Skip to content
craftwebcare
PrivacyCookiesTerms
Contact us

Legal information

Privacy policy

This policy explains what personal information CraftWebCare handles across our website, managed websites, client dashboard and support services.

Last updated: 19 July 2026

On this page
Who we areInformation we collectHow and why we use itClient websitesWho we share it withInternational transfersHow long we keep itYour rightsContact and complaints

1. Who we are

CraftWebCare is a website design, hosting and maintenance service operated by Achraf Bouhadou. For information collected for our own business—such as sales enquiries, client accounts and billing records—CraftWebCare is the data controller.

You can contact us about privacy at achraf.bouhadou@craftwebcare.co.

Two roles, kept clear. When someone contacts a business through a website we manage, that business normally decides why the information is collected and is the controller. CraftWebCare processes it to provide the website, lead inbox, reporting and support services. See “Client websites” below.

2. Information we collect

ContextInformation
Enquiries and salesYour name, email address, phone number if supplied, business name, website details, and anything you include in messages or calls with us.
Client accountsName, business contact details, account email, password hash, role, tenant/business settings, domain and branding information, notification preferences, service requests and correspondence.
Website leads and bookingsName, phone, email, requested service, message, optional photo link, source page, referral and campaign details, device class, lead status, notes, values and appointment information where used.
Cookieless website analyticsPage path, event type, time, and a one-way daily identifier made from the IP address and browser user-agent. We store the identifier—not the source IP address or user-agent—in the analytics event record.
Security and diagnosticsIP address, user-agent, session and login information, server logs, account and tenant identifiers, and error or performance details. Diagnostic tools are configured not to collect request bodies, cookies, authorisation headers, lead messages, phone numbers or email addresses by default.
Service and financial recordsPlan, invoices, payments, service history, agreed work, and records needed for accounting, disputes or legal compliance. We do not store full payment-card details.

Please do not send sensitive personal information unless it is genuinely needed. If a client website asks for health or other sensitive information, that client is responsible for providing the additional privacy information and lawful basis required for its service.

3. How and why we use information

PurposeUK data-protection basis
Reply to enquiries, prepare a preview or proposal, and take steps requested before a contractSteps before entering a contract and our legitimate interest in responding to genuine business enquiries.
Build, host, secure, maintain and support websites and client accountsPerformance of our contract and our legitimate interests in operating a reliable service.
Receive leads, display dashboard records, send notifications and manage appointments or requests for a clientWe act on the client controller’s documented instructions. The client determines its lawful basis.
Measure website use using privacy-focused, cookieless eventsOur and our clients’ legitimate interests in measuring service performance and improving websites, balanced against visitors’ privacy.
Prevent spam, fraud and unauthorised access; investigate incidents; keep systems workingLegitimate interests in security and, where applicable, compliance with legal obligations.
Keep accounting, tax, contract and complaint recordsLegal obligations and legitimate interests in establishing, exercising or defending legal claims.
Send service messages and relevant business updatesContract and legitimate interests. We use consent where the law requires it, and you can object to direct marketing at any time.

We do not sell personal information. We do not use a client’s lead data to market CraftWebCare to those leads, and we do not make solely automated decisions that have legal or similarly significant effects on people.

4. Information collected on client websites

Our managed websites may send first-party events—such as a page view, call-button click, WhatsApp click or form event—to the CraftWebCare dashboard. The event system does not set cookies or use local storage. A daily, one-way identifier helps count distinct visitors without building a persistent profile.

When you submit a form on a client website, your information goes to that business and is displayed in its private CraftWebCare dashboard. The business is normally the controller and should provide its own privacy notice. Requests about the business’s use of your enquiry should normally be sent to that business first; we will assist it with verified requests where required.

Attribution details such as the page you visited, referrer, UTM campaign values or advertising click ID may be attached to a form submission so the business can understand how the enquiry arrived. These details are not used for cross-site advertising by CraftWebCare.

5. Who we share information with

We only share information where needed for the purposes above. Recipients may include:

  • the CraftWebCare client whose website or dashboard the information relates to;
  • hosting, database and infrastructure providers that run the website and dashboard;
  • Cloudflare for restricted backup storage;
  • Resend or another configured transactional-email provider for account and lead notifications;
  • Sentry for privacy-limited error and performance diagnostics;
  • professional advisers, insurers, auditors or prospective business transferees under appropriate confidentiality; and
  • courts, regulators, law enforcement or other authorities where disclosure is required or legally justified.

Providers acting for us are restricted by contract and may only use information to deliver the relevant service. A current subprocessor list is available on request.

6. International transfers

Some service providers may process information outside the United Kingdom. Where UK transfer rules apply, we use a recognised safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, and carry out the required assessment where appropriate.

You may ask us for more information about the safeguard relevant to your information.

7. How long we keep information

RecordTypical retention
Cookieless raw analytics events90 days, after which they are pruned. Aggregated statistics may be retained longer where they no longer identify a visitor.
Security sessionsNormally until sign-out or after 2 hours of inactivity. Limited security logs may be kept longer where needed to investigate abuse or incidents.
Sales enquiries that do not become clientsNormally up to 24 months after the last meaningful contact, unless needed for a complaint, legal claim or a request not to contact you.
Client account, contract and payment recordsFor the service relationship and normally six years afterwards where needed for tax, accounting, contract or legal-claim purposes.
Lead, appointment and request records held for clientsFor the period set by the client controller or while needed to provide the contracted dashboard service. Verified deletion instructions are applied subject to legal exceptions.
Database backupsRolling backups are normally deleted after 14 days. Deleted live records may remain in a backup until that backup expires.
Error diagnosticsAccording to the configured monitoring-provider retention period and only for as long as reasonably needed to diagnose and prevent faults.

We may keep information for longer where law requires it, where a dispute or investigation is active, or to establish, exercise or defend legal claims. We review retention and delete or anonymise information when it is no longer needed.

8. Security

We use measures appropriate to the risk, including encrypted transport, access controls, password hashing, tenant separation, restricted backups, rate limits, security cookies, logging controls and tested recovery procedures. No online system is completely risk-free, so please contact us promptly if you believe information has been exposed or an account has been misused.

9. Your rights

Depending on the circumstances, UK data-protection law may give you the right to:

  • be informed about how your information is used;
  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask for deletion or restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive information you provided in a portable format where the right applies; and
  • raise concerns about automated decision-making. CraftWebCare does not currently make significant decisions about people solely by automated means.

These rights are not absolute. We may need to verify your identity, and if another business is the controller we may pass the request to it or help you contact it. We will not charge a fee unless the law permits one.

10. Contact, complaints and updates

Send a privacy request or data-protection complaint to achraf.bouhadou@craftwebcare.co. Please include enough detail for us to identify the relevant service and investigate. We acknowledge data-protection complaints within 30 days and respond without undue delay, keeping you informed where an investigation takes longer.

If you remain unhappy, you can complain to the Information Commissioner’s Office (ICO). We would appreciate the chance to resolve the concern first.

We may update this policy when our services, providers or legal duties change. The date at the top shows the latest version.

© 2026 craftwebcare
PrivacyCookiesTerms
achraf.bouhadou@craftwebcare.co