Compliance
Every website we build collects enquiries, and every business that collects enquiries owes the person who sent one an explanation. Most small-business websites do not give them one. This page says what ships with ours, and where to check it.
Your site arrives with its legal pages written
A privacy notice, a cookie statement and an accessibility statement, published on your own domain from the day the site goes live.
They are generated rather than filled into a template. The list of companies that can see an enquiry comes from the same register this page links below, so it cannot name seven while twenty-one are running. What the enquiry form collects is listed from the fields the form actually writes. Where we do not have a fact — your ICO registration number, say — the section is left out rather than published with a gap in it, because an invented registration number in a privacy notice is a worse problem than a missing one.
You will need your own ICO registration. Most businesses holding customer enquiries do, the fee is modest, and it takes about ten minutes at ico.org.uk. We cannot do it for you and we will not pretend it is unnecessary — but once you have the number, we put it on your privacy notice.
No cookie banner, because there is nothing to consent to
Visitor statistics on your site are cookieless. Your typefaces are served from your own site rather than a font network, so loading a page does not tell anyone else that a visitor was there. The spam check on the enquiry form loads when somebody submits it and not before.
The result is a site that needs no consent banner — no overlay between a customer and your phone number, and nothing to click past on a phone. That is a conversion argument as much as a legal one.
Who is responsible for what
When someone fills in the enquiry form on your website, that record is yours. You decide why it is held and what happens to it; we hold it on your behalf and act on your instructions. In data protection terms you are the controller and we are the processor.
The terms that govern it are part of every plan agreement and published in full: processor terms , and the wider GDPR statement covering both halves.
Every company that touches an enquiry is named
The sub-processor register lists them, what each one does, where it holds data and under what transfer safeguard.
It is kept honest by the build rather than by good intentions: adding an integration fails our tests until somebody decides whether it sees personal data, and the shorter list published on your own site's privacy notice is checked against this one. We give 30 days' notice before adding or replacing a sub-processor, and you can object.
Where the data lives
The application and its database run in Amsterdam, Netherlands (EU). Where data leaves the UK it is covered by the UK's adequacy regulations or by the International Data Transfer Addendum to the standard contractual clauses.
If you leave, we deliver an export and then delete what we hold on your behalf — enquiries included — within 30 days of the site coming down.
Accessibility
Sites are built to the Web Content Accessibility Guidelines, and automated checks against them run over every site before a release. Forms carry real labels and errors that say what to do; links are underlined rather than distinguished by colour alone; contrast is measured rather than eyeballed.
Automated testing finds something between a third and a half of what a person would, so we publish an accessibility statement only for sites somebody has actually checked, and it says which it is.
What we do not do
We do not sell your customers' details. There are no advertising pixels on your site, no trackers that follow a visitor to another website, and no third-party marketing scripts. If that ever changes, the cookie statement changes first.
The rest of the technical posture is on the security statement . If something here matters to a tender or an accreditation and you need it in writing, ask support@tradesplace.co.uk.