Privacy Policy
Last updated 21 September 2026
This policy explains what happens to your personal information when you use this website. It is written to be read, not to be skimmed past — if anything in it is unclear, please ask.
1. Who we are
This website is operated by S D Ross Ltd, trading as David Ross Digital. We are the data controller for the information described in this policy, which means we decide what is collected and what happens to it.
- Registered in England, company number 11145573.
- Registered office: Cromla, High Street, Freshwater, Isle of Wight PO40 9JT.
This policy covers this website only. If we build, host or maintain a website for you as a client, how we handle information on that site is covered by our agreement with you and our terms of business.
2. What this site does not do
It is shorter to start with what is absent, because most of it is. This website has no analytics, no advertising, no tracking pixels, no social media trackers and no embedded content from other companies. Apart from the spam check described in section 3, which loads on every page, it loads no fonts, images or scripts from anyone else’s servers — everything else it uses, it serves itself. We do not buy, sell, rent or swap personal information with anybody.
We set no cookies of our own, and nothing on this site profiles you or makes automated decisions about you. The only thing that may store anything in your browser is the spam check described in section 3, and it is there to keep the forms usable rather than to learn anything about you. That is why you are not asked to accept cookies when you arrive: there is nothing to accept.
3. What we collect, and when
When you send us an enquiry
The contact form asks for your name, your email address, your phone number and your message. Your phone number is optional. We use what you send to reply to you and, if we end up working together, to get the work started.
When you sign up for emails or ask for the free guide
The newsletter sign-up, the footer sign-up and the guide request ask for your name and your email address. We add you to our mailing list, send you the guide if that is what you asked for, and send you the emails you signed up for. You can leave the list at any time using the unsubscribe link in any email we send, and we will stop.
When you book a call
Our “book a call” links take you to Microsoft Outlook Bookings, which is a separate service. Whatever you enter there — your name, your email address, the time you choose — is collected by Microsoft on our behalf and appears in our calendar. Microsoft’s own privacy notice applies to that booking page.
Every time anyone visits
This site is delivered by Cloudflare. Like any web host, Cloudflare records the technical details of each request — the IP address it came from, the page asked for, the time, and what browser and operating system made the request. These records exist so that pages can be delivered, faults can be diagnosed, and attacks and abuse can be blocked. We do not use them to identify individual visitors, and we do not combine them with anything else.
The spam check, on every page
Our forms are protected by Cloudflare Turnstile, which works out whether a submission comes from a person or from a bot. It does not wait until you submit something: the sign-up form sits in the footer of every page, so Turnstile’s script loads on every page you open, this one included. That means Cloudflare sees your IP address and some technical information about your browser whenever you visit any page here, whether or not you ever fill anything in, and it may store a short-lived token in your browser. It is a security measure and it is strictly necessary for the forms to work; it does not track you around the internet and it does not build a profile of you.
4. Why we are allowed to use it
Data protection law requires us to have a lawful basis for each use. Ours are:
- Answering your enquiry — because it is in both of our legitimate interests that a message you send us reaches us and gets a reply, and because responding is often a step towards a contract between us.
- Marketing emails and the free guide — your consent, given when you sign up, and withdrawable at any time.
- Keeping the site available and free of abuse — our legitimate interest in a website that works and is not overwhelmed by bots.
- Records we must keep — where the law requires it, for example keeping invoices and related records for tax purposes.
5. Who else handles it
We use a small number of established service providers to run this site and our business. They act on our instructions and may not use your information for their own purposes:
- Cloudflare — hosting and delivering this website, and the spam check on our forms.
- Amazon Web Services — delivering the email that carries your enquiry from the website to our inbox.
- MailerLite — holding our mailing list and sending the emails and the guide.
- Microsoft — Microsoft 365 for our email and calendar, and the booking page behind our “book a call” links.
We will also disclose information if the law requires us to — for example in response to a court order — or to establish or defend a legal claim.
6. Where your information is held
Some of the providers above hold or process information outside the United Kingdom. The email carrying your enquiry is sent through Amazon Web Services in Ireland, and our other providers operate across the European Economic Area and, in some cases, the United States. The UK government recognises the EEA as offering protection equivalent to our own law, so nothing extra is needed for information that stays there. Where information goes further than that, it is covered by the safeguards data protection law requires — in practice the UK’s international data transfer agreement or addendum.
7. How long we keep it
- Enquiries — for up to two years after our last contact about them, unless they become part of a client relationship, in which case they are kept with that client’s records.
- Mailing list — until you unsubscribe or ask us to remove you. We keep a note that you have unsubscribed, so that you are not added again by mistake.
- Client and financial records — for as long as we work together, and then for six years after the end of the relevant financial year, which is what tax law requires of us.
- Website and security logs — for the short period our hosting provider retains them, which is measured in days, not years.
8. Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal information we hold about you;
- have inaccurate information corrected;
- ask us to delete information we no longer have a good reason to keep;
- ask us to restrict how we use it, or object to our using it;
- ask us to send certain information to you, or to someone else, in a portable format; and
- withdraw your consent at any time, where consent is what we relied on.
To exercise any of these, get in touch or write to us at the address in section 1. We will respond within one month. Exercising your rights is free, and asking costs you nothing.
We are registered with the Information Commissioner’s Office as a data controller. If you are unhappy with how we have handled your information, please tell us first so we have a chance to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk, by telephone on 0303 123 1113, or by writing to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
9. Keeping it safe
This site is served only over an encrypted connection, so what you type into a form is encrypted in transit. We take no payment details through this website. Access to the systems holding your information is limited to those who need it and protected by a strong, unique password for each one, with multi-factor authentication in place on our email and on the services that offer it. No system is perfect, but we take the security of what you send us seriously, and if something does go wrong we will tell the people affected and the regulator where the law requires it.
10. Children
This website is aimed at business owners, not children, and we do not knowingly collect information about anyone under 13. If you believe a child has sent us their details, please tell us and we will delete them.
11. Changes to this policy
If what we do changes, this page changes with it, and the date at the top will tell you when it last did. There is no archive of previous versions; if a change matters to people already on our mailing list, we will say so in an email rather than quietly editing the page.
12. Contacting us
For anything in this policy, including a request about your own information, please use thecontact form or write to S D Ross Ltd, Cromla, High Street, Freshwater, Isle of Wight PO40 9JT.
