Witham Systems logo
WITHAMSYSTEMS
Back to Home
UK GDPR & DPA 2018 Compliant

Privacy Policy

Last updated: September 2026. Compliant with the UK Data Protection Act 2018 & UK GDPR.

1. Identity of the Data Controller

Witham Systems is operated by Kieran Perham, trading as Witham Systems, based in Boston, Lincolnshire, United Kingdom. Kieran Perham is the Data Controller responsible for your personal data within the meaning of the UK GDPR and the Data Protection Act 2018.

Data Controller: Kieran Perham, trading as Witham Systems

Location: Boston, Lincolnshire, UK

info@mail.withamsystems.co.uk

2. What Personal Data We Collect

We collect only the information necessary to respond to your enquiry and provide our services. This includes:

  • Contact form submissions: your name, business name, phone number, email address, website URL, and any self-reported business pain points or notes you choose to share.
  • Basic analytical telemetry, such as anonymised page views and device type, used solely to improve the website.
  • Correspondence records, including emails and WhatsApp messages, where you contact us directly.

3. Lawful Basis for Processing

Under the UK GDPR, we rely on the following lawful bases for processing your personal data:

  • Legitimate Interests (Article 6(1)(f)) — responding to B2B business enquiries, providing digital audits, and delivering the services you have requested.
  • Consent (Article 6(1)(a)) — where you have explicitly opted in to receive follow-up marketing or ongoing communications. You may withdraw consent at any time.

4. How We Use Your Data

Your data is used strictly to provide website development, automated communication setups, and consultation audits. We use your information to respond to enquiries, prepare recommendations, deliver agreed services, and maintain business correspondence.

We never sell, rent, or trade personal data to third parties or offshore call centres.

5. Third-Party Processors

To deliver our services, we work with trusted infrastructure providers who act as data processors under appropriate data transfer agreements. These may include:

  • UK and EU-based website hosting providers for site delivery and security.
  • CRM and marketing automation infrastructure used to manage enquiries and client communications.
  • Communications APIs, such as WhatsApp and SMS/telephony providers, used to facilitate direct contact where you have requested it.
  • Stripe, for the secure processing of card and deposit payments.

All processors are engaged under written agreements that ensure compliance with UK GDPR data transfer requirements.

6. Data Retention

We retain personal data from enquiries only for as long as necessary to fulfil service delivery or maintain business correspondence. Unless a contractual relationship is formed, enquiry data is typically retained for up to 12 months, after which it is securely deleted or anonymised. Where a client relationship exists, data is retained for the duration of the engagement and the statutory accounting period thereafter.

7. Your Rights Under UK GDPR

As a data subject, you have the following rights regarding your personal data:

  • The right of access to your personal data.
  • The right to rectification of inaccurate data.
  • The right to erasure, also known as the "right to be forgotten".
  • The right to restriction of processing.
  • The right to data portability.

To exercise any of these rights, contact us at info@mail.withamsystems.co.uk.

8. Supervisory Authority

If you believe that your data has not been handled in accordance with the law, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). You can contact the ICO at ico.org.uk or by calling their helpline.