LEGAL
Privacy Notice
Fractal Studio takes your data privacy seriously. Because we collect and use personal data to provide our services, we are a "Data Controller" and are responsible for complying with Data Protection Laws and the General Data Protection Regulation (GDPR).
LAST UPDATED: 21 AUGUST 2026
In this Privacy Notice, we want to inform you what information we collect, how we use it, and what rights individuals have in relation to the collection and processing of their personal data.
Our contact details
Daniel Carpenter, 80 Alexander McLeod Place, Fallin, Stirling FK7 7HP
dan@fractalstudio.co.uk · 07942 275326
If you have any questions about this Privacy Notice or how we manage your personal data, please contact us using the details above.
What personal data we collect and process
- General contact details, such as name, address, email address, and telephone number
- Details of goods and services provided to you
- Financial details, such as payment or invoicing information
- Information obtained through our use of cookies and similar technologies (see Cookies & Similar Technologies below)
- Your marketing preferences
How we collect your information
In most cases we collect your data directly from you. We collect and process it when you:
- Complete an online "contact us" form
- Speak to us on the telephone to discuss or use our services
- Email or write to us to enquire about or use our services
- View our website via your browser's cookies
Why we collect your information
Where we collect and process personal data, we identify both the purpose and legal basis for doing so. There are six possible legal bases:
- Consent: where we have consent from the individual to process their personal data for one or more specific purposes.
- Contract: where the processing is necessary for the performance of a contract to which you are party, or to take steps at your request prior to entering into a contract.
- Legal obligation: where the processing is necessary for compliance with a legal obligation we are subject to.
- Vital interests: where the processing is necessary to protect the vital interests of you or another person.
- Public interest: where the processing is necessary for a task carried out in the public interest or in the exercise of official authority.
- Legitimate interests: where the processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your own interests or fundamental rights and freedoms, in particular where you are a child.
In practice, this means we use your information to:
- Understand your requirements before entering into a contract of service with you, and to ensure any contract meets your needs (Contract)
- Fulfil our contract with you and provide the agreed services (Contract)
- Manage our business operations and comply with internal policies and procedures (Legitimate interests)
- Notify you about changes that may affect you (Legitimate interests)
- Market similar services to existing clients where relevant to you (Legitimate interests)
- Send electronic marketing to new contacts (Consent)
- Comply with legal obligations, and requirements from law enforcement, courts, or regulatory bodies (Legal obligation)
- Identify and prevent fraud (Legitimate interests)
- Communicate with you about a potential or existing contract for services (Contract)
Where we rely on your consent, you have the right to withdraw it at any time by contacting us using the details above. Where we rely on legitimate interests, this is to improve our service, security, and to prevent fraud or illegal activity, in favour of the wellbeing of our clients and business.
Who we share your information with
From time to time we may share your personal information with:
- Accountants and auditors
- Payment service providers
- Lawyers
- Specialist experts, such as website operators or marketing companies
- Fraud detection agencies
- Police and law enforcement agencies, where reasonably necessary for the prevention or detection of crime
- Regulators and governing bodies, such as HMRC
We do not transfer personal data outside of the EU/UK. Where a recipient of your personal data is located outside your country, or has offices in a country where data protection laws provide a different level of protection than your own, we put appropriate safeguards in place.
Automated decision-making or profiling
We do not process personal data for automated decision-making or profiling.
How long we keep personal data
We retain personal data in accordance with legal and regulatory requirements, and for no longer than necessary to fulfil the purposes set out in this notice. The retention period depends on why the information was collected, and is never indefinite. We delete personal data, or render it anonymous, in line with our retention and deletion practices, unless we're legally required to keep it longer (for example, for tax, accounting, or auditing purposes).
In general, we retain data:
- For as long as it's necessary for the provision of our services: for the duration of any contract with you, and for 12 months afterwards, to maintain and improve our services, keep our systems secure, and maintain appropriate business and financial records.
- Where required by statutory, contractual, or similar obligations: for example, storage obligations arising from law or regulation, or in relation to a pending or future legal dispute.
Your rights as a data subject
- Right to access: request details of the personal information we hold or process about you, and copies of it. We do not usually charge for this.
- Right to rectification: request that we correct information you believe is inaccurate, or complete information you believe is incomplete.
- Right to erasure: request that we erase your personal information under certain conditions.
- Right to restrict processing: request that we restrict the processing of your personal data under certain circumstances.
- Right to object: object to our processing of your data under certain conditions.
- Right to data portability: request that we transfer the data we've collected to another organisation, or directly to you, under certain conditions.
- Right to withdraw consent: where you've previously given consent, withdraw it at any time.
To exercise any of these rights, please contact us using the details at the top of this page.
You also have the right to complain to the supervisory authority. If you feel we haven't addressed your concern satisfactorily, you can contact the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Cookies & similar technologies
We use a small number of cookies and similar technologies:
- Google reCAPTCHA (
_GRECAPTCHA), expires after 730 days. Used to protect our contact form from spam and abuse. This one is always active, as it's necessary for the contact form to work. - Google Analytics (
_ga,_ga_<container-id>), expires after 13 months. Used to understand how visitors use the site (pages viewed, time on site) in aggregate, so we can improve it. This only runs if you accept it in the cookie banner shown on your first visit, and you can decline it there. - Theme preference (stored in your browser's local storage, not a cookie), remembers whether you've chosen light or dark mode. Strictly necessary for the site to display correctly on your return visits, and never shared with anyone.
See Google's own Privacy Policy for how they process data collected via reCAPTCHA and Analytics. We do not use any advertising or cross-site tracking cookies.
Data security
We protect your personal data through technical and organisational security measures, to minimise risks of data loss, misuse, unauthorised access, and unauthorised disclosure or alteration. Data is stored on secure servers, and we use appropriate safeguards including encryption where relevant.
Changes to this Privacy Notice
We keep this Privacy Notice under regular review. This notice was last updated on 21 August 2026.