Last updated: April 2026
SanXpert Digital Ltd ("we", "us", "our") is a specialist digital marketing agency for trade businesses, incorporated in England and Wales.
Company name: SanXpert Digital Ltd
Registered address: [Your Registered Address], United Kingdom
ICO Registration Number: [Your ICO Number — register at ico.org.uk if not done]
Email: contact@sanxpertdigital.co.uk
Phone: 07404 030389
Website: https://sanxpertdigital.co.uk
We are the Data Controller for personal data collected through this website. This means we are responsible for deciding how and why your personal data is used. We are registered with the Information Commissioner's Office (ICO) as required by UK law.
This Privacy Policy applies to all personal data we collect and process in connection with:
This policy does not apply to third-party websites linked from our site. We encourage you to read the privacy policies of any websites you visit through links on our site.
When you contact us, complete a form or use our services, we may collect:
When you visit our website, we automatically collect certain technical data:
We may receive personal data about you from:
We do not intentionally collect any special category personal data (such as health information, racial or ethnic origin, religious beliefs, or political opinions). Please do not submit this type of information to us.
UK GDPR requires us to have a lawful basis for each use of your personal data. The table below sets out what we do with your data and why we are lawfully permitted to do so.
| Purpose | What this means | Lawful basis |
|---|---|---|
| Responding to enquiries | Contacting you after you submit a form, email or call us | Legitimate interests — it is in both our and your interests to respond to a business enquiry you initiated |
| Providing our services | Delivering digital marketing services under a contract with you | Contract — processing is necessary to perform our agreement with you |
| Invoicing and payments | Sending invoices, processing payments, maintaining financial records | Contract and Legal obligation — required by HMRC and UK accounting law |
| Direct marketing by email | Sending you information about our services, case studies or updates you may find relevant | Legitimate interests (for existing clients and B2B contacts) or Consent (where required by PECR). You can opt out at any time. |
| Improving our website | Analysing how visitors use our site to improve content and user experience | Legitimate interests — improving our service is a reasonable business activity |
| Legal compliance | Complying with legal obligations, court orders, regulatory requirements | Legal obligation — we are required by law to retain certain records |
| Fraud prevention and security | Protecting our business and users from fraud, abuse or security threats | Legitimate interests — maintaining the security of our systems |
Legitimate interests: Where we rely on legitimate interests as our lawful basis, we have carried out a balancing test to confirm that our interests do not override your rights and freedoms. You can request details of this assessment by contacting us.
We may contact you with information about our services that we believe may be relevant to your business. Under UK PECR regulations:
You can opt out at any time by clicking the unsubscribe link in any marketing email, emailing us at contact@sanxpertdigital.co.uk, or calling 07404 030389. We will process your opt-out within 5 working days and you will not be charged for opting out.
We never sell, rent or share your personal data with third parties for their own marketing purposes.
Our website uses cookies — small text files stored on your device that help us understand how you use our site and improve your experience.
| Cookie type | Purpose | Provider | Duration |
|---|---|---|---|
| Strictly necessary | Required for the website to function — cannot be disabled | SanXpert Digital | Session |
| Analytics | Understanding visitor behaviour, pages viewed, traffic sources | Google Analytics (GA4) | Up to 2 years |
| Advertising | Measuring Google Ads campaign performance, conversion tracking | Google Ads | Up to 90 days |
Analytics and advertising cookies are only set with your consent where required by PECR. You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect website functionality.
Google Analytics data is processed by Google LLC. We have enabled IP anonymisation so that full IP addresses are never stored. For information on how Google processes data, see: policies.google.com/privacy.
We do not sell your personal data. We share it only where necessary with trusted parties under strict controls:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Hostinger International Ltd | Website hosting and email hosting | Data processing agreement in place; servers in EU |
| Google LLC | Analytics (GA4), Google Ads, Google Business Profile management | Standard Contractual Clauses; Privacy Shield successor framework |
| Meta Platforms Ireland Ltd | Facebook/Instagram advertising where applicable | Standard Contractual Clauses |
| Accounting software provider | Invoicing and financial record keeping | Data processing agreement in place |
| Professional advisors | Legal, accountancy or insurance advice when required | Bound by confidentiality obligations |
| HM Revenue & Customs | Where legally required to disclose financial records | Legal obligation — no agreement required |
All third-party processors are required to process your data only on our instructions and in compliance with UK GDPR.
Some of our third-party service providers (including Google) process data outside the UK and European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, including:
You can request details of the specific safeguards applicable to any transfer by contacting us at contact@sanxpertdigital.co.uk.
We retain personal data only for as long as necessary for the purposes it was collected, or as required by law. Our standard retention periods are:
| Data type | Retention period | Reason |
|---|---|---|
| Client contract and service records | 7 years after contract end | HMRC requirement and potential legal claims (Limitation Act 1980) |
| Financial records and invoices | 7 years | Companies Act 2006 and HMRC requirements |
| Enquiry and lead data (non-converting) | 12 months | Legitimate interests in following up business enquiries |
| Marketing contact data | Until opt-out or 3 years of inactivity | Legitimate interests; deleted upon opt-out request |
| Website analytics data | 26 months (GA4 default) | Improving website performance |
| Email correspondence | 3 years | Business record keeping and potential dispute resolution |
At the end of the applicable retention period, personal data is securely deleted or anonymised. Where data is anonymised it can no longer be used to identify you and therefore falls outside the scope of UK GDPR.
The UK GDPR grants you the following rights in relation to your personal data. All requests are free of charge and will be responded to within one calendar month (extendable to three months for complex requests).
| Right | What it means |
|---|---|
| Right of access | You can request a copy of all personal data we hold about you (a Subject Access Request or SAR) |
| Right to rectification | You can ask us to correct any inaccurate or incomplete personal data we hold about you |
| Right to erasure | You can ask us to delete your personal data where there is no compelling reason for us to keep it. This is not an absolute right and applies in specific circumstances. |
| Right to restrict processing | You can ask us to pause the processing of your personal data in certain circumstances, for example while accuracy is disputed |
| Right to data portability | Where we process your data by automated means based on your consent or a contract, you can ask us to provide it in a structured, commonly used, machine-readable format |
| Right to object | You can object to processing based on legitimate interests or for direct marketing purposes. We must stop marketing activities immediately upon request. |
| Rights related to automated decisions | You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not make such decisions. |
| Right to withdraw consent | Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. |
Submit your request by:
We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests. We reserve the right to charge a reasonable administrative fee or refuse manifestly unfounded or excessive requests.
Our services are directed exclusively at business owners and professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at contact@sanxpertdigital.co.uk and we will delete it promptly.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction or alteration. These measures include:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach as required by UK GDPR Article 33, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to those individuals.
Our website contains links to third-party websites, including our clients' websites, social media platforms and partner tools. We are not responsible for the privacy practices of those sites. Clicking a link to a third-party site takes you outside our control and we recommend you read their privacy policy before providing any personal information.
We review this Privacy Policy at least annually and whenever there are significant changes to our processing activities or applicable law. When we make material changes, we will:
We encourage you to review this policy periodically. Continued use of our website after changes are posted constitutes acceptance of those changes.
If you have a concern about how we handle your personal data, we ask that you contact us first so we can try to resolve the matter:
We will acknowledge your complaint within 5 working days and aim to resolve it within 30 days.
If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
Live chat: available at ico.org.uk
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
For any questions about this Privacy Policy or how we handle your personal data, please contact us:
SanXpert Digital Ltd
[Your Registered Address]
United Kingdom
Email: contact@sanxpertdigital.co.uk
Phone: 07404 030389
Website: https://sanxpertdigital.co.uk
This Privacy Policy was prepared in accordance with the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). It reflects ICO guidance current as of the date shown above.