Privacy Policy
Last reviewed: June 2026
This Privacy Policy explains how Brylo Ltd collects, uses, shares and protects your personal data when you visit our website, make an enquiry, or use our services. We are committed to protecting your privacy and handling your information transparently and lawfully in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Brylo Ltd ("Brylo", "we", "us", "our") is the data controller responsible for your personal data. We are a company registered in England and Wales (company number 17298503), with our registered office at [REGISTERED OFFICE ADDRESS].
We are registered with the Information Commissioner's Office (ICO), registration number [ICO REGISTRATION NUMBER]. You can contact us about anything in this policy at info@brylo.co.uk.
2. What this policy covers
This policy applies to personal data we process as a controller through our website and in the course of providing our services (web design and development, hosting, domains, digital marketing, AI and automation, and related support). Where we process personal data on behalf of a client (for example, data held within a website or system we host or manage), we act as a processor and that client is the controller — see our GDPR & Data Protection page.
3. The personal data we collect
Depending on how you interact with us, we may collect:
- Identity and contact data — name, email address, phone number, company name and address.
- Account data — username, a securely hashed password, and two-factor authentication settings.
- Enquiry and project data — the details you share when you contact us or brief a project.
- Transaction and billing data — services purchased, invoices and billing address. We do not store card details — payments are processed securely by our payment provider.
- Domain and hosting data — registrant details required to register and manage domains and hosting on your behalf.
- Technical and usage data — IP address, browser and device type, and pages visited, collected via cookies and similar technologies (see our Cookie Policy).
- Marketing and communications preferences.
We do not routinely collect special category data (such as data about health, race or religion). Please do not send us such information unless we have specifically asked for it.
4. How we collect your data
- Directly from you — when you complete a form, create an account, email or call us, or place an order.
- Automatically — through cookies and similar technologies when you use our website (non-essential cookies only with your consent).
- From third parties — such as our payment provider, domain registrars, or publicly available sources.
5. Our lawful bases for processing
Under the UK GDPR we must have a lawful basis to process your personal data. We rely on:
- Contract — to provide the quotes, services and support you request, and to manage our relationship with you.
- Legitimate interests — to run and improve our business, respond to enquiries, keep our systems secure, and market our services to existing clients. We balance our interests against your rights and freedoms.
- Consent — for non-essential cookies and, where required, marketing to prospective clients. You can withdraw consent at any time.
- Legal obligation — to comply with accounting, tax, anti-fraud and other legal requirements.
6. How and why we use your data
- To provide quotes and deliver the services you have asked for.
- To create and manage your account and authenticate you (including two-factor authentication).
- To take payment and issue invoices.
- To register and manage domains and hosting on your behalf.
- To communicate with you about your project, account and support.
- To send marketing, where we have a lawful basis — you can opt out at any time.
- To improve our website and services, including analytics (with your consent).
- To detect, prevent and respond to fraud, security incidents and misuse.
- To comply with our legal and regulatory obligations.
7. Marketing communications
We will only send you marketing where we have your consent or another lawful basis (such as the "soft opt-in" for existing customers). You can unsubscribe at any time using the link in our emails or by emailing info@brylo.co.uk. We do not sell your personal data, and we do not share it with third parties for their own marketing.
8. Cookies
We use cookies and similar technologies to run the site and, with your consent, to measure and improve it. You can manage your choices at any time. Please see our Cookie Policy for full details.
9. Who we share your data with
We share personal data only where necessary, with carefully selected providers who act as our processors under contract and only on our instructions, including:
- Hosting and infrastructure — our website and platform hosting and database providers (configured to store data in the UK/EEA where possible).
- Payments — our payment provider, who processes card payments securely.
- Email and productivity — our business email and office tools provider.
- Domain registrars — including Nominet for .uk domains, as required to register and manage domains.
- Analytics — only where you have consented to analytics cookies.
We may also share data with our professional advisers (accountants and lawyers), with authorities or regulators where required by law, and with a buyer in connection with a sale or reorganisation of our business.
10. International transfers
We aim to keep your personal data within the UK and European Economic Area (EEA). Where a provider processes data outside the UK, we put in place appropriate safeguards required by law, such as transfers to countries covered by UK "adequacy" regulations, the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK Addendum.
11. How long we keep your data
We keep personal data only for as long as necessary for the purposes set out above, including to meet legal, accounting and reporting requirements. As a guide:
- Enquiries that do not become projects — up to 24 months.
- Client and contract records — for the duration of our relationship and then up to 6 years (to meet limitation and tax requirements).
- Accounting and tax records — 6 years, as required by HMRC.
- Marketing data — until you unsubscribe or withdraw consent.
When data is no longer needed, we securely delete or anonymise it.
12. How we protect your data
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), hashed passwords, two-factor authentication, access controls, and reputable, secure infrastructure providers. No method of transmission or storage is completely secure, but we take the protection of your data seriously and review our measures regularly.
13. Your rights
Under the UK GDPR you have the right to:
- Be informed about how we use your data (this policy).
- Access a copy of the data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), where applicable.
- Restrict our processing of your data.
- Data portability — receive your data in a portable format.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time, where we rely on consent.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects.
To exercise any right, email info@brylo.co.uk. We will respond within one month (which may be extended for complex requests) and there is usually no charge. We may need to verify your identity first.
14. Complaints
If you have a concern, please contact us first so we can put things right. You also have the right to complain to the Information Commissioner's Office (ICO):
Website: ico.org.ukHelpline: 0303 123 1113
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
15. Children
Our website and services are intended for businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
16. Third-party links
Our website may contain links to third-party websites. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.
17. Changes to this policy
We may update this policy from time to time. The "last reviewed" date above shows when it was last changed. Where changes are material, we will take reasonable steps to notify you.
18. Contact us
For any privacy or data protection question, email info@brylo.co.uk (please mark it "Data Protection"), or write to Brylo Ltd at [REGISTERED OFFICE ADDRESS].