- 20+ years professional development
- Elgin-based, working UK-wide
- Fixed-price proposals
- 90-day managed launch care
- PageSpeed 80+ on every build
- UK company & ICO-registered
- Cloudflare-protected
- Stripe secure payments
Who we are
Smaoin Ltd, based in Elgin, Scotland, is the data controller for the personal data described in this policy — we decide how and why it’s used.
For anything about how we handle your data, or to exercise any of the rights below, contact us and select “A privacy or data request” as your reason, so it reaches the right place.
What we collect, why, and on what basis
We only collect what a given activity actually needs:
| When | What we collect | Why | Lawful basis |
|---|---|---|---|
| Contact form | Name, email, company (optional), your message | To respond to your enquiry | Legitimate interest (running the business) |
| Free website scans | Domain entered, your IP address (hashed, for fair-use rate limiting), scan results | To run the scan and stop abuse of the free tool | Legitimate interest |
| Buying a report or care plan | Name, email, billing details (card details go straight to Stripe — we never see or store them) | To take payment and deliver what you bought | Contract (fulfilling your purchase) |
| Client portal account | Email, login records, support tickets, invoices, findings history | To run your account and deliver the service you’re paying for | Contract |
| Hosted platforms | Whatever your own site/system stores or processes | To host, back up, and keep it running | Contract (you’re our client) — you remain the controller of your own site’s data (see our Data Processing Agreement) |
| Analytics (Google Analytics) | Aggregated usage statistics (GA4 does not record full IP addresses) | To understand how the site is used, so we can improve it | Consent — only loads if you accept the cookie banner |
We never use any of this for advertising, and we don’t sell personal data. See our Cookie Policy for the detail on cookies specifically.
How long we keep it
- Contact form enquiries: up to 24 months, so we can follow up on things that take a while to come back around.
- Free scan results: up to 12 months, then deleted — long enough for you to compare a re-scan.
- Client portal & billing records: for as long as your account is active, plus whatever period UK tax and accounting law requires afterwards (typically 6 years).
- Analytics data: retained by Google under our GA4 data-retention setting; GA4 does not store full IP addresses.
Who we share it with
We don’t sell your data. We share it only with the specific processors that make the service work, each under their own confidentiality and security terms:
- Microsoft Azure — cloud infrastructure and secrets storage (Key Vault)
- Microsoft Graph — sending email on our behalf (reports, notifications)
- Stripe — payment processing (we never see full card details)
- Cloudflare — content delivery, DDoS protection, and bot filtering (Turnstile)
- Fasthosts — UK-based hosting infrastructure for client platforms
- Google Analytics — only after you accept the cookie banner
Some of these providers may process data outside the UK. Where that happens, it’s covered by a UK-recognised safeguard — the UK International Data Transfer Agreement (IDTA) or Addendum, or the UK Extension to the EU-US Data Privacy Framework.
For platforms we host on your behalf, the full register of sub-processors that touch your platform’s data — and the terms that govern them — is maintained in Annex A of our Data Processing Agreement.
Your rights
Under UK GDPR, you can ask us to:
- Give you a copy of the personal data we hold about you
- Correct anything that’s inaccurate or incomplete
- Delete your data, where we’re not required to keep it for legal reasons
- Restrict or object to certain processing
- Give you your data in a portable format
- Withdraw consent at any time, where consent is the basis (e.g. analytics)
Contact us to exercise any of these. If you’re not satisfied with how we’ve handled your data, you can complain to the Information Commissioner’s Office (ICO).
Our security measures
We implement appropriate technical and organisational controls to protect your data.
These include encryption in transit and at rest, role-based access control, and continuous security monitoring.
Changes to this policy
We may update this policy from time to time, for example as our services or processors change. Significant changes will be reflected here with an updated date. This policy was last reviewed in July 2026.