Who we are
Firelake Ltd is the data controller for the personal data described in this policy. That means we decide why and how it is processed, and we are responsible to you for it.
We are not required to appoint a Data Protection Officer, and we have not appointed one. Data protection questions are handled directly by the company at the address above.
What this policy covers
This policy covers personal data we collect through the website at firelake-dev.com and through correspondence that begins there.
Where we go on to provide services to a client, the handling of personal data within that engagement is governed by the data protection terms of the relevant written agreement — which will usually appoint us as a processor acting on the client's instructions, rather than as a controller. This policy does not describe that processing.
This policy should be read alongside our Cookie Policy and our Terms and Conditions.
The short version
If you send us an enquiry, we keep your name, email address and message so that we can reply and remember the conversation. Our hosting provider keeps ordinary server logs. That is all. We set no cookies, we run no analytics, we do not track you, we do not profile you, we do not send marketing, and we never sell or rent personal data to anyone.
The rest of this policy sets out the same thing in the detail the UK GDPR requires.
Personal data we collect
We collect the following categories of personal data:
| Category | What it includes | Source |
|---|---|---|
| Enquiry data | Your name, email address and the content of the message you send us | You, via the contact form or by email |
| Correspondence | Emails exchanged with you, and any attachments or notes arising from them | You and us |
| Technical data | IP address, browser type and version, operating system, date and time of request, pages requested, and referring address | Automatically, in server logs kept by our hosting provider |
We do not ask for and do not want special category data — information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation — nor data about criminal convictions or offences. Please do not send any of it to us. If you do, we will delete it unless we are required to keep it.
Providing your details is entirely voluntary. There is no statutory or contractual obligation to give them to us. If you choose not to, we simply will not be able to reply to you.
Why we use it, and our lawful basis
Under the UK GDPR we must have a lawful basis for every use of personal data. Ours are set out below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Replying to your enquiry and discussing possible work | Enquiry data, correspondence | Legitimate interests, Article 6(1)(f) — responding to a business enquiry that you initiated. Where the discussion moves towards an engagement, also Article 6(1)(b), steps taken at your request before entering a contract. |
| Keeping a record of who contacted us and what was discussed | Enquiry data, correspondence | Legitimate interests, Article 6(1)(f) — maintaining an accurate record of our business dealings and being able to answer questions about them later. |
| Keeping the website available, secure and free from abuse | Technical data | Legitimate interests, Article 6(1)(f) — operating and defending our own infrastructure. |
| Complying with legal and regulatory obligations | Any of the above, as applicable | Legal obligation, Article 6(1)(c). |
| Establishing, exercising or defending legal claims | Any of the above, as applicable | Legitimate interests, Article 6(1)(f). |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and we consider that it is not: you contacted us, the data is limited to what you chose to send, it is used only for the purpose you sent it for, and you can object at any time. You can ask us for our assessment.
What we do not do
So that there is no doubt, we confirm that we do not:
- sell, rent or trade personal data to anyone, in any circumstances;
- use analytics, advertising pixels, tracking scripts or fingerprinting on this website;
- build profiles of visitors, or track visitors across other websites;
- carry out automated decision-making that produces legal or similarly significant effects, within the meaning of Article 22 of the UK GDPR;
- send marketing emails or newsletters, or add enquirers to any mailing list; or
- use enquiry data for any purpose other than replying to and recording the enquiry.
Who we share data with
We share personal data only with the following recipients, and only so far as is necessary:
- Our hosting provider, which operates the servers this website runs on and keeps the server logs described in section 4.
- Our email provider, which transmits and stores the correspondence between us.
- Professional advisers — such as our accountants, auditors, insurers or lawyers — where they need the data to advise us, and subject to their own duties of confidentiality.
- Law enforcement, regulators or courts, where we are required by law to disclose data, or where disclosure is necessary to establish, exercise or defend legal claims.
Each of our suppliers acts as a processor on our instructions under a written contract that meets the requirements of Article 28 of the UK GDPR. None of them is permitted to use your data for their own purposes.
If our business is sold or reorganised, personal data may be transferred to the acquiring entity. We would tell you before that happened and the acquirer would be bound by this policy.
Transfers outside the UK
Some of our suppliers are established outside the United Kingdom, or store data outside it. Where personal data is transferred outside the UK, we ensure a similar degree of protection is afforded to it by relying on one of the following safeguards:
- transfer to a country the UK government has decided provides an adequate level of protection (a UK adequacy decision); or
- a contract incorporating the UK International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment.
This website itself makes no third-party requests. Every asset it needs — its stylesheet, its typefaces and its images — is served from our own domain. Loading a page of this site therefore discloses your IP address to our hosting provider and to nobody else.
You may ask us for a copy of the safeguards in place for any specific transfer.
How long we keep data
We keep personal data only for as long as we actually need it.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to an engagement | 24 months from the last contact, then deleted |
| Correspondence relating to an engagement | 6 years from the end of the engagement, reflecting the limitation period for contractual claims in England and Wales |
| Records we must keep by law, such as accounting records | As required by the relevant legislation, currently 6 years |
| Server logs | As retained by our hosting provider in the ordinary course, typically no more than 12 months |
You can ask us to delete your data sooner, and we will unless we are required to keep it. See section 11.
How we protect data
This website is served over HTTPS, so traffic between your browser and the site is encrypted in transit. Access to correspondence is limited to those members of our team who need it, and is protected by multi-factor authentication.
Email is not a secure channel end to end. As we say in our Terms and Conditions, please do not send confidential or sensitive material through the website or by unencrypted email. If you need to share confidential material, ask us for a non-disclosure agreement and we will agree a secure channel with you.
We have procedures to deal with any suspected personal data breach. Where we are required to, we will notify the Information Commissioner's Office within 72 hours, and we will tell you if the breach is likely to result in a high risk to your rights and freedoms.
Your rights
Under the UK GDPR you have the following rights. They are free to exercise.
- Access — to be told whether we hold personal data about you and to receive a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where there is no good reason for us to keep it.
- Restriction — to have our use of your data paused, for example while its accuracy is being checked.
- Objection — to object to processing carried out on the basis of legitimate interests. If you object, we will stop unless we can show compelling legitimate grounds that override your interests.
- Portability — to receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or on a contract and is carried out by automated means.
- Withdrawal of consent — where we rely on consent, to withdraw it at any time. This does not affect the lawfulness of anything done before you withdrew it.
Because we do not carry out automated decision-making within the meaning of Article 22, the associated right to object to it does not arise in practice.
How to exercise your rights
Write to business@firelake-dev.com and tell us what you want. You do not need to use any particular form of words.
We will respond within one month. If your request is complex, or if you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do.
We may ask you for information to confirm your identity before we act. This is to make sure we do not disclose your data to someone else.
Cookies
This website sets no cookies. It stores nothing on your device, uses no local storage or session storage for tracking, and contains no analytics or advertising technology. That is why you were not asked to accept anything when you arrived.
Our Cookie Policy explains this in full, including the one third-party request the site does make and how to block it.
Third-party links
This website may link to third-party sites. We are not responsible for their privacy practices, and this policy does not apply to them. We encourage you to read the privacy policy of every site you visit.
Children
This website is directed at businesses. It is not intended for children, and we do not knowingly collect personal data relating to children. If you believe we hold data about a child, please tell us and we will delete it.
Changes to this policy
We may update this policy from time to time. The version number and date at the foot of this page show when it was last revised. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to your attention.
It is important that the personal data we hold about you is accurate and current. Please tell us if it changes.
How to complain
If you are unhappy with how we have handled your personal data, please tell us first at business@firelake-dev.com. We would rather put it right ourselves.
You also have the right to complain at any time to the Information Commissioner's Office at ico.org.uk, the UK supervisory authority for data protection. Complaining to us first does not affect that right.