Privacy Policy
Last Updated: December 7, 2025
1. Introduction
Canarlo ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner's Office (ICO).
2. Data Controller Information
The data controller responsible for your personal data is:
Canarlo
Leeds, United Kingdom
Email: info@canarlo.com
Phone: 07861 858394
3. Information We Collect
3.1 Personal Information You Provide
When you contact us or request our services, we may collect:
- Name and contact details (email address, phone number)
- Company name and business information
- Project requirements and specifications
- Any other information you choose to provide in contact forms or communications
3.2 Automatically Collected Information
When you visit our website, we automatically collect certain information:
- Browser type and version
- Operating system
- IP address (anonymized)
- Pages visited and time spent on pages
- Referring website addresses
- Device information
3.3 Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your browsing experience. For detailed information about our use of cookies, please see our Cookie Policy.
4. Legal Basis for Processing
Under UK GDPR, we process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific purposes (e.g., marketing communications, analytics cookies)
- Contractual Necessity: To perform a contract with you or take steps at your request before entering into a contract
- Legitimate Interests: For our legitimate business interests, such as improving our services, provided these don't override your rights
- Legal Obligation: To comply with legal requirements
5. How We Use Your Information
We use your personal information for the following purposes:
- To respond to your inquiries and provide customer support
- To deliver our services and fulfill contractual obligations
- To send you important updates about our services
- To improve our website and services through analytics
- To prevent fraud and ensure website security
- To comply with legal obligations
- To send marketing communications (only with your explicit consent)
6. Data Sharing and Third Parties
We may share your personal information with the following third parties:
6.1 Service Providers
- Google Analytics: For website analytics and performance monitoring (anonymized data)
- Vercel: For website hosting and analytics
- Resend: For email communications
6.2 Legal Requirements
We may disclose your information if required by law, court order, or to protect our rights, property, or safety, or that of others.
7. International Data Transfers
Some of our service providers may process your data outside the UK. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the UK authorities
- Adequacy decisions recognizing equivalent data protection standards
- Other legally approved mechanisms ensuring data protection
8. Data Retention
We retain your personal information only for as long as necessary:
- Contact Inquiries: Up to 3 years after last contact
- Client Data: Duration of contract plus 6 years (for legal and tax purposes)
- Analytics Data: Maximum 26 months (Google Analytics)
- Cookie Consent: 12 months
9. Your Data Protection Rights
Under UK GDPR, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request limitation on how we use your data
- Right to Data Portability: Request transfer of your data to another service
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, please contact us at info@canarlo.com. We will respond within one month.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- SSL/TLS encryption for data transmission
- Secure hosting infrastructure
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.
13. Complaints and ICO Contact
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Canarlo
Email: info@canarlo.com
Phone: 07861 858394
Address: Leeds, United Kingdom