Privacy Policy

1. Who we are

This website is operated by Appeal Marketing Limited, trading as Appeal Digital (“we”, “us”, “our”). We are the data controller for the personal data described in this policy.

Registered company name Appeal Marketing Limited
Trading name Appeal Digital
Company number 10705670 (registered in England and Wales)
Registered office Origin Workspace, 40 Berkeley Square, Bristol, England, BS8 1HP
VAT number GB267021910
ICO registration number ZA247006
Privacy contact [email protected]

We are registered with the Information Commissioner’s Office (ICO) as a data controller. We have not appointed a statutory Data Protection Officer, as we are not required to do so. Privacy questions are handled by our Privacy Lead at the address above.

We process personal data in accordance with the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) and the Privacy and Electronic Communications Regulations 2003 (PECR, as amended).

2. What this policy covers

This policy explains what we do with personal data when you:

  • visit appeal.digital or any of our subdomains
  • complete an enquiry, contact or download form
  • subscribe to our emails
  • engage us as a client or supplier, or discuss doing so
  • apply for a role with us

Where we build, host or support a website or application for a client, that client is the data controller for their own visitors’ and users’ data. We act as their processor under a written contract. This policy does not cover that processing.

3. Personal data we collect, why, and our lawful basis

What we collect Why Lawful basis
Name, work email, phone, job title, company name, and the content of your message To respond to your enquiry and provide the information you asked for Legitimate interests — responding to a request you initiated. Where you ask us to send marketing, consent
Contact and billing details, project correspondence, purchase orders To deliver contracted services, invoice, and keep business records Contract, and legal obligation for accounting records
Email address and marketing preferences To send you our newsletter and service updates Consent, or the PECR soft opt-in where you are an existing customer or have enquired about similar services. You can withdraw at any time
IP address, and the business or organisation we can infer from it, together with pages viewed, referrer, session duration, approximate location, device and browser type To understand which organisations are researching our services so our sales team can follow up appropriately Legitimate interests — B2B business development. See section 5
Aggregated statistics about how the site is used (page views, journeys, conversions) To measure and improve the website Consent for cookies and similar technologies under PECR, and legitimate interests under the UK GDPR for the resulting analysis
Advertising and remarketing identifiers To measure our advertising and show relevant ads to people who have visited our site Consent
CV, covering letter, work history, references To assess a job application Legitimate interests, and contract where we make an offer
Records of your consent choices, objections and requests To evidence our compliance Legal obligation

We do not knowingly collect special category data, and we do not collect data from children. We do not carry out any solely automated decision-making that produces legal effects or otherwise significantly affects you, and we do not profile individuals.

4. Cookies and similar technologies

We use cookies and comparable technologies. When you first arrive, our consent banner lets you accept or reject each category. Rejecting is as easy as accepting — there is a “Reject all” control with the same prominence as “Accept all”.

Category What it does Consent needed
Strictly necessary Security, load balancing, form submission, remembering your cookie choices No — exempt under PECR
Statistics Google Analytics 4. Aggregated measurement of site usage so we can improve the site Yes — off until you accept
Marketing Google Ads conversion tracking and remarketing; HubSpot tracking for identifying and following up your interactions with us Yes — off until you accept

Non-essential cookies and tags are blocked until you consent. We manage this with Borlabs Cookie and Google Consent Mode v2, and we keep a record of consents given.

You can change or withdraw your choices at any time using the Cookie settings link in our footer, or by clearing cookies in your browser.

A full, current list of every cookie, its provider, purpose and lifespan is available in our Cookie Policy.

5. Business visitor identification

We use Leadfeeder (provided by Leadfeeder Finland Oy, part of the Dealfront group) to identify the organisations visiting our website. It works by looking up the IP address your device sends when it requests a page, and matching it against a database of business IP ranges.

What this means in practice:

  • The purpose is to identify companies, not individuals. We do not use it to build a profile of you as a person, and we do not attempt to identify you by name from your IP address.
  • It tells us, for example, that someone at a named company viewed our web development pages. It does not tell us who.
  • An IP address can still be personal data under the UK GDPR, so we treat it as such.
  • We rely on legitimate interests for this processing. We have carried out and documented a Legitimate Interests Assessment weighing our interest in business development against your interests and reasonable expectations. You can request a summary of it.
  • Where Leadfeeder sets cookies to recognise returning visitors, those cookies are placed only if you accept the Marketing category in our banner.
  • Leadfeeder acts as our processor under a written data processing agreement, and processes the data within the EU.

You can object. If you would prefer we did not process your IP address in this way, email [email protected] and we will suppress your IP address or range. You can also use our cookie settings to decline the associated cookies.

6. Who we share personal data with

We do not sell personal data. We share it with the following categories of recipient, each under a written contract that restricts them to processing on our instructions:

Recipient What they do Where data is processed
HubSpot CRM, marketing email, forms and website tracking United States
Google (Analytics 4, Google Ads) Website analytics and advertising measurement United States and other locations
Leadfeeder / Dealfront Business visitor identification European Union
Digital Ocean / Vultr Website hosting and backups Dependent on data centre location
Google Workspace Business email and document storage United States
Xero Invoicing and accounting records United States
Professional advisers, insurers, auditors Legal, accounting and insurance advice United Kingdom

We may also disclose personal data where we are legally required to, for example in response to a court order, a regulatory request, or to establish or defend legal claims.

7. International transfers

Some of our providers process personal data outside the UK. Where they do, we make sure the transfer is protected by one of the mechanisms permitted under the UK GDPR:

  • transfer to a country the UK Government has found to provide adequate protection, or
  • the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

Transfers to the EU rely on the UK’s adequacy findings. Transfers to the United States, including to HubSpot and Google, rely on the UK Addendum or the UK Extension to the EU-US Data Privacy Framework where the provider is certified.

You can ask us for details of the safeguards applying to a particular transfer.

8. How long we keep personal data

Data Retention period
Website enquiries that do not become clients 36 months from last contact
Client records and project correspondence 7 years from the end of the engagement
Accounting and tax records 7 years from the end of the relevant financial year (statutory)
Marketing contacts and email subscribers Until you unsubscribe, or 36 months of no engagement, whichever is sooner
Analytics data 14 months (Google Analytics 4 retention setting)
Leadfeeder visitor data 36 months
Consent and objection records 6 years, as evidence of compliance
Unsuccessful job applications 24 months, unless you ask us to keep them longer
Server and security logs 12 months

9. Your rights

Under the UK GDPR you have the right to:

  • be informed about how we use your data — this policy
  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data erased in certain circumstances
  • restrict how we use your data
  • object to processing based on legitimate interests, including our business visitor identification
  • object to direct marketing at any time, absolutely
  • receive your data in a portable format where processing is based on consent or contract
  • withdraw consent at any time, where we rely on it

To exercise any of these, email [email protected]. We will respond within one month. We may ask you to verify your identity, and we are only required to carry out reasonable and proportionate searches when locating your data.

There is no charge, unless a request is manifestly unfounded or excessive.

10. Complaints

Complain to us first. If you are unhappy with how we have handled your personal data, email [email protected] with the detail of your complaint.

  • We will acknowledge your complaint within 30 days.
  • We will investigate and respond without undue delay.

If you are not satisfied with our response, or we do not respond, you can complain to the Information Commissioner’s Office:

  • Online: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

You also have the right to seek a remedy through the courts.

11. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include access controls and least-privilege permissions, multi-factor authentication on business systems, encryption in transit (TLS) and at rest where supported, regular patching of software and plugins, managed backups, and staff training on data protection.

No transmission over the internet can be guaranteed completely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours, and we will tell you directly where the risk is high.

12. Changes to this policy

We review this policy at least annually, and whenever we change our tools or the law changes. The version number and date at the top show when it was last updated. Where changes are significant, we will tell you directly.

13. Contact

Becky Radford
Appeal Marketing Limited t/a Appeal Digital
Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP
[email protected]

14. Your data consent history & updating preferences