WebSharpPrivacy Policy
Privacy Policy

Privacy Policy.

Last updated: 7 May 2026 · Effective from this date

WebSharp (“WebSharp”, “we”, “us”) is the data controller for personal data processed in connection with our website and services. This policy explains what we collect, why, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Plain summary. We collect only the personal data we genuinely need to deliver our services (your name, email, account credentials, and project information). We don't sell your data. We don't use third-party advertising trackers. You can ask for a copy of your data, ask us to correct it, or ask us to delete it at any time.

01Who we are

WebSharp is an independent web design studio based in London, United Kingdom. You can reach us at hello@websharp.co.uk for any privacy-related question.

02What we collect

We collect personal data in the following categories:

Account data

  • Your name
  • Your email address
  • A salted, hashed password (we never store your plain-text password)
  • Your role (admin or client)

Project data

  • Project names, status, progress notes, and timeline updates we post
  • Plan, monthly amount, and subscription status (where applicable)
  • Any messages, briefs, or files you submit to us

Inquiry data

  • Requests submitted from your client dashboard, including the message you wrote

Technical data

  • Authentication session cookies (strictly necessary; see section 7)
  • Standard server logs (IP address, request path, timestamp, user-agent)

03How we use it

We use your personal data to:

  • Provide and operate the Services, including authentication and your project workspace
  • Communicate with you about your project, billing, and the Services
  • Respond to inquiries and support requests
  • Maintain security, prevent abuse, and diagnose problems
  • Comply with legal and regulatory obligations

04Lawful basis for processing

We process your personal data on the following lawful bases under UK GDPR Article 6:

  • Contract — processing is necessary to deliver the Services you have signed up for or commissioned;
  • Legitimate interests — to operate, secure, and improve our Services, where these interests are not overridden by your rights;
  • Legal obligation — to comply with tax, accounting, and regulatory requirements;
  • Consent — where we ask for it explicitly (you may withdraw at any time without affecting prior processing).

05Sharing with third parties

We do not sell your personal data. We share data only with third-party service providers strictly as needed to operate the Services, under appropriate contractual data-protection terms. These may include:

  • Hosting and infrastructure providers
  • Email and communications providers, where used to contact you
  • Payment processors, where used to take subscription payments
  • Analytics, where used and limited to first-party, privacy-respecting tooling
  • Professional advisors (accountants, legal advisors), where strictly necessary

We may also disclose personal data where required by law, court order, or to protect our rights or the safety of others.

06How long we keep it

We keep personal data only as long as we need it for the purposes set out in this policy. Typical retention periods:

  • Account & project data — for the duration of your engagement, plus six (6) years after termination, in line with statutory limitation periods;
  • Billing records — six (6) years to meet UK accounting and tax requirements;
  • Server logs — up to ninety (90) days;
  • Inquiry messages — up to two (2) years from creation, unless converted into a project engagement.

On request, we will delete or anonymise personal data sooner where we have no overriding legal obligation to retain it.

07Cookies

We use only strictly necessary cookies — primarily an authentication session cookie that keeps you signed in to your account. We do not use advertising cookies, cross-site tracking, or social-media pixels. If we add any non-essential cookies in future we will ask for your consent first.

08Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you;
  • Have inaccurate or incomplete data corrected;
  • Have your data deleted, where there's no overriding legal reason to keep it;
  • Restrict or object to certain processing;
  • Receive your data in a portable format;
  • Withdraw consent, where consent is the basis for processing;
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.

To exercise any of these rights, email us at hello@websharp.co.uk. We'll respond within thirty (30) days.

09Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure — including encryption in transit (TLS), salted password hashing, restricted access, and regular review of our infrastructure. No system is perfectly secure; if we ever experience a personal-data breach that is likely to result in risk to your rights, we will notify the ICO and, where required, you, in line with our legal obligations.

10International transfers

Some of our service providers may be located outside the UK or the EEA. Where personal data is transferred internationally, we rely on UK-approved transfer mechanisms — such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or transfers to jurisdictions that have UK adequacy regulations.

11Children

The Services are not directed at, and we do not knowingly collect personal data from, anyone under the age of sixteen (16). If we learn we have collected such data, we will delete it.

12Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new “last updated” date. For material changes we will, where practicable, also notify you by email.

13Contact

Questions about this policy or how we handle your personal data? Email hello@websharp.co.uk.

© 2026 WebSharp · LondonTerms · Home