1. Introduction

Groundwork Guild (“we,” “us,” or “our”) operates the website at your-domain.com (the “Site”). We are committed to protecting your personal data and respecting your privacy rights in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and all applicable privacy laws.

This Privacy Policy explains what personal information we collect, why we collect it, how it is used, and your rights regarding that information. By using our Site, you acknowledge you have read and understood this policy. If you do not agree, please discontinue use of the Site.

2. Data Controller

The data controller responsible for your personal information is:

Groundwork Guild
Website: your-domain.com
Email: [email protected]

3. Information We Collect

We collect personal data in the following ways:

3.1 Information You Provide Directly

  • Contact forms: Name, email address, phone number, and message content.
  • Account registration: Username, email address, and password (stored encrypted).
  • Newsletter sign-up: Email address and name.
  • Service enquiries: Project details, company name, and contact preferences.

3.2 Information Collected Automatically

  • Usage data: Pages visited, time spent on site, referral URLs, browser type, and device information.
  • IP address: Collected for security, fraud prevention, and approximate geolocation.
  • Cookies and tracking technologies: As described in Section 5 below.

3.3 Information from Third Parties

We may receive information about you from analytics providers, advertising partners, and social media platforms when you interact with our content on those services.

4. Legal Basis and Purposes for Processing

Purpose Legal Basis
Responding to enquiries and providing servicesLegitimate interests / Contract performance
Processing transactions and bookingsContract performance
Sending marketing emails (with opt-in)Consent
Website analytics and performance improvementLegitimate interests
Fraud prevention and securityLegitimate interests / Legal obligation
Complying with legal and regulatory obligationsLegal obligation

5. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Site and enhance your experience. Cookies are small text files stored on your device. The types we use include:

  • Essential cookies: Required for the Site to function (e.g., session management, security). These cannot be disabled.
  • Analytics cookies: Help us understand how visitors use the Site (e.g., Google Analytics). Collected anonymously where possible.
  • Preference cookies: Remember your settings and choices to personalise your experience.
  • Marketing cookies: Used to deliver relevant advertisements and track campaign effectiveness. Only placed with your consent.

You can manage cookie preferences at any time via our Cookie Settings tool or through your browser settings. Disabling certain cookies may affect Site functionality. For more information, visit aboutcookies.org.

6. Third-Party Services and Data Sharing

We do not sell your personal data. We may share your data with trusted third parties solely to operate our Site and deliver services:

  • Google Analytics: Website traffic analysis. Data is anonymised where possible. Google Privacy Policy.
  • Google Ads / Meta Ads: Advertising and remarketing services (only with your consent).
  • Email service providers: For transactional and marketing communications (e.g., Mailchimp, SendGrid).
  • Payment processors: Secure payment handling (e.g., Stripe, PayPal). We do not store full card details.
  • Hosting providers: Cloud infrastructure for Site operation, bound by data processing agreements.
  • Legal authorities: Where required by law, court order, or to protect rights and safety.

All third-party processors are contractually bound to handle your data securely and only for specified purposes. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy or as required by law:

  • Contact enquiries: Retained for up to 2 years from the date of last contact.
  • Customer / service records: Retained for up to 7 years for legal and accounting compliance.
  • Marketing consent records: Retained until you withdraw consent, plus 1 year for audit purposes.
  • Analytics data: Anonymised data retained for up to 26 months.
  • Account data: Retained while your account is active, plus 30 days following deletion request.

After these periods, data is securely deleted or anonymised.

8. Your Privacy Rights

Under GDPR and applicable privacy law, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data where there is no lawful reason for continued processing.
  • Right to restrict processing: Ask us to limit how we use your data in certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Withdraw consent at any time where processing is consent-based, without affecting prior processing.
  • Right to lodge a complaint: You have the right to complain to the relevant supervisory authority (e.g., the ICO in the UK at ico.org.uk).

To exercise any of these rights, please contact us using the details in Section 10. We will respond within 30 days. We may need to verify your identity before processing your request.

9. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include SSL/TLS encryption, access controls, regular security audits, and secure data storage practices. However, no method of internet transmission is 100% secure, and we cannot guarantee absolute security.

10. Contact Us

For any privacy-related questions, requests, or concerns, please contact us:

Groundwork Guild — Privacy Enquiries
Email: [email protected]
Website: your-domain.com/contact

We aim to respond to all legitimate privacy requests within 30 calendar days. Complex requests may take up to 3 months, and we will notify you if this is the case.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. The “Last updated” date at the top of this page will reflect the most recent revision. For significant changes, we will notify you by email or prominent notice on the Site. We encourage you to review this policy periodically.

Groundwork Guildyour-domain.com • This policy was last reviewed and updated on January 1, 2025.