Privacy Policy
We Are Neidin Limited
Last updated: June 2026
Thank you for trusting us with information about you. We take that trust seriously. This Privacy Policy explains what personal information we collect, how we use it, who we may share it with, how long we keep it for, and the rights you have under UK data protection law.
We have written this in plain English where possible. Some parts still need to be precise, but the aim is simple: you should know what we do with your information and why.
1. Who we are
We Are Neidin Limited is the data controller for the personal information described in this Privacy Policy. This means we are responsible for deciding how and why we use your personal information.
| Detail | Information |
|---|---|
| Company name | We Are Neidin Limited |
| Company number | 17094788 |
| Registered office | 12 Rosemary Way, Frome, England, BA11 5ET |
| hello@weareneidin.com | |
| Website | www.weareneidin.com |
We are registered with the Information Commissioner’s Office (ICO), the UK regulator for data protection. If you have a question about this Privacy Policy or how we use personal information, please contact us first using the email address above.
We do not have a statutory Data Protection Officer, but data protection queries can be sent to hello@weareneidin.com.
2. Who this Privacy Policy applies to
This Privacy Policy applies to personal information we collect and use about:
- people who visit our website or contact us through our website, email, phone, social media, contact forms or other channels;
- potential clients, including business contacts and people who ask for quotes or proposals;
- clients who buy services from us and client contacts who work for, represent or support those clients;
- people whose information is supplied to us by our clients so we can provide services to those clients;
- suppliers, associates, subcontractors, referrers and business partners; and
- people who interact with our marketing, email updates or social media content.
If you work for us, are employed by us, or are engaged by us under a separate contract, additional privacy information may be included in your contract or supplied separately where appropriate.
3. The types of personal information we collect
The personal information we collect depends on how you interact with us. We may collect and use the following types of information:
| Type of information | Examples |
|---|---|
| Identity and contact information | Name, business name, job title, email address, phone number, postal address, social media handles and other contact details. |
| Business and enquiry information | Information you give us when you contact us, request a quote, ask a question, complete a form, book a call or discuss a project. |
| Client and project information | Information needed to provide services, manage projects, create content, update websites, support social media activity, maintain client records and communicate with you. |
| Financial and transaction information | Invoice details, payment records, bank details where needed for supplier payments, and limited payment confirmation information from payment processors. |
| Communications information | Emails, messages, call notes, meeting notes, support requests, complaints, feedback and records of our interactions with you. |
| Marketing information | Your preferences for receiving marketing from us, records of consent, unsubscribe requests, email engagement such as opens and clicks, and responses to campaigns. |
| Website and technical information | Information about how you use our website, such as IP address, browser type, pages viewed, device information and analytics data. More detail is provided in our separate Cookie Policy. |
| Publicly available information | Information published on websites, business directories, public social media profiles or other publicly available sources, where relevant to our business relationship with you. |
| Third-party information supplied by clients | Personal information about a client’s customers, suppliers, staff, followers, contacts or other third parties where we need it to provide services to that client. |
We do not routinely collect special category information, such as health information, religious beliefs, political opinions, sexual orientation or biometric data. Please do not send us this type of information unless it is genuinely necessary. If you do provide it, we will only use it where we have a lawful basis and an appropriate condition under data protection law.
Our services are not aimed directly at children. If we process children’s information as part of work for a client, we usually do so on that client’s instructions and the client is normally responsible for explaining how that information is used.
4. How we collect personal information
We may collect personal information in the following ways:
- directly from you when you contact us, complete a form, email us, message us, book a call, buy from us or work with us;
- from our clients where they provide information so we can deliver services to them;
- from suppliers, associates, subcontractors, referrers and business partners;
- from publicly available sources such as websites, business directories and public social media profiles;
- from social media platforms when you interact with our pages, posts, adverts or messages; and
- automatically through our website and email tools, including cookies and similar technologies where applicable.
5. How and why we use personal information
We only use personal information where we have a lawful reason to do so. The table below explains the main ways we use personal information and the lawful bases we usually rely on.
| Purpose | What this means | Lawful basis |
|---|---|---|
| Responding to enquiries and messages | To reply to you, answer questions, provide information and keep a record of what was discussed. | Legitimate interests; steps before entering into a contract. |
| Providing quotes and proposals | To understand your needs, prepare pricing, recommend services and follow up where appropriate. | Legitimate interests; steps before entering into a contract. |
| Providing services to clients | To deliver website, social media, content, admin, design, marketing, support, hosting, maintenance or related services. | Contract; legitimate interests. |
| Managing client relationships | To manage projects, keep records, provide support, review work, deal with queries and maintain communication. | Contract; legitimate interests. |
| Client-provided third-party data | To provide services to a client where that client has supplied information about their own contacts, customers, suppliers, staff or users. | Usually processed on the client’s instructions as processor; the client determines the lawful basis. |
| Invoicing, payments and accounting | To issue invoices, process payments, keep accounting records, manage debts and meet tax obligations. | Contract; legal obligation; legitimate interests. |
| Supplier and associate management | To manage contracts, pay invoices, commission work and keep records of work carried out. | Contract; legal obligation; legitimate interests. |
| Email newsletters and updates | To send updates, resources, offers or information you have signed up to receive. | Consent, or legitimate interests where permitted by law. |
| Marketing to business contacts | To contact relevant business contacts about services that may be of interest, where lawful and appropriate. | Legitimate interests, balanced against your rights and interests. |
| Improving our website and services | To understand what works, improve user experience, assess performance and develop our services. | Legitimate interests; consent where required for cookies or similar technologies. |
| Handling complaints, requests and disputes | To respond to data protection requests, complaints, legal issues, chargebacks, insurance matters or disputes. | Legal obligation; legitimate interests. |
| Security and business protection | To protect our systems, accounts, files, website, clients, business and legal rights. | Legitimate interests; legal obligation where applicable. |
Where we rely on legitimate interests, we consider whether our use of your information is fair, proportionate and within what you would reasonably expect. You can object to processing based on legitimate interests in certain circumstances. See section 14 for more information about your rights.
6. Email marketing and communications
If you sign up to our email list, download a resource, ask to receive updates or otherwise opt in to marketing from us, we may send you relevant emails. We may use email marketing software to understand whether emails have been opened and whether links have been clicked, so we can improve what we send.
Existing clients and business contacts may receive occasional updates about services that are relevant to their business relationship with us, where this is allowed by law. You can opt out of marketing emails at any time by using the unsubscribe link in our emails or by contacting us at hello@weareneidin.com.
We do not sell, rent or trade email lists with anyone else.
7. Website, cookies and similar technologies
We use cookies and similar technologies on our website. These may help the website work properly, understand how visitors use the site, improve performance, remember preferences, support security and, where used, help with marketing or advertising activity.
Full details of the cookies and similar technologies we use, why we use them, and how you can manage your choices are set out in our separate Cookie Policy.
Where consent is required for cookies, pixels, analytics, advertising or similar technologies, we will ask for consent through our cookie banner or consent management tool.
8. Social media
We use social media platforms such as Facebook, Instagram, LinkedIn and other relevant platforms. If you interact with our pages, posts, comments, adverts or messages, we may see and keep a record of that interaction.
Social media platforms also use your information for their own purposes. Their own privacy notices explain how they collect and use personal information when you use their services.
Where we manage social media pages, content, competitions, messages, comments or adverts for a client, we may process information on that client’s behalf. In those cases, the client is usually the controller and we act in line with their instructions.
9. When we act for clients
Some of our work involves handling personal information for our clients. For example, we may help with websites, forms, mailing lists, social media pages, messages, content planning, community outreach, customer enquiries, design work, analytics or other support services.
Where a client decides why and how personal information is used, the client is usually the data controller. In that situation, we usually act as a data processor and only process the information in line with the client’s instructions, our contract with them and applicable data protection law.
If you contact us about personal information we process on behalf of a client, we may need to pass your request to that client or ask you to contact them directly. We will still support the client where needed so they can respond properly.
10. Who we share personal information with
We may share personal information with trusted third parties where this is necessary to run our business, provide our services, meet legal obligations or protect our rights. These may include:
- website hosting providers, domain providers and website support tools;
- email, cloud storage, file sharing and productivity platforms;
- accounting software, banks, payment processors and bookkeepers or accountants;
- project management, CRM, form, booking and communication tools;
- email marketing, analytics, advertising and social media platforms;
- IT support, security providers, developers, designers, virtual assistants, subcontractors and associates;
- professional advisers such as accountants, insurers, legal advisers and consultants;
- clients, where we are processing information for them or helping them respond to a request;
- regulators, law enforcement, HMRC, courts or other authorities where required by law; and
- third parties involved in a business sale, restructure or similar transaction, if this ever becomes relevant.
We only share personal information where there is a proper reason to do so. Where third parties process information for us, we expect them to protect it properly and only use it for the agreed purpose.
11. International transfers
Some of the platforms and service providers we use may process personal information outside the UK. This is common for small businesses using mainstream tools such as cloud storage, email, analytics, website, accounting, payment, marketing and social media platforms.
Where personal information is transferred outside the UK, we take steps to make sure appropriate safeguards are in place. This may include adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, International Data Transfer Agreements, the UK Addendum to EU Standard Contractual Clauses, or other safeguards permitted under UK data protection law.
12. How we keep information secure
We take reasonable steps to protect personal information from loss, misuse, unauthorised access, disclosure, alteration or destruction. This includes using appropriate technical and organisational measures, such as password protection, access controls, secure systems, limited user permissions, backups and confidentiality obligations for people who work with us.
No system is completely risk-free, but we aim to use trusted tools and sensible working practices. Access to personal information is limited to people who need it for their role or for the service being provided.
13. How long we keep personal information
We only keep personal information for as long as we need it for the purpose it was collected, including to provide services, manage our relationship with you, meet legal, accounting and tax requirements, resolve disputes, respond to complaints and protect our business.
The periods below are general guidelines. We may keep information for longer where required by law, where there is an ongoing dispute, where we need to protect our legal rights, or where another valid reason applies.
| Type of information | Typical retention period |
|---|---|
| General enquiries | Up to 2 years after the last meaningful contact, unless the enquiry becomes a client relationship. |
| Quotes and proposals | Up to 2 years after the last contact, or longer if they become part of a client record. |
| Client records and project files | Up to 6 years after the end of the client relationship, unless a longer period is needed for legal, contractual, insurance or dispute reasons. |
| Invoices, accounting and payment records | Usually 6 years from the end of the relevant financial year, or longer where required by law. |
| Website and contact form submissions | Up to 2 years, unless they become part of a client record or complaint. |
| Email marketing records | Until you unsubscribe or we remove inactive contacts. We may keep a suppression record to make sure we do not contact you again by mistake. |
| Supplier, associate and subcontractor records | Up to 6 years after the end of the working relationship. |
| Complaints and data protection requests | Up to 6 years after the complaint or request is resolved. |
| Client-provided third-party data | In line with our contract with the client, the client’s instructions and the nature of the service provided. |
14. Your rights
Depending on the circumstances, you may have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to delete your personal information;
- ask us to restrict how we use your personal information;
- object to our use of your personal information;
- ask us to transfer your personal information to another provider where this right applies;
- withdraw consent where we rely on consent; and
- complain to the Information Commissioner’s Office.
To exercise your rights, please contact us at hello@weareneidin.com. We may need to ask for information to confirm your identity before responding.
If you ask for a copy of the personal information we hold about you, we will respond without undue delay and normally within one month. We will carry out reasonable and proportionate searches for the information requested. If we need clarification to deal with your request, we may ask you for more information.
Some rights are not absolute. For example, we may need to keep certain records to comply with legal, accounting, tax, contractual, insurance or regulatory obligations.
15. Complaints
If you have a complaint about how we use your personal information, or how we have responded to a data protection request, please contact us first so we can try to resolve it.
Please email hello@weareneidin.com and include your name, contact details, what your concern relates to, and what outcome you are looking for.
We will acknowledge your complaint within 30 days of receiving it. We will then investigate and respond without undue delay, keep you informed where appropriate, and tell you the outcome of our review.
If you are not happy with our response, you can complain to the Information Commissioner’s Office at www.ico.org.uk.
16. Keeping your information up to date
It is important that the personal information we hold about you is accurate and up to date. Please let us know if your details change by emailing hello@weareneidin.com.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be available on our website. If we make significant changes, we may take additional steps to let people know where appropriate.
End of Privacy Policy
