Last updated: 22 October 2025
This privacy policy explains how Glitch Marketing Essex Ltd (“we”, “us”, “our”) collects and uses personal information when you use https://glitchmarketing.co.uk (and any page that links to this policy) or when you interact with us (enquiries, proposals, projects, events, or marketing).
1) Who we are (data controller)
Controller: Glitch Marketing Essex Ltd, company number 14810881.
Registered office: 8 Poultry Close, Fordham Heath, Colchester, CO3 9FZ, United Kingdom.
Privacy contact: hello@glitchmarketing.co.uk (preferred) or by post to the address above.
2) What information we collect
Information you provide to us
- Identification and contact details (name, role, company, email, phone).
- Project and billing details (project scope, service history, addresses, VAT details).
- Content you send us (messages, briefs, attachments, testimonials).
Information collected automatically
- Technical and usage data: IP address, device and browser details, operating system, pages viewed, time stamps, referring URLs, error logs, and approximate location inferred from IP.
- Cookies and similar technologies (see our Cookie Policy for details and choices).
Information from third parties
- Business contact data from public sources (e.g., company websites, LinkedIn) and partners.
- Analytics/advertising partners (aggregated audience insights).
- Payment processors/accounting tools (transaction references; we do not store full card numbers).
We do not intentionally collect special category data (e.g., health or biometric data) via our website.
3) How we use your information (purposes)
- Respond to enquiries and provide proposals.
- Deliver and administer services, projects, and contracts, including working with trusted partner companies and suppliers where needed.
- Operate, secure, and improve our website (diagnostics, analytics, performance).
- Provide customer support and manage our CRM.
- Send service communications and (where permitted) marketing.
- Keep business, tax, and compliance records.
- Defend or exercise legal claims and prevent fraud.
- Produce anonymised/aggregated insights (not identifying you).
We do not make automated decisions that have legal or similarly significant effects. We may use limited profiling (e.g., advertising audience segmentation) without such effects.
4) Our legal bases (UK GDPR)
Depending on context, we rely on:
- Contract – to take steps at your request before a contract and to perform a contract (quotes, project delivery, support).
- Legitimate interests – to run and protect our business and website; B2B marketing to relevant roles; prevent fraud; improve services (balanced against your rights).
- Consent – for non-essential cookies/analytics and some direct marketing. You can withdraw consent at any time.
- Legal obligation – to meet tax, accounting, and compliance duties.
5) Marketing & PECR
- We send marketing to business contacts where permitted by legitimate interests, and to anyone who has consented.
- For existing customers, we may use the soft opt-in for similar services (where allowed).
- You can opt out at any time via the unsubscribe link in our emails or by emailing hello@glitchmarketing.co.uk.
- We never sell your personal data.
6) Who we share information with (categories of recipients)
We use trusted processors acting on our instructions with appropriate security measures, including:
- Hosting, infrastructure, content delivery, and security/performance tools.
- Email and productivity services (e.g., business email and document tools).
- Customer relationship management (CRM) and support/ticketing systems.
- Analytics, tag management, search and measurement tools.
- Advertising platforms for campaign delivery, audience management, and reporting.
- Social media management/scheduling platforms.
- Payment processing and accountancy providers (if applicable).
- Professional advisers (legal, financial) and insurers.
- Specialist partner companies and contractors we engage to help deliver our services.
Where we engage partner companies or contractors, they may act as our processors (working under our instructions and covered by appropriate contracts) or as independent controllers for their own legal obligations. We only share the minimum information necessary, require confidentiality, and expect them to protect personal data in line with applicable law.
We may also disclose information if required by law, to protect rights and safety, to prevent fraud, or in connection with a merger, acquisition, or reorganisation.
7) International transfers
Some providers (for example, our hosting/infrastructure, email and productivity services, analytics and tag management tools, advertising platforms, social media scheduling tools, and specialist partner companies) may process data outside the UK/EEA. Where this occurs, we rely on:
- UK adequacy regulations, or
- Approved safeguards such as the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, plus additional measures where appropriate.
8) Cookies and similar technologies
We use cookies and similar technologies for functionality, analytics, and (where consented) advertising. Our cookie banner enables you to manage preferences and prevents non-essential cookies until you consent. You can also adjust your browser settings; blocking some cookies may affect site features.
See our Cookie Policy for the cookie list (types, purposes, durations, vendors) and to update your choices.
9) Retention (how long we keep data)
We keep data only as long as necessary for the purposes above, then delete or anonymise it, except where noted below.
- Enquiries (email/forms): retained indefinitely as part of our business records unless you exercise your rights to deletion (subject to legal obligations and our need to keep records of communications).
- Photo and video content we create: retained indefinitely in our project archives and creative portfolio libraries (for project history, client support, and—where permitted—promotion of our services). You may object to our continued use for marketing; we will honour valid objections subject to contractual, copyright, or licensing obligations.
- Client/project records (non-media): 6 years after project end.
- Financial records: 7 years (statutory).
- Marketing contacts: until you opt out or after 24 months of inactivity.
- Web analytics: typically 26 months (see Cookie Policy).
10) Security
We use appropriate technical and organisational measures (e.g., encryption in transit, access controls, least-privilege, monitoring, staff awareness). No method is 100% secure. If a personal-data incident affects you, we will act promptly in line with legal duties.
11) Children
Our services are aimed at adults. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact hello@glitchmarketing.co.uk so we can delete it.
12) Your rights
Subject to conditions and legal exceptions, you may have the right to: access, rectify, erase, restrict, object (including to direct marketing at any time), and withdraw consent where that is our legal basis.
To exercise your rights, contact hello@glitchmarketing.co.uk. We may need to verify your identity. We aim to respond within one month.
13) Third-party links
Our site may link to third-party websites/services with their own privacy policies. We are not responsible for their practices.
14) Do Not Track
There is no agreed industry standard for responding to DNT signals. We do not currently respond to DNT.
15) Changes to this policy
We may update this policy. We will change the “Last updated” date above and, where appropriate, provide a more prominent notice.