Skip to content
Legal · Data protection

GDPR & Data Protection Notice

Last updated January 2026.

Template notice. This page is a professionally-worded starting point. Before publishing, review the highlighted [bracketed] fields with your business details, and have a lawyer in your jurisdiction confirm the final text.

This notice explains how [Legal Business Name] complies with the EU General Data Protection Regulation (GDPR), the UK GDPR and equivalent frameworks. It supplements — and does not replace — our Privacy Policy.

1. Data Controller

[Legal Business Name], registered at [registered address, country], is the Data Controller for personal data collected via this website (visitor forms, analytics cookies, newsletter). For enquiries write to privacy@nextsite-agency.com.

2. Data Processor role

When we deliver Services to Clients, we generally act as a Data Processor on the Client's behalf (for example, processing enquiries submitted through a Client website we host). A Data Processing Addendum ("DPA") is available on request.

3. Lawful bases we rely on

  • Contract — to deliver Services requested by a Client (Art. 6(1)(b) GDPR).
  • Legitimate interests — for site security, fraud prevention and improving our Services (Art. 6(1)(f) GDPR).
  • Consent — for analytics, marketing cookies and newsletter (Art. 6(1)(a) GDPR).
  • Legal obligation — for tax records and anti-money-laundering compliance (Art. 6(1)(c) GDPR).

4. Categories of data we process

  • Identity data (name, company).
  • Contact data (email, phone, address).
  • Content of enquiries you submit.
  • Billing data (invoice details).
  • Technical data (IP address, device, browser — anonymised in analytics).

We do not collect special-category data unless you voluntarily include it in an enquiry. We do not use automated decision-making with legal effect.

5. Retention periods

  • Prospect enquiries: [24 months] from last contact.
  • Client project data: for the duration of the engagement + [7 years] for tax records.
  • Newsletter: until you unsubscribe.
  • Backups: rolling 30 days.

6. International transfers

Some of our sub-processors (hosting, email, analytics) are located outside the EEA/UK. Where personal data is transferred, we rely on European Commission adequacy decisions or Standard Contractual Clauses ("SCCs"). A current sub-processor list is available on request.

7. Your rights

Under GDPR / UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Request erasure (subject to legal-retention exceptions).
  • Restrict or object to processing.
  • Data portability in a machine-readable format.
  • Withdraw consent at any time (for consent-based processing).
  • Lodge a complaint with your national data-protection authority.

To exercise any of these rights, email privacy@nextsite-agency.com. We respond within 30 days.

8. Data-protection contact

Data Protection contact: privacy@nextsite-agency.com
Postal: [registered address, country]

9. Supervisory authority

If you believe your rights have been infringed you may lodge a complaint with the data-protection authority of your country of residence. For UK residents, this is the Information Commissioner's Office (ICO). For EU residents, refer to your national authority.

10. Contact

General enquiries: hello@nextsite-agency.com