Home

Privacy Policy

Drewdan Limited — Company No. 16948593

Last updated: April 2026


1. Who We Are

This Privacy Policy explains how Drewdan Limited ("we", "us", "our") collects, uses, and protects personal data.

Drewdan Limited is a private limited company registered in England and Wales (Company No. 16948593), with a registered office at 13 Tudor Crescent, Casnewydd, Newport, NP10 9BS.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Drewdan Limited is the data controller for personal data collected through this website and in connection with our services.


2. What Data We Collect

2.1 Through the Quote / Contact Form

When you submit a project enquiry, we collect:

  • Your name and email address
  • Company name (if provided)
  • Project description, budget range, and timeline
  • How you heard about us (if provided)

2.2 Website Analytics

We may collect anonymised, aggregated data about how visitors use this website (e.g. pages viewed, referral sources, approximate location by country). Where analytics tools are used, they are configured to minimise personal data collection.

2.3 Cookies

This website may use essential cookies required for basic functionality (e.g. storing your colour mode preference). We do not currently use tracking or advertising cookies.

2.4 Communications

If you contact us by phone, WhatsApp, or email, we will retain records of that communication.


3. How We Use Your Data

We use the data collected to:

PurposeLawful Basis
Respond to your project enquiryLegitimate interests / Pre-contractual
Provide and manage contracted servicesContract
Send invoices and manage paymentsContract / Legal obligation
Maintain records required by lawLegal obligation
Improve our website and servicesLegitimate interests

We will not use your personal data for automated decision-making or profiling.


4. Who We Share Your Data With

We do not sell your personal data. We may share it with:

  • Email service providers (e.g. Resend) — to deliver enquiry notifications
  • Accountancy software (FreeAgent) — for invoicing and financial record-keeping
  • Hosting and infrastructure providers — our website is hosted on Cloudflare's infrastructure

All third-party processors are required to handle your data in accordance with applicable data protection law.

We will not share your data with any other third party without your explicit consent, except where required by law.


5. Data Retention

  • Enquiry data: Retained for up to 2 years after the last communication, or for the duration of any resulting contract plus 6 years (to comply with statutory record-keeping requirements).
  • Financial records: Retained for 6 years as required by HMRC.
  • Analytics data: Retained in anonymised, aggregated form indefinitely.

6. Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data (subject to legal retention obligations)
  • Restriction — request that we restrict processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent

To exercise any of these rights, please contact us via our Contact page.

We will respond within 30 days.


7. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO.


8. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include:

  • Encrypted data transmission (HTTPS)
  • Access controls limiting who can view enquiry data
  • Use of reputable, security-audited third-party services

No method of transmission over the internet is completely secure. If you have concerns about sharing sensitive information, please contact us to discuss alternatives.


9. International Transfers

Our primary infrastructure is operated by Cloudflare, which may process data in locations outside the UK. Cloudflare maintains appropriate safeguards for such transfers in accordance with UK GDPR requirements.


Our website may contain links to third-party websites (e.g. SimpleSocket.io, GitHub, LinkedIn). This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party services you visit.


11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The latest version will always be available on this page, with the "last updated" date at the top.


12. Contact

For any privacy-related questions or to exercise your rights:

Drewdan Limited
13 Tudor Crescent, Casnewydd, Newport, NP10 9BS
Company No. 16948593

Use our Contact page to get in touch.