Telipato Marketing Ltd (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, share and protect personal data when you visit our website, enquire about our services, or work with us as a client. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where applicable — the EU General Data Protection Regulation (Regulation (EU) 2016/679).
1. Who we are
The data controller is Telipato Marketing Ltd, a marketing services company registered in England and Wales, with its registered office at 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. You can contact our data protection lead at hello@telipato.co.uk.
2. Personal data we collect
- Enquiry data: name, work email, company, phone, budget range and the contents of your message.
- Client data: billing details, signed contracts, project communications and meeting notes.
- Usage data: IP address, device, browser, pages visited, referral source — collected via privacy-friendly analytics where consent permits.
- Marketing data: your preferences for receiving communications.
3. Legal bases for processing
We rely on the following lawful bases under Article 6 UK GDPR:
- Contract: to perform our service agreements with clients.
- Legitimate interests: to respond to business enquiries, prevent fraud, secure our systems, and improve our services — balanced against your rights.
- Consent: for non-essential cookies, marketing emails and similar tracking.
- Legal obligation: to keep accounting records and respond to regulatory requests.
4. How we use personal data
- To respond to enquiries and prepare proposals.
- To deliver, manage and improve our services.
- To invoice and process payment.
- To send service updates and, with consent, marketing communications.
- To comply with legal, regulatory and tax obligations.
5. Sharing & sub-processors
We share personal data only with trusted sub-processors who help us operate, including hosting (Cloudflare, AWS), email delivery, CRM (HubSpot), analytics (Google Analytics 4, server-side), and accounting (Xero). Each is bound by data processing agreements compliant with UK and EU GDPR. A full list is available on request.
6. International transfers
Where personal data is transferred outside the UK or EEA, we rely on adequacy decisions or the UK International Data Transfer Addendum / EU Standard Contractual Clauses, supplemented by additional safeguards where required.
7. Retention
We retain enquiry data for up to 24 months, client records for 7 years after the engagement ends (to satisfy tax and accounting obligations), and marketing data until you withdraw consent.
8. Your rights
Under UK and EU GDPR you have the right to access, rectify, erase, restrict or object to processing, and to data portability. You may also withdraw consent at any time and lodge a complaint with the UK Information Commissioner’s Office (ICO) or your local supervisory authority. To exercise any right, contact hello@telipato.co.uk.
9. Security
We use industry-standard technical and organisational measures, including TLS encryption in transit, encryption at rest, least-privilege access controls, MFA, regular vulnerability scanning, and staff training.
10. Changes
We may update this policy from time to time. Material changes will be highlighted on this page with an updated effective date.