Privacy Policy
Last updated:
Ullmatech respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store and protect personal information when you visit our website, use our Website Health Check, contact us, become a client, subscribe to communications or otherwise interact with Ullmatech. It also explains your rights under applicable UK data protection law.
Who we are
Ullmatech provides website design and development, digital marketing, graphic design, website support and related digital services.
For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, Ullmatech is the controller of personal information collected through our website and services, except where we specifically act as a processor on behalf of a client.
Website: https://ullmatech.co.uk/
Email: hello@ullmatech.co.uk
Telephone: 01428 751188
Address: 21 Chapel Lane, Butleigh, Somerset, BA6 8TB, United Kingdom
Information we collect
The information we collect depends on how you interact with us.
Information you provide directly
This may include:
- your name;
- company or organisation name;
- job title;
- email address;
- telephone number;
- website address;
- information submitted through forms;
- project requirements and enquiries;
- correspondence with us;
- information provided when requesting a quote, consultation or review;
- marketing preferences; and
- information required to provide services to you.
We ask that you do not provide sensitive personal information unless it is genuinely necessary for the service you have requested.
Information collected automatically
When you use our website or digital services, we may collect technical and usage information such as:
- IP address;
- browser and device type;
- operating system;
- pages visited;
- referring pages;
- approximate location derived from technical information;
- dates and times of visits;
- interactions with pages and features;
- website performance and error information;
- analytics events;
- cookie and consent preferences; and
- other technical information required for security and operation of the website.
Some of this information is collected only where you have given the appropriate cookie or analytics consent.
Website Health Check
Ullmatech provides a Website Health Check that analyses websites and produces an automated report.
When you use the Website Health Check, we may process:
- the website address submitted for analysis;
- technical information collected from the website being analysed;
- website performance data;
- SEO information;
- mobile and usability information;
- technical website information;
- accessibility-related automated checks;
- Health Scores and category scores;
- issues identified during the analysis;
- priorities and recommendations generated from the analysis;
- the date and status of the Health Check;
- information about interactions with the resulting report; and
- technical information required to operate and secure the service.
If you unlock a report, request a Human Review or otherwise provide your details, we may also collect information such as your name, company or organisation and email address.
We use this information to:
- perform the Website Health Check;
- generate and deliver your report;
- provide access to your report;
- identify website improvement opportunities;
- respond to requests for further assistance;
- provide a Human Review where requested;
- improve the accuracy, usefulness and operation of the Health Check;
- understand how people use the Health Check;
- prevent misuse and protect the service; and
- where permitted by law, provide relevant information about Ullmatech services.
Automated analysis
The Website Health Check uses automated processes to analyse websites and generate scores, findings, priorities and recommendations.
These results are intended to provide useful guidance and highlight areas that may warrant further investigation. Automated testing cannot assess every aspect of a website and should not be treated as a substitute for appropriate professional or manual review.
In particular, automated accessibility testing does not constitute a complete accessibility or WCAG compliance audit.
The Website Health Check does not make decisions about individuals that produce legal or similarly significant effects.
Human Reviews
You may ask Ullmatech to carry out a Human Review following your Website Health Check.
If you request a Human Review, we may use information from your Health Check together with information publicly available on your website to assess areas such as:
- website design and usability;
- messaging and positioning;
- user experience;
- conversion opportunities;
- SEO;
- performance;
- mobile experience;
- technical issues; and
- other opportunities we consider relevant.
We may contact you using the details you provided to discuss the review and any recommendations.
Requesting a Human Review does not oblige you to purchase any services from Ullmatech.
How we use your information
We may use personal information to:
- provide our website and services;
- respond to enquiries;
- provide quotations or proposals;
- perform Website Health Checks;
- provide Human Reviews;
- manage client projects;
- communicate with clients and prospective clients;
- provide customer and technical support;
- administer contracts and payments;
- improve our website, services and user experience;
- analyse how our website and services are used;
- protect our systems against fraud, abuse and security threats;
- maintain appropriate business and financial records;
- comply with legal and regulatory obligations; and
- send relevant marketing communications where permitted by law.
We do not sell personal information.
Our lawful bases for processing
Under UK data protection law, we must have a lawful basis for processing personal information.
Depending on the circumstances, we may rely on:
Contract
Where processing is necessary to provide a service you have requested or to take steps at your request before entering into a contract.
For example, responding to a request for a quotation or delivering agreed services.
Legitimate interests
Where processing is necessary for our legitimate business interests and those interests are not overridden by your rights and interests.
These interests may include:
- operating and improving our business;
- responding to business enquiries;
- developing and improving our services;
- understanding how our services are used;
- maintaining relationships with clients and prospective clients;
- protecting our systems and services;
- preventing fraud and abuse; and
- relevant business-to-business marketing where permitted by law.
Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate and balance our interests against the rights and expectations of the individuals concerned.
Consent
Where you have specifically agreed to processing, such as certain analytics technologies or marketing communications where consent is required.
You can withdraw your consent at any time.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
Legal obligation
Where we need to process information to comply with a legal, regulatory, accounting or taxation requirement.
Marketing communications
We may send relevant information about Ullmatech services, website improvement opportunities, website design and development, digital marketing, support services and related services where permitted by law.
The rules governing electronic marketing depend partly on who the recipient is.
For corporate subscribers, such as limited companies and limited liability partnerships, UK electronic marketing rules generally permit relevant business-to-business marketing emails without prior consent. Where personal information relating to an individual business contact is used, UK data protection law still applies and we must have an appropriate lawful basis.
Different rules apply to individuals, sole traders and certain partnerships. Where consent is required by law, we will obtain the appropriate consent before sending marketing communications unless another lawful exception, such as the soft opt-in, applies.
You can opt out of marketing communications at any time by:
- clicking the unsubscribe link in our emails; or
- contacting us at hello@ullmatech.co.uk.
We will respect valid objections to the use of personal information for direct marketing.
We may retain limited information on a suppression list after you unsubscribe so that we can ensure we do not inadvertently add you back to marketing communications.
Current ICO guidance confirms this distinction between corporate subscribers and sole traders/certain partnerships.
Email automation and CRM
We use customer relationship management and email automation systems to manage enquiries, Website Health Check users, prospective clients and client communications.
This may include FluentCRM, which is operated within our WordPress environment.
Depending on your interaction with Ullmatech, our CRM may contain:
- your name;
- email address;
- company or organisation;
- website address;
- Website Health Score;
- category scores;
- identified website issues;
- Website Health Check priorities and recommendations;
- report information;
- marketing preferences;
- information about requests for a Human Review;
- tags or classifications relating to relevant services or website issues; and
- information about email engagement where permitted.
We may use this information to organise enquiries, provide requested communications, personalise relevant follow-up, understand areas where we may be able to assist and manage our relationship with you.
Automated tags, categories or scores within our CRM are used to organise information and communications. They are not used to make decisions about individuals that produce legal or similarly significant effects.
PostHog analytics and session replay
With your consent, we use PostHog to understand how visitors use Ullmatech websites and digital services.
PostHog may collect information relating to:
- pages visited;
- navigation through the website;
- clicks and interactions;
- feature usage;
- Website Health Check journey and conversion events;
- technical browser and device information;
- website performance;
- anonymous or pseudonymous identifiers;
- Health Check scores or broad result categories where configured; and
- session recordings showing how visitors interact with pages.
We use this information to understand how our website and services are being used, identify usability problems, investigate technical issues, understand where visitors abandon processes and improve our services.
Session replay
Where analytics consent has been given, PostHog’s session replay functionality may record a visual reconstruction of how a visitor interacts with our website.
This can include mouse movements, clicks, scrolling, navigation and interactions with website elements.
We configure session replay to mask form inputs and take steps to avoid deliberately sending names, email addresses, telephone numbers, submitted website addresses, report tokens, form contents or other unnecessary personal information to PostHog through our custom analytics events.
Session replay is used to understand website usability and technical problems, not to monitor individuals for unrelated purposes.
PostHog analytics and session replay should not activate until the appropriate analytics consent has been given. If analytics consent is withdrawn, analytics tracking and session recording will be stopped in accordance with our consent controls.
Website security and infrastructure
We use technical infrastructure and security services to operate and protect our websites.
These may process technical information such as IP addresses, request information, browser information and security signals where necessary to:
- deliver website content;
- prevent malicious traffic;
- detect bots;
- prevent attacks;
- maintain availability; and
- investigate technical or security problems.
This may include services provided by our hosting, content delivery network and security providers, including Cloudflare-related security technologies used by our hosting infrastructure.
Third-party service providers
We use trusted third-party service providers to help operate our business and provide our services.
Depending on the service, these may include providers of:
- website hosting and infrastructure;
- content delivery and security;
- analytics;
- consent management;
- email delivery;
- customer relationship management;
- website development infrastructure;
- payment processing;
- accounting;
- communications;
- project management;
- cloud storage; and
- other business software.
Current services may include PostHog, CookieYes, our hosting and security providers and other providers necessary to operate Ullmatech.
Where a provider processes personal information on our behalf, we take reasonable steps to ensure appropriate contractual and data protection arrangements are in place.
Some services may act as independent controllers for particular processing activities. Where applicable, their own privacy policies also apply.
Client websites and platforms
Where Ullmatech provides services involving a client’s website, application, CRM, email system or other digital platform, we may require access to systems or information controlled by that client.
This may include:
- website administration accounts;
- hosting accounts;
- analytics systems;
- CRM systems;
- mailing systems;
- databases;
- customer information; or
- other systems necessary to perform the agreed work.
We access and use this information only as necessary to provide the agreed services and subject to applicable contractual and legal obligations.
When we act as a processor
In some circumstances Ullmatech processes personal information solely on behalf of a client.
In those circumstances, the client is normally the controller and Ullmatech acts as its processor.
We process that information according to the client’s documented instructions and the applicable agreement between Ullmatech and the client.
Individuals wishing to exercise rights relating to information controlled by one of our clients may need to contact that client directly.
How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, accounting and business requirements.
As a general guide:
Website Health Checks and related lead information may normally be retained for up to 24 months after the most recent meaningful interaction, unless a longer period is appropriate because you become a client, continue to engage with us, request continued access to a service or we are required to retain information for another lawful reason.
General enquiries and prospective client information may normally be retained for up to 24 months after the last meaningful interaction.
Client and project information may be retained for the duration of our relationship and afterwards where reasonably necessary for contractual, legal, professional or business purposes.
Financial and accounting records may normally be retained for at least six years where required for taxation, accounting or legal purposes.
Marketing information may be retained while there is an appropriate lawful basis for marketing to you. If you unsubscribe or object, we may retain minimal suppression information for as long as necessary to respect that preference.
Analytics and session replay information is retained according to our configured analytics retention periods and business requirements. Session recordings may have a shorter retention period than aggregated analytics information.
We may delete or anonymise information earlier where it is no longer required.
Security
We take reasonable technical and organisational measures designed to protect personal information against:
- unauthorised access;
- accidental loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Measures may include access controls, authentication, encryption where appropriate, security monitoring, firewalls, backups, software updates and limiting access to information to people who need it.
No internet-based system can be guaranteed to be completely secure, but we regularly review our systems and security arrangements.
International transfers
Some of the service providers we use may process or store information outside the United Kingdom.
Where personal information is transferred internationally, we take reasonable steps to ensure an appropriate legal mechanism is in place where required.
Depending on the destination and provider, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another legally recognised transfer mechanism.
We also consider the safeguards provided by relevant service providers when selecting and configuring services.
Your data protection rights
Depending on the circumstances, UK data protection law may give you the right to:
- request access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to erase your information;
- ask us to restrict how we process your information;
- object to processing based on legitimate interests;
- object to the use of your personal information for direct marketing;
- request transfer of certain information in a portable format;
- withdraw consent where processing is based on consent; and
- complain to the Information Commissioner’s Office.
These rights are not absolute and may depend on the circumstances and the lawful basis on which information is processed.
To exercise a right, contact:
We may need to verify your identity before responding to certain requests.
Your right to object to direct marketing
You have the right to object to the processing of your personal information for direct marketing purposes.
If you object, we will stop using your personal information for that purpose.
You can also unsubscribe from marketing emails using the unsubscribe link included in the message.
We may retain sufficient information to record and respect your objection.
Complaints
If you have concerns about how we use your personal information, please contact us first so that we have an opportunity to resolve the issue.
You also have the right to complain to the UK’s data protection regulator:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk/
Children’s privacy
Our website and services are intended for businesses and professionals and are not directed at children.
We do not knowingly seek to collect personal information from children.
If you believe a child has provided personal information to us, please contact us.
External links
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices, content or security of external websites.
We recommend reviewing the privacy information provided by those websites before submitting personal information to them.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- our services;
- the technologies we use;
- our business practices; or
- legal and regulatory requirements.
The latest version will be published on this page and the “Last updated” date will be amended.
Where a change is significant, we may provide additional notice where appropriate.
Contact & legal information
If you have questions about this Privacy Policy, how we use personal information or your data protection rights, contact:
Ullmatech
21 Chapel Lane
Butleigh
Somerset
BA6 8TB
United Kingdom
Telephone: +44 (0) 1428 751188
Email: hello@ullmatech.co.uk
Website: www.ullmatech.co.uk
