Get a free audit

Privacy Notice

Version 0.4 (draft). Last updated [DATE].

This notice explains how Padon collects and uses personal data, and what rights you have. It covers:

1. Who we are

Padon is the trading name of [Max Okunev], a sole trader based in England. We are the controller of the personal data described in sections 3 to 5. Our address for service of documents is [VIRTUAL OFFICE ADDRESS]. We are registered with the Information Commission (ICO), the UK data protection regulator, under number [ICO REGISTRATION NUMBER].

Contact us about anything in this notice at [email protected], or by post at the address above. We are a small business and have not appointed a data protection officer.

2. Summary

3. Businesses we look at or contact about a new website

What we collect and where it comes from

We look at UK limited companies and limited liability partnerships that might benefit from a new website. We collect:

Most of this is information about the business, not about you as a person. It becomes personal data where it identifies you, for example a director’s name or a named email address such as [email protected].

Previews: your facts, our visuals

A preview uses only factual information about the business: its name, services, phone number, opening hours and area served. We write all the text ourselves and use our own illustrations or placeholder images. We do not reuse the business’s photos, logo or text, or any review text, before it becomes a client. Previews may show the business’s average star rating and number of reviews, never reviewers’ names or photos.

Addressing emails to a director

We are testing whether emails addressed to a person are more useful than emails addressed to the business. For about half the companies we contact, we take the first name and surname of one current director from the public Companies House register and address the email to their first name. For the other half we address the business only.

If you are a director and receive one of these emails, it includes a link to this notice, so you have this information from our first contact (Article 14(3)(b) UK GDPR). If you do not reply, we delete your name within 30 days of our last email. If you opt out, we keep only the suppression record described below.

We only send these emails to limited companies and LLPs. We do not send them to sole traders or ordinary partnerships.

Businesses we look at but do not contact

We look at more businesses than we contact. If we decide not to contact a business, we delete any personal data we collected about it, such as a director’s name or a named email address, within [30] days. Telling each person individually that we briefly held their details would involve disproportionate effort, so we rely on Article 14(5)(b) of the UK GDPR and publish this notice instead. Our legitimate interests assessment explains the safeguards we use.

Why we use it and our lawful basis

We use this data to decide whether a business might want a new website, to prepare the audit and preview, to send one email to tell the business about them, with a follow-up [NUMBER OF FOLLOW-UPS, e.g. at most one], and to compare how well different ways of addressing our emails work.

Our lawful basis is legitimate interests (Article 6(1)(f) UK GDPR). Our interest is in offering our services to businesses that may benefit from them. We think this is fair because the information is published by the business, on a public listing or on the public register for business purposes, we write to the business about its own website, and you can stop us at any time with one click or one reply. We have carried out a legitimate interests assessment, and you can ask us for a copy of its conclusions.

Your right to object, and how to opt out

You have an absolute right to object to direct marketing. To stop us contacting you or your business, use the opt-out link in any of our emails, or reply or write to [email protected]. We will stop straight away.

When you opt out, we delete the outreach data we hold about your business, except a short record on our suppression list (the email address, the website domain, the company number and the date you opted out). We keep that record permanently, because it is the only way we can make sure we never contact you again. We use it for nothing else.

4. Free audit requests and clients

Free audit requests

If you ask for a free audit on our homepage, we collect your website address, business name and email address. We use them to prepare and send your audit and preview, and to follow up about it. Our lawful basis is legitimate interests in responding to a business’s request (or, if you are a sole trader, steps taken at your request before a contract). If you do not go ahead, we delete the request [12] months after our last contact.

What we collect from clients

We do not see or store full card or bank account numbers. GoCardless and Stripe collect those directly (see section 7).

The contact, billing and acceptance details in the go-live form are needed to enter into and perform our contract. If you do not give them, we cannot put your website live. Other questions are optional.

Why we use it and our lawful basis

Purpose Lawful basis
Building, hosting and looking after your website, and managing your account Contract, where you are the contracting party; otherwise legitimate interests in performing our contract with your business
Keeping a record of your acceptance of our terms Legitimate interests (being able to show what was agreed)
Taking payments and keeping accounting and tax records Legal obligation, and contract or legitimate interests as above
Service messages, such as monthly enquiry reports, changes to our terms and service updates Contract or legitimate interests as above. These are not marketing, and you cannot opt out of them while you are a client
Occasional marketing emails about new services, if you opted in Consent, which you can withdraw at any time using the link in any such email or by emailing us
Dealing with complaints and legal claims Legitimate interests (protecting our business)

AI tools

We use AI tools to design and build websites. The content of your website, your questionnaire answers and your change requests are processed by our AI provider (see section 7) to do that. Under its commercial terms, our AI provider may not use that content to train its models. A person reviews every website before it goes live. We do not use AI to make decisions about you that have legal or similarly significant effects.

5. Visitors to our website, preview pages and go-live form

How we measure use of preview pages and the go-live form

Each business we contact gets a personal preview page with its own web address. When that page, the preview or our go-live form is used, we record:

We do not use cookies or fingerprinting for this, do not combine it with data from other sources, and do not look up who you are from your IP address. Our hosting provider sees your IP address to deliver the page, but we do not store it with these records.

We use page opens, preview opens and “Go live” clicks to understand the interest of the business we contacted and to time any follow-up. We use scroll depth and form progress only as statistics to improve our pages and form. Our lawful basis is legitimate interests. We keep these records for 12 months.

To object to this measurement, use the “Don’t measure my visit” link on the preview page, or email [email protected]. We will stop recording visits to that page.

Questionnaire answers

When you fill in our questionnaire, your answers are saved in your browser’s local storage on your own device, so you do not lose them if you leave the page. They are not sent to us until you press submit. You can delete them at any time by clearing your browser’s site data. Once submitted, we treat them as described in section 4.

Cookies and similar technologies

We do not use cookies or similar technologies for analytics or advertising, and our emails contain no tracking pixels or tracked links. The local storage described above is used only to provide the questionnaire you are filling in, which is strictly necessary for the service you asked for. Measuring scroll depth and form progress uses a small script on the page. Where that involves reading information from your device, we rely on the exception in the Privacy and Electronic Communications Regulations for collecting statistics to improve a service, which applies because we tell you about it here and give you a simple, free way to object. If we start using anything else that needs consent, we will ask for it first.

Technical data

Like any website, our hosting provider (Cloudflare) processes technical information, such as your IP address, browser type and the pages requested, to deliver pages and protect the site from attacks. Our lawful basis is legitimate interests in running a secure website.

6. People who send an enquiry through a website we host

If you sent an enquiry through a form on a website that we built and host for one of our clients, that business is the controller of your data. We process your enquiry on its behalf, as its processor: we email it to the business and keep a record of it for a limited period so we can report enquiry numbers to the business.

The business’s own privacy notice explains how it uses your data. To exercise your rights, please contact the business. If you contact us, we will pass your request to the business.

7. Who we share personal data with

We use these service providers. They process personal data on our instructions, except where we say they act as independent controllers.

Provider What they do Location
Cloudflare, Inc. Hosting, form handling and storage Global network; USA-based company
Resend Sending emails USA
Anthropic, PBC AI processing of website content, audits and briefs USA
Google LLC (Google Workspace) [DELETE IF NOT USED] Our business email USA and other countries
GoCardless Ltd Direct Debit payments. GoCardless is an independent controller of payment data and has its own privacy notice UK and EEA
Stripe Card payments, if used. Stripe is an independent controller of payment data for its own purposes, such as fraud prevention and regulatory compliance, and has its own privacy notice UK, EEA and USA

We may also share personal data with our professional advisers (such as accountants and lawyers), with HMRC, the police or other authorities when the law requires it, and with a buyer if we sell our business. We do not sell personal data.

8. Transfers outside the UK

Some of our providers are based in, or use services in, the USA and other countries. When personal data is transferred outside the UK, we make sure it is protected by one of the safeguards allowed by UK law: either the UK-US data bridge (for US companies certified under the UK Extension to the EU-US Data Privacy Framework) or contract terms approved under UK law, such as the International Data Transfer Addendum to the EU Standard Contractual Clauses. You can ask us for details.

9. How long we keep personal data

Data How long we keep it
Personal data about businesses we look at but do not contact Up to [30] days, then deleted
Directors’ names used to address emails, where there is no reply 30 days after our last email, then deleted
Outreach records (company details, audit, preview, emails) for businesses that do not reply [6] months after our last email, then deleted
Outreach records for businesses that reply but do not become clients [12] months after our last contact, then deleted
Suppression list entry after an opt-out Permanently (see section 3)
Personal preview pages Taken down [90] days after our first email, or sooner on request
Records of how preview pages and the go-live form were used 12 months, then deleted
Free audit requests that do not lead to a contract [12] months after our last contact, then deleted
Questionnaire answers in your browser Until you submit them or clear your browser data
Client account, correspondence, website content and acceptance records For the length of the contract plus 6 years, to deal with any legal claims
Invoices and payment records 6 years from the end of the financial year they relate to, as tax law requires
Marketing consent records For as long as you are opted in, plus 2 years
Enquiries processed for clients As set out in our Data Processing Agreement, then deleted
Complaints (including those sent through our complaint form) 6 years after the complaint is closed

10. Your rights

You have the right to:

To use any of these rights, email [email protected]. We will respond within one month, which may be extended by up to two further months for complex requests. We may need to confirm your identity first.

11. Complaints

If you are unhappy with how we have handled your personal data, please tell us first. You can use our complaint form at https://padon.ai/complaints, email [email protected], or write to us at the address in section 1. We will acknowledge your complaint within 30 days, keep you informed of progress, and tell you the outcome without undue delay.

You also have the right to complain to the Information Commission (ICO):

12. Changes to this notice

We will update this notice when our practices change, and show the version and date at the top.