SEOwebs
  • Services
  • Projects
  • Why Us
  • Process
  • Contact
  • Services
  • Projects
  • Why Us
  • Process
  • Contact

Information and transparency

Privacy policy

How we use enquiry and payment information, our lawful bases, retention, providers and your rights.

Last reviewed: 20 September 2026

On this page

  1. Controller and scope
  2. Information we use
  3. Purposes and lawful bases
  4. Payment information
  5. Marketing and automated decisions
  6. Retention
  7. Providers and disclosures
  8. International transfers
  9. Website resources and cookies
  10. Security and client information
  11. Your rights
  12. Data protection complaints
  13. Law and updates

1. Controller and scope

SEO WEBS AND MUCH MORE LTD is the controller for the personal information it uses to manage this corporate website, enquiries, customer administration and payments.

Company
SEO WEBS AND MUCH MORE LTD
Number
14411289 · Registered in England and Wales
Registered office
85 Great Portland Street, First Floor, London, W1W 7LT, United Kingdom
Contact address
63/66 Hatton Garden, Fifth Floor, Suite 23, London, EC1N 8LE, United Kingdom
Email
info@seowebs.co.uk
Telephone
+44 20 4577 1369

Other platforms or directories may involve different processing and require their own notices. This notice does not authorise publication of personal profiles or photographs on other sites. Where we process information solely on a client’s instructions, the client is the controller and a separate processor agreement applies.

2. Information we use

We receive information you provide by email or telephone, such as your name, contact details, business role and enquiry. For a contract we may also need billing details, correspondence, deliverables and payment references. A user code that can be linked to an individual is personal information even if it does not display their name.

Information normally comes from you or your authorised business contact. If received from another source, we will explain that source and provide the information required by law unless an applicable exception applies. Servers may record IP addresses, request times, resources and errors for operation and security.

Only provide information needed for the task. Do not put sensitive information, passwords or complete card details in a user-code field or email. If required contact or transaction information is missing, we may be unable to respond or fulfil the service.

3. Purposes and lawful bases

Enquiries and orders: steps you request before a contract and performance of a contract with you. For general enquiries and business representatives, we rely on legitimate interests in responding and administering the business relationship, subject to necessity and a balancing of rights.

Billing and records: performance of the contract and compliance with tax, accounting and other legal duties. Security: legitimate interests in protecting our systems and investigating incidents. Claims: legitimate interests in establishing, exercising or defending legal rights and relevant legal duties.

Where we rely on legitimate interests, you may ask about the assessment and object on grounds relating to your situation. Where consent is required for a separate purpose, it will be requested specifically and may be withdrawn without affecting previous lawful use. Merely browsing or paying does not consent to additional purposes.

4. Payment information

A payment procedure provided to registered users may collect a user reference and service details to prepare an operation and redirect to an external payment provider. We use necessary transaction references and status information to reconcile payments, provide the service and handle refunds. The lawful bases are contract performance and relevant legal obligations.

Card and authentication information is entered in the external provider’s environment. Payment providers and banks supply their own privacy information for the processing they undertake, including authentication and fraud checks. Outsourcing payment processing does not remove our responsibility for information we control.

5. Marketing and automated decisions

Enquiry and service communications are not subscriptions to marketing. This notice does not authorise newsletters or promotional campaigns. Any new marketing activity must have an appropriate lawful basis and comply with the Privacy and Electronic Communications Regulations (PECR), including consent where required and an accessible opt-out.

The corporate enquiry processing described here does not involve solely automated decisions with legal or similarly significant effects. Payment-provider decisions are subject to that provider’s information. We will explain any new significant automated decision-making we introduce and the applicable safeguards.

6. Retention

We retain enquiries for as long as needed to deal with them and any necessary follow-up, then delete or appropriately restrict information no longer needed. Contracts, invoices and transaction records may need longer retention to meet legal duties and address claims; applicable periods depend on the document and circumstances.

UK company accounting records normally need to be kept for six years from the end of the last company financial year they relate to, with longer periods in some cases. This is not a blanket six-year rule for all messages or technical logs. Technical logs and backups should be retained only as necessary for their purpose, with specific incident records preserved where justified.

Information required for a legal hold or claim is restricted to that purpose and deleted when no longer needed. A minimal suppression record may be kept to respect an objection to marketing.

7. Providers and disclosures

Hosting, email, IT support and administrative providers may access information as needed for their contracted functions. Processors acting for us must be subject to appropriate written terms, confidentiality and security obligations. Banks and payment providers process payment information according to their role.

Information may be disclosed to professional advisers to handle duties or legal claims, and to authorities or courts where lawfully required. We do not treat engagement of a provider as permission for unrestricted disclosure. You can request details of providers relevant to your information at info@seowebs.co.uk.

8. International transfers

Provider locations and remote access arrangements determine whether information is transferred outside the UK. Where a restricted transfer occurs, it must be covered by UK adequacy regulations or another lawful mechanism, such as the UK International Data Transfer Agreement or UK Addendum to the EU standard contractual clauses, together with the required assessment and additional measures where necessary.

The external Google Fonts resources described below involve Google’s international operations. Google publishes its transfer frameworks. The mechanism must apply to the specific recipient and transfer; a provider’s brand or an EU contract alone does not prove compliance with UK transfer rules. Contact info@seowebs.co.uk for information about applicable recipients, destinations and a copy of relevant safeguards.

9. Website resources and cookies

The supplied corporate page provides information and email and telephone contact links. Its code does not include analytics, advertising pixels or tracking storage. This describes the supplied page, not a technical audit of every server component or an external payment provider.

The design requests Fraunces and DM Sans fonts from Google Fonts. Loading them sends Google an IP address and technical request data even if no cookie is set. See Google’s privacy policy. Payment providers may use their own technologies under their notices.

If we add technology that requires consent under PECR, it must not operate before valid consent is obtained. Continuing to browse or accepting a service contract does not constitute that consent. We will update this information when the technology changes.

10. Security and client information

We must apply technical and organisational measures proportionate to the risks, limit access and review safeguards. Absolute security cannot be promised. Incidents will be assessed and reported to the ICO and affected people where required by law.

Where we process information on a client’s behalf, the processor agreement must cover instructions, confidentiality, security, subprocessors, assistance, and return or deletion at the end. We must not reuse that information for unrelated purposes merely because we have access to it.

11. Your rights

Subject to the applicable legal conditions, you can request access, rectification, erasure, restriction, portability and object to processing. You may withdraw consent and exercise rights relating to significant automated decisions where relevant. Direct marketing objections can be made at any time.

Contact info@seowebs.co.uk or our contact address. Explain your request and provide enough information to locate your records. We will not routinely require a passport or identity document; proportionate additional evidence may be requested where identity is reasonably in doubt. You may use an authorised representative.

Rights requests are generally free and are normally answered within one month. An extension of up to two further months may apply for complex or numerous requests, with an explanation within the initial period. Any permitted clarification or identity-check pause, refusal or charge must meet the applicable legal conditions and be explained. A complaint acknowledgement deadline does not replace the deadline for a rights request.

12. Data protection complaints

To complain about our use of personal information, email info@seowebs.co.uk or write to our contact address. You can use the optional complaint template below electronically or on paper. Identify the issue, relevant dates, the information involved and the outcome you seek. Do not send unnecessary sensitive documents.

We will acknowledge a data protection complaint within 30 days, investigate appropriately without undue delay, keep you informed as appropriate and communicate the outcome. If you remain dissatisfied, you can complain to the Information Commissioner’s Office (ICO). The ICO normally expects you to give the organisation an opportunity to address the complaint first.

Optional data protection complaint template
Name and reply contact: ____________________.
What happened and when: ____________________.
Relevant service or reference: ____________________.
Outcome requested: ____________________.

Send to info@seowebs.co.uk or our contact address. No particular form is compulsory.

13. Law and updates

This notice is based on the UK GDPR, the Data Protection Act 2018 and PECR, as amended, including relevant changes under the Data (Use and Access) Act 2025. The review date identifies this version. Material changes will be explained appropriately, and new purposes require a valid legal basis; publication of an amended notice does not itself supply consent.

SEOwebs
Legal noticePrivacy policyTerms & conditionsCancellation & refunds
Registered in England and Wales · Company no. 14411289
Registered office: 85 Great Portland Street, First Floor, London, W1W 7LT
© 2026 SEO WEBS AND MUCH MORE LTD