Privacy Policy
Privacy Policy
Last updated: [23/04/26]
The short version: We collect the minimum information we need to answer your questions, run our business, and improve this website. We never sell your data. You have rights under UK GDPR and we respect them. If you want us to delete your information, just ask.
1. Who's responsible for your data
The data controller for buildforleads.com is BuildForLeads.
Email: info@buildforleads.com
2. What information we collect
Information you give us directly
- Contact details when you fill in a form, email us, or book a call: name, email address, phone number, business name, website URL
- Details about your business that you choose to share — your services, goals, current marketing, budget
- Payment information if you become a client: processed by our payment provider, not stored by us directly
- Correspondence — emails, call recordings (only with your consent), and meeting notes
Information we collect automatically
- Technical data: your IP address, browser type, device type, operating system, referring URL
- Usage data: which pages you visit, how long you stay, what you click
- Cookies and similar technologies — see section 4 below
Information from third parties
If you click an ad of ours on Google or Meta and land on our site, those platforms pass us basic information about where you came from. If you book a call through Calendly or a similar tool, we receive your booking details.
3. Why we collect it and our legal basis
Under UK GDPR, we need a lawful reason to process your data. Here's what we do and why:
To respond to your enquiry
Legal basis: Legitimate interest (answering people who contact us) or, if you're an existing client, performance of our contract with you.
To deliver our services
Legal basis: Performance of contract.
To improve our website and marketing
We analyse anonymised and aggregated usage data to understand which pages work, which don't, and where visitors come from.
Legal basis: Your consent (via the cookie banner) for analytics and advertising cookies; legitimate interest for essential analytics.
To send you marketing
We only send marketing emails to people who have asked to receive them or who are existing clients. You can unsubscribe any time.
Legal basis: Your consent, or legitimate interest (for existing clients with the ability to opt out).
To comply with the law
We keep financial records for the period required by UK tax law.
Legal basis: Legal obligation.
4. Cookies and tracking
A cookie is a small text file a website places on your device. We use cookies for three things.
Essential cookies
These keep the website working — remembering your cookie choices, maintaining your session if you log into anything, and keeping the site secure. These don't need your consent because without them the site can't function.
Analytics cookies (Google Analytics 4)
We use Google Analytics to understand how visitors use our site — which pages are popular, where people come from, where they drop off. This helps us improve the site. Google Analytics uses cookies and processes data on Google's servers. We've configured it to anonymise IP addresses where possible.
Advertising cookies (Meta Pixel and Google Ads)
We use the Meta Pixel (for Facebook and Instagram advertising) and Google Ads conversion tracking. These cookies help us show relevant ads to people who've visited our site, and measure whether our advertising works. When you interact with our site, limited information about your activity may be shared with Meta and Google.
Your choice
Analytics and advertising cookies only run if you accept them via our cookie banner. You can change your mind any time by clicking the "Cookie preferences" link in our site footer, or by clearing cookies in your browser.
Blocking cookies won't break the site; you'll still be able to use everything. It just means we won't see your visit in our analytics and you won't see our retargeting ads.
5. Who we share data with
We share data with a small number of trusted service providers who help us run our business. Each of them is bound by contract to protect your data and use it only for the purposes we've agreed:
- Duda — our website platform (site hosting and forms)
- Google — Google Analytics, Google Workspace (email, drive), Google Ads
- Meta — Meta Pixel for advertising
- Our payment processor — [Stripe]
- Our email marketing tool — [Mailchimp], if you subscribe to our list
- Our accountant — for tax and bookkeeping purposes
We never sell your personal data. Ever.
We may disclose information if we're legally required to — for example in response to a court order or to comply with tax law.
6. International transfers
Some of our service providers — including Google and Meta — are based in the United States. This means your data may be transferred outside the UK. When this happens, we rely on approved safeguards (such as the UK International Data Transfer Agreement or the UK Extension to the EU-US Data Privacy Framework) to make sure your data is protected to UK standards.
7. How long we keep data
- Enquiries that don't become clients: up to 2 years, then deleted
- Client records: for the length of our relationship plus 6 years (for UK tax purposes)
- Marketing list subscribers: until you unsubscribe
- Website analytics: Google Analytics data is retained for 14 months
8. Your rights under UK GDPR
You have the right to:
- Access — ask for a copy of the personal data we hold about you
- Rectification — ask us to correct anything that's wrong
- Erasure — ask us to delete your data ("the right to be forgotten")
- Restriction — ask us to stop using your data in certain ways
- Portability — ask for your data in a format you can take elsewhere
- Objection — object to us using your data for marketing or based on legitimate interest
- Withdraw consent — any time, for anything we do on the basis of consent
To exercise any of these rights, email info@buildforleads.com. We'll respond within one month.
If you're not happy with how we've handled your data, you have the right to complain to the UK Information Commissioner's Office at ico.org.uk. We'd appreciate the chance to put things right ourselves first.
9. Security
We take data security seriously. We use industry-standard measures to protect your information: encrypted connections (HTTPS everywhere), password-protected systems with two-factor authentication on everything that supports it, and regular reviews of who has access to what.
That said, no online service can guarantee absolute security. If we ever have a data breach that affects you, we'll notify you and the ICO as UK GDPR requires.
10. Children
Our services are for businesses, not individuals under 18. We don't knowingly collect data from children. If you believe a child has given us their data, please email us and we'll delete it.
11. Changes to this policy
We'll update this policy from time to time. When we make a material change, we'll update the "last updated" date and — if the change is significant — email existing clients and newsletter subscribers to let them know.
12. Contact us
Privacy questions or requests: email info@buildforleads.com. We respond to all privacy requests within one month, usually much sooner.



