top of page
Blue Light Gradient
jse-bg-dual-blue-v3.jpg

Privacy & Policy

1. Who We Are

 Just Simplifying Everything Ltd is a company registered in England and Wales.
 

  • Company number:   16842023

  • Registered office:       167–169 Great Portland Street, 5th Floor, London W1W 5PF

  • Email:                             enquiries@jsedigital.co.uk

  • Telephone:                 0330 043 8655

  • Website:                        www.jsedigital.co.uk


We have not appointed a Data Protection Officer. We are not required to. Data protection questions should be sent to the email address above. 

2. The two roles we act in 1

This matters, because different rules apply to each.
As a controller
For our own business  our website, our enquiries, our clients, our suppliers and our recruitment ,we decide why and how personal data is used. We are the controller. This policy describes that processing.

As a processor
When we build, host, maintain or optimise a website for a client, that website may collect personal data from the client’s own customers  contact forms, bookings, accounts, newsletter sign-ups. For that data, our client is the controller and we act on their instructions as their processor. We do not decide what that data is used for and we do not use it for our own purposes. If you are a customer of one of our clients and you want to know how your data is used, contact that business. Their privacy policy applies, not this one. If you contact us instead, we will pass your request to them and tell you we have done so. Our clients and JSE enter into a written data processing agreement covering that work, as required by Article 28 of the UK GDPR. 

3.  The personal data we collect 

Website visitors

  •  Technical data IP address, browser type and version, device type, operating system, screen size, and the pages you view.

  •  Usage data  how you arrived at the site, which pages you visit, how long you stay, and what you click.

  • Cookie and similar identifiers — see the Cookies section below.


People who enquire

  •  Name, business name, email address and telephone number.

  •  Your current website address, if you give it to us.

  •  What you tell us about your project

  •  including your budget band and timescale.

  •  A record of our correspondence with you.


Clients and their staff

  •  Contact details for the people we work with at your organisation.

  •  Contract, scope, project and correspondence records.

  •  Billing details and payment records. We do not store full card numbers

  •  payments are handled by our payment provider.

  •  Access credentials you give us for your own systems, held only for as long as we need them.


Suppliers and contractors

  • Contact details, engagement terms, invoices and payment records.


Job applicants

  • Your CV, application, portfolio and the notes we make during recruitment.

  • Right to work information, where we make an offer. 

4. Where we get personal data form

Mostly from you directly — when you fill in a form, email us, call us, or work with us. We also collect some data automatically when you use our website, and we may receive your details from:

  •  A colleague or another business who refers you to us.

  •  Publicly available sources such as your company’s website, Companies House, or a professional network

  • The analytics and platform providers listed later in this policy. 

5. Why we use it, and our lawful basis 

Under the UK GDPR we must have a lawful basis for each purpose. Ours are set out below. 

What we do
Data used
Lawful basis
Meet our legal and regulatory duties, and establish or defend legal claims
Any of the above as relevant
Legal obligation; and our legitimate interest in protecting our position
Recruit
Application data
Steps at your request before entering a contract; and our legitimate interest in assessing candidates
Show completed work in our portfolio
Project data and, where relevant, a named quote
Our legitimate interest in demonstrating our work, with your agreement to anything attributed to you
Send marketing emails about our services
Contact details
Your consent, or our legitimate interest where you are an existing client and we are marketing similar services
Understand how our website is used and improve it
Analytics data
Our legitimate interest in improving our services see the Cookies section
Keep our website working, secure and fast
Technical and usage data
Our legitimate interest in running a secure, functioning website
Provide support and care plans
Client and technical data
Performance of our contract
Deliver the services we have agreed Invoice you and collect payment
Client and project data
Performance of our contract; and our legal obligation to keep accounting records
Respond to your enquiry and prepare a proposal
Enquiry data
Steps at your request before entering a contract; and our legitimate interest in responding to approaches

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can ask us for that assessment, and you can object  see “Your rights”. Where we rely on consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it. 

6.  Marketing 

We will only send you marketing emails where you have asked us to, or where you are an existing client and we are telling you about services similar to those we have already provided. Every marketing email has an unsubscribe link, and we act on it promptly. We do not sell your details to anyone. 

7.  Cookies and similar technologies 

Cookies are small files placed on your device. Some are essential; others are not.

Cookies we set without asking

We do not need your consent for cookies that are strictly necessary for the website to work  for example, remembering what you have put in a form, security, and load balancing. Since 5 February 2026, the Data (Use and Access) Act 2025 has also removed the consent requirement for a small number of low-risk categories: cookies used purely for statistical purposes to improve the service, cookies that remember display preferences such as language or appearance, and cookies used to provide emergency assistance. Where we use these, we still tell you about them here and we still give you a simple way to opt out. 

Cookies we ask permission for
We ask for your consent before setting any cookie used for advertising, cross-site tracking, or building a profile of you. If you do not consent, we do not set them. 

Cookie or provider
Purpose
Consent needed?
Wix Analytics
Aggregate statistics about how the site is used
No — statistical, with an optout below
Wix (platform)
Essential site function, security and session management
No — strictly necessary

You can change your choices at any time using the cookie settings link in the website footer, and you can block or delete cookies in your browser settings. Blocking essential cookies may stop parts of the site working. 

8.  Who we share personal data with

We do not sell personal data. We share it only with organisations that help us run our business, and only as far as they need it. 

Who
Why
Law enforcement, regulators or courts
Where we are legally required to, or to establish or defend legal claims
Subcontractors we bring onto a project
Delivering your work, under written confidentiality and data protection terms
Our accountant, insurers and professional advisers
Running the business, and taking advice where we need it
Wix Analytics
Website statistics
Stripe and PayPal
Taking card and online payments
Zapier
Connecting our tools so enquiries and admin route automatically
Fillout
Enquiry and brief forms
Google Workspace (Google Ireland Ltd)
Email, calendar and document storage
Wix.com Ltd
Website platform and hosting, for our site and for sites we build

Everyone in this list who processes personal data on our behalf does so under a written contract that requires them to keep it secure and use it only for the purpose we have given them. 

9.  Sending personal data outside the UK 

Some of the providers above are based outside the United Kingdom, or store data outside it. Where that happens, we make sure the transfer is covered by one of the safeguards the law allows: 

  • The country has UK adequacy regulations, meaning the Government has decided its protection is not materially lower than the UK’s.

  • We have the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, in place with the provider

  • Another safeguard permitted by the UK GDPR applies. You can ask us for details of the safeguard used for a particular transfer. 

10.  How long we keep it 

What
How long
Why
Access credentials for client systems
Deleted within 30 days of the engagement ending
We should not hold keys we no longer need
Website analytics
Up to 26 months
To see trends over time
Unsuccessful job applications
6 months
To answer questions about the decision
Marketing contacts
Until you unsubscribe, then a suppression record indefinitely
So we do not email you again by accident
Invoices and accounting records
6 years from the end of the accounting period
Required by HMRC and the Companies Act 2006
Client records, contracts and project files
6 years after the engagement ends
The limitation period for contract claims in England and Wales
Enquiries that do not become work
24 months from last contact
So we recognise you if you come back

When a retention period ends we delete the data, or anonymise it so it can no longer identify anyone. 

11.  How we keep it safe

Access is limited to the people who need it to do their job.

  • Accounts are protected with strong, unique passwords and two-factor authentication where the provider supports it.

  • Data is encrypted in transit, and at rest where our providers offer it.

  • Devices are encrypted, kept up to date and locked when unattended.

  • Client credentials are stored in a password manager, never in email or a spreadsheet.

  • We keep a record of what we hold and where, and review it annually. 

No system is perfectly secure. If a breach happens that is likely to result in a risk to people’s rights, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell the people affected without undue delay where the risk to them is high. 

12.  Automated decision-making 

We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you, and we do not profile you in that way. 

13.  Your rights 

You have the following rights over your personal data. They are not all absolute

  • some only apply in particular circumstances, and we will explain if one does not apply to your request.

  • Access— to be told whether we hold data about you, and to get a copy of it.

  • Rectification — to have inaccurate data corrected, and incomplete data completed.

  • Erasure — to have data deleted where we no longer have a good reason to hold it.

  • Restriction — to have us pause using your data while a dispute about it is resolved.

  • Objection — to object to processing based on our legitimate interests, and an absolute right to object to direct marketing.

  • Portability — to receive data you gave us in a machine-readable format, or have us send it to someone else, where it is processed by automated means on the basis of consent or contract.

  • Withdrawing consent — at any time, where we relied on consent.

Complaining — to us, and to the ICO. See the next section. 

How to exercise them

Email enquiries@jsedigital.co.uk and tell us what you want. There is no charge.

We will respond within one month. That month starts once we have what we need to deal with the request  so if we need to confirm who you are, or if your request is very broad and we need you to narrow it, the clock is paused while we wait for you. We will ask for any of that promptly rather than at the end of the month, and we will tell you when the clock has paused and when it has restarted.

When we search for your data we will make a search that is reasonable and proportionate. That does not
always mean every archive and backup, but we will tell you what we searched and why we left anything out.

If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it. If we refuse, we will explain why and tell you how to challenge it. 

14.  Complaints 

If you are unhappy with how we have handled your personal data, please tell us first. We would rather put it right ourselves.
By email : enquiries@jsedigital.co.uk
Online form : www.jsedigital.co.uk/privacy-complaint
By post : 167–169 Great Portland Street, 5th Floor, London W1W 5PF

We will acknowledge your complaint within 30 days of receiving it. We will then investigate it and take appropriate steps to respond, and we will tell you the outcome without undue delay.

You can also complain to the Information Commissioner’s Office at any time. Complaining to us first does not take that right away.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Helpline: 0303 123 1113

ico.org.uk 

15.  Changes to this policy 

We review this policy at least once a year and whenever our processing changes. The version and date are at the foot of every page. Where a change materially affects you we will tell you directly rather than relying on you to notice.

16.  Contact us 

Email enquiries@jsedigital.co.uk, call 0330 043 8655, or write to us at 167–169 Great Portland Street, 5th Floor, London W1W 5PF. 

bottom of page