of the material, and remain responsible for reviewing the output. AI output can be incomplete or inaccurate and is not treated as an authoritative decision about a person.

Client calls are routinely recorded and transcribed using Fathom, where held via Google Meet or similar. You’ll be given notice when a call is being recorded and can ask for an alternative.

We do not use solely automated processing to make decisions about you that produce legal or similarly significant effects. If that changes, this notice will be updated before that processing begins.

Full detail is in our AI and Data Use Notice.

7. Marketing

You can unsubscribe from marketing emails at any time by using the unsubscribe link in the message or emailing hello@redrite.co.uk. Withdrawing marketing consent does not affect service, transaction or legal communications.

For individuals, sole traders and certain partnerships, we send electronic marketing where we have consent or where the requirements of the customer soft opt-in are met. For limited companies and other corporate subscribers, consent is not always required under PECR, but named business contacts still have data-protection rights and every marketing message provides a way to opt out.

We maintain a suppression record when someone opts out so we can respect the request. We do not sell personal information or share it with another organisation for that organisation’s independent marketing without permission.

8. Cookies, analytics and advertising

The website uses essential technologies needed for security and operation. It also uses Google Analytics and the Meta Pixel.

Non-essential analytics and advertising technologies are not used until the required choice has been made, unless the use meets a specific legal exception. You can change your choices using the website’s cookie controls. Details of individual technologies, providers, purposes and durations are set out in the Cookie Policy.

9. Who receives personal information

We use service providers where reasonably necessary to run the website and business or deliver agreed work. Depending on your interaction with us, these may include:

  • Google, for Google Workspace, email, cloud storage, Google Meet and Google Analytics;
  • Fathom, for meeting recording, transcription, summaries and notes;
  • Microsoft, for Microsoft Bookings and calendar administration;
  • Stripe, for card payments;
  • GoCardless, for direct debit payments;
  • QuickFile, for accounting and financial administration;
  • MailerLite, for mailing lists, forms and email campaigns;
  • Anthropic (Claude) and Google (Gemini), where AI-assisted processing is appropriate;
  • Meta, for the Meta Pixel and advertising measurement where you consent;
  • WordPress, website hosting, and IT support and security providers;
  • professional advisers such as accountants, insurers and lawyers; and
  • public authorities or regulators where disclosure is required or permitted by law.

Where a supplier acts as our processor, it may only process the information for the contracted purpose and under appropriate data-protection terms. Some suppliers also process limited information as independent controllers for matters such as fraud prevention, account security or their own legal obligations.

If you’re a client and material you give us relates to your own tools (such as GoHighLevel or ActiveCampaign accounts you control), we work within your account under your instructions — we’re not the controller for the data held in your own systems.

10. International transfers

Some suppliers process or make personal information accessible outside the United Kingdom, including in the United States. An international transfer can include remote access from another country, not only the physical movement of a file.

Where the UK GDPR restricted-transfer rules apply, we use an available lawful transfer mechanism. Depending on the supplier and transfer, this may include:

  • UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the particular US recipient is actively certified for the relevant information;
  • the UK International Data Transfer Agreement;
  • the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum; or
  • another safeguard or limited exception permitted by the UK GDPR.

Where contractual safeguards are used, we assess the transfer as required and consider whether additional technical or organisational measures are needed. You can ask for more information about the safeguard relevant to your information.

11. How long we keep information

We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, including legal, accounting, reporting and dispute-resolution requirements. The usual periods are set out below.

Record

Usual retention period

Unsuccessful enquiries and prospective-client correspondence

Normally two years after the last meaningful contact.

Client contracts, project records and substantive correspondence

Normally six years after the client relationship or relevant contract ends.

Invoices, transactions and accounting records (QuickFile)

Normally six years after the end of the relevant financial year, or longer if legally required.

Fathom recordings and full transcripts

Normally deleted within 24 months of the meeting or the end of the related client engagement, whichever is later. Relevant notes or agreed outputs may be retained in the client file for the client-record period.

Newsletter subscription records (MailerLite)

For as long as you remain subscribed. Essential evidence of consent and suppression information may be retained after unsubscribe.

Website analytics

Normally no longer than 14 months for identifiable or pseudonymous analytics data.

Complaints and individual-rights requests

Normally three years after final resolution, unless a longer period is needed for an ongoing dispute or legal obligation.

Testimonials and promotional permissions

For as long as the material remains in use, with the related permission record retained for up to six years after removal.

Opt-out and suppression records

For as long as needed to ensure the opt-out continues to be respected.

These are normal periods, not guarantees that every record will be kept for the full period. Information may be deleted sooner when it is no longer needed, or retained longer where required for a dispute, legal hold, or other lawful reason.

12. Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction. Measures include access controls, secure accounts, appropriate device and account security, supplier due diligence and limiting access to people who have a genuine business need. RedRite holds Professional Indemnity, Public Liability and Cyber insurance cover.

No online service can be guaranteed completely secure. If a personal data breach occurs, we assess it and notify the Information Commissioner’s Office and affected people where the law requires this.

13. Your rights

Depending on the circumstances, you may have the right to:

  • be informed about how your personal information is used;
  • ask for access to your personal information;
  • ask for inaccurate information to be corrected;
  • ask for information to be erased;
  • ask for use of information to be restricted;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain information in a portable format;
  • withdraw consent at any time where processing relies on consent; and
  • raise a complaint about the use of your information.

These rights are not absolute and do not all apply in every situation. To exercise a right, email hello@redrite.co.uk. We may ask for information needed to confirm your identity, but we will not request disproportionate identification.

There is normally no fee. A reasonable fee may be charged, or a request may be refused, where the law permits this, including where a request is manifestly unfounded or excessive. We normally respond without undue delay and within one month. Where clarification is reasonably required, the response period may be paused while we wait for it.

14. Complaints

If you have a concern about how we’ve collected, used, stored or shared your personal information, or about how we’ve handled a rights request, please contact us at hello@redrite.co.uk.

What happens next:

  • We’ll acknowledge your complaint within 30 days of receiving it.
  • We’ll investigate without undue delay, and keep you informed of progress.
  • We’ll let you know the outcome and what action, if any, we’re taking.

You don’t have to complain to us first, and you’re free to contact the Information Commissioner’s Office at any time:

ICO website: ico.org.uk/make-a-complaint
ICO helpline: 0303 123 1113

15. Children

Our website and services are intended for adults and business users. We do not knowingly collect personal information from children through the website. If you believe a child has provided personal information to us, please contact us so we can investigate and take appropriate action.

16. Third-party websites

The website may link to third-party websites, applications or services. Those organisations are responsible for their own privacy information and practices. Please read their privacy notices when you follow an external link or use an embedded service.

17. Changes to this notice

We review this notice at least annually and when our services, suppliers or legal obligations change. The date at the top of the notice shows when it was last updated. If a change materially affects how we use information already collected, we’ll take reasonable steps to bring it to the attention of the people affected.