This policy explains what personal data we collect when you use this website or contact us about a project, why we hold it, how long we keep it and what rights you have over it. We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are (data controller)

This website is operated by Currentli Ltd, a company registered in England & Wales (company number 17269052), registered office 45 Badgers Rise, Reading, RG5 3AJ, United Kingdom. In this policy, "we", "us" and "our" refer to Currentli Ltd, which is the data controller for the personal data described below.

2. Contacting us about your data

Send data protection requests and questions to [email protected], or write to the registered office above. We have not appointed a Data Protection Officer, as we are not required to; requests are handled by a company director.

3. What personal data we collect

SourceData
Enquiry form on this website Your name, email address, the services you ticked, and the message you write. Nothing on the form is compulsory except your name, email address and message.
Email, telephone or a call you book with us Your name, contact details, company name if you give one, and the content of what we discuss, including any technical detail about your systems that you choose to share.
Client and project records Contact details for the people we work with, contracts, estimates, invoices and payment records. Where we hold credentials for your systems, they are stored in an encrypted password manager and are not shared outside the two of us.
Web server logs (created by our hosting provider) IP address, browser and device type, pages requested, date and time. Used for security and to keep the site running.
Your browser's local storage A single entry recording whether you accepted or declined non-essential cookies. It contains no identifier and never leaves your device. See our Cookie Policy.

We do not run analytics, advertising or tracking scripts on this website, and we do not collect special category data. We do not knowingly collect data about children.

4. Why we process it, and our lawful basis

PurposeLawful basis (Art. 6 UK GDPR)
Replying to your enquiry, preparing a proposal or estimate Legitimate interests — you have approached us about work, and answering you is the obvious expectation on both sides.
Delivering a project we have agreed, and supporting it afterwards Contract — processing is necessary to perform our agreement with you.
Invoicing, accounting and tax records Legal obligation — the Companies Act 2006 and UK tax law require us to keep these records.
Keeping the website and our systems secure Legitimate interests — preventing abuse, fraud and downtime.
Non-essential cookies, if we ever add any Consent — nothing non-essential loads unless you accept it, and you can change your mind at any time.

We do not send marketing email. If we ever do, it will be on the basis of your consent or the soft opt-in under PECR, and every message will carry an unsubscribe link.

5. How long we keep it

6. Who we share it with

We do not sell your personal data, and we do not share it for anybody else's marketing. We use a small number of service providers who process data on our instructions:

We may also disclose data where the law requires it, or to take or defend legal claims.

7. International transfers

Our own hosting and email are located in the United Kingdom or the European Economic Area. Google and Cloudflare, named above, may process the technical request data outside the UK, including in the United States. Those transfers rely on the UK's adequacy regulations for the EEA where applicable, and otherwise on the International Data Transfer Addendum to the European Commission's standard contractual clauses. You can ask us for details of the safeguard applied to a specific provider.

8. Your rights

Under the UK GDPR you have the right to:

Withdrawing consent

Where we rely on consent, you can withdraw it at any time and it costs you nothing. For cookies, clear this site's data in your browser and the banner will ask you again. Withdrawal does not affect processing that already happened lawfully.

How to exercise your rights

Email [email protected] and tell us what you want. We respond within one month of receiving your request, as the UK GDPR requires. If the request is complex we may extend that by up to two further months, and we will tell you if that happens. We may ask you to confirm your identity first. There is no charge.

9. Complaints

If you think we have handled your data badly, tell us first — email [email protected] and we will look into it.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): www.ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

10. Security

This site is served over HTTPS. Access to email, code repositories and client credentials is protected with multi-factor authentication and a password manager. Only the two of us have access. If a breach ever affects your rights and freedoms, we will notify the ICO within 72 hours and tell you without undue delay.

11. Cookies

This site sets no cookies of its own and loads no analytics or advertising scripts. The consent banner records your choice in your browser's local storage. The full detail, including the third-party requests described in section 6, is in our Cookie Policy.

12. Changes to this policy

If we change how we handle personal data we will update this page and move the date at the top. Where a change materially affects you, we will tell you by email.