• 20+ years professional development
  • Elgin-based, working UK-wide
  • Fixed-price proposals
  • 90-day managed launch care
  • PageSpeed 80+ on every build
  • UK company & ICO-registered
  • Cloudflare-protected
  • Stripe secure payments

Who we are

Smaoin Ltd, based in Elgin, Scotland, is the data controller for the personal data described in this policy — we decide how and why it’s used.

For anything about how we handle your data, or to exercise any of the rights below, contact us and select “A privacy or data request” as your reason, so it reaches the right place.

What we collect, why, and on what basis

We only collect what a given activity actually needs:

When What we collect Why Lawful basis
Contact form Name, email, company (optional), your message To respond to your enquiry Legitimate interest (running the business)
Free website scans Domain entered, your IP address (hashed, for fair-use rate limiting), scan results To run the scan and stop abuse of the free tool Legitimate interest
Buying a report or care plan Name, email, billing details (card details go straight to Stripe — we never see or store them) To take payment and deliver what you bought Contract (fulfilling your purchase)
Client portal account Email, login records, support tickets, invoices, findings history To run your account and deliver the service you’re paying for Contract
Hosted platforms Whatever your own site/system stores or processes To host, back up, and keep it running Contract (you’re our client) — you remain the controller of your own site’s data (see our Data Processing Agreement)
Analytics (Google Analytics) Aggregated usage statistics (GA4 does not record full IP addresses) To understand how the site is used, so we can improve it Consent — only loads if you accept the cookie banner

We never use any of this for advertising, and we don’t sell personal data. See our Cookie Policy for the detail on cookies specifically.

How long we keep it

  • Contact form enquiries: up to 24 months, so we can follow up on things that take a while to come back around.
  • Free scan results: up to 12 months, then deleted — long enough for you to compare a re-scan.
  • Client portal & billing records: for as long as your account is active, plus whatever period UK tax and accounting law requires afterwards (typically 6 years).
  • Analytics data: retained by Google under our GA4 data-retention setting; GA4 does not store full IP addresses.

Who we share it with

We don’t sell your data. We share it only with the specific processors that make the service work, each under their own confidentiality and security terms:

  • Microsoft Azure — cloud infrastructure and secrets storage (Key Vault)
  • Microsoft Graph — sending email on our behalf (reports, notifications)
  • Stripe — payment processing (we never see full card details)
  • Cloudflare — content delivery, DDoS protection, and bot filtering (Turnstile)
  • Fasthosts — UK-based hosting infrastructure for client platforms
  • Google Analytics — only after you accept the cookie banner

Some of these providers may process data outside the UK. Where that happens, it’s covered by a UK-recognised safeguard — the UK International Data Transfer Agreement (IDTA) or Addendum, or the UK Extension to the EU-US Data Privacy Framework.

For platforms we host on your behalf, the full register of sub-processors that touch your platform’s data — and the terms that govern them — is maintained in Annex A of our Data Processing Agreement.

Your rights

Under UK GDPR, you can ask us to:

  • Give you a copy of the personal data we hold about you
  • Correct anything that’s inaccurate or incomplete
  • Delete your data, where we’re not required to keep it for legal reasons
  • Restrict or object to certain processing
  • Give you your data in a portable format
  • Withdraw consent at any time, where consent is the basis (e.g. analytics)

Contact us to exercise any of these. If you’re not satisfied with how we’ve handled your data, you can complain to the Information Commissioner’s Office (ICO).

Our security measures

We implement appropriate technical and organisational controls to protect your data.

These include encryption in transit and at rest, role-based access control, and continuous security monitoring.

Changes to this policy

We may update this policy from time to time, for example as our services or processors change. Significant changes will be reflected here with an updated date. This policy was last reviewed in July 2026.