BR Digital Solutions Ltd Trading as Bold North Agency Customer Privacy Notice
This privacy notice tells you what to expect us to do with your personal information under the UK General Data Protection Regulation (UK GDPR).
Contact Details
- Company Name: BR Digital Solutions Ltd
- Trading As: Bold North Agency
- Corporate Email: admin@boldnorthagency.uk
What Information We Collect, Use, and Why
We collect or use the following information to provide and improve products and services for clients:
- Names and contact details
- Business names and corporate credentials
- Gender
- Usage data (including information about how you interact with and use our website, products, and services)
- Website user information
We collect or use the following personal information for information updates or marketing purposes:
- Names and contact details
- Profile information
- Marketing preferences
- Website and app user journey information
We collect or use the following personal information for research or archiving purposes:
- Names and contact details
- Website and app user journey information
Cookies & Tracking Technologies
Cookies are small files stored on your device that help us understand how you interact with our website. We use them to analyse traffic metrics, measure user activity, and optimise your browsing experience. These tracking metrics include time spent on pages, click-through paths, and device parameters. You can choose to disable or manage cookies through your browser settings, though disabling them may limit specific interactive features.
Third-Party Services
To operate efficiently and deliver our core services, we utilise trusted third-party tools and sub-processors. These external platforms process limited data strictly on our behalf under secure, compliant parameters. Each provider is contractually obligated to protect your data and use it solely for authorised commercial purposes.
- Google Analytics: Utilised for technical website performance insights and visitor traffic diagnostics.
- Payment Processors: Utilised for secure invoicing cycles and FCA-regulated financial transaction pathways.
- Cloud Platforms: Utilised for secure project documentation and centralised client asset collaboration.
Lawful Bases and Data Protection Rights
Under UK data protection law, we must have a "lawful basis" for collecting and using your personal information. There are specific lawful bases outlined in the UK GDPR.
Your data protection rights under UK GDPR include:
- Your right of access – You have the right to ask us for copies of your personal information, including where we get it from and who we share it with.
- Your right to rectification – You can ask us to correct or delete personal information you think is inaccurate or incomplete.
- Your right to erasure – You can ask us to delete your personal information.
- Your right to restriction of processing – You can ask us to limit how we use your personal information.
- Your right to object to processing – You can object to the processing of your personal data.
- Your right to data portability – You can ask us to transfer your personal information to another organisation or to you.
- Your right to withdraw consent – When consent is our lawful basis, you can withdraw it at any time.
If you make a request, we must respond without undue delay and within one month. To make a data protection rights request, contact us using the details at the top of this privacy notice.
Our Lawful Bases for Data Collection
To Provide and Improve Products and Services
- Consent – We have your permission after giving all relevant information.
- Contract – We need the information to enter into or carry out a contract.
- Legitimate interests – We use information in a way that benefits you or us without causing undue harm. Our interests include understanding client needs, delivering services effectively, and supporting client growth.
For Information Updates or Marketing
- Consent – We have your permission.
- Legitimate interests – We send occasional updates to existing contacts to share service changes or offer relevant insights. Communications always include an opt-out option.
For Research or Archiving Purposes
- Consent – We have your permission.
- Legal obligation – We must keep data to meet legal requirements.
- Legitimate interests – We retain minimal data to improve service quality and ensure continuity.
Data Sources and Retention
Where We Get Personal Information From
- Directly from you (e.g., website contact forms, audit requests, discovery meetings)
- Public sources (e.g., company websites, business directories, social media profiles)
- Referrals from clients or professional partners
- Internal tracking tools (e.g., domain registrars, site analytics, CRM systems)
How Long We Keep Information
- Client financial records: Retained for 6 years.
- Active project files: Retained for 2 years.
- Marketing contact data: Retained for no longer than 24 months without renewed consent.
Who We Share Information With
Data Processors
Bradley Roberts and authorized third-party infrastructure processors performing essential business functions:
- Website hosting and domain services
- Email and marketing automation tools
- Payment processing and FCA-regulated invoicing systems
- Secure cloud storage for project files
- IT infrastructure and security services
- CRM systems
Others We Share With
- Financial or fraud investigation authorities
- Regulatory or legal authorities where required by UK law
- Suppliers and professional service providers involved directly in delivering your contract
How to Complain
If you have concerns about how we use your personal data, contact us using the corporate details above. If you remain dissatisfied, you can complain directly to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website:ico.org.uk