How it works What we do Blog Contact Get started

UK GDPR and data protection

Our role, the third parties we rely on, and your rights.

Last updated: 24 July 2026

This page sets out how Stagg Studios meets its obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It sits alongside our Privacy Policy, which explains what we collect and why, and our Terms and Conditions.

1. Controller or processor

We act in two different roles, and the distinction matters.

We are a controller for our own business data: enquiries sent through this website, correspondence, invoicing and our own analytics. We decide what to collect and why.

We are a processor for personal data on a client's website. The client decides what is collected, why, and how long it is kept. We act only on their documented instructions. If we ever process that data for our own purposes, we would become a controller for that element, so we do not do it. We do not reuse client data to benchmark other clients, and we do not retain it to improve our own methods.

2. Our contract with clients

Where we act as a processor, UK GDPR Article 28 requires a written contract. Every client engagement includes one covering the subject matter, duration, nature and purpose of the processing, the types of data and categories of data subject, and the eight mandatory processor obligations: acting only on documented instructions, confidentiality, security, sub-processor authorisation, assistance with data subject rights, assistance with breaches and impact assessments, deletion or return of data at the end of the engagement, and audit rights.

3. Sub-processors

We use a small number of third parties to deliver the service. Each is engaged under a written contract, and we remain fully liable to our clients for their compliance. We will tell clients in advance of any change and they may object.

  • Website hosting and delivery, for this website and for delivering our work.
  • Form processing, currently FormSubmit, which receives what you type into a form on this site and forwards it to our email.
  • Email, for correspondence with clients and enquirers.
  • AI and automation providers, used to analyse website structure and generate technical recommendations. Where a client's website content passes through such a provider, that provider acts as our sub-processor under a written data processing agreement.
  • Analytics and search tools, such as Google Search Console and Bing Webmaster Tools, accessed with the client's own permission on their own accounts.

Clients can request our current sub-processor list at any time by emailing hello@staggstudios.com.

4. International transfers

Some of the providers above are based outside the United Kingdom, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards under Article 46, typically the International Data Transfer Addendum to the EU Standard Contractual Clauses, and we carry out a transfer risk assessment (a "data protection test") before relying on them.

5. Client website access

We never ask for a client's own password. Access is granted through a separate, named account or a revocable key that the client creates and can withdraw at any time without contacting us first. Access is scoped to the minimum needed to do the work. We keep a record of every change we make, including the previous value, so that any change can be identified and reversed.

6. Security

Credentials are held in an access-controlled password manager, one entry per client, never in plain text, notes or chat logs. Access to client systems is logged. We take a snapshot before making changes so work can be rolled back. We use multi-factor authentication on every account that supports it.

7. Data retention

Client data is deleted or returned at the end of an engagement, at the client's election, other than records we are required to keep for legal or accounting purposes. Change logs are retained for six years, which is the limitation period for contract claims in England and Wales, so that work can be evidenced if it is ever questioned.

8. Your rights

Under UK GDPR you have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision making. We do not make solely automated decisions that produce legal or similarly significant effects about people.

If we hold your data as a controller, email hello@staggstudios.com and we will respond within one month. If your data sits on a client's website, the client is the controller and we will pass your request to them promptly and help them answer it.

9. Data breaches

Where we act as a processor, we will notify the affected client without undue delay after becoming aware of a personal data breach, and assist them in meeting their own obligations. Where we act as a controller, we will report qualifying breaches to the Information Commissioner's Office within 72 hours.

10. Complaints

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk

11. Contact

Stagg Studios, London, United Kingdom. Email hello@staggstudios.com.