Privacy Policy | OrangeWidow

Privacy Policy

Last updated: September 2026

OrangeWidow (“we”, “us”, “our”, or “OrangeWidow”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal information when you use our website and services.

We are a UK-based business and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Data Controller: OrangeWidow
Contact Email: [email protected]
Website: orangewidow.com

If you have any questions about this Privacy Policy or how we handle your data, please contact us using the details above.

2. Information We Collect

2.1 Information You Provide Directly

When you use our services, contact us, or create an account, we may collect:

  • Identity Data: Name, job title, company name.
  • Contact Data: Email address, phone number, postal address.
  • Financial Data: Bank account details, payment card information (processed securely by our payment processor; we do not store full card details).
  • Transaction Data: Details of services you have purchased from us.
  • Technical Project Data: Website credentials, hosting access details, and project specifications necessary to deliver our services.
  • Communications: Records of your correspondence with us, including support tickets and emails.

2.2 Information Collected Automatically

When you visit our website, we automatically collect:

  • Technical Data: IP address, browser type and version, time zone setting, browser plug-in types, operating system and platform.
  • Usage Data: Information about how you use our website, including pages viewed, time spent on pages, and navigation paths.
  • Cookie Data: See Section 9 (Cookies) below for details.

2.3 Information from Third Parties

We may receive information about you from:

  • Analytics providers (e.g., Google Analytics).
  • Search information providers.
  • Payment processors (to confirm transaction status).

3. How We Use Your Information

We use your personal data only where we have a lawful basis to do so. The bases we rely on are:

PurposeLawful BasisData Used
To provide and manage our servicesContractual necessityIdentity, Contact, Financial, Technical Project
To process payments and send invoicesContractual necessityIdentity, Contact, Financial, Transaction
To communicate with you about your account or projectsContractual necessity / Legitimate interestIdentity, Contact, Communications
To provide technical supportContractual necessityIdentity, Contact, Communications, Technical Project
To send service updates and security noticesLegitimate interest / Legal obligationIdentity, Contact
To improve our website and servicesLegitimate interestTechnical, Usage, Cookie
To comply with legal obligationsLegal obligationAll relevant categories
To prevent fraud and protect our businessLegitimate interest / Legal obligationIdentity, Contact, Financial, Technical, Usage

We do not use your personal data for automated decision-making that produces legal or similarly significant effects.

4. How We Share Your Information

We do not sell your personal data. We only share it in the following circumstances:

4.1 Service Providers

We share data with trusted third parties who help us deliver our services:

  • Payment processors (to process card and bank payments).
  • Hosting infrastructure providers (for server management and data centre operations).
  • Email service providers (for transactional and support communications).
  • Analytics providers (to understand website usage and improve our services).

All third-party providers are contractually bound to process your data only for specified purposes and in accordance with UK GDPR.

4.2 Legal Requirements

We may disclose your personal data if required to do so by law, or in response to valid requests by public authorities (e.g., a court or government agency).

4.3 Business Transfers

If OrangeWidow is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before this occurs.

5. International Data Transfers

Our servers are located in the United Kingdom. Some of our service providers may process data outside the UK (e.g., cloud services, email providers).

When we transfer your personal data outside the UK, we ensure a similar degree of protection is afforded to it by:

  • Only transferring to countries deemed by the UK government to provide an adequate level of protection.
  • Using specific contracts approved by the UK Information Commissioner’s Office (ICO) that give personal data the same protection it has in the UK.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data against:

  • Unauthorised access, alteration, or disclosure.
  • Accidental loss or destruction.

These measures include:

  • Encryption of data in transit (TLS/SSL).
  • Secure server infrastructure with active monitoring (cpGuard, firewalls).
  • Access controls and authentication requirements.
  • Regular security audits and staff training.

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

7.1 Retention Periods

  • Client account data: Retained for 6 years after the end of our business relationship (to comply with UK tax and accounting laws).
  • Website project files and credentials: Retained for 12 months after project completion or service termination, then securely deleted.
  • Support ticket records: Retained for 3 years for quality assurance and dispute resolution.
  • Server logs and analytics: Retained for 12 months, then anonymised or deleted.
  • Payment records: Retained for 6 years to comply with HMRC requirements.

7.2 Deletion Requests

You may request deletion of your personal data at any time (see Section 10 — Your Rights). We will comply unless we have a legal obligation to retain it.

8. Your Data Protection Rights

Under UK GDPR, you have the following rights:

8.1 Right to Access

You have the right to request copies of your personal data. We may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

8.2 Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

8.3 Right to Erasure (“Right to be Forgotten”)

You have the right to request that we erase your personal data, under certain conditions (e.g., where we no longer need it and there is no legal basis for continued processing).

8.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

8.5 Right to Object to Processing

You have the right to object to our processing of your personal data where we rely on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

8.6 Right to Data Portability

You have the right to request that we transfer the data we have collected to another organisation, or directly to you, in a structured, commonly used, machine-readable format.

8.7 Right to Withdraw Consent

Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.

8.8 How to Exercise Your Rights

To exercise any of these rights, please email us at [email protected] with:

  • Your full name and contact details.
  • The right you wish to exercise.
  • Any relevant account or project information.

We aim to respond to all requests within 30 days.

8.9 Complaints

If you are not satisfied with how we handle your data, you have the right to complain to the UK Information Commissioner’s Office (ICO):

9. Cookies & Tracking Technologies

9.1 What Are Cookies?

Cookies are small text files placed on your device when you visit our website. They help us provide you with a good experience and allow us to improve our site.

9.2 How We Use Cookies

We use the following types of cookies:

CategoryPurposeExamples
EssentialRequired for the website to functionSession cookies, security cookies
AnalyticsHelp us understand how visitors interact with our siteGoogle Analytics, B.I.T.E. tracking
FunctionalRemember your preferencesLanguage selection, form auto-fill
MarketingTrack visitors across websites for advertising purposesWe currently do not use marketing cookies

9.3 Managing Cookies

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or not function properly.

9.4 Third-Party Cookies

Our website uses Google Analytics, which sets cookies to collect information about your use of our site. This information is aggregated and anonymised where possible. For more information, see Google’s Privacy Policy.

10. Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected] and we will delete the information.

11. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of every website you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Material changes will be notified via:

  • A prominent notice on our website.
  • Direct email communication to active clients.

The “Last updated” date at the top of this policy will always reflect the most recent revision. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Contact: [email protected]
General Enquiries: [email protected]
Website: orangewidow.com

By using OrangeWidow’s website and services, you acknowledge that you have read and understood this Privacy Policy.