Legal
Privacy Policy
How we handle personal data under UK GDPR and the Data Protection Act 2018.
1. Who we are (data controller)
CodeFusion UK (“we”, “us”, “our”) is the data controller for personal data processed through our website, client portal, billing systems and project communications. We trade from 10 Rectory Close, Alton Barnes, Wiltshire, SN8 4LE. Contact: hello@codefusionuk.com or +44 7801 972492.
This Privacy Policy explains how we collect, use, store and share personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What personal data we collect
Depending on how you interact with us, we may process:
- Identity & contact data — name, email, phone, company name, job title, postal address.
- Project & commercial data — briefs, requirements, feedback, files you upload, quotes, invoices, payment status, subscription details.
- Account data — portal login email, hashed password, session logs needed for security.
- Payment data — Stripe customer/payment references. We do not store full card numbers on our servers; Stripe processes card data as an independent payment provider.
- Technical data — IP address, browser type, device information, pages viewed, and similar diagnostics when you use our site or portal.
- Marketing preferences — only where you have opted in or where soft opt-in rules under PECR apply to existing customers for similar services.
- Website audit product data — email and website URL you submit for a paid or free site review, plus the generated report.
We do not intentionally collect special category data (e.g. health, religion). Please do not send such information unless we have agreed a lawful basis in writing.
3. How we collect data
- Directly from you (contact forms, email, phone, portal, checkout).
- Automatically via essential cookies/session technology and, if enabled, analytics tools.
- From payment processors (Stripe) when you pay.
- From publicly available business information you ask us to review (for example a public website URL for an audit).
4. Purposes and lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Respond to enquiries and provide quotes | Legitimate interests / steps prior to contract |
| Deliver projects, hosting, support and portal access | Contract |
| Invoicing, subscriptions, accounting and tax records | Contract / Legal obligation |
| Payment processing via Stripe | Contract |
| Website/security monitoring and abuse prevention | Legitimate interests |
| Optional analytics (if configured) | Consent or legitimate interests, as configured |
| Service updates to existing customers | Legitimate interests / PECR soft opt-in where applicable |
| Website audit reports you request | Contract / steps to enter a contract |
Where we rely on legitimate interests, we balance those interests against your rights and expectations.
5. Sharing your data
We do not sell personal data. We share data only with trusted processors/service providers as needed to operate the business, including:
- Stripe — payments and billing.
- Hosting providers (currently including Hostinger infrastructure) — website and application hosting.
- Email/SMTP providers — transactional email (quotes, invoices, password resets, audit links).
- Analytics providers (e.g. Google Analytics) — only if enabled in our settings.
- Professional advisers (accountant, solicitor, insurer) where required.
- Authorities where legally required.
Processors act on our instructions under appropriate contracts. Some providers may process data outside the UK; where they do, we rely on appropriate transfer safeguards (for example UK IDTA / Addendum or adequacy decisions).
6. Retention
We keep personal data only as long as needed for the purpose collected:
- Enquiry records — typically up to 24 months if no project proceeds.
- Customer/project/billing records — for the life of the relationship and thereafter as required for tax, accounting and legal claims (often up to 6 years after the end of the financial year in which the engagement ended).
- Portal accounts — while active, then deleted or anonymised after a reasonable wind-down period.
- Security logs — for shorter operational periods unless needed to investigate incidents.
7. Your rights
Under UK GDPR you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain circumstances
- Restrict or object to processing
- Data portability
- Withdraw consent where processing is consent-based
To exercise rights, email hello@codefusionuk.com. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
8. Security
We use appropriate technical and organisational measures including HTTPS, hashed passwords for portal accounts, access controls, and least-privilege admin access. No method of transmission or storage is 100% secure; please use strong unique passwords for the portal.
9. Children
Our services are aimed at businesses and adults. We do not knowingly offer services to children.
10. Changes
We may update this policy from time to time. The “Last updated” date at the bottom of this page will change when we do. Material changes may also be notified by email to active customers.
Last updated 27 September 2026. CodeFusion UK · 10 Rectory Close, Alton Barnes, Wiltshire, SN8 4LE · hello@codefusionuk.com · +44 7801 972492.
These policies apply to our UK trading activities. If anything in a signed quote or order conflicts with a general policy, the signed document takes priority for that engagement.