1. Who is responsible for your information
CrownViolet is the controller of personal information described in this policy. The legal name and contact email must be completed in the site configuration before launch. Where applicable, controller details will appear in the footer.
2. Information collected
CrownViolet may collect your name, business name, business address, email address, optional phone number, enquiry subject and message. Project enquiries may also include your optional existing website, requested website type, approximate page count, domain ownership, branding or logo readiness, and project description. If you become a client, records may also include quotes, contracts, invoices, project communications, supplied content and payment status. Do not send card or bank details through website forms.
3. How information is collected
Information is collected when you submit an enquiry, correspond with CrownViolet, or enter into a project. The site also stores your cookie preference in your browser. No analytics provider is currently configured.
4. Purposes and lawful bases
- To respond to enquiries and prepare quotes: legitimate interests in operating and developing the business, or steps requested before entering a contract.
- To deliver and administer services: performance of a contract.
- To keep financial and tax records: compliance with legal obligations.
- To maintain site security and diagnose faults: legitimate interests in running a secure, reliable service.
- Optional analytics, if introduced: consent. It remains disabled until consent is given.
5. Retention
Unsuccessful enquiries should normally be deleted within 12 months after the last meaningful contact unless there is a reason to keep them longer. Client project and financial records should normally be retained for the period required by applicable tax, accounting and legal obligations. These periods must be confirmed against CrownViolet’s actual operating requirements. Information is deleted or anonymised when no longer needed.
6. Service providers
CrownViolet may use providers for hosting, email, form delivery, project collaboration, invoicing, accounting and website services. Only providers actually selected by CrownViolet will receive relevant information. A form provider has not yet been configured and must be documented here before the forms go live.
7. International transfers
Some selected providers may process information outside the UK. Where that happens, CrownViolet will check that an appropriate safeguard applies, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, as appropriate.
8. Security
Reasonable technical and organisational measures are used to protect personal information, including access controls, secure provider configuration and limiting data to what is needed. No internet service can promise absolute security.
9. Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict your information, object to processing, receive portable information, and withdraw consent without affecting earlier lawful processing. You may also ask for a decision involving solely automated processing to be reviewed. Identity may need to be verified before a request is completed.
10. Complaints
Please contact CrownViolet first so the concern can be addressed. You may also complain to the UK Information Commissioner’s Office (ICO) through ico.org.uk/make-a-complaint or by using the current contact details published by the ICO.
11. Contact
Use the contact form. A professional contact email must be added to the central business configuration before launch.
12. Changes
This policy may be updated when services, providers or legal requirements change. The effective date above will be updated when a revised policy takes effect.