1. Who we are
Hookline LTD ("Hookline", "we", "us", "our") is the data controller for the personal data described in this policy.
- Company name
- Hookline LTD
- Registered in
- England and Wales
- Company number
- [COMPANY NUMBER]
- Registered office
- Office 10367, 321-323 High Road, Chadwell Heath, Essex, RM6 6AX, United Kingdom
- Privacy contact
- hello@hookline.click
We are not currently required to appoint a Data Protection Officer, and our processing does not currently require registration beyond our entry in the Information Commissioner's register of fee payers where applicable. Privacy queries go to the address above and are handled directly.
2. What this policy covers
This policy explains how we handle personal data when you visit this website, contact us, enquire about our services, or work with us as a client or supplier.
It does not cover personal data we process on behalf of a client as part of delivering our services — see section 8 for how that works.
3. What we collect
Information you give us
- Contact form and email: your name, email address, company name, the budget range you select, and the content of your message.
- Client and supplier records: contact details, billing details, company and VAT information, correspondence, contracts and project documentation.
- Anything else you choose to send us in the course of a conversation or project.
Information collected automatically
Our hosting provider records standard server logs when a page is requested. These typically include the IP address, the time of the request, the page requested, the referring page and basic browser information. These logs are used for security, diagnostics and keeping the site running.
We do not create marketing profiles from this data, and we do not attempt to identify individual visitors from it.
4. Why we use it, and our legal basis
Under the UK GDPR and the Data Protection Act 2018 we must have a lawful basis for each use of personal data. Ours are:
- Replying to enquiries
- To respond to your message, prepare a proposal and discuss a possible engagement. Legal basis: our legitimate interests in responding to people who contact us, and taking steps at your request before entering a contract.
- Delivering our services
- To carry out the work, communicate about it, and manage the relationship. Legal basis: performance of a contract.
- Invoicing, accounting and tax
- To issue invoices, keep financial records and meet statutory obligations. Legal basis: legal obligation, and performance of a contract.
- Website security and reliability
- To protect the site from abuse, detect faults and investigate incidents. Legal basis: our legitimate interests in keeping our systems secure.
- Marketing emails, if you opt in
- To send occasional updates, if and only if you have asked for them. Legal basis: consent, which you can withdraw at any time.
- Legal claims
- To establish, exercise or defend legal claims. Legal basis: our legitimate interests, and legal obligation where applicable.
We do not use automated decision-making or profiling that produces legal or similarly significant effects for you.
5. Cookies and tracking
This website does not set analytics, advertising or profiling cookies. There is no tracking pixel, no advertising tag, and no cross-site tracking on this site, which is why you are not being asked to dismiss a consent banner.
Your browser may store standard local data needed to display the page, and our host may use strictly necessary cookies for security or load balancing. Strictly necessary cookies are exempt from the consent requirement under the Privacy and Electronic Communications Regulations 2003 (PECR).
6. Fonts and third-party resources
This site loads its typefaces from Google Fonts. When your browser requests those font files, your IP address and basic request information are sent to Google in order to serve them. Google states that it does not use Google Fonts requests to create advertising profiles. If you would prefer to avoid this entirely, a browser extension that blocks third-party requests will prevent it, and the site will fall back to system typefaces.
7. Who we share data with
We do not sell personal data, and we do not share it for anyone else's marketing. We do share it with service providers who help us operate, each acting under contract and only on our instructions:
- website hosting and domain providers;
- email and productivity providers;
- accounting, invoicing and payment providers;
- project management and file storage tools;
- professional advisers such as accountants and lawyers, where needed.
We may also disclose personal data where we are legally required to, or where it is necessary to protect our rights, property or safety — or those of others.
If our business is sold or reorganised, personal data may be transferred as part of that transaction. Any recipient would remain bound by this policy or an equivalent one.
8. Data we process for clients
When we deliver marketing services, we sometimes handle personal data belonging to a client — for example a mailing list, CRM records, or audience data in an advertising account.
In those situations the client is the data controller and Hookline acts as a data processor. We process that data only on the client's documented instructions, keep it confidential, apply appropriate security measures, use sub-processors only under equivalent obligations, assist with data subject requests, and delete or return the data at the end of the engagement.
Where this applies, we put a written data processing agreement in place that meets the requirements of Article 28 of the UK GDPR. If you believe your data was handled by us on behalf of one of our clients, contact that organisation in the first instance, or contact us and we will point you in the right direction.
9. International transfers
Some of our service providers operate outside the United Kingdom. Where personal data is transferred abroad, we rely on an appropriate safeguard under Chapter V of the UK GDPR — usually UK adequacy regulations covering the destination country, or the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and any additional measures required.
You can ask us for details of the safeguards applied to a specific transfer.
10. How long we keep data
- Enquiries that go nowhere
- Up to 24 months from the last contact, then deleted.
- Client project records
- For the duration of the engagement and up to six years afterwards, covering the limitation period under the Limitation Act 1980.
- Accounting and tax records
- Six years from the end of the accounting period, as required by the Companies Act 2006 and HMRC rules.
- Marketing list data
- Until you unsubscribe or ask us to remove you, plus a minimal suppression record so we don't contact you again by mistake.
- Server logs
- Short retention periods set by our hosting provider, generally measured in weeks.
When data is no longer needed we delete it or anonymise it so it can no longer be linked to you.
11. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), access controls, multi-factor authentication on key accounts, reputable providers, and limiting access to the people who need it.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where required, and notify you directly where the risk is high.
12. Your rights
Under the UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete data, where there is no overriding reason to keep it.
- Restriction — ask us to pause processing in certain circumstances.
- Portability — receive data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, and object to direct marketing at any time.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these, email hello@hookline.click. We will respond within one month. If a request is complex we may extend that by up to two further months and will tell you if so. We may ask you to verify your identity before acting. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
13. Marketing choices
We only send marketing email to people who asked for it or who are existing clients receiving information about closely related services. Every marketing email includes an unsubscribe link, and you can also just reply and ask us to stop. We will act on it promptly and won't ask you to explain yourself.
14. Children
Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Other websites
This site may link to third-party websites. We are not responsible for their privacy practices, and this policy does not apply to them. Read their policies before giving them your data.
16. Changes to this policy
We may update this policy as our practices, tools or legal obligations change. The current version is always published here with its last-updated date. Where a change is significant, we will take reasonable steps to tell people it affects.
17. Contact and complaints
Questions, requests or concerns about privacy:
- hello@hookline.click
- Post
- Hookline LTD, Office 10367, 321-323 High Road, Chadwell Heath, Essex, RM6 6AX, United Kingdom
We would always prefer to sort a problem out with you directly. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — telephone 0303 123 1113 (ico.org.uk). If you are in the EU or EEA, you may complain to your local supervisory authority instead.