Privacy policy
What this site collects, why we are allowed to hold it, how long it stays, and what you can make us do with it.
Privacy policy in full
Last updated
This policy applies to ostfro.com and to enquiries made through it. Earlier versions are replaced in full on publication.
1. Who we are
[PLACEHOLDER_TRADING_NAME], trading as Ostfro, is the data controller for the personal data described in this policy. We are based in the United Kingdom and work remotely with businesses across the UK.
We are registered with the Information Commissioner’s Office under registration number [PLACEHOLDER_ICO_NUMBER].
For anything to do with your data, questions, requests, complaints, email hello@ostfro.com. There is no separate data protection officer; enquiries go to the same inbox and are handled by the person who runs the business.
2. What we collect
Almost everything we hold about you is something you typed into the contact form and chose to send:
- Name, so a reply is addressed to a person.
- Email address, the only way we answer an enquiry.
- Company, optional, and only ever used for context.
- What you need and which plan interests you, the two answers that decide whether we are the right fit before anyone spends time on a call.
- Your message, whatever you choose to write. Please do not send special category data (health, ethnicity, political or religious views, biometric or genetic data) or anyone else’s personal data unless it is genuinely needed to answer the question.
If the enquiry turns into a plan, we will also hold the ordinary business-contact and billing details needed to run it, the people we deal with, correspondence, invoices and payment records. Card details are handled by our payment provider and never reach us.
The site sets no cookies, runs no analytics, no advertising pixels and no third-party trackers. We do not build profiles and we make no automated decisions about you.
The site loads its typeface from Google Fonts. Your browser requests those font files directly from Google’s servers, which means Google receives your IP address and standard request headers as part of that connection. We receive nothing from it. Our hosting provider also keeps routine server logs, which can include IP addresses, for security and troubleshooting.
3. Lawful basis
Under UK GDPR we have to name a lawful basis for each use. Ours are:
- Legitimate interests (Article 6(1)(f)), reading and replying to an enquiry, and keeping a record of what was discussed. Our interest is in running a business that answers the people who contact it; that sits squarely within what anyone filling in a contact form expects, and it is hard to see it prejudicing your rights.
- Steps prior to entering a contract, and performance of it (Article 6(1)(b)), scoping and quoting, and, once a plan starts, building, running and billing for the systems it covers.
- Legal obligation (Article 6(1)(c)), keeping invoices and accounting records for as long as HMRC requires.
We do not rely on consent for the contact form, so there is no consent to withdraw. You can still object to our use of legitimate interests, see your rights.
We will not add you to a mailing list or send you marketing off the back of an enquiry.
4. Who else sees it
We do not sell personal data, and we do not share it for anyone else’s marketing. It is seen by the people who need it to answer you, and by the suppliers who carry the message:
- Our website host, which serves this site and keeps server logs.
- Our form and email providers, which transmit and store the enquiry itself.
- For active plans only: our payment provider, which handles the monthly billing; our accounting software; and any tool your build genuinely requires.
Each of these acts as a processor under a written contract and may only use the data to provide the service to us. We may also disclose data where the law requires it, or to establish or defend a legal claim.
Where a system we build for you processes personal data belonging to your own customers or staff, you are the controller of that data and we are your processor. That relationship is governed by a separate written data processing agreement, put in place before the processing starts.
5. How long we keep it
- Enquiries that do not become work, deleted within 12 months of the last message between us.
- Enquiries that become plans, kept for as long as the plan runs, and then for 6 years after the final invoice, which covers the accounting record and the limitation period for a contract claim.
- Server logs, kept for a short period by our host and then rotated out.
When a plan ends, the data held inside the systems we ran for you is returned or exported to you, then deleted from our side at the end of the notice period, apart from the billing records above. If you ask us to erase something sooner, we will, unless we are required to keep it for one of the reasons given here.
6. Security
The site is served over HTTPS. Enquiries land in an access-controlled inbox protected by multi-factor authentication, on accounts that only we can reach. Access to project data is limited to what a given piece of work needs. No transmission over the internet is ever perfectly secure, but if a breach did occur and it was likely to be a risk to your rights, we would report it to the ICO within 72 hours and tell you where the law requires it.
7. International transfers
Our suppliers may store or process data outside the UK. Where that happens, the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. You can ask us which suppliers are involved and what mechanism applies to each.
8. Your rights
Under UK GDPR you have the right to:
- Be informed, which is what this page is for.
- Access a copy of the personal data we hold about you.
- Rectification of anything inaccurate or incomplete.
- Erasure of your data where we have no overriding reason to keep it.
- Restrict processing while a dispute about accuracy or our grounds is resolved.
- Data portability, a machine-readable copy of data you gave us, where processing is automated and based on contract or consent.
- Object to processing based on legitimate interests, including any direct marketing, which we would stop on request without exception.
- Not be subject to automated decision-making or profiling with legal or similarly significant effects. We do none.
To exercise any of these, email hello@ostfro.com and say what you want. It is free, and we will respond within one month. If a request is genuinely complex we may extend that by a further two months, and we will tell you why inside the first month. We may ask for enough information to confirm who you are before we release anything.
9. Complaints
If you are unhappy with how we have handled your data, tell us first at hello@ostfro.com, most things are quicker to fix directly.
You also have the right to complain to the UK’s supervisory authority at any time, and doing so does not affect any other legal remedy:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
10. Changes to this policy
We update this page when what we do changes. The date in the panel above is the version in force. If a change materially affects how we handle data you have already sent us, we will tell you by email rather than quietly editing the page.
Still want to get in touch?
Now you know exactly what happens to the message. Tell us what you want.
Terms of service