Who we are
Saggar Studio is a trading name of Magixis Limited, a company registered in England and Wales (company number 17372370), whose registered office is Bartle House, 9 Oxford Court, Manchester, M2 3WQ. In this notice “we”, “us” and “our” mean Saggar Studio.
We are the controller of the personal data described here. Arun Paul, the founder, is responsible for data protection. We are not required to appoint a data protection officer.
We are registered with the Information Commissioner’s Office (ICO) under registration number ZC223083.
Contact: contact@saggarstudio.co.uk. Post: Bartle House, 9 Oxford Court, Manchester, M2 3WQ.
What this notice covers
This notice covers people who visit saggarstudio.co.uk, people who contact us or enquire, our clients and the people who work for them, and our suppliers.
It does not cover visitors to the websites we build and host for clients. Each client is the controller for its own website and has its own privacy notice. For that data we act as a processor under our data processing agreement.
What we collect and why
UK GDPR requires a lawful basis for each use of personal data. The table shows ours.
| When | What we collect | Why | Lawful basis | How long we keep it |
|---|---|---|---|---|
| You enquire by form or email | Name, business name, email, phone number, your message and anything you choose to attach | To reply, understand what you need and send a quote | Legitimate interests (answering a business enquiry), or steps you asked for before a contract | 12 months from our last contact, unless you become a client |
| You become a client | Contact details, billing details, contract and proposal, correspondence, meeting notes | To deliver the work, invoice, and keep records | Contract; legal obligation for tax and accounting records | The length of the contract plus six years |
| We do a review or search work | Details about your business, access to your website, Google Business Profile, Search Console and analytics accounts | To carry out the review, build or search work you asked for | Contract | Access is removed when the work ends; records as for clients |
| You give us logins | Usernames and passwords for your hosting, domain or platforms | To do the work | Contract | Stored in an encrypted Bitwarden vault, protected by two-factor authentication, and deleted when the work ends |
| You visit this website | IP address, browser type, pages requested and time, held in the host’s server logs | To keep the site running and secure, and to investigate misuse | Legitimate interests (security) | 90 days |
| You make a cookie choice | Whether you accepted or rejected, stored in your own browser | To remember your choice | Strictly necessary; no consent needed | Until you clear your browser storage |
| You agree to a case study | Your business name, screenshots, a description of the work, and any quote you approve | To publish the case study you agreed to | Contract (launch offer) or consent | Until you ask us to remove it, subject to the launch offer terms |
| You are a supplier | Contact and payment details | To buy from you and pay you | Contract; legal obligation | The length of the relationship plus six years |
We do not ask for special category data, such as health information. Please do not send it to us unless we have agreed how it will be handled.
Marketing
We do not send marketing emails unless you have asked for them or, as an existing client, you have not opted out. Every marketing email has a one-click unsubscribe link.
What we do not do
- We do not sell or rent personal data.
- We do not use advertising cookies, tracking pixels or cross-site tracking on this website.
- We do not build profiles of you or make decisions about you by automated means that have legal or similarly significant effects.
- We do not use your data to train AI models.
Transfers outside the UK
Some of our providers store or access data outside the UK, mainly in the United States. Where they do, we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework for certified providers) or on the ICO’s International Data Transfer Agreement or Addendum. Ask us and we will tell you which safeguard applies to a provider.
How we protect it
- Two-factor authentication on every account that holds personal data.
- Client logins kept only in an encrypted Bitwarden vault protected by two-factor authentication, never in email or chat.
- Access limited to the people doing the work.
- Encrypted laptops with screen locks.
- Where a personal data breach is likely to put you at risk, we report it to the ICO within 72 hours. If the risk to you is high, we tell you directly.
Your rights
You have the right to:
- see the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted where we no longer need it;
- restrict how we use it while a concern is looked into;
- object to our use of it where we rely on legitimate interests, and to any direct marketing at any time;
- receive data you gave us in a portable format;
- withdraw consent at any time, where we rely on consent.
Email contact@saggarstudio.co.uk. It is free. We will reply within one month. If a request is complex we can extend that by up to two more months, and we will tell you why within the first month. We may ask you to confirm your identity first.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at contact@saggarstudio.co.uk, with “Data protection complaint” in the subject line.
- We acknowledge your complaint within 30 days.
- We look into it, and tell you what we are doing and when to expect an answer.
- We tell you the outcome without undue delay.
You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113. The ICO normally expects you to raise a complaint with us first.
Changes to this notice
When we change this notice we update the date at the top. If a change affects how we use a client’s data, we email the client before it takes effect.