← Back to site
Legal

Privacy Policy

Last updated: 9 August 2026

This Privacy Policy explains how Maskrey Studio collects, uses, shares and protects your personal data when you visit maskrey.studio, book a call, or otherwise get in touch — and when we contact people at businesses about our services. It also sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are committed to handling your data lawfully, fairly and transparently.

Contents

  1. Who we are and how to contact us
  2. The personal data we collect
  3. How we collect your data
  4. How we use your data and our lawful bases
  5. Who we share your data with
  6. International data transfers
  7. How long we keep your data
  8. How we keep your data secure
  9. Your data protection rights
  10. Cookies and similar technologies
  11. Children's privacy
  12. Changes to this policy
  13. How to complain

01Who we are and how to contact us

Maskrey Studio ("we", "us", "our") is a web design studio based in Derbyshire, England, operated by Joe Maskrey. For the purposes of UK data protection law, we are the data controller responsible for your personal data.

If you have any questions about this policy or how we handle your data, contact us:

Maskrey Studio — data protection enquiries

Email: joe@maskrey.studio

Post: Belper, Derbyshire, England (full postal address available on request)

02The personal data we collect

We only collect the data we need to respond to you and run our business. Depending on how you interact with us, this may include:

  • Enquiry and booking data — your name, email address, time zone, the date and time you choose, and any information or notes you provide when you book a call with us through our online scheduling tool.
  • Communications data — the content of emails and messages you send us, and our correspondence with you, including any details you share about your business, your project or your requirements.
  • Technical and usage data — your IP address, approximate location derived from it, browser type and version, device and operating system, referring website, and the pages you view. This is generated automatically when any website is loaded and is processed by our hosting and content-delivery providers largely for security and to serve the site.
  • Usage analytics — aggregated, anonymous statistics about how the site is used (such as pages viewed, the referring site, and general country, browser and device type), measured by our cookieless analytics tool. This does not identify you individually and sets nothing on your device.
  • Newsletter data — if you subscribe to our newsletter, your email address, the date you subscribed and confirmed, and standard email engagement data recorded by our email provider (whether an issue was delivered and opened, and which links you clicked). We use this to see which topics are useful and to keep our list clean; we do not use it to build a profile of you or to target advertising.

We use a privacy-friendly, cookieless analytics tool (Plausible) to understand how the site is used — it does not set cookies, does not collect data that identifies you, and does not track you across other websites. We do not run advertising or behavioural-tracking tools, and we do not build marketing profiles of visitors. We do not knowingly collect any special category data (such as data about health, ethnicity, religion or political views). Please don't send us special category data unless it's genuinely necessary.

Business contact data

Separately from the above, when we contact a business about our services we may hold the following about an individual at that business:

  • Name
  • Business email address
  • Job title
  • Employer name, website and business address
  • Publicly listed company information, such as staff numbers
  • LinkedIn profile URL
  • Any correspondence between us

We do not collect or hold special category data, financial information, or personal data about anyone in a private capacity.

03How we collect your data

  • Directly from you — when you book a call, email us, subscribe to our newsletter, or otherwise get in touch.
  • Automatically — when you load the site, technical data is collected by your browser's requests to our hosting, content-delivery and font providers (see section 5).
  • From third parties — if you book through our scheduling tool, we receive the booking details you submit to that tool.
  • From a business data provider — where we contact a business about our services, we obtain business contact data from a commercial B2B data provider, named below.

Where our business contact data comes from

We obtain business contact data from Apollo.io, a commercial B2B data provider, accessed via AmpleLeads. Apollo compiles business contact information from publicly available sources and its own contributor network.

We also verify email deliverability using MillionVerifier.

Where you contact us directly, we hold the information you give us.

04How we use your data and our lawful bases

Under UK GDPR we must have a valid "lawful basis" for using your personal data. We rely on the following:

What we doWhyLawful basis
Respond to enquiries and bookings To reply to you, arrange and hold a call, and discuss whether we can work together Taking steps at your request before entering a contract; and our legitimate interests in responding to enquiries
Provide our services To plan, design and deliver work if you become a client Performance of a contract with you
Operate, secure and maintain the website To deliver the site reliably, prevent abuse and keep it secure Our legitimate interests in running a safe, functioning website
Keep records and manage our business Correspondence, quotes, and business administration Our legitimate interests; and, where relevant, compliance with a legal obligation (e.g. tax and accounting)
Introduce our services to businesses To send a small number of business-to-business emails to organisations we believe may find our services relevant, and to respond to anyone who replies Our legitimate interests in promoting our services to relevant businesses
Send you our newsletter To email you the newsletter you asked for, and to see which issues and topics are useful Your consent, which you give by subscribing and confirming your email address, and can withdraw at any time
Measure how the site is used (analytics) To understand which pages and calls-to-action work, and improve the site Our legitimate interests in understanding and improving our website, using privacy-friendly, cookieless analytics

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we believe our use is proportionate and expected. Where our client is a company or other organisation rather than you personally, the contract is with that organisation, so we rely on our legitimate interests in delivering the contracted work and communicating with our client's staff and contacts.

Our outreach emails

We use this data to send a small number of business-to-business emails introducing our website design services to organisations we believe may find them relevant, and to respond to anyone who replies.

Our lawful basis is legitimate interests (UK GDPR Article 6(1)(f)). Our legitimate interest is in promoting our services to relevant businesses.

We have carried out a legitimate interests assessment and concluded that this processing is proportionate, is limited to people in their professional capacity at organisations plausibly interested in our services, and is unlikely to cause harm or distress. A copy is available on request.

We contact corporate subscribers only — limited companies, LLPs, PLCs and Scottish partnerships — in line with the Privacy and Electronic Communications Regulations 2003.

Our newsletter

We send a newsletter about designing and building websites. We only ever send it to people who have asked for it: you enter your email address on our newsletter page, and we then email you a link you must click to confirm (known as double opt-in). Until you confirm, we don't add you to the list. That confirmation is your consent, and it is the only lawful basis we rely on to send you the newsletter.

You can withdraw that consent whenever you like — every issue carries an unsubscribe link, one click is enough, and you never have to give a reason. You can also email joe@maskrey.studio and we will remove you. Withdrawing your consent does not affect emails already sent, and it will not affect any other dealings you have with us: subscribing is not a condition of enquiring, booking a call, or becoming a client, and we do not add clients or enquirers to the newsletter unless they subscribe themselves.

Our newsletter is delivered by Kit (see section 5), which records standard email engagement data — whether an issue reached you, whether you opened it, and which links you clicked. We use this to judge which topics are worth writing about and to stop sending to addresses that no longer work. We do not use it to profile you, to score or rank you as a sales prospect, or for advertising, and we do not sell or rent our list to anyone.

Do you have to provide your data?

Providing your personal data is not a statutory requirement. Where you contact us or book a call, giving us your name, email address and any details you choose to share is necessary for us to respond to you and, if you become a client, to enter into and perform a contract with you. If you choose not to provide this information, we won't be able to reply to your enquiry or provide our services. Subscribing to the newsletter is entirely optional; if you don't give us your email address for that purpose, we simply won't send it to you.

05Who we share your data with

We never sell your personal data. We share it only with the providers who help us run our website and business, and only as far as needed. Most of them act as our processors, handling data under a contract and only on our instructions (for example our hosting and booking providers). Some — such as Google Fonts and the code-library service (a JavaScript library served from Cloudflare's cdnjs), which your browser connects to directly when a page loads — receive limited technical data (such as your IP address) as independent controllers under their own privacy terms. The main ones are:

ProviderWhat they do for usData involved
Cloudflare, Inc. Website hosting (Cloudflare Pages), content-delivery network, DNS and security, as our processor. Separately, your browser fetches a JavaScript library from Cloudflare's public cdnjs service, and Cloudflare receives limited technical data for that request under its own terms. Technical and usage data, including IP address
Cal.com, Inc. Online scheduling — powers the "book a call" tool used to arrange your call. The tool loads when you scroll to the booking section near the foot of the page. Your name, email, time zone, chosen slot and any notes; and technical data such as your IP address when the tool loads
Google (Google Ireland Ltd / Google LLC) Google Fonts serves the site's typography; your browser requests these files directly from Google IP address and technical data (received by Google when fonts load)
Plausible Analytics (Plausible Insights OÜ) Privacy-friendly, cookieless website analytics — aggregated statistics on how the site is used. Hosted in the European Union. Aggregated usage data (pages viewed, referrer, browser and device type, general location); no cookies and no personal profile
Kit, Inc. (formerly ConvertKit) Email newsletter platform, as our processor — stores our subscriber list, sends the confirmation email and each issue, and handles unsubscribes. Our signup form posts your email address directly to Kit; we do not load any Kit script or set any Kit cookie on this website. Your email address, subscription and confirmation dates, email engagement data (deliveries, opens, link clicks), and technical data such as your IP address when you submit the form
Our email and business tools Email, and the customer-management and productivity tools we use to handle enquiries and client work Your name, email and the content of your messages

You can read how these providers handle data in their own privacy policies: Cloudflare, Cal.com, Google, Plausible and Kit.

Outreach and client-management providers

Where we contact a business about our services, we use the following service providers, who process data on our behalf under contract:

ProviderPurposeLocation
PlusVibe Email sending and inbox management United States
MillionVerifier Email address verification European Union
Apollo.io / AmpleLeads Business contact data United States
Attio Customer relationship management United States

We do not sell personal data, and we do not share it for anyone else's marketing.

We may also disclose your data if required to do so by law, to comply with a legal or regulatory obligation, to establish, exercise or defend legal claims, or to protect our rights, property or safety or those of others.

06International data transfers

Some of our providers (including Cloudflare, Cal.com, Google and Kit) are based in, or store or process data in, countries outside the UK, such as the United States. Kit, which runs our newsletter, is based in the United States and stores subscriber data there. Where we engage a provider as our processor and your data is transferred outside the UK, we rely on appropriate safeguards — for example UK "adequacy" regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with additional measures where appropriate. Some transfers instead happen because your browser connects directly to a provider (such as Google Fonts or the code-library service) as you load the site; in those cases the provider receives limited technical data under its own terms and safeguards rather than under an arrangement we have put in place. Our analytics provider, Plausible, stores its data within the European Union rather than outside it. You can ask us for more detail on the safeguards that apply.

Our outreach and client-management providers (PlusVibe, Apollo.io / AmpleLeads and Attio) are based in the United States; MillionVerifier is in the European Union. Where data is transferred outside the UK, we rely on the UK International Data Transfer Addendum or equivalent safeguards provided by those suppliers.

07How long we keep your data

We keep your personal data only for as long as we need it for the purposes set out above. In practice:

  • Enquiries and bookings that don't lead to work: we generally keep these for up to 24 months in case you get back in touch, then delete them.
  • Client records: if you become a client, we keep relevant records for the duration of our engagement and afterwards as required for legal, accounting and tax purposes (generally up to 6 years).
  • Newsletter subscribers: we keep your email address for as long as you stay subscribed. If you unsubscribe, we remove you from the mailing list straight away; we keep a minimal record of the unsubscribe (your email address and the fact you opted out) so that we don't email you again by mistake. If you never confirm your subscription, the unconfirmed address is removed within 3 months.
  • Businesses we contact — no reply, or a decline: contact details are deleted within 12 months, except the minimum needed to keep you on our suppression list.
  • Suppression list: we keep your email address indefinitely, for the sole purpose of making sure we never contact you again. This is the least intrusive way to honour an opt-out.
  • Technical logs held by our hosting and security providers are kept for a limited period — typically no more than a few months — in line with their retention policies.

You can ask us to delete your data sooner — see your rights below.

08How we keep your data secure

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse or alteration. These include serving the site over an encrypted HTTPS connection, choosing reputable providers with strong security practices, and limiting access to your data to those who need it. No method of transmission or storage is completely secure, but we take reasonable steps to protect your information and to notify you and the regulator of any serious breach where the law requires us to.

09Your data protection rights

Your right to object. You can object at any time to our use of your personal data where we rely on legitimate interests, including for direct marketing. If you object to direct marketing we will stop immediately, with no questions asked, and you never have to give a reason. Email joe@maskrey.studio, or see Stopping our emails below.

Under UK data protection law you have the following rights, free of charge in most cases:

  • Access — to be told whether we hold data about you and to receive a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to ask us to delete your data ("the right to be forgotten") in certain circumstances.
  • Restriction — to ask us to limit how we use your data in certain circumstances.
  • Objection — to object to processing based on our legitimate interests.
  • Portability — to receive certain data in a portable, machine-readable format.
  • Withdraw consent — where we rely on your consent, to withdraw it at any time (this won't affect processing already carried out). For our newsletter, the unsubscribe link in any issue does this immediately.
  • Rights around automated decisions — we do not make decisions about you by solely automated means or carry out profiling.

To exercise any of these rights, email joe@maskrey.studio. We may need to verify your identity. We will respond within one month of receiving a valid request; where a request is complex or you have made several, we may extend this by up to two further months, as the law permits, and will let you know if we need to.

Stopping our emails

Reply to any email from us with "no", "stop", or "unsubscribe" and we will add you to our suppression list immediately and permanently. You do not need to give a reason. Our newsletter carries an unsubscribe link in every issue, which does the same thing in one click.

10Cookies and similar technologies

This website does not use analytics or advertising cookies — our analytics tool (Plausible) is cookieless. The cookies that may be set are those strictly necessary to deliver the site securely, plus functional cookies that our booking tool (Cal.com) may set — that tool loads automatically as you scroll near the booking section at the foot of the page, rather than only when you actively use it. Our newsletter signup form sets no cookies and loads no third-party script — it simply sends your email address to Kit when you submit it. For the full list, and how to control or avoid these cookies, see our Cookie Policy.

11Children's privacy

Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.

12Changes to this policy

We may update this policy from time to time to reflect changes to our practices or the law. When we do, we will revise the "last updated" date at the top of this page. Where changes are significant, we will take reasonable steps to bring them to your attention.

13How to complain

If you have a concern about how we handle your data, please contact us first so we can try to put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk