Privacy Policy
1. Who we are
This website is operated by Appeal Marketing Limited, trading as Appeal Digital (“we”, “us”, “our”). We are the data controller for the personal data described in this policy.
Registered company name
Appeal Marketing Limited
Trading name
Appeal Digital
Company number
10705670 (registered in England and Wales)
Registered office
Origin Workspace, 40 Berkeley Square, Bristol, England, BS8 1HP
VAT number
GB267021910
ICO registration number
ZA247006
Privacy contact
[email protected]
We are registered with the Information Commissioner’s Office (ICO) as a data controller. We have not appointed a statutory Data Protection Officer, as we are not required to do so. Privacy questions are handled by our Privacy Lead at the address above.
We process personal data in accordance with the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) and the Privacy and Electronic Communications Regulations 2003 (PECR, as amended).
2. What this policy covers
This policy explains what we do with personal data when you:
- visit appeal.digital or any of our subdomains
- complete an enquiry, contact or download form
- subscribe to our emails
- engage us as a client or supplier, or discuss doing so
- apply for a role with us
Where we build, host or support a website or application for a client, that client is the data controller for their own visitors’ and users’ data. We act as their processor under a written contract. This policy does not cover that processing.
3. Personal data we collect, why, and our lawful basis
| What we collect | Why | Lawful basis |
|---|---|---|
| Name, work email, phone, job title, company name, and the content of your message | To respond to your enquiry and provide the information you asked for | Legitimate interests — responding to a request you initiated. Where you ask us to send marketing, consent |
| Contact and billing details, project correspondence, purchase orders | To deliver contracted services, invoice, and keep business records | Contract, and legal obligation for accounting records |
| Email address and marketing preferences | To send you our newsletter and service updates | Consent, or the PECR soft opt-in where you are an existing customer or have enquired about similar services. You can withdraw at any time |
| IP address, and the business or organisation we can infer from it, together with pages viewed, referrer, session duration, approximate location, device and browser type | To understand which organisations are researching our services so our sales team can follow up appropriately | Legitimate interests — B2B business development. See section 5 |
| Aggregated statistics about how the site is used (page views, journeys, conversions) | To measure and improve the website | Consent for cookies and similar technologies under PECR, and legitimate interests under the UK GDPR for the resulting analysis |
| Advertising and remarketing identifiers | To measure our advertising and show relevant ads to people who have visited our site | Consent |
| CV, covering letter, work history, references | To assess a job application | Legitimate interests, and contract where we make an offer |
| Records of your consent choices, objections and requests | To evidence our compliance | Legal obligation |
We do not knowingly collect special category data, and we do not collect data from children. We do not carry out any solely automated decision-making that produces legal effects or otherwise significantly affects you, and we do not profile individuals.
4. Cookies and similar technologies
We use cookies and comparable technologies. When you first arrive, our consent banner lets you accept or reject each category. Rejecting is as easy as accepting — there is a “Reject all” control with the same prominence as “Accept all”.
Category
What it does
Consent needed
Strictly necessary
Security, load balancing, form submission, remembering your cookie choices
No — exempt under PECR
Statistics
Google Analytics 4. Aggregated measurement of site usage so we can improve the site
Yes — off until you accept
Marketing
Google Ads conversion tracking and remarketing; HubSpot tracking for identifying and following up your interactions with us
Yes — off until you accept
Non-essential cookies and tags are blocked until you consent. We manage this with Borlabs Cookie and Google Consent Mode v2, and we keep a record of consents given.
You can change or withdraw your choices at any time using the Cookie settings link in our footer, or by clearing cookies in your browser.
A full, current list of every cookie, its provider, purpose and lifespan is available in our Cookie Policy.
5. Business visitor identification
We use Leadfeeder (provided by Leadfeeder Finland Oy, part of the Dealfront group) to identify the organisations visiting our website. It works by looking up the IP address your device sends when it requests a page, and matching it against a database of business IP ranges.
What this means in practice:
- The purpose is to identify companies, not individuals. We do not use it to build a profile of you as a person, and we do not attempt to identify you by name from your IP address.
- It tells us, for example, that someone at a named company viewed our web development pages. It does not tell us who.
- An IP address can still be personal data under the UK GDPR, so we treat it as such.
- We rely on legitimate interests for this processing. We have carried out and documented a Legitimate Interests Assessment weighing our interest in business development against your interests and reasonable expectations. You can request a summary of it.
- Where Leadfeeder sets cookies to recognise returning visitors, those cookies are placed only if you accept the Marketing category in our banner.
- Leadfeeder acts as our processor under a written data processing agreement, and processes the data within the EU.
You can object. If you would prefer we did not process your IP address in this way, email [email protected] and we will suppress your IP address or range. You can also use our cookie settings to decline the associated cookies.
6. Who we share personal data with
We do not sell personal data. We share it with the following categories of recipient, each under a written contract that restricts them to processing on our instructions:
Recipient
What they do
Where data is processed
HubSpot
CRM, marketing email, forms and website tracking
United States
Google (Analytics 4, Google Ads)
Website analytics and advertising measurement
United States and other locations
Leadfeeder / Dealfront
Business visitor identification
European Union
Digital Ocean / Vultr
Website hosting and backups
Dependent on data centre location
Google Workspace
Business email and document storage
United States
Xero
Invoicing and accounting records
United States
Professional advisers, insurers, auditors
Legal, accounting and insurance advice
United Kingdom
We may also disclose personal data where we are legally required to, for example in response to a court order, a regulatory request, or to establish or defend legal claims.
7. International transfers
Some of our providers process personal data outside the UK. Where they do, we make sure the transfer is protected by one of the mechanisms permitted under the UK GDPR:
- transfer to a country the UK Government has found to provide adequate protection, or
- the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
Transfers to the EU rely on the UK’s adequacy findings. Transfers to the United States, including to HubSpot and Google, rely on the UK Addendum or the UK Extension to the EU-US Data Privacy Framework where the provider is certified.
You can ask us for details of the safeguards applying to a particular transfer.
8. How long we keep personal data
| Data | Retention period |
|---|---|
| Website enquiries that do not become clients | 36 months from last contact |
| Client records and project correspondence | 7 years from the end of the engagement |
| Accounting and tax records | 7 years from the end of the relevant financial year (statutory) |
| Marketing contacts and email subscribers | Until you unsubscribe, or 36 months of no engagement, whichever is sooner |
| Analytics data | 14 months (Google Analytics 4 retention setting) |
| Leadfeeder visitor data | 36 months |
| Consent and objection records | 6 years, as evidence of compliance |
| Unsuccessful job applications | 24 months, unless you ask us to keep them longer |
| Server and security logs | 12 months |
9. Your rights
Under the UK GDPR you have the right to:
- be informed about how we use your data — this policy
- access the personal data we hold about you
- have inaccurate data corrected
- have your data erased in certain circumstances
- restrict how we use your data
- object to processing based on legitimate interests, including our business visitor identification
- object to direct marketing at any time, absolutely
- receive your data in a portable format where processing is based on consent or contract
- withdraw consent at any time, where we rely on it
To exercise any of these, email [email protected]. We will respond within one month. We may ask you to verify your identity, and we are only required to carry out reasonable and proportionate searches when locating your data.
There is no charge, unless a request is manifestly unfounded or excessive.
10. Complaints
Complain to us first. If you are unhappy with how we have handled your personal data, email [email protected] with the detail of your complaint.
- We will acknowledge your complaint within 30 days.
- We will investigate and respond without undue delay.
If you are not satisfied with our response, or we do not respond, you can complain to the Information Commissioner’s Office:
- Online: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You also have the right to seek a remedy through the courts.
11. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include access controls and least-privilege permissions, multi-factor authentication on business systems, encryption in transit (TLS) and at rest where supported, regular patching of software and plugins, managed backups, and staff training on data protection.
No transmission over the internet can be guaranteed completely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours, and we will tell you directly where the risk is high.
12. Changes to this policy
We review this policy at least annually, and whenever we change our tools or the law changes. The version number and date at the top show when it was last updated. Where changes are significant, we will tell you directly.
13. Contact
Becky Radford
Appeal Marketing Limited t/a Appeal Digital
Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP
[email protected]