WebPolisher Privacy Policy
Version: privacy-v4.1
Legal set: webpolisher-legal-set-2026-08-27-v8
Status: Candidate.
1. Who we are
WebPolisher is a trading name of PeckUK Limited.
PeckUK Limited is the controller for personal data used to operate WebPolisher, handle enquiries, create reports, administer accounts, bill customers, secure the service, communicate with business contacts and meet legal obligations.
PeckUK Limited is registered in England and Wales under company number 08756155.
Registered office: 90 Stowmarket Road, Needham Market, Ipswich, Suffolk, IP6 8DX, United Kingdom.
Privacy contact: updates@webpolisher.co.uk with the subject Privacy request.
2. When we are a processor
A WebPolisher customer is normally the controller for personal data submitted through its hosted website, such as contact-form enquiries.
PeckUK Limited acts as that customer's processor when it stores or otherwise handles that data only on the customer's documented instructions. The WebPolisher Data Processing Agreement applies to that processing.
If you submitted information through a customer's website, contact that customer first. We will assist the customer with your request where required.
3. Personal data we collect
Depending on how WebPolisher is used, we may collect:
- names, business roles, business names, email addresses, telephone numbers and postal addresses;
- account identifiers, authentication records and authorised-user details;
- website addresses submitted for review;
- publicly available website text, images, technical evidence and screenshots;
- report, concept, project, approval, change-request and support records;
- Customer Content and hosted website-form submissions;
- company status, billing address, tax details, invoices, payment status, refunds and Stripe references;
- service, device, IP, security, consent and audit records;
- transactional email and delivery information;
- optional analytics events where consent has been given; and
- correspondence, complaints and privacy requests.
Stripe collects full payment-card information directly. PeckUK Limited does not store full payment-card numbers or security codes.
4. Sources of personal data
We obtain personal data from:
- you;
- the business you work for or represent;
- an authorised user of a customer account;
- publicly available business websites submitted for review;
- service providers involved in authentication, payment, email delivery, security or support; and
- technical activity generated when the website or service is used.
We do not use a free website review to build an unrelated contact database.
If we obtain personal data from a public source and then use it to contact an individual or for a new purpose, we will provide appropriate privacy information at the first communication or within the period required by law, unless a valid legal exception applies.
5. Purposes and lawful bases
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Respond to an enquiry or requested free report | Business contact details, submitted website, report evidence and correspondence | Steps requested before a contract where the person is the prospective customer; otherwise legitimate interests in responding to business enquiries |
| Review a submitted public website | Public website content, screenshots and technical evidence | Legitimate interests in providing the requested assessment, subject to the submitter's authority and a bounded review |
| Create and administer an account or service | Account, contact, order, approval, project and support data | Contract where the individual is the customer; otherwise legitimate interests in administering a contract with the represented business |
| Process orders, invoices, tax and payments | Billing identity, company, address, tax, invoice and payment-status data | Contract, legitimate interests in collecting business charges, and legal obligations for tax and accounting |
| Secure the service and prevent fraud or misuse | Authentication, IP, device, audit, error and security records | Legitimate interests in protecting customers, systems and PeckUK Limited; legal obligations where applicable |
| Deliver transactional messages | Contact details, message content and delivery records | Contract or legitimate interests in administering the requested service |
| Improve service quality | Support themes, de-identified or minimised usage and reliability information | Legitimate interests in maintaining and improving the service, balanced against individual rights |
| Optional analytics | Consented analytics events and limited device or network information | Consent |
| Direct marketing | Business contact details, preferences and campaign records | Consent where PECR requires it; otherwise legitimate interests only where electronic-marketing and data-protection law permit |
| Handle legal claims, complaints and rights requests | Identity, correspondence, contract, audit and relevant service records | Legal obligation and legitimate interests in establishing, exercising or defending legal rights |
Where we rely on legitimate interests, our interests include responding to requested business communications, providing and improving a B2B service, securing systems, preventing fraud, maintaining business records and promoting relevant services lawfully. We assess necessity, reasonable expectations and privacy impact before relying on this basis.
6. Information required from you
Some information is needed to take requested steps or perform a contract, including customer identity, billing contact, service address or website, package selection and payment information.
If required information is not provided, we may be unable to create a report, accept an order, verify authority, collect payment, provide the service or respond to a request.
Optional analytics and marketing choices are not required to buy or use the service.
7. Automated tools, crawling and AI
WebPolisher uses a bounded first-party crawler to access public pages submitted for review. It may capture public text, images, page structure, technical evidence and screenshots needed for the report.
Approved OpenAI API services may process bounded public website evidence, customer instructions, report context, prompts and generated outputs to assist with analysis, drafting, concepts and quality checks.
By default, OpenAI states that API inputs and outputs are not used to train its models unless the account holder opts in. Standard API abuse-monitoring logs may be retained for up to 30 days. Some API features can hold application state, so WebPolisher must not enable a feature that creates longer provider retention for production customer data unless that use and retention are first approved and recorded in this policy and the provider register.
WebPolisher does not use these tools to make decisions that produce legal or similarly significant effects about individuals.
Do not submit private, special-category or criminal-offence personal data for a public website report.
8. Providers and other disclosures
We disclose only the data reasonably needed to providers that host, secure, store, generate, email, monitor, maintain source or deployment records, or process payment for WebPolisher.
The WebPolisher Subprocessor Schedule records active, conditional, held and disabled provider status. It covers Vercel, Supabase, Stripe, Twilio SendGrid, Better Stack, OpenAI and GitHub for the purposes recorded there. A provider marked Held or Disabled must not receive production customer personal data.
We may also disclose personal data:
- to professional advisers who owe duties of confidentiality;
- where required by law, court or regulator;
- to investigate fraud, misuse or a security incident; or
- as part of a properly managed sale, restructuring or transfer of the business, subject to appropriate protections.
9. International transfers
Some providers process personal data outside the United Kingdom.
Where a restricted transfer requires a safeguard, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, Binding Corporate Rules or another lawful mechanism.
Where required, we complete and retain the applicable transfer risk assessment, now referred to in UK legislation as the data protection test, and record any supplementary measures.
The Subprocessor Schedule summarises the provider position. A provider may not receive production customer data until its role, contract, transfer mechanism and account configuration have been recorded and approved.
10. Retention
We keep personal data only for as long as reasonably needed for its purpose, including legal, accounting, security and dispute requirements.
| Record | Normal retention |
|---|---|
| Unconverted enquiry and free-report intake | 90 days after last activity, then deletion or anonymisation |
| Report, crawl, screenshot, concept and project records | Service term and 24 months afterwards |
| Customer Content and support records | Service term and 24 months afterwards, unless an earlier valid deletion duty applies |
| Account, authentication, consent and operational audit records | Account or service term and 12 months afterwards |
| Security and error-monitoring events | Normally no more than 90 days unless required for an active investigation |
| Transactional email delivery records | Service term and 12 months afterwards |
| Contracts, acceptances, invoices, VAT, payment and accounting records | Six years after the relevant transaction or contract ends |
| Customer-hosted form data processed for a customer | Returned or deleted within 30 days after the affected service ends; protected backups expire within 35 days |
| Direct-marketing suppression records | The minimum information needed to respect the opt-out for as long as the address remains relevant |
A legal hold, dispute, fraud investigation or statutory duty may require longer retention. Access to retained data is restricted to the relevant purpose.
11. Direct marketing
We do not treat a report request, contract acceptance or cookie choice as general marketing consent.
Where marketing is permitted, we will:
- identify PeckUK Limited or WebPolisher;
- provide a simple opt-out in each electronic marketing message;
- apply additional consent requirements for individual subscribers, including relevant sole traders and some partnerships;
- honour objections and unsubscribe requests promptly; and
- retain a minimal suppression record so that an opt-out is not accidentally reversed.
You may object to direct marketing at any time by using the message opt-out or contacting the privacy address above.
12. Your rights
Depending on the law and circumstances, you may have rights to:
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- receive portable data;
- object to processing based on legitimate interests;
- object absolutely to direct marketing; and
- withdraw consent without affecting earlier lawful processing.
We normally respond within one month. We may need to verify identity and authority. A right can be limited where the law permits, and we will explain a refusal or restriction.
13. Children and sensitive data
WebPolisher is a B2B service and is not directed at children.
Do not intentionally provide special-category or criminal-offence data unless WebPolisher has expressly agreed the purpose and documented appropriate safeguards in advance.
If we discover that unsuitable data has been submitted, we may restrict access and delete or return it as appropriate.
14. Security
We use technical and organisational measures appropriate to the nature and risk of the service. These include role-based access, multi-factor authentication for privileged access, encryption in transit, provider-managed encryption at rest, tenant and resource scoping, logging, backups, recovery controls, credential management, dependency maintenance and incident handling.
No online service is risk-free. Customers must also protect their accounts, content, devices and credentials.
15. Cookies and browser storage
The Cookie and Browser Storage Policy explains necessary storage, optional analytics, consent choices and current durations.
16. Complaints
Please contact us first so that we can investigate.
You may also complain to the Information Commissioner's Office:
- Website:
https://ico.org.uk/make-a-complaint/ - Telephone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
17. Changes
We review this policy at least annually and when a material processing activity or provider changes.
We will publish a new version and effective date for material changes. Where appropriate, we will give existing customers advance notice.
18. Supplier details
WebPolisher is a trading name of PeckUK Limited.
PeckUK Limited is registered in England and Wales under company number 08756155.
Registered office: 90 Stowmarket Road, Needham Market, Ipswich, Suffolk, IP6 8DX, United Kingdom.
VAT number: 173 8752 74.