Privacy
What I do with
your details.
Short version: if you contact me or book a call, I keep what you sent so I can reply. I do not sell it, share it for marketing, or send you anything you did not ask for.
Last reviewed 1 October 2026
Who is responsible
ADAMROE. LTD, a private limited company registered at Companies House in England and Wales, company number 17466558, registered office 6 Northampton Road, Lavendon, Olney, MK46 4EY. I am the data controller for everything described here, apart from sites I host or look after for clients, where I am their processor, as explained below. Registered with the Information Commission under number ZC252978. Based in Milton Keynes, working across the UK.
Contact: hello@adamroe.co.uk, +44 7533 973013, or by post at 6 Northampton Road, Lavendon, Olney, MK46 4EY.
What I collect, and why
If you use the contact form
Your name, email address, company if you give one, how soon you need the work, and whatever you write in the message. I use it to answer you and, if it goes further, to scope and price the work.
If you book a call
Your name, email address, your company if you give one, anything you add in the notes, and anyone you invite. I use it to hold the call and prepare for it. The booking goes into my calendar and generates a video link. The form does not ask for a phone number.
If we are on a call together
I may record it and have it transcribed and written up, so that I can listen to you rather than write while you talk, and so what we agreed is not left to my memory. The recording holds your voice, your picture if your camera is on, and whatever is said. The tool also reads the calendar entry, so it has the meeting itself and the email address of everyone invited.
You are told when the call is arranged, and asked again at the start, so nobody discovers halfway through that they are being recorded. You can say no. Saying no changes nothing else: the call happens either way and I take notes by hand instead. If you change your mind afterwards, tell me and I will delete it.
If you email me directly
Whatever is in the email, kept in my mailbox.
If you pay me
Card payments and Direct Debits are taken by Stripe, which collects your card or bank details itself. If you set up a Direct Debit, the portal keeps whether it is active, Stripe's reference for it and the last four digits of the account, so you can recognise it. I never hold your full card number, account number or sort code. I use this to take the payments we agreed, and the record of each payment is kept as a financial record, because the law requires it.
When you just read the site
Page views are counted by Plausible Analytics, hosted in Germany. Its script reads the address of the page and the page you came from, and checks one setting in your browser's storage to see whether you have asked not to be counted. Your IP address and browser details are passed to Plausible with each page view so it can filter out bots and tell visits apart. It turns them into a code that changes every day and does not store them. It sets no cookies, and neither of us can identify you from the counts. I use it to know which pages are read, so I can improve the site.
If JavaScript is switched off in your browser, the counting script does not run and you are not counted.
If you would rather not be counted, use the switch above. It is free, it works straight away in this browser, and you can turn counting back on at any time.
Nothing else on the page reaches out anywhere. The typefaces are served from this site rather than from Google Fonts, so reading a page does not announce your IP address to anyone but me and my host, and there is no advertising, no embedded video and no third-party script of any kind.
Three things touch your device, and none needs a banner because none is used to track you. If you switch the site to dark mode, that choice is remembered in your browser so it survives the next page. If you sign in to the client portal, a session cookie keeps you signed in. And the counting check above reads one setting, which the switch writes. The first two are exempt from the consent rules because you asked for them or sign-in cannot work without them; the third is allowed for counting visits because you are told about it here and can turn it off.
If someone else gave me your details
If you were invited to a call by the person who booked it, or a client gave you access to a project in the portal, your name and email address came from them. I use them only to hold the call, or to give you access to the project and send you its notices. The rest of this notice applies to you in the same way, including your rights and how to complain. If the call is recorded, you are asked at the start, like everyone else.
My lawful basis
For answering an enquiry or holding a call: legitimate interests, you contacted me and expect a reply, or steps prior to a contract where we go on to work together. Not consent, which is why there is no tick box.
For the client portal, invoices and taking payment by card or Direct Debit: performance of our contract, where you are the client yourself, as a sole trader or a partner. Where you work for an organisation that is my client, it is legitimate interests: giving the people working on a project access to it, and getting paid for the work.
For keeping invoices and payment records, including the copy in my accounting software: legal obligation, because company and tax law require them.
For recording who approved something, when, from which IP address and in which browser: legitimate interests, so that both of us can show later exactly what was agreed and when. For keeping this site and the portal working and secure, including the IP address that comes with every request and the record of each sign-in link sent, and for counting page views: legitimate interests, looking after the site and the people who use it, and knowing which pages are read.
For recording a call: consent. It is the one thing on this page that runs on consent, which is why it is the one thing you are asked to agree to. Nothing is recorded unless you say yes, and you can withdraw it afterwards and have the recording deleted.
Your right to object
Where I rely on legitimate interests (answering an enquiry, holding a call, keeping the site secure, counting page views, recording approvals, and portal access for people who work for a client), you can object at any time, on grounds relating to your own situation. Email hello@adamroe.co.uk. I will stop unless I can show compelling legitimate grounds that override your interests, or I need the data to make or defend a legal claim. For page views, the switch above does it straight away.
Do you have to give me your details?
Nobody has to contact me or book a call. If we work together, I need the name, email address and billing details of whoever is buying, and card or bank details if you pay by card or Direct Debit. Without them I cannot agree the work, invoice it or take payment, and invoices have to be kept as company and tax records, so if they are not given I cannot take the work on. A portal picture and anything you add to a booking note are up to you.
Who else processes it
I am a one-person business. Nobody else reads your enquiry. These providers handle your details on my behalf, apart from the part of Stripe's work explained in its row:
| Provider | What it handles | Where |
|---|---|---|
| Cloudflare | Hosting. Every request to this site passes through it, and the site itself runs on their network. It also prints each invoice to PDF, keeping nothing afterwards. | Global edge, nearest location to you |
| Supabase | The client portal: sign-in, the database, and everything in your project records. | London |
| Google Workspace | Email, the calendar, the booking itself and the video call. | EU/US, see transfers below |
| Stripe | Card payments and Direct Debits. It holds the name, email address, billing address and card or bank details given to it, and what has been paid or collected. I never see a full card number, sort code or account number. Stripe also uses payment data for some purposes of its own, such as preventing fraud and meeting its own legal duties, and for that part it is responsible itself, under its own privacy notice at stripe.com/privacy. | Global, see transfers below |
| FreeAgent | My accounts: a copy of each invoice, the name, address and email it went to, and what has been paid. | Ireland |
| Plausible Analytics | Counting page views. No cookies. Your IP address and browser details are used for a moment to count the visit and are never stored. | EU (Germany) |
| Fathom | Recording a call, transcribing it and writing it up, where one is recorded. It also reads the calendar entry, so it sees the meeting and who was invited. Its AI providers are contractually barred from keeping your data or training on it. Fathom itself uses de-identified data to improve its own systems. | United States |
I do not sell your data, and I do not pass it to anyone for marketing. Ever.
The client portal
If we work together you get a login to a portal that holds the project. There are no passwords: signing in sends a single-use link to your email address.
What is in there:
- Your account, being your name, your email address, and which projects you can see.
- Your picture, only if you add one. It is made small on your own device before it is sent, which also removes details such as where the photo was taken, and only people on your projects can see it. You can remove it at any time, and it is deleted with your account.
- Your company details, being the name, address and VAT number that go on an invoice.
- The project itself, being milestones, the work, dates, and anything written on a story by either of us.
- Invoices, and what has been paid against them. Each issued invoice is also kept as a PDF, which is attached to the email that sends it.
- Your Direct Debit, if you set one up: whether it is active, Stripe's reference for it, and the last four digits of the account.
When you approve something, whether that is a milestone, a statement of work, or the price of a change, I record who approved it, when, the IP address it came from and which browser was used. That is the point of approving in the portal rather than by email: months later, both of us can show exactly what was agreed and when. It is kept for the same reason a signed document is kept, and it is never used for anything else.
An issued invoice also gets a private link so that whoever pays it does not need an account. The link is long and unguessable, it is not indexed by search engines, and it shows that one invoice and nothing else.
The portal database, the PDF of each invoice and any profile pictures are stored by Supabase in London, so this data is stored in the UK. The lawful basis for all of this is set out under My lawful basis above. Portal records are kept for the life of the engagement and then as set out below.
Sites I host or look after
If I host your WordPress site, or look after a site on a care plan, a take-on check, an audit or a migration, whatever personal data sits in that site and your other systems is still yours. For that work I am your processor rather than the controller, acting on your instructions and on the data processing terms attached to your statement of work, and you decide what happens to it.
A site I host is on my account with a managed WordPress host, named to you in writing before anything moves. The site runs on servers in the UK, and the host keeps its backups in the United States, under the safeguards described below. If you need everything kept in the UK, I host it with a UK host instead.
I ask for the least access that does the job, and for the shortest time it is needed. Where a service offers a read-only or restricted role, that is the one I ask for. When the work finishes, removing my access is a task on the project rather than something either of us has to remember, and I do not keep copies of your data beyond what the work produced: a report, a redirect map, a backup we agreed I would hold.
Transfers outside the UK
The portal database and invoice PDFs are stored in London, so portal data is stored in the UK. Pages, including invoices being printed to PDF, are served through Cloudflare, covered below.
Plausible is hosted in Germany and FreeAgent in Ireland. UK law treats the EU and the EEA as giving adequate protection, under UK adequacy regulations, so no further safeguard is needed for them.
Google Workspace, Cloudflare and Stripe may process data outside the UK, including in the United States. Each provides the UK Addendum to the EU Standard Contractual Clauses in its data processing terms, which is the safeguard I rely on. For a site I host, the host's backups in the United States are covered the same way, and I keep a written check that the protection there is not materially lower than in the UK.
Fathom processes in the United States, and a call recording is the most personal thing on this page, so it is worth being plain about where it goes. It is engaged under a data processing agreement carrying the same Standard Contractual Clauses and UK Addendum. Fathom's own AI providers are contractually barred from keeping your data or training on it, and Fathom publishes the current list of who they are at trust.fathom.video. That list is the one to believe if it ever disagrees with this page. Fathom itself uses de-identified data to improve its own systems, which is its decision rather than mine, and is why it is named here rather than described vaguely as a transcription tool.
You can ask me for a copy of the safeguard that covers any of these transfers: email hello@adamroe.co.uk.
How long I keep it
- Enquiries and bookings that do not become work, 2 years from the last time anything changed on them, then deleted.
- Invoices and the records of work I was paid for, including each invoice's PDF and every card and Direct Debit payment record, kept for 6 years from the end of the company's financial year they relate to, as a limited company must, then deleted. Longer only where the law requires it, such as during an HMRC enquiry.
- Portal accounts and project records, kept for the life of the engagement. Afterwards the account is closed and anything not needed as a financial record is deleted. Approvals are kept with the financial records, since they are the evidence of what was agreed.
- Records of each sign-in link sent, 1 year, then deleted.
- A record of each email the site sends: who it went to, the subject and whether it went, 1 year, then deleted.
- Portal alerts you have already read, 2 years, then deleted.
- A call recording and its transcript, 90 days, then deleted. The write-up is kept with the enquiry or the project and runs out on the same clock as the rest of it.
- Emails, kept while they are relevant to an enquiry or a project and reviewed every September. An email about an enquiry that never became work is deleted at the first review after two years.
Deleting a record removes it from the live database at once. It stays in the database backups for up to seven days after that, then ages out, so a deletion is complete within a week. If you want yours gone sooner and there is no tax record to keep, ask and I will delete it.
Your rights
- Access
- Ask what I hold about you, and get a copy.
- Correction
- Have anything wrong put right.
- Deletion
- Ask me to delete it. If there is no tax record to keep, I will.
- Restriction
- Ask me to stop using it while something is being sorted out.
- Objection
- Object to my relying on legitimate interests, as the section above explains.
- Portability
- Get what you gave me in a machine-readable form.
Email hello@adamroe.co.uk and I will deal with it within one month. There is no charge.
Complaints
If you are unhappy with how I have used your personal data, you have the right to complain to me. Email hello@adamroe.co.uk with "Complaint" in the subject line, or write to me at the registered office above. I will confirm I have received it within 30 days, look into it, keep you told how it is going, and tell you the outcome.
You also have the right to complain to the Information Commission, the UK's data protection regulator, which still calls itself the ICO, at ico.org.uk or on 0303 123 1113. You can go to the Commission whether or not you have complained to me first.
Changes
If this changes materially I will update the date at the top. This version was last reviewed on 1 October 2026.