ZSM Digital
  • Home
  • About
  • Our Values
  • Portfolio
  • Services
  • Pricing
Contact Project Portal Get a Quote
  • Home
  • About
  • Our Values
  • Portfolio
  • Services
  • Pricing
Contact Project Portal Get a Quote
Home / GDPR & Data Protection

GDPR & Data Protection

How we handle personal data, your rights under data protection law, and how to contact us about privacy.

  • We only use personal data when we have a clear reason and a lawful basis.
  • We do not sell personal data.
  • You can ask us what we hold about you, request changes, or request deletion where the law allows.
01 Who We Are (Data Controller)
  • Data Controller: ZSM Digital
  • Business address: 25 Enterprise Dr, Lye, Stourbridge DY9 8QH, United Kingdom
  • General contact: [email protected]
  • Data protection enquiries: [email protected]

If we act as a data processor for a client project (for example hosting or maintaining a client's website), the client is the data controller for their website visitors' data. In those cases we process personal data only under our client's instructions and the relevant contract.

02 What Personal Data We Collect

When you contact us or request a quote

  • Identity & contact data: name, email address, phone number (if provided)
  • Enquiry content: message text, project description, and any information you choose to include

When you use our client portal

  • Account data: email address and login/access code
  • Portal usage data: timestamps and actions in the portal
  • Project data: files, comments, and deliverables you upload or enter

When you browse our website

  • Technical data: IP address, device and browser information, pages visited, approximate location (country/city level), and security/performance logs
  • Cookie & consent preferences: your choices in our cookie consent banner
03 Why We Use Your Data & Lawful Bases
Purpose Lawful Basis
Respond to enquiries & provide quotes Contract (pre-contract steps) / Legitimate Interests
Deliver services to clients Contract
Client portal administration Contract / Legitimate Interests
Security & fraud prevention Legitimate Interests
Accounting, tax, and legal compliance Legal Obligation
Marketing emails to prospects Consent (opt-in required)
Marketing emails to existing customers Legitimate Interests (soft opt-in where applicable)

You will always have a clear opt-out in every marketing message we send.

04 Cookies & Similar Technologies

We use cookies in the following categories, depending on your settings:

  • Strictly necessary: required for core website functions and security. These cannot be disabled.
  • Preferences: remember settings you choose (where used).
  • Analytics: help us understand website usage and improve pages (only with your consent).
  • Marketing: used to measure and improve advertising (only with your consent).

You can change your cookie preferences at any time using the Cookie Settings link or by visiting our Cookie Policy page.

If you reject non-essential cookies, the website will still work normally.

05 Who We Share Data With

We share personal data only when necessary to operate our business and deliver services. This usually means our service providers ("processors").

Category Purpose Location
Website hosting Hosting, logs, uptime UK
Email provider Receiving and sending emails UK/EEA
Backups & storage Disaster recovery UK
Payments & invoicing Billing UK/EEA
06 International Transfers
If any of our suppliers process personal data outside the UK or outside the European Economic Area, we will only transfer personal data where the law permits and where appropriate safeguards are in place (for example the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus any required transfer risk assessment).
07 How Long We Keep Data

We keep personal data only as long as needed for the purpose it was collected for, then we delete, anonymise, or securely archive it.

Data Type Period Reason
Enquiry & quote emails 12–24 months Follow-ups and audit trail
Client project records 6 years after project end Legal claims and business records
Invoices & tax records 6 years (or as required) Legal and tax obligations
Security logs 30–180 days Security and troubleshooting
Cookie consent logs 12–24 months Demonstrate consent

We may keep some information longer if needed for legal claims, disputes, or to comply with the law.

08 Your Rights

Under data protection law, you have the following rights:

  • Access: ask for a copy of your personal data.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data where we do not have a lawful reason to keep it.
  • Restriction: ask us to limit how we use your data in certain cases.
  • Portability: ask for data you provided to us in a portable format (where applicable).
  • Objection: object to processing based on legitimate interests. You can always object to direct marketing, and we will stop.
  • Withdraw consent: where we rely on consent, you can withdraw it at any time.
09 How to Exercise Your Rights

Email: [email protected]
Subject line: "Data protection request"

To protect your data, we may ask for reasonable identity verification before we act on a request.

We aim to respond within one month. If a request is complex, we may extend this by up to two additional months, but we will tell you within the first month if that happens.

10 Automated Decision-Making
We do not make decisions about you that are based solely on automated processing that produces legal effects or similarly significant effects. If this changes, we will update this page and explain what we do and why.
11 Security Measures

We use appropriate technical and organisational measures to protect personal data, including:

  • TLS/HTTPS encryption in transit
  • Access controls and least-privilege permissions
  • Multi-factor authentication where available
  • Backups and restore testing
  • Logging and monitoring for security events
  • Secure development and patching processes

No system is 100% secure, but we work to reduce risk and respond quickly if issues arise.

12 Complaints

If you have concerns, please contact us first so we can try to resolve it:

  • Email: [email protected]

UK Supervisory Authority

If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO).

  • Website: ico.org.uk
  • Helpline: 0303 123 1113

EEA Supervisory Authority

If EU GDPR applies to your situation, you can also complain to your local EEA supervisory authority.

13 Changes to This Policy
We may update this page from time to time. Changes will be posted here with an updated effective date. We encourage you to review this page periodically.

Last updated — 25 February 2026

Services

Web Design E-commerce SEO & Analytics Maintenance

Company

About Us Portfolio

Support

Contact Us Project Portal

Legal

Terms of Service Privacy Policy GDPR & Data Protection Cookie Policy Modern Slavery
Site Directory

© 2026 ZSM Digital. All Rights Reserved.

🍪

Cookie Preferences

We use cookies to make this site work. With your permission, we also use analytics cookies to understand how the site is used and improve it. Learn more

Cookie Settings

Control which cookies you allow. Strictly necessary cookies cannot be disabled as they are essential for the website to function.

Strictly Necessary

Essential for the website to function. Cannot be disabled.

Always on

Preferences

Remember your settings and choices for a better experience.

Analytics

Help us understand how visitors use the site so we can improve it.

Marketing

Used to deliver relevant advertisements and track campaign performance.