Skip to content

Cookie settings

Essential storage is always on because the site needs it. Everything else stays off until you switch it on, and you can change your mind at any time from the Cookie settings link at the bottom of every page.

This site does not currently use any optional cookies, so there is nothing to switch on or off. If that changes, you will be asked first.

Legal

Privacy policy

What we collect, why, who sees it, and how to make us delete it. Written to UK, EU and US standards, whichever applies to you.

This policy explains how Owlyn Tech Limited (“Owlyn Tech”, “we”) uses personal data when you visit this website, contact us, apply for a website or become a client. It is written to meet the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation, and the privacy laws of US states, including California.

It does not cover the websites we build for clients. On those, the client decides how their customers’ data is used and publishes their own privacy policy. We handle that data only on the client’s instructions, under the data processing terms in our terms of service.

Who is responsible for your data

Owlyn Tech Limited is the controller of the personal data described here. We are a small company and are not required to appoint a data protection officer. Write to contact@owlyntech.com about anything in this policy and a person will answer.

What we collect, and where it comes from

  • Enquiries and applications. Your name, business name, email address, phone number and current website, and what you tell us about your business, such as what you sell, rough sales volumes and your budget. You give us this through our forms, by email, by phone or on WhatsApp.
  • Submission records. With each form submission we store your IP address and your browser’s identifying string (its “user agent”). We also keep a one-way hash of your IP address for up to an hour to stop the forms being flooded. This is how we detect spam and abuse.
  • Client records. Once you are a client: contact details for you and your staff, our agreement, invoices and instalment payments, and the order data we need to calculate and check our fee, such as order value, fee, date and refund status. We never see or store card numbers; Stripe handles those.
  • Messages and calls. What you send us by email or WhatsApp, the address or number you contact us from, and notes we make of anything agreed on a call.
  • Server logs. Our host automatically records the IP address, browser, page requested and time of each visit, as every web server does.
  • No analytics or advertising tracking. We do not currently run any. If that changes, nothing will load until you agree, and it will be listed in our cookie policy.

We do not ask for, and do not want, sensitive information such as health data. We never ask for passwords by email or message.

Why we use it, and our lawful basis

UK and EU law require a lawful basis for each use of personal data. Ours are:

What we doLawful basis
Reply to an enquiry you sentLegitimate interests: answering people who contact us
Assess an application and prepare a quoteSteps you asked us to take before entering a contract
Provide our services, calculate fees and bill youPerformance of our contract with you
Keep accounting and tax recordsLegal obligation
Prevent spam, fraud and abuse, and keep the site secureLegitimate interests: protecting our systems and the people who use them
Analytics or marketing cookies, if we ever use themYour consent, which you can withdraw at any time

Where we rely on legitimate interests, we have weighed them against your rights and are satisfied they do not override them. You can object at any time.

You do not have to give us any information. Without contact details we cannot reply to you, and without the details a contract needs we cannot take you on as a client.

No decision about you is made by automated means alone. Every application is read and decided by a person, and we do not profile visitors.

We do not send marketing emails unless you have asked for them, and every one would include a way to unsubscribe. Sending an enquiry does not put you on a mailing list.

Who we share it with

We do not sell personal data, and we do not share it for targeted or cross-context behavioural advertising. We share it only with:

  • Service providers acting on our instructions: Namecheap, which hosts this website and stores form submissions, and our email provider. They may not use the data for their own purposes.
  • WhatsApp, run by Meta, if you choose to message us there. WhatsApp handles those messages under its own terms and privacy policy.
  • Stripe, for clients, which processes payments on the sites we build under its own privacy policy.
  • Professional advisers, such as our accountants and lawyers, who are bound by confidentiality.
  • Authorities, where the law requires it. We will tell you when we are allowed to.
  • A buyer of our business, if Owlyn Tech is ever sold or merged. They would be bound by this policy.

International transfers

We are based in the United Kingdom. If you are in the EU or EEA, your data can come to us freely: the European Commission has decided that the UK protects personal data adequately, a decision renewed in December 2025 and valid until December 2031.

Some of our providers store or access data outside the UK, including in the United States. Where they do, we rely on the safeguards UK and EU law provide: an adequacy decision or data bridge where one exists, such as the UK Extension to the EU-US Data Privacy Framework for certified US companies, or otherwise standard contractual clauses such as the UK International Data Transfer Agreement. Ask us and we will send you details of the safeguard that applies.

How long we keep it

  • Enquiries and applications that do not lead to work: 24 months from our last contact, so we can pick up a conversation you come back to. Then they are deleted.
  • Client records: for as long as you are a client, then six years, which is how long UK tax law requires business records to be kept.
  • IP address and browser details stored with a submission: deleted together with the submission.
  • Server logs: kept by our host for a short period, typically around 30 days.

How we protect it

The whole site runs over an encrypted HTTPS connection. Form submissions are stored in a database that cannot be reached from the web, its credentials are kept out of public reach, and only the people who need the data for their work can see it. No system is perfectly secure, but if a breach ever puts your data at risk, we will tell you and the regulator as the law requires.

Your rights

In the UK, the EU and the EEA

You can ask us at any time to:

  • Tell you whether we hold data about you, and give you a copy.
  • Correct anything inaccurate or incomplete.
  • Delete your data, where we are not legally required to keep it.
  • Restrict how we use it while a question is resolved.
  • Give you your data in a portable, machine-readable format.
  • Stop using it where we rely on legitimate interests, and always for direct marketing.
  • Withdraw consent you gave, at any time. This does not affect anything done before you withdrew it.

In the United States

Depending on the state you live in, including California, Colorado, Connecticut, Texas and Virginia, you may have the right to know what personal information we collect and how we use it, to access it, to have it corrected or deleted, and to opt out of its sale, its sharing for targeted advertising, and profiling. We do not sell or share personal information, so there is nothing to opt out of. Even so, we honour all of these requests from anyone who asks, whether or not their state’s law applies to a business of our size, and we will never treat you differently for using your rights.

You can use an authorised agent to make a request for you. If we decline a request, you can ask us to reconsider, and we will explain our decision in writing. If you are still unhappy, you can contact your state attorney general.

Do Not Track and Global Privacy Control

We do not track visitors across other websites, so this site behaves the same whether or not your browser sends a Do Not Track signal. We treat a Global Privacy Control signal as a valid request to opt out of the sale or sharing of your personal information, and as a refusal of marketing cookies.

How to make a request

Write to contact@owlyntech.com. We may ask you to confirm your identity first, using only what we need to check it is you. We reply within one month if you are in the UK or EU, or within 45 days if you are in the US. For complex requests the law lets us extend that, and if we need to we will tell you why. There is no charge.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first at contact@owlyntech.com and say that it is a data protection complaint. We will acknowledge it within 30 days, look into it properly, and tell you the outcome without undue delay.

You can also complain to a regulator at any time:

Cookies

Everything this site stores on your device, and why, is listed in our cookie policy. Anything optional, such as analytics or marketing cookies, only loads after you agree, and you can change your choice at any time from the Cookie settings link at the bottom of every page. Blocking cookies will not break the site.

Children

This site is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us information, contact us and we will delete it.

Changes to this policy

If this policy changes materially we will update the date on this page and, for active clients, tell you directly rather than relying on you to notice.

Contact and company details

Owlyn Tech Limited
Registered in England and Wales, company number 17445397
Registered office: Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom
contact@owlyntech.com