1. Data Controller Information
This Privacy Policy sets out how SK FLOW LTD (“Company”, “we”, “us”, or “our”) processes, stores, and protects personal data obtained from visitors, prospective clients, active clients, and contractors who interact with our website (skflowltd.com) and our digital agency services.
Company Name: SK FLOW LTD
Company Registration Number: 17463288 (Incorporated in England & Wales)
Registered Office Address: 19 Ardsheal Close, Worthing, BN14 7RP, United Kingdom
Designated Data Protection Contact: Privacy Officer (contact@skflow.co.uk)
Official Telephone & WhatsApp: +44 7862 601814
We are dedicated to upholding the highest standards of data protection and privacy in full accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR).
2. Fundamental Data Protection Principles
Under the UK GDPR, we adhere strictly to the core data protection principles. We ensure that personal data is:
- Processed lawfully, fairly, and in a transparent manner in relation to the data subject.
- Collected for specified, explicit, and legitimate business purposes and not further processed in a manner incompatible with those purposes.
- Adequate, relevant, and limited to what is strictly necessary in relation to the purposes for which it is processed (data minimization).
- Accurate and, where necessary, kept up to date; reasonable steps are taken to ensure inaccurate data is erased or rectified without delay.
- Kept in a form which permits identification of data subjects for no longer than is necessary for the processing purposes.
- Processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage using appropriate technical and organizational measures.
3. Comprehensive Categories of Personal Data Collected
Depending on your interaction with SK FLOW LTD, we may collect, record, organize, structure, store, retrieve, or disclose the following categories of personal information:
- Identity Data: First name, maiden name, last name, username or similar identifier, marital status, title, and date of birth (where required for director verification).
- Contact Data: Billing address, delivery address, corporate trading address, email address, and direct telephone/WhatsApp mobile numbers (+44 7862 601814).
- Commercial Enquiry & Account Data: Specific digital services requested (including Product Listings, Shopify Store Setup, YouTube SEO, TikTok Commerce, Meta/Google Ads, and Product Sourcing), business size, store URLs (e.g. Shopify, Amazon, WooCommerce), creative briefs, advertising spend limits, project milestones, and records of customer support correspondence.
- Financial & Invoicing Data: Bank account payment details, VAT registration numbers, invoicing records, payment transaction identifiers, and credit notes. Please note: Online payments are processed through secure, PCI-DSS compliant third-party payment gateways (e.g. Stripe, PayPal, or major UK banking rails). SK FLOW LTD does not directly store, capture, or transmit raw credit card or debit card numbers on its servers.
- Technical & Telemetry Data: Internet Protocol (IP) address, login credentials, browser type and version, time zone setting, location data, browser plug-in types and versions, operating system and platform, and device identifiers.
- Usage & Interaction Data: Information about how you navigate our website, page response times, download errors, duration of visits to specific pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
- Marketing & Communications Data: Your preferences in receiving marketing and promotional materials from us and your communication preferences.
4. How We Collect Your Personal Data
We use diverse methods to collect data from and about you, including:
- Direct Interactions: You provide your Identity, Contact, and Project data by filling out forms on our website (skflowltd.com/#contact), communicating with our team via WhatsApp (+44 7862 601814), emailing us, or signing service proposals.
- Automated Technologies & Interactions: As you navigate our site, we may automatically collect Technical and Telemetry Data using cookies, server logs, and similar tracking technologies.
- Third Parties & Publicly Available Sources: We may receive personal data about you from various third parties such as UK Companies House, business directories, and analytics providers operating inside the UK or EEA.
5. Lawful Bases for Processing Under UK GDPR (Article 6)
We will only process your personal data when the law allows us to. Most commonly, we rely on the following lawful bases:
| Purpose / Activity | Type of Data | Lawful Basis for Processing (UK GDPR) |
|---|---|---|
| To register you as a new client and prepare formal proposals | Identity, Contact, Commercial Enquiry | Performance of a contract (Art. 6(1)(b)) |
| To deliver agreed digital agency services, manage milestones, and process payments | Identity, Contact, Financial, Transaction | Performance of a contract (Art. 6(1)(b)) & Legal obligation (Art. 6(1)(c)) |
| To manage client relationship, notify you of changes to terms, and respond to queries | Identity, Contact, Communications | Performance of a contract (Art. 6(1)(b)) & Legitimate interests (Art. 6(1)(f)) |
| To administer and protect our business and website (troubleshooting, cybersecurity, testing) | Identity, Contact, Technical | Legitimate interests (fraud prevention & network security) & Legal obligation |
| To maintain statutory accounting, tax records, and HMRC reporting | Identity, Contact, Financial, Transaction | Compliance with a legal obligation (Art. 6(1)(c)) |
| To deliver marketing updates where consent has been specifically provided | Identity, Contact, Marketing | Consent (Art. 6(1)(a)) – revocable at any time |
6. Data Sharing & Third-Party Subprocessors
SK FLOW LTD does not sell, rent, monetize, or trade personal data under any circumstances. We disclose personal data only to authorized third parties who assist us in operating our business, subject to strict Data Processing Agreements (DPAs) ensuring equivalent UK GDPR protections:
- Hosting & Cloud Infrastructure: ISO-certified enterprise cloud hosting providers located in the United Kingdom and European Economic Area (EEA).
- Communication & Support Systems: Meta Platforms Ireland Ltd / WhatsApp Business API for direct instant messaging communications.
- Payment Gateways & Banking Partners: Authorized UK clearing banks and FCA-regulated payment service providers.
- Professional Regulated Advisors: Qualified UK chartered accountants, tax consultants, auditors, insurers, and legal advisors who are bound by statutory professional secrecy obligations.
- Public Authorities: HM Revenue & Customs (HMRC), law enforcement agencies, or UK regulatory bodies when compelled to do so by a binding court order or statutory obligation.
7. International Data Transfers
Whenever we transfer personal data outside the United Kingdom, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Secretary of State (Adequacy Regulations).
- Where we use service providers outside the UK, we use specific contracts approved for use in the UK (the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission Standard Contractual Clauses (SCCs)) which give personal data the same protection it has in the UK.
8. Technical & Organizational Data Security Measures
We have implemented robust, multi-layered security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed:
- Encryption: All web traffic is encrypted in transit using Transport Layer Security (TLS 1.3 / SSL 256-bit encryption).
- Access Control: Access to personal data is restricted to authorized employees, contractors, and agents who have a strict business “need-to-know” and are bound by confidentiality obligations.
- WordPress Security: Anti-brute-force protection, WordPress CSRF token verification (nonces), secure salted password hashing, and regular security patching.
- Incident Response: We maintain procedures to deal with any suspected personal data breach and will notify you and the Information Commissioner’s Office (ICO) of a breach where we are legally required to do so within 72 hours.
9. Data Retention Schedules
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements:
- Client Contracts, Invoices & Transaction Data: Retained for a minimum of 6 years plus the current financial year following contract completion, in accordance with the UK Companies Act 2006, the Limitation Act 1980, and HMRC corporate tax rules.
- General Enquiries & Quotation Requests: Where no commercial contract is concluded, enquiry details submitted through our contact form are permanently erased after 12 months.
- Marketing Consent Records: Maintained until such time as you withdraw your consent or unsubscribe.
10. Your Enforceable Statutory Rights Under UK GDPR
Under the UK Data Protection Act 2018 and the UK GDPR, you have comprehensive rights in respect of your personal data:
- Right of Access (Subject Access Request – SAR): You have the right to request a copy of the personal information we hold about you, together with detailed information regarding our processing activities. This is provided free of charge within one calendar month.
- Right to Rectification: You have the right to obtain without undue delay the rectification of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion or removal of personal data where there is no compelling or lawful reason for its continued processing.
- Right to Restrict Processing: You have the right to request that we suspend the processing of your personal data in certain circumstances (e.g. while accuracy is being verified).
- Right to Data Portability: You have the right to obtain personal data you provided to us in a structured, commonly used, and machine-readable format (CSV, JSON) and transmit it to another data controller.
- Right to Object: You have the absolute right to object to the processing of your personal data for direct marketing purposes at any time. You also have the right to object to processing based on our legitimate interests.
- Rights in Relation to Automated Decision Making and Profiling: SK FLOW LTD does not employ automated decision-making or profiling algorithms that produce legal or similarly significant effects.
To exercise any of these rights, please contact our Data Protection Officer in writing at contact@skflow.co.uk or via postal mail at 19 Ardsheal Close, Worthing, BN14 7RP, United Kingdom.
11. Children’s Privacy Protection
Our website and professional digital agency services are directed exclusively to business professionals and individuals aged 18 and over. We do not knowingly solicit or collect personal information from individuals under the age of 18. If we discover that a minor under 18 has provided us with personal information, we will delete that data immediately from our servers.
12. External Links & Third-Party Integrations
Our website may include links to third-party websites, plug-ins, and applications (including WhatsApp, Shopify, TikTok, YouTube, and Meta). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.
13. Changes to This Privacy Policy
We review and update this policy periodically to reflect statutory amendments, regulatory guidance, or operational adjustments. Any material changes will be published on this page with an updated revision date. We encourage you to review this policy periodically.
14. Supervisory Authority & Right to Complain
You have the statutory right to make a complaint at any time to the UK supervisory authority for data protection issues:
The Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113 (standard local rate)
Official Website: https://ico.org.uk
We would, however, appreciate the opportunity to resolve any concerns or queries you may have before you approach the ICO, so please contact our Worthing office directly at contact@skflow.co.uk or via WhatsApp at +44 7862 601814.