

Privacy & Policy
1. Who We Are
Just Simplifying Everything Ltd is a company registered in England and Wales.
-
Company number: 16842023
-
Registered office: 167–169 Great Portland Street, 5th Floor, London W1W 5PF
-
Email: enquiries@jsedigital.co.uk
-
Telephone: 0330 043 8655
-
Website: www.jsedigital.co.uk
We have not appointed a Data Protection Officer. We are not required to. Data protection questions should be sent to the email address above.
2. The two roles we act in 1
This matters, because different rules apply to each.
As a controller
For our own business our website, our enquiries, our clients, our suppliers and our recruitment ,we decide why and how personal data is used. We are the controller. This policy describes that processing.
As a processor
When we build, host, maintain or optimise a website for a client, that website may collect personal data from the client’s own customers contact forms, bookings, accounts, newsletter sign-ups. For that data, our client is the controller and we act on their instructions as their processor. We do not decide what that data is used for and we do not use it for our own purposes. If you are a customer of one of our clients and you want to know how your data is used, contact that business. Their privacy policy applies, not this one. If you contact us instead, we will pass your request to them and tell you we have done so. Our clients and JSE enter into a written data processing agreement covering that work, as required by Article 28 of the UK GDPR.
3. The personal data we collect
Website visitors
-
Technical data IP address, browser type and version, device type, operating system, screen size, and the pages you view.
-
Usage data how you arrived at the site, which pages you visit, how long you stay, and what you click.
-
Cookie and similar identifiers — see the Cookies section below.
People who enquire
-
Name, business name, email address and telephone number.
-
Your current website address, if you give it to us.
-
What you tell us about your project
-
including your budget band and timescale.
-
A record of our correspondence with you.
Clients and their staff
-
Contact details for the people we work with at your organisation.
-
Contract, scope, project and correspondence records.
-
Billing details and payment records. We do not store full card numbers
-
payments are handled by our payment provider.
-
Access credentials you give us for your own systems, held only for as long as we need them.
Suppliers and contractors
-
Contact details, engagement terms, invoices and payment records.
Job applicants
-
Your CV, application, portfolio and the notes we make during recruitment.
-
Right to work information, where we make an offer.
4. Where we get personal data form
Mostly from you directly — when you fill in a form, email us, call us, or work with us. We also collect some data automatically when you use our website, and we may receive your details from:
-
A colleague or another business who refers you to us.
-
Publicly available sources such as your company’s website, Companies House, or a professional network
-
The analytics and platform providers listed later in this policy.
5. Why we use it, and our lawful basis
Under the UK GDPR we must have a lawful basis for each purpose. Ours are set out below.
What we do | Data used | Lawful basis |
|---|---|---|
Meet our legal and regulatory duties, and establish or defend legal claims | Any of the above as relevant | Legal obligation; and our legitimate interest in protecting our position |
Recruit | Application data | Steps at your request before entering a contract; and our legitimate interest in assessing candidates |
Show completed work in our portfolio | Project data and, where relevant, a named quote | Our legitimate interest in demonstrating our work, with your agreement to anything attributed to you |
Send marketing emails about our services | Contact details | Your consent, or our legitimate interest where you are an existing client and we are marketing similar services |
Understand how our website is used and improve it | Analytics data | Our legitimate interest in improving our services see the Cookies section |
Keep our website working, secure and fast | Technical and usage data | Our legitimate interest in running a secure, functioning website |
Provide support and care plans | Client and technical data | Performance of our contract |
Deliver the services we have agreed Invoice you and collect payment | Client and project data | Performance of our contract; and our legal obligation to keep accounting records |
Respond to your enquiry and prepare a proposal | Enquiry data | Steps at your request before entering a contract; and our legitimate interest in responding to approaches |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can ask us for that assessment, and you can object see “Your rights”. Where we rely on consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.
6. Marketing
We will only send you marketing emails where you have asked us to, or where you are an existing client and we are telling you about services similar to those we have already provided. Every marketing email has an unsubscribe link, and we act on it promptly. We do not sell your details to anyone.
7. Cookies and similar technologies
Cookies are small files placed on your device. Some are essential; others are not.
Cookies we set without asking
We do not need your consent for cookies that are strictly necessary for the website to work for example, remembering what you have put in a form, security, and load balancing. Since 5 February 2026, the Data (Use and Access) Act 2025 has also removed the consent requirement for a small number of low-risk categories: cookies used purely for statistical purposes to improve the service, cookies that remember display preferences such as language or appearance, and cookies used to provide emergency assistance. Where we use these, we still tell you about them here and we still give you a simple way to opt out.
Cookies we ask permission for
We ask for your consent before setting any cookie used for advertising, cross-site tracking, or building a profile of you. If you do not consent, we do not set them.
Cookie or provider | Purpose | Consent needed? |
|---|---|---|
Wix Analytics | Aggregate statistics about how the site is used | No — statistical, with an optout below |
Wix (platform) | Essential site function, security and session management | No — strictly necessary |
You can change your choices at any time using the cookie settings link in the website footer, and you can block or delete cookies in your browser settings. Blocking essential cookies may stop parts of the site working.
8. Who we share personal data with
We do not sell personal data. We share it only with organisations that help us run our business, and only as far as they need it.
Who | Why |
|---|---|
Law enforcement, regulators or courts | Where we are legally required to, or to establish or defend legal claims |
Subcontractors we bring onto a project | Delivering your work, under written confidentiality and data protection terms |
Our accountant, insurers and professional advisers | Running the business, and taking advice where we need it |
Wix Analytics | Website statistics |
Stripe and PayPal | Taking card and online payments |
Zapier | Connecting our tools so enquiries and admin route automatically |
Fillout | Enquiry and brief forms |
Google Workspace (Google Ireland Ltd) | Email, calendar and document storage |
Wix.com Ltd | Website platform and hosting, for our site and for sites we build |
Everyone in this list who processes personal data on our behalf does so under a written contract that requires them to keep it secure and use it only for the purpose we have given them.
9. Sending personal data outside the UK
Some of the providers above are based outside the United Kingdom, or store data outside it. Where that happens, we make sure the transfer is covered by one of the safeguards the law allows:
-
The country has UK adequacy regulations, meaning the Government has decided its protection is not materially lower than the UK’s.
-
We have the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, in place with the provider
-
Another safeguard permitted by the UK GDPR applies. You can ask us for details of the safeguard used for a particular transfer.
10. How long we keep it
What | How long | Why |
|---|---|---|
Access credentials for client systems | Deleted within 30 days of the engagement ending | We should not hold keys we no longer need |
Website analytics | Up to 26 months | To see trends over time |
Unsuccessful job applications | 6 months | To answer questions about the decision |
Marketing contacts | Until you unsubscribe, then a suppression record indefinitely | So we do not email you again by accident |
Invoices and accounting records | 6 years from the end of the accounting period | Required by HMRC and the Companies Act 2006 |
Client records, contracts and project files | 6 years after the engagement ends | The limitation period for contract claims in England and Wales |
Enquiries that do not become work | 24 months from last contact | So we recognise you if you come back |
When a retention period ends we delete the data, or anonymise it so it can no longer identify anyone.
11. How we keep it safe
Access is limited to the people who need it to do their job.
-
Accounts are protected with strong, unique passwords and two-factor authentication where the provider supports it.
-
Data is encrypted in transit, and at rest where our providers offer it.
-
Devices are encrypted, kept up to date and locked when unattended.
-
Client credentials are stored in a password manager, never in email or a spreadsheet.
-
We keep a record of what we hold and where, and review it annually.
No system is perfectly secure. If a breach happens that is likely to result in a risk to people’s rights, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell the people affected without undue delay where the risk to them is high.
12. Automated decision-making
We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you, and we do not profile you in that way.
13. Your rights
You have the following rights over your personal data. They are not all absolute
-
some only apply in particular circumstances, and we will explain if one does not apply to your request.
-
Access— to be told whether we hold data about you, and to get a copy of it.
-
Rectification — to have inaccurate data corrected, and incomplete data completed.
-
Erasure — to have data deleted where we no longer have a good reason to hold it.
-
Restriction — to have us pause using your data while a dispute about it is resolved.
-
Objection — to object to processing based on our legitimate interests, and an absolute right to object to direct marketing.
-
Portability — to receive data you gave us in a machine-readable format, or have us send it to someone else, where it is processed by automated means on the basis of consent or contract.
-
Withdrawing consent — at any time, where we relied on consent.
Complaining — to us, and to the ICO. See the next section.
How to exercise them
Email enquiries@jsedigital.co.uk and tell us what you want. There is no charge.
We will respond within one month. That month starts once we have what we need to deal with the request so if we need to confirm who you are, or if your request is very broad and we need you to narrow it, the clock is paused while we wait for you. We will ask for any of that promptly rather than at the end of the month, and we will tell you when the clock has paused and when it has restarted.
When we search for your data we will make a search that is reasonable and proportionate. That does not
always mean every archive and backup, but we will tell you what we searched and why we left anything out.
If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it. If we refuse, we will explain why and tell you how to challenge it.
14. Complaints
If you are unhappy with how we have handled your personal data, please tell us first. We would rather put it right ourselves.
By email : enquiries@jsedigital.co.uk
Online form : www.jsedigital.co.uk/privacy-complaint
By post : 167–169 Great Portland Street, 5th Floor, London W1W 5PF
We will acknowledge your complaint within 30 days of receiving it. We will then investigate it and take appropriate steps to respond, and we will tell you the outcome without undue delay.
You can also complain to the Information Commissioner’s Office at any time. Complaining to us first does not take that right away.
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
15. Changes to this policy
We review this policy at least once a year and whenever our processing changes. The version and date are at the foot of every page. Where a change materially affects you we will tell you directly rather than relying on you to notice.
16. Contact us
Email enquiries@jsedigital.co.uk, call 0330 043 8655, or write to us at 167–169 Great Portland Street, 5th Floor, London W1W 5PF.
