Privacy Policy
This Privacy Policy explains how Calaweb (a trading name of Adam Engberg) collects, uses and protects personal data when you visit calaweb.co.uk or sign up for our newsletter. We are the data controller for all personal data collected through this website.
We take your privacy seriously and process personal data only where we have a lawful basis to do so under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Calaweb is a trading name of Adam Engberg, a sole trader based at Aston Magna, GL56 9QJ, England. For data protection enquiries, contact us at privacy@calaweb.co.uk.
2. What Data We Collect and Why
2.1 Website Analytics
We use Google Analytics 4 (GA4) to understand how visitors use our website. GA4 is configured with IP anonymisation enabled, which means your full IP address is never stored or processed by Google. No personally identifiable information is collected through analytics.
Analytics data includes pages visited, time spent on the site, the type of device and browser used, and the general geographic region of the visitor (country or region level only). This data is used in aggregate to improve the website.
Lawful basis: Legitimate interest (improving our website). Analytics cookies are only placed with your prior consent via our cookie banner.
2.2 Newsletter and Marketing Emails
If you sign up for our newsletter or marketing emails, we collect your first name and email address. This data is used solely to send you information about Calaweb's services, offers and updates.
You can unsubscribe at any time by clicking the unsubscribe link in any email we send, or by emailing privacy@calaweb.co.uk. On unsubscription, your details will be removed from our active mailing list promptly.
We periodically review our mailing list. If you have not opened or engaged with any email from us in the preceding 12 months, we will send you a re-engagement email. If you do not respond, we will remove you from our list.
Lawful basis: Consent. You may withdraw your consent at any time by unsubscribing.
2.3 Cookies
Our website uses cookies. A cookie consent banner is displayed on your first visit, and analytics cookies are only placed if you accept them. Strictly necessary cookies (required for the site to function) are placed without consent, as permitted under UK PECR.
You can change your cookie preferences at any time using the cookie settings link in the footer of our website.
The cookies we use are:
- Strictly necessary cookies: used to remember your cookie consent choice. No personal data is collected.
- Analytics cookies (Google Analytics 4, placed only with consent): used to collect anonymised data about how visitors use the site. IP anonymisation is enabled. These cookies do not identify you personally.
3. Third-Party Processors
We use the following third-party services to operate this website and our mailing list. Each is engaged as a data processor acting on our instructions, under a Data Processing Agreement or equivalent legal mechanism.
| Processor | Role | Location | Safeguard |
|---|---|---|---|
| Google LLC (GA4) | Anonymised website analytics | US-headquartered, EU/US infrastructure | SCCs + UK Addendum |
| MailerLite Limited | Newsletter and email marketing | EU (Ireland / Lithuania) | No transfer outside EU for UK customers |
| Nimbus Hosting | WordPress website hosting (where applicable) | UK | UK data residency |
| Cloudflare, Inc. | CDN, DDoS protection, edge delivery | US-headquartered, global infrastructure | SCCs + UK Addendum |
| Lovable AB | Hosting platform for custom web applications | Sweden / EU | SCCs + UK Addendum |
| Supabase, Inc. | Database and file storage (custom sites only) | US-headquartered, EU/US regions | SCCs + UK Addendum |
We do not sell your personal data to any third party. We do not use your data for profiling or automated decision-making.
4. International Data Transfers
Some of the processors listed above are based outside the United Kingdom, including in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place.
Google (GA4) and Cloudflare operate under Standard Contractual Clauses (SCCs) supplemented by the UK International Data Transfer Addendum (UK Addendum) issued by the ICO. Lovable AB and Supabase similarly operate under SCCs with the UK Addendum.
MailerLite processes data for UK customers via MailerLite Limited, an EU entity. Subscriber data does not leave the EU.
IP anonymisation in GA4 means that no full IP address is transferred to Google's servers at any point.
5. How Long We Keep Your Data
| Data type | Retention period | Reason |
|---|---|---|
| Newsletter subscriber data | Until you unsubscribe, or 12 months after last engagement | Consent-based marketing |
| Anonymised analytics data | Up to 14 months (Google Analytics default) | Website improvement |
| Cookie consent records | 12 months | PECR compliance |
| Server and security logs (Cloudflare) | Approximately 30 days | Security and abuse prevention |
| Email correspondence | 3 years | Business records and dispute resolution |
When data is no longer required, it is deleted or anonymised. We do not retain personal data for longer than is necessary for the purpose for which it was collected.
6. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure: you may ask us to delete your personal data, subject to any legal obligations we have to retain it.
- Right to restriction: you may ask us to restrict how we use your data in certain circumstances.
- Right to data portability: where processing is based on consent or contract, you may request your data in a commonly used, machine-readable format.
- Right to object: you may object to processing based on legitimate interests. We will stop unless we have compelling grounds to continue.
- Right to withdraw consent: where processing is based on consent (such as newsletter sign-up or analytics cookies), you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email us at privacy@calaweb.co.uk. We will respond within one calendar month.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
7. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss or disclosure. Our website is served over HTTPS. Access to mailing list data is restricted to authorised personnel only.
No method of transmission over the internet is completely secure. While we take appropriate precautions, we cannot guarantee the absolute security of data transmitted to or from our website.
8. Children
Our website is not directed at children under the age of 13 and we do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@calaweb.co.uk and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Where a change is material, we will take reasonable steps to inform you, such as by updating the date at the top of this page. We encourage you to review this policy periodically.
The current version is always available at calaweb.co.uk/privacy.
10. Contact
For any questions about this Privacy Policy or about how we handle your data, contact us at privacy@calaweb.co.uk.
Calaweb, a trading name of Adam Engberg, Aston Magna, GL56 9QJ, England.
