Legal
Privacy Policy
Last updated: 25 July 2026
1. Introduction
Essor AWD (“we”, “us”, “our”) is an independent web studio based in United Kingdom. We take the privacy of everyone who visits our website, uses our tools, or engages us as a client seriously. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where we act as a data controller, we are responsible for deciding how your personal data is handled. Where we process data on behalf of our clients (for example, data flowing through a website we build and host), we act as a data processor and only handle it on documented instructions.
2. Information we collect
Depending on how you interact with us, we may collect:
- Your name
- Email address
- Telephone number
- Business or trading name
- Billing and payment information (processed by our payment provider)
- Account details, including a hashed password if you register
- Messages you submit through contact, brief or support forms
- Files, briefs and content you upload to your client portal
- Inputs and prompts you submit to our AI-assisted tools
- Cookies and similar technologies (see section 5)
- Device information (type, operating system, screen size)
- Browser information (name, version, language)
- IP address and approximate location derived from it
- Analytics information about the pages you visit and actions you take
- Aggregated usage statistics about how our services are used
3. How we use your information
We use personal data for the following purposes:
- Providing the services you have requested
- Operating and maintaining core website functionality
- Delivering AI-assisted features you have chosen to use
- Providing customer support and responding to enquiries
- Managing your account and client workspace
- Preventing fraud and abuse
- Security monitoring, logging and incident response
- Improving our services, tools and content
- Meeting legal, tax and regulatory obligations
- Sending marketing communications where you have given consent
Our lawful bases include performance of a contract, our legitimate interests in running a secure and well-functioning service, compliance with legal obligations, and — where required — your consent, which you may withdraw at any time.
4. AI processing
Some features on this website use AI systems to generate suggestions such as meta descriptions, headlines or audit summaries. Information you submit to these tools may be sent to a trusted AI provider solely to produce the output you have requested. We do not use your inputs to train third-party public models, and we do not sell your data.
You should avoid submitting unnecessary personal or sensitive information (such as health, financial or identity data belonging to third parties) into any AI tool on this or any other website. AI outputs are provided as a starting point and should always be reviewed by a human before being relied on.
5. Cookies and similar technologies
We use a small number of cookies and similar technologies:
- Essential cookies — required for the site to work, such as remembering your session and CSRF protection.
- Authentication cookies — keep you signed in to the client portal or admin area.
- Security cookies — help detect abuse and protect against automated attacks.
- Analytics cookies — help us understand which pages are useful and where the site can be improved.
Where cookies are not strictly necessary, we ask for consent before setting them. You can control cookies through your browser settings, but disabling essential cookies will prevent the site from working properly.
6. Third parties we work with
We rely on a small number of trusted service providers to deliver our services. Where applicable, these include:
- Stripe — payment processing
- Google — authentication (Sign in with Google)
- Email delivery providers — sending transactional and support email
- Hosting and infrastructure providers — running the website and databases
- Analytics providers — measuring aggregate site usage
- AI providers — generating output for the tools you have chosen to use
These providers only receive the information they need to perform their part of the service, are bound by contractual data-protection terms, and are not permitted to use your data for their own purposes. Where data is transferred outside the UK, it is protected by appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
7. Data retention
We keep personal data only for as long as we need it for the purposes described in this policy. Contact enquiries are typically retained for up to 24 months so we can follow up on conversations. Client records, projects, invoices and related accounting information are retained for at least 6 years to meet UK tax and regulatory requirements. Security logs and audit trails are retained for up to 24 months.
You may request that we delete data we hold about you at any time. Where we are legally required to keep certain records (for example, invoices), we will explain this and delete anything not covered by that obligation.
8. Security
We use industry-standard security practices to protect personal data, including encryption in transit and at rest, strong authentication, role-based access controls, activity logging, and continuous monitoring for suspicious behaviour. Access to client data is restricted to staff who need it.
No system connected to the internet can be guaranteed to be completely secure. We maintain an incident response process and will notify affected individuals and the Information Commissioner's Office where required by law.
9. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Ask us to correct inaccurate or incomplete data
- Ask us to erase your personal data where legally possible
- Restrict how we process your data in certain circumstances
- Receive a copy of your data in a portable format
- Object to processing based on our legitimate interests
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk)
To exercise any of these rights, email us at hello@essorawd.com. We will respond within one month.
10. Contact us
For any questions about this policy or how we handle your data, contact:
Essor AWD
United Kingdom
hello@essorawd.com
11. Updates to this policy
We may update this policy from time to time to reflect changes in our services or legal obligations. The latest version will always appear on this page with the revised “last updated” date at the top. Material changes will be communicated to registered users by email or in-app notice.
See also our Terms of Service.
