Privacy Policy
Last updated: September 2026Reforge Studios respects your privacy and is committed to protecting your personal data. This policy explains what we collect, why, and the rights you have over it. It applies to our website, our clients, and anyone who contacts us.
1. Who we are
Reforge Studios is a web design and development studio based in Southampton, UK. We are the controller of the personal data you provide to us. You can reach us at hello@reforgestudios.co.uk.
2. What we collect
- Contact details you give us – name, business name, email address, phone number, and address.
- Project content: text, images, logos, and access credentials you provide so we can build or maintain your website.
- Message content: anything you write in our contact forms or emails to us.
- Technical data: browser type, device, and pages visited, collected via privacy-friendly analytics on our own website.
3. Why we use it
We use your data to reply to enquiries, prepare quotations, deliver the work you commission, host and maintain your website, send invoices, and keep records for tax and accounting as required by UK law. Where we rely on your consent (for example, marketing emails), you may withdraw it at any time and we will stop.
4. Legal basis
We process personal data under the UK GDPR and Data Protection Act 2018, relying on: performance of a contract with you, taking steps before entering a contract, compliance with a legal obligation, and your consent where you have given it. We never sell your data, and we do not use it to profile you.
5. Who sees it
Only the people at Reforge Studios who need it to do their job. We use trusted third parties for hosting, email delivery, and accounting, each of whom is under contract to keep your data safe and only process it on our instructions. We do not transfer your data outside the UK or EEA without safeguards in place. Authorities may receive data where we are legally required to disclose it.
6. How long we keep it
Project data is kept for the life of our relationship plus seven years, to cover warranty and accounting requirements. Contact-form enquiries from people who do not become clients are deleted after two years. Hosting backups are rotated every 30 days.
7. Security
We take reasonable technical and organisational measures: encrypted connections (HTTPS), access limited to named staff, strong authentication, and regular updates. No system is perfectly secure, so we also keep backups and will notify you, and the ICO where required, of any breach likely to risk your rights.
8. Cookies
Our website uses only essential cookies and privacy-friendly analytics. We do not use advertising or tracking cookies, and we do not sell data to advertisers. You can clear or block cookies in your browser without affecting how the site works.
9. Your rights
Under UK data protection law you have the right to access your data, have it corrected, erased, or restricted, object to processing, receive a copy in a portable format, and withdraw consent at any time. To exercise any of these rights, email us at the address above. We respond within one month, and there is no charge unless a request is clearly unfounded or excessive.
10. Complaints
We hope to resolve any concern directly with you. If you are not satisfied, you may complain to the Information Commissioner's Office at ico.org.uk, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Changes to this policy will be posted on this page with an updated date above.