Matthew Alexander Design
Privacy Policy
Introduction
This Privacy Policy explains how I, Matthew Alexander Design (“I”, “me”, “my”), collect, use, store, and protect your personal data when you visit this website (matthewalexanderdesign.com), get in touch with me, or become a client of mine.
By using this website, you agree to the terms set out in this policy. This policy applies alongside my Cookie Policy, which covers cookies in more detail, and my Website Design & Development Agreement, which covers data protection terms specifically for clients.
Who This Policy Applies To
This policy applies to:
- Anyone who visits this website
- Anyone who gets in touch via the contact form, by phone, or by email
- Clients who engage me for a website build, and anyone on an ongoing Care Plan
It doesn't apply to:
- Other Websites — This site sometimes links to other sites — for example, live client websites in my portfolio, or my social media pages. I'm not responsible for how those sites handle your data, and I'd encourage you to check their own privacy policies.
- Children — This website is aimed at business owners and isn't directed at children. I don't knowingly collect personal data from anyone under 18. If you believe a child has given me personal data, please contact me at hello@matthewalexander.design so I can remove it.
Information I collect
a. Automatically, via cookies
This website uses cookies, set through Squarespace, my website hosting provider. Essential cookies are always active, as the site can't function properly without them. Optional Squarespace Analytics cookies are only used if you consent to them via the cookie banner, and help me understand which pages are useful so I can improve the site. I don't currently use Google Analytics, Facebook Pixel, or any advertising or tracking cookies — see my Cookie Policy for the full detail on what's used and how to change your preferences at any time.
b. Information you give me directly
- Contact form — your name, business name, email address, phone number, what you'd like help with, and your message.
- Onboarding Questionnaire (clients only) — business details, website content, style preferences, and the practical information I need to build your site. This is collected via a Google Form.
- Becoming a client — your name, business details, contact details, and the information needed to invoice and deliver your project.
- Care Plan clients — your bank details, if you pay by Direct Debit (collected and held securely by GoCardless, not by me directly), plus whatever details you send me as part of an update request.
Third-Party Services & Data Sharing
I use a small number of trusted third-party services to run this business. Some of these process personal data on my behalf. Here's who they are and what they do:
- Squarespace — hosts this website, runs the contact form, and (with your consent) collects analytics data about how the site is used.
- Zapier —automatically passes new contact form submissions from Squarespace into my private client records, so I don't lose track of an enquiry.
- Google (Forms, Sheets, Workspace) — stores onboarding questionnaire responses and client records, and runs my business email.
- GoCardless — a UK-based Direct Debit provider. If you're on a Care Plan, GoCardless processes and holds your bank details directly — I never see or store your full bank details myself.
- Stripe — used only as a backup card payment option. If you choose to pay this way, Stripe processes your card details directly.
It's worth understanding the difference between a data controller and a data processor. I'm the data controller for this website and my client relationships — I decide what personal data is collected and why. The companies above are data processors: they handle certain data on my behalf, under my instructions, but don't decide how it's used. I only work with processors I trust to handle data responsibly, and I don't sell or share your personal information with anyone for marketing purposes.
How I Use Your Information
I use your information to respond to enquiries, deliver the website or Care Plan you've agreed with me, keep accurate business and accounting records, and — only where you've given consent — understand how this website is used so I can improve it.
Legal basis for processing
Under UK GDPR, I need a valid reason for using your personal data. Depending on the situation, I rely on one of the following:
- Consent — for example, using optional analytics cookies. You can withdraw this consent at any time via the cookie preferences link on the site.
- Contractual Necessity — for example, using your details to design, build, and invoice your website, or to deliver your Care Plan.
- Legitimate Interests— for example, replying to an enquiry, keeping basic records of who's contacted me, or showcasing completed projects in my portfolio (see Section 11). You can object to this at any time.
- Legal Obligation — for example, retaining invoices and contracts for tax and accounting purposes.
Data Storage & Security
Your data is stored securely through the services listed in Section 4 — Squarespace, Google, Zapier, GoCardless, and Stripe. I take reasonable, industry-standard steps to keep your information secure, but no method of online storage or transmission can ever be guaranteed 100% secure, and by using this website you understand and accept that.
Data Retention
I only keep personal data for as long as I actually need it:
- Enquiries that don't become a project — kept for up to 12 months, then deleted.
- Client records, contracts, and invoices — kept for at least 6 years after our work together ends, in line with standard UK tax and accounting record-keeping requirements.
- Cookie data — retention varies by cookie type — see my Cookie Policy, and Squarespace's own cookie documentation, for specifics.
If you'd like any of your data updated, corrected, or deleted sooner than this, get in touch and I'll take reasonable steps to accommodate your request.
International Data Transfers
Some of the services I use — including Squarespace, Zapier, and Google — are based in, or process data in, the United States. GoCardless is UK-based. Where a service does transfer data outside the UK, that transfer is protected either by a UK-recognised adequacy arrangement (such as the UK Extension to the EU-US Data Privacy Framework) or by Standard Contractual Clauses, as required under UK GDPR. If you have any concerns about this, feel free to get in touch.
Your Data Protection Rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data I hold about you.
- Rectification — ask me to correct anything inaccurate or incomplete.
- Erasure — ask me to delete your personal data, in certain circumstances.
- Restriction — ask me to limit how I use your data.
- Objection — object to my use of your data where I'm relying on legitimate interests.
- Portability — request your data in a structured, commonly used format.
- Withdraw Consent — where I'm relying on consent (such as analytics cookies), withdraw it at any time.
To use any of these rights, just email me at hello@matthewalexander.design
Automated Decision Making
I don't use your personal data for any automated decision-making or profiling that has a legal or similarly significant effect on you. Every enquiry and project is looked at by me, personally.
Testimonials & Portfolio Use
If you become a client, I may show your completed website in my portfolio and marketing materials, including on this website and my social media pages, unless you ask me not to, in writing — as set out in my Website Design & Development Agreement. If you give me a testimonial, I'll only publish it with your permission, and I'll use your name and business name as you've given them to me, unless you ask me to anonymise it.
Third-Party Links
This website may contain links to other websites — for example, live client sites in my portfolio, or my social media profiles. I'm not responsible for the privacy practices of these external sites, and I'd recommend checking their own policies before sharing any personal data with them.
Data Breach Commitment
If a personal data breach occurs that's likely to put your rights and freedoms at risk, I'll report it to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to you specifically, I'll also contact you directly, without undue delay.
How to Complain
If you're unhappy with how I've handled your personal data, please contact me first at hello@matthewalexander.design — I'll always try to put things right.
If you're not satisfied with my response, or would rather raise it independently, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:
- Website — www.ico.org.uk/make-a-complaint
- Helpline — 0303 123 1113
- Post — Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
More Information
If you have any questions about this Privacy Policy, contact me at hello@matthewalexander.design
Data Controller Information
Matthew Alexander Design (“I”, “me”, “my”)
Sole trader, UK-based
Changes to This Policy
I may update this policy from time to time — for example, if I start using a new tool on the website. The “last updated” date at the top will always reflect the most recent version. If you continue to use this website after an update, that means you accept the revised policy.