Skip to content

Legal · Privacy

Privacy policy. in plain english.

The short version: we collect what we need to do the job, we don't sell it, we don't hoard it, and you can ask us to get rid of it whenever you want.

Controller
Unf-ck Ltd
Jurisdiction
UK GDPR
Last updated
2026-04-20
Contact
contact form

Placeholder: This policy is drafted for readability. Before launch it'll be reviewed by a solicitor to confirm it covers our actual data handling end-to-end.

01 · Who we are

Unf-ck is a UK limited company providing digital rescue, rebuild, audit and marketing services. Registered in England and Wales. Our registered office, company number and VAT number are listed on the contact page.

For the purposes of UK GDPR and the Data Protection Act 2018, we are a data controller for personal data we collect via this website, and a data processor for personal data we handle on behalf of clients during engagements.

02 · What we collect

We keep this deliberately short. We only collect what we actually need to do the job.

What Why Retention
Contact form submissions So we can reply. 24 months, then purged automatically. Or sooner on request.
Email correspondence To continue conversations and for our records. Seven years for accounting and tax reasons, then purged.
Website analytics To understand which content is useful and which isn't. 14 months (GA default) then purged.
Booking data (Cal.com) To let you pick a time that works for both of us. As long as the booking is in our calendar, plus Cal.com's own retention period.
Uploaded files (audits, rescues) So we can do the work you commissioned. For the duration of the engagement plus 12 months. Deletable on request.

03 · Lawful basis

We rely on the following lawful bases under UK GDPR Article 6:

  • Legitimate interests for the contact form, audit uploads, email correspondence, and basic server logs. Our interest is in running the business and replying to you. Your rights override ours; you can object at any time.
  • Consent for analytics cookies and optional marketing emails. You can withdraw at any point.
  • Contract for data collected during a paid engagement with us.
  • Legal obligation for anything we're required to keep by UK law (invoices, tax records, etc.).

04 · Who we share with

We use a small, named list of processors. None of them are ad networks. None of them will sell your data.

  • Mailgun (EU region), transactional email delivery.
  • Cal.com, booking software.
  • Google Tag Manager / Analytics, only if you accept the analytics cookie.
  • Our UK-based hosting provider, server infrastructure.
  • Our accountants and solicitors, where a legal or tax obligation requires.

We won't add anyone to this list without updating this page first. We won't sell your data. Nobody's ever offered us a good enough price and we wouldn't take it if they did.

05 · Your rights

Under UK GDPR you have the right to:

  • Know what data we hold about you (access)
  • Correct data we hold that's wrong (rectification)
  • Have us delete your data (erasure)
  • Restrict how we process your data
  • Take your data elsewhere (portability)
  • Object to processing based on legitimate interests
  • Complain to the Information Commissioner's Office (ico.org.uk)

To action any of these, use the contact form and flag it as a privacy request. Expect a response within three working days; resolution within 30, almost always sooner.

06 · Cookies

Short list:

  • Essential cookies, session, CSRF tokens, your accepted theme and cookie choice. No consent needed because the site can't work without them.
  • Analytics cookies, only fire after you accept. Aggregated usage data, no personal identifiers.
  • Third-party cookies, only when you use an embedded tool (Cal.com booking widget). Those are subject to their own cookie policies.

Full details on the cookies page. You can change your choice any time via the banner at the bottom of the screen.

07 · Security

The website runs on a UK VPS with HTTPS enforced, modern TLS, and the usual hardening (CSP, HSTS, X-Frame-Options, input validation on every form endpoint, rate limits on auth and contact forms, parameterised queries, bcrypt on passwords). Database is encrypted at rest. Backups are encrypted and stored offsite.

We're a small team. There's no scenario in which a junior account exec is handling your data.

08 · Changes to this policy

If we change how we handle data materially, we'll update this page and, for active clients, email you. The "last updated" date at the top of the page always reflects the latest revision.

09 · Contact us

For privacy questions, data-subject requests, or anything else related to how we handle your data, use our contact form and flag the message as a privacy matter. A named senior will reply within one working day.

Information Commissioner's Office (if you think we've got this wrong): ico.org.uk


This policy also exists alongside our terms of service and cookies notice. Read in combination.