How Vita Heritage Digital collects, uses, stores and protects your personal information
Vita Heritage Digital respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store and protect personal information when you:
For the purposes of UK data protection law, the organisation responsible for your personal information is:
Legal business name: Vita Heritage Ltd
Trading name: Vita Heritage Digital
Registered office: 1 Harps Hill, Markyate, St Albans AL3 8LN
Company number: 09574793
Email: [email protected]
In this policy, "Vita Heritage Digital", "we", "us" and "our" refer to the business identified above.
Depending on the circumstances, we may act as either a data controller or a data processor.
We act as a data controller when we decide why and how personal information is used. This includes information relating to our own website visitors, prospects, clients, suppliers and business contacts.
We may act as a data processor when we handle personal information on behalf of a client, for example when we configure or manage a client's CRM, website forms, marketing automations, appointment systems, communication tools or customer database.
Where we act as a processor, the relevant client remains responsible for determining the purposes and lawful basis for processing. Our handling of that information will be governed by our contract and, where required, a data processing agreement.
We may collect and process the following categories of personal information.
Name, job title, company or organisation name, business address, postal address, email address, telephone or mobile number, and social media profile information.
Information submitted through website forms; consultation and appointment details; messages sent by email, SMS, WhatsApp, webchat or social media; call notes; call recordings (where recording is used and appropriate notice is provided); feedback, reviews and survey responses; and information about your business, requirements, systems or objectives.
Services requested or purchased; proposals, contracts and order details; account and billing information; invoices and payment status; project correspondence; onboarding information; support requests; and service usage and account activity. We do not normally store complete payment-card details — payments may be processed by third-party payment providers.
Marketing preferences, consent records, email engagement, campaign responses, lead source, event or webinar registrations, downloads of guides or resources, and information about services in which you have shown an interest.
IP address, browser type and version, device type, operating system, time zone and approximate location, referral source, pages visited, time spent on the website, buttons or links selected, website session and interaction data, and cookie and tracking preferences.
We may receive personal information from clients and business partners, referral partners, publicly available websites and business directories, social media platforms, advertising platforms, analytics providers, CRM and automation platforms, payment processors, calendar and appointment providers, and communications providers. Where another person provides us with your information, they are responsible for ensuring they are permitted to do so.
We may collect personal information directly from you when you complete a form, book a consultation or appointment, purchase or enquire about a service, communicate with us, download a resource, subscribe to marketing, or interact with our website or advertisements. We may also collect it from a client or referral partner, from publicly available business sources, or automatically through cookies and similar technologies.
We will only use personal information where we have a lawful basis for doing so.
We use contact, enquiry and business information to respond to questions, assess your requirements, arrange consultations, prepare audits and proposals, and provide information about relevant services. Our lawful basis is usually taking steps at your request before entering into a contract, or our legitimate interests in responding to prospective clients.
We use personal information to open and manage client accounts, onboard clients, design and deliver services, manage projects, provide training and support, and maintain client records. Our lawful basis is usually the performance of a contract.
We use information to issue proposals and invoices, collect and reconcile payments, manage overdue accounts, and maintain accounting and tax records. Our lawful bases may include performance of a contract, compliance with a legal obligation, and our legitimate interests in operating our business.
We may use technical and usage information to maintain website security, identify faults, understand performance, and improve content and customer experience. Our lawful basis may be our legitimate interests. Where consent is required for cookies or tracking technologies, we will rely on consent.
We may use contact and marketing information to send relevant service updates, newsletters and offers, manage marketing campaigns, and follow up on previous enquiries. We will rely on consent where the law requires it. You may unsubscribe at any time using the unsubscribe link in any marketing message or by contacting us. Unsubscribing from marketing will not prevent essential service or contractual communications.
We may use personal information to comply with legal and regulatory requirements, respond to lawful requests from authorities, establish or defend legal claims, investigate complaints, and protect our systems and business. Our lawful bases may include compliance with a legal obligation and our legitimate interests.
Depending on the circumstances, we may rely on consent, contract (where processing is necessary to enter into or perform a contract with you), legal obligation (where processing is required to comply with the law), legitimate interests (where processing is reasonably necessary for our business), vital interests, or public task.
Where we rely on legitimate interests, those interests may include providing services, managing client relationships, improving our systems, protecting our business, preventing fraud, and carrying out proportionate business-to-business marketing.
We do not intentionally request special-category personal information through our general website forms. Special-category information includes data about health, race or ethnicity, religious beliefs, political opinions, trade-union membership, genetics, biometrics, or sexual life and orientation.
Because some of our clients operate in regulated sectors such as health and social care, information configured or processed within a client's system may include sensitive information. Where this occurs, we will normally process it only on the client's documented instructions and under appropriate contractual and security arrangements.
We may use automation and artificial intelligence tools to support activities such as organising enquiries, routing leads, generating draft communications, scheduling appointments, summarising information, supporting customer service, and analysing marketing or service performance.
We do not intend to make solely automated decisions that produce legal or similarly significant effects on individuals unless this is lawful, necessary and accompanied by appropriate safeguards.
Where we process personal information for a client using automation or AI, the client is responsible for ensuring that its intended use is lawful and transparent.
We may share personal information with trusted third parties where reasonably necessary, including website hosting providers, CRM and marketing-automation providers, GoHighLevel and associated service providers, email, SMS, telephone and messaging providers, calendar and appointment-booking providers, analytics and advertising providers, cloud-storage and IT-support providers, payment processors, accountants and professional advisers, subcontractors and technical partners, regulators and law-enforcement bodies, and potential buyers or advisers in connection with a business sale or investment.
Third parties may act as processors, independent controllers or joint controllers depending on the service and circumstances. We do not sell personal information as a standalone commercial product.
Some suppliers and technology providers may process or store personal information outside the United Kingdom. Where personal information is transferred internationally, we will take reasonable steps to ensure appropriate safeguards are in place. These may include transferring information to a country with an adequate level of protection, using approved contractual safeguards, or relying on another lawful transfer mechanism. Further information may be requested using the contact details in this policy.
We use reasonable technical and organisational measures to protect personal information against unauthorised access, accidental loss, alteration, misuse, disclosure, and destruction. Measures may include access controls, password protection, multi-factor authentication, encryption, backups, monitoring and contractual confidentiality obligations.
No website, email system or online platform is completely secure. You are responsible for using secure passwords, protecting account credentials and notifying us promptly of suspected unauthorised access.
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, security and contractual requirements.
| Category of Information | Typical Retention Period |
|---|---|
| General enquiries that do not become clients | Up to 24 months after last meaningful contact |
| Client contracts and core service records | Contract duration plus up to 7 years |
| Invoices, payment and accounting records | Usually 6 years after the relevant financial year |
| Marketing records and consent evidence | While marketing continues, plus a reasonable suppression period |
| Unsuccessful proposals | Up to 24 months, unless a longer period is justified |
| Technical and security logs | Commonly between 30 days and 24 months |
| Complaint and dispute records | Duration of matter plus up to 7 years |
| Backups | Until overwritten under the relevant backup cycle |
These periods may be extended where information is required for a legal claim, investigation, regulatory requirement or unresolved dispute.
Our website may use cookies, pixels, tags, scripts and similar technologies to make the website function, remember preferences, maintain security, analyse traffic and performance, support forms and appointment booking, measure advertising, and personalise content or marketing.
Strictly necessary cookies may be used without consent where legally permitted. Non-essential analytics, advertising or targeting technologies should not be activated until the required consent has been obtained. You can manage your choices using our cookie banner or cookie settings tool.
We may send marketing communications where you have asked to receive them, you have given consent, or the communication is otherwise permitted by applicable law. You can object or unsubscribe at any time. We may retain limited information on a suppression list to ensure that we respect an unsubscribe request.
Depending on the circumstances, you may have the right to: request access to your personal information; request correction of inaccurate or incomplete information; request deletion; request restriction of processing; object to processing based on legitimate interests; object to direct marketing; request transfer of information in a portable format; withdraw consent at any time; ask for human intervention in relation to certain automated decisions; and complain about how your information has been handled.
These rights are not absolute and may be subject to legal exemptions. To exercise a right, contact us using the details in this policy. We may need to verify your identity before responding.
You may submit a complaint directly to us by contacting [email protected] or writing to 1 Harps Hill, Markyate, St Albans AL3 8LN. We will acknowledge, investigate and respond to data protection complaints in accordance with applicable legal requirements.
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO). We would appreciate the opportunity to address your concern before you approach the ICO, but you are not required to contact us first.
Our website may contain links to third-party websites, platforms or services. We do not control those third parties and are not responsible for their privacy practices. You should review the privacy information provided by the relevant third party before submitting personal information.
Our website and services are primarily intended for businesses and people aged 18 or over. We do not knowingly collect personal information directly from children through our general website. Contact us if you believe that a child has provided personal information to us without appropriate authority.
We may update this Privacy Policy to reflect changes in our services, technology, suppliers or legal obligations. The latest version will be published on this page with an updated revision date. Material changes may also be communicated through the website or by email where appropriate.
Questions about this Privacy Policy or our use of personal information should be sent to:
Vita Heritage Digital
Legal entity: Vita Heritage Ltd
Address: 1 Harps Hill, Markyate, St Albans AL3 8LN
Email: [email protected]
Company number: 09574793