Privacy Policy
1. Who we are
Charnette Ltd (trading as Charnette Labs) builds websites, mobile applications and push notification systems, specialising in tourism businesses.
Data Controller: Charnette Ltd, registered in England and Wales No. 17167712
Registered address: 20 Wenlock Road, London, England, N1 7GU
ICO registration: ZC206607 — you can check this entry yourself on the ICO’s public register at ico.org.uk/register
Contact for data enquiries: hello@charnette.io
We have not appointed a Data Protection Officer. Neither trigger in Article 37 applies to us, and appointing one voluntarily would import the Articles 38–39 framework without a corresponding benefit. Data enquiries reach Graeme Watson at the address above.
2. When we are the controller, and when we are not
This distinction decides which policy applies to you, so it comes first.
We are the controller — and this policy applies — for people who visit charnette.io, send us an enquiry, correspond with us, or work with us as a client contact. We decide why and how that data is processed.
We are a processor, not a controller, for personal data held in the websites, apps and notification systems we build, host and maintain for our clients. If you booked with a safari lodge, subscribed to a tour operator’s notifications, or filled in a form on a site we built for someone else, that business is the controller and its own privacy policy governs what happens to your data. We act only on its written instructions.
If you are unsure which applies, ask us and we will tell you, or point you to the right controller. Our terms for client work are set out in our Data Processing Agreement.
3. What we collect, and why
We collect only what you give us and what a web server necessarily records. There is no tracking, no profiling and no advertising technology on this site.
Enquiry data. Our contact form asks for your name and email address, and optionally your business name, business type and the service you are interested in. Name and email are required; without them we cannot reply, which is the only consequence of not providing them. There is no statutory or contractual obligation to give us any of it.
Correspondence. If you email us, we keep the exchange so we can answer you and keep a record of what was agreed.
Server logs. Our host records the usual technical data for every request — IP address, browser type, the page requested and the time. This is how a site is served and how abuse is spotted.
Aggregate usage data. We measure page views and page performance in aggregate. The tools we use for this are cookieless and do not identify you or follow you between sites (see section 6).
Staff and client administrator accounts. If you hold a login for an admin area we operate, we process your email address and authentication data to run that account.
We do not take payment through this website, so we hold no card details here.
4. Our lawful basis for each purpose
Article 6 requires a basis for every purpose, not one for the whole policy, so they are set out separately.
- Answering your enquiry — legitimate interests (Art 6(1)(f)). Our interest is responding to someone who has approached us about work. You asked us to get in touch, so this is unlikely to override your interests, but you can object at any time and we will stop.
- Delivering a project you have engaged us for — performance of a contract (Art 6(1)(b)), or legitimate interests where the contract is with your employer rather than you personally.
- Serving and securing the website, including server logs — legitimate interests. Our interest is keeping the site up and resisting abuse.
- Aggregate usage and performance measurement — legitimate interests. Our interest is knowing which pages are read and whether they load quickly. Because the measurement is cookieless and non-identifying, the impact on you is minimal.
- Running staff and administrator accounts — performance of a contract, and legitimate interests in securing our systems.
- Keeping business and tax records — legal obligation (Art 6(1)(c)).
We do not rely on consent for anything on this site, and we do not send marketing email. If that changes we will ask for consent first and say so here.
5. Who receives your data
We name our providers rather than describing them generically, so you can check each one yourself.
Vercel — hosting, content delivery, server logs, and the cookieless page-view and performance measurement in section 6. United States, with UK/EU infrastructure.
Postmark (ActiveCampaign) — delivers your contact-form enquiry to us by email. It is the transport, not a store of enquiries. United States.
Supabase — authentication for staff and client administrator accounts only. No website visitor or enquiry data is stored there.
Each is engaged under a written data processing agreement that binds it to process only on our instructions. We do not sell, rent or trade personal data, and we do not share it for anyone else’s marketing.
We may disclose data where the law requires it — a court order, or a request from a regulator with the power to compel. We will not volunteer it.
If our business or part of it were sold, personal data could transfer as part of that. We would tell affected individuals where we are able to, though a transaction can complete faster than a notification round, so we will not promise advance notice we might not be able to give.
6. Cookies
This site sets no analytics, advertising or tracking cookies, and needs no cookie banner.
Until 27 July 2026 it ran Google Analytics 4, which set non-essential cookies without asking. That was removed rather than gated. The measurement that replaced it — Vercel Analytics and Speed Insights — is cookieless: it stores nothing on your device, sets no persistent identifier, and does not follow you to other sites.
The only storage we use is what the site needs to function, such as remembering a signed-in session in an admin area. Regulation 6 of PECR exempts strictly necessary storage of that kind from the consent requirement; nothing outside it is set.
You can block or delete cookies in your browser at any time. Doing so will not stop you reading anything on this site.
7. How long we keep it
- Enquiries that do not become work — 2 years from your last contact, then deleted.
- Client project correspondence and records — 6 years from the end of the engagement, matching the limitation period for a contract claim and UK business record-keeping.
- Server logs — retained by our host on its own short operational cycle, measured in days, not kept by us separately.
- Aggregate usage data — retained indefinitely. It is aggregate and does not identify anyone, so it is outside the scope of these rights.
- Staff and administrator accounts — for as long as the account is needed, then deleted.
You can ask us to delete your data sooner and we will, unless we are required to keep it for a legal or tax obligation — in which case we will tell you which, and for how long.
8. Where your data goes
Some of our providers are established in the United States. Where personal data is transferred outside the UK, we rely on the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it.
You are entitled to see those safeguards. Email hello@charnette.io and we will send you a copy of the relevant clauses, or tell you where the provider publishes them.
9. Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict how we use it, to receive it in a portable format, and to object to processing based on legitimate interests — which covers most of what we do with your data on this site.
To exercise any of them, email hello@charnette.io. We will respond within one month, which is the deadline Article 12(3) sets. If a request is unusually complex we may extend that by up to two further months, and we will tell you inside the first month if we do. There is no fee.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
You can complain to the regulator, and you do not have to come to us first. We would rather have the chance to put it right, but that is a preference, not a condition.
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk/make-a-complaint
If you are in the EU or EEA you may instead complain to the supervisory authority where you live.
10. Security
Traffic to this site is encrypted in transit. Admin areas require a per-person account, and access is limited to an allowlist rather than a shared password, so it can be withdrawn for one person without affecting anyone else. We review what we hold and remove what we no longer need.
No transmission over the internet is completely secure, and we will not claim otherwise. If a breach affects your rights and freedoms we will notify you, and the ICO within 72 hours where the threshold in Article 33 is met.
11. Changes
The date at the top shows when this policy last changed. If we change it in a way that materially affects you, we will tell affected clients by email rather than relying on you to notice a new date.