Privacy Policy
Last updated: 14 January 2026
1. Introduction
This privacy policy explains how Sam Kendall ("I", "me", "my") collects, uses, and protects your personal information when you visit this website (the "Site"). I am committed to protecting your privacy and ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
The data controller for this website is:
Sam Kendall
You can contact me via the contact form on this website.
3. Information I Collect
3.1 Information You Provide
When you use the contact form on this website, I collect:
- Your name
- Your email address
- Subject of your message
- The content of your message
Contact Form Processing: Contact form submissions are processed through Web3Forms, a third-party email service provider. When you submit the contact form, your information is transmitted securely to Web3Forms, which forwards it to my email address. Web3Forms does not store your data beyond the delivery process. For more information about how Web3Forms handles data, please see their Privacy Policy.
3.2 Automatically Collected Information
When you visit this website, certain information is automatically collected:
- Your IP address
- Browser type and version
- Device information
- Pages you visit and time spent on pages
- Referring website addresses
This information is collected through server logs and is necessary for the website to function properly and to ensure security.
4. How I Use Your Information
I use the information I collect for the following purposes:
- To respond to enquiries: If you contact me through the contact form, I use your information to respond to your message.
- To improve the website: I analyse how visitors use the website to improve its functionality and user experience.
- To ensure security: I use technical information to protect the website from security threats and to prevent fraud.
- To comply with legal obligations: I may process your data to comply with applicable laws and regulations.
5. Legal Basis for Processing
Under UK GDPR, I process your personal data on the following legal bases:
- Consent: When you voluntarily provide information through the contact form, you consent to me processing that information to respond to your enquiry.
- Legitimate interests: I process technical information (such as IP addresses) for legitimate interests including website security, preventing fraud, and improving the website's functionality.
- Legal obligation: I may process data to comply with legal obligations.
6. Data Sharing and Disclosure
I do not sell, trade, or rent your personal information to third parties. I may share your information only in the following circumstances:
- Service providers: I may share information with third-party service providers who assist in operating the website (such as hosting providers), but only to the extent necessary for them to perform their services.
- Web3Forms: Contact form submissions are processed through Web3Forms, a third-party email service provider. When you submit the contact form, your information (name, email address, subject, and message) is transmitted securely to Web3Forms via HTTPS encryption. Web3Forms forwards this information to my email address and does not store your data beyond the delivery process. Web3Forms is compliant with GDPR and other data protection regulations. For more information, see the Web3Forms Privacy Policy.
- Legal requirements: I may disclose information if required by law or in response to valid legal requests.
- Protection of rights: I may disclose information to protect my rights, property, or safety, or that of others.
7. Data Retention
I retain your personal information only for as long as necessary to fulfil the purposes outlined in this privacy policy:
- Contact form submissions: I retain messages sent through the contact form for up to 2 years, unless you request earlier deletion.
- Server logs: Technical information in server logs is typically retained for up to 90 days.
After the retention period, I will securely delete or anonymise your personal information.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: You have the right to request copies of your personal data.
- Right to rectification: You have the right to request that I correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to erasure: You have the right to request that I erase your personal data, under certain conditions.
- Right to restrict processing: You have the right to request that I restrict the processing of your personal data, under certain conditions.
- Right to object to processing: You have the right to object to my processing of your personal data, under certain conditions.
- Right to data portability: You have the right to request that I transfer the data that I have collected to another organisation, or directly to you, under certain conditions.
- Right to withdraw consent: Where processing is based on consent, you have the right to withdraw your consent at any time.
To exercise any of these rights, please contact me using the contact form. I will respond to your request within one month.
9. Data Security
I implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. This includes:
- Encrypted transmission: All contact form submissions are transmitted over HTTPS encryption to ensure data protection during transit.
- Secure processing: Contact form submissions are processed through Web3Forms, which uses secure, encrypted connections and does not store data beyond delivery.
- Access controls: I limit access to your personal information to those who have a legitimate need to know.
However, no method of transmission over the internet or electronic storage is 100% secure, and I cannot guarantee absolute security.
10. International Data Transfers
This website is hosted on servers that may be located outside the UK. Contact form submissions are processed through Web3Forms, which may process data on servers located outside the UK. If your data is transferred outside the UK, I ensure that appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements. Web3Forms is compliant with GDPR and implements appropriate data protection measures for international transfers.
11. Children's Privacy
This website is not intended for children under the age of 13. I do not knowingly collect personal information from children under 13. If you believe I have collected information from a child under 13, please contact me immediately.
12. Changes to This Privacy Policy
I may update this privacy policy from time to time. I will notify you of any changes by posting the new privacy policy on this page and updating the "Last updated" date. You are advised to review this privacy policy periodically for any changes.
13. Complaints
If you have concerns about how I handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Phone: 0303 123 1113
14. Contact Me
If you have any questions about this privacy policy or wish to exercise your rights, please contact me using the contact form on this website.