Privacy Policy
Arafatcro Ltd ("Arafatcro", "we", "us", "our"), registered in England & Wales under company number 17325504, registered office 167-169 Great Portland Street, Fifth Floor, London, England, W1W 5PF, is the data controller for the personal data described in this policy. We are committed to protecting your privacy and handling your data in line with the UK GDPR and the Data Protection Act 2018.
1. Who this policy covers
This policy applies to people who visit our website (arafatcro.com), enquire about our services, and engage us as clients.
2. What we collect
We collect only what we need to run the business:
- Contact and enquiry data — name, email address, company name, and the content of messages you send us.
- Client and engagement data — information needed to deliver and administer your engagement, including correspondence and project details.
- Account and portal data — if you use our client portal, your account login is managed by our authentication provider (Clerk), and any test briefs or files you upload are stored on Cloudflare R2.
- Payment data — payments are processed by Stripe. We do not store your full card details; Stripe handles card data as a separate controller/processor under its own terms. We receive limited transaction information (such as that a payment succeeded).
- Website data — basic technical data such as IP address and browser type, and (if enabled) analytics about how you use our site.
3. How we use it and our legal basis
| Purpose | Legal basis |
|---|---|
| Respond to enquiries | Legitimate interests / steps to enter a contract |
| Deliver our services | Performance of a contract |
| Send invoices and take payment | Performance of a contract |
| Keep accounting and tax records | Legal obligation |
| Improve and secure our website | Legitimate interests |
| Marketing emails (if you opt in) | Consent |
4. Sharing your data
We share data only with parties that help us run the business, including:
- Stripe — payment processing;
- Clerk — client-portal account authentication;
- Cloudflare — website and client-portal hosting, and file storage (R2);
- our accountant and professional advisers;
- IT, email, and hosting providers;
- authorities where required by law.
We do not sell your personal data.
5. International transfers
Because we operate internationally, your data may be processed outside the UK/EEA. Where it is, we rely on appropriate safeguards (such as UK adequacy regulations or standard contractual clauses) to protect it.
6. How long we keep it
We keep enquiry data for up to 24 months, and client and financial records for at least 6 years to meet UK tax and accounting requirements, after which we delete or anonymise it.
7. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to our use of your personal data, and to data portability. To exercise any right, email dev@arafatcro.com. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
Our website may use essential cookies and, if enabled, analytics cookies. Where required, we ask for your consent before setting non-essential cookies. You can control cookies through your browser settings.
9. Processing client data
Where, as part of an engagement, we process personal data on your behalf (for example, data relating to your website visitors within an experimentation platform), we act as your data processor and you remain the controller. In that case, the data-processing terms in our Engagement Agreement or a separate Data Processing Agreement apply.
10. Contact
Arafatcro Ltd167-169 Great Portland Street, Fifth Floor
London, England, W1W 5PF
Registered in England & Wales, company no. 17325504
Email: dev@arafatcro.com
This document is a starting template, not legal advice. Have it reviewed by a qualified data protection professional before publishing, particularly section 9 if you handle client visitor data.