Comprehensive Privacy Policy & AI Data Processing Notice

Effective Date: 15 August 2026 | Last Revised: 15 August 2026

Data Controller: Webfit Ltd (operating site2.uk)

ICO Registration Number: Registered with the Information Commissioner's Office (UK)

Privacy Contact: Please contact us via our Contact Form (select "Privacy" as the heading).

1. Introduction & Overview

Webfit Ltd ("we", "us", "our") operates the site2.uk platform and automated marketing assistant ("Raye"). We are fully committed to protecting individual privacy and processing personal data in full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

This Privacy Policy & AI Data Processing Notice explains how we collect, store, process, transfer, and safeguard personal data when you interact with site2.uk, utilize our WhatsApp intake workflows, browse our directory, or register for subscription services.

2. Categories of Personal Data We Collect

We collect personal information across distinct operational channels:

Data Category Specific Data Points Collected Primary Collection Method
Account & Registration Data Full name, trade business name, UK postcode, town, county, email address, mobile phone number, and trade domain categories. User signup forms & dashboard profile settings.
Media & Interaction Assets Project photos, job descriptions, voice notes, trade annotations, and messaging metadata submitted to Raye. WhatsApp messaging API, email intake, & web uploaders.
Technical & Authentication Data IP address, browser type, operating system, magic-link session logs, and Cloudflare Turnstile bot verification tokens. Automated system logs & security middleware.
Connected Social Media Data OAuth access tokens, profile handles, and API posting logs for connected Facebook and Instagram business pages. OAuth integration authorized by the Subscriber.
Public Directory Engagement Consumer contact form inquiries, IP address, device telemetry, and public review submissions. Public site2.uk directory forms.

3. Legal Bases for Processing Data

We process personal data strictly where a valid legal basis exists under Article 6 of the UK GDPR:

4. Automated Processing & Third-Party AI Sub-Processors

To operate our automated marketing assistant ("Raye"), uploaded media and project notes are processed via Cloudflare R2 storage infrastructure and Google Generative AI (Google Gemini API). Raw job photos and project prompts sent to Google Gemini API are stripped of non-essential metadata and processed through anonymized folder identifiers on Cloudflare R2 edge storage. Third-party AI sub-processors are contractually restricted from utilizing submitted data to train public foundation models outside our secure tenant environment.

AI algorithms generate automated marketing text and tags. As detailed in our Master Terms, Subscribers maintain the mandatory obligation to review and verify all AI outputs before public broadcast.

5. Data Sharing & Third-Party Processors

We do not sell, rent, or trade personal data to third parties. Data is shared exclusively with vetted processors who operate under strict data processing agreements compliant with UK GDPR Article 28:

Third-Party Sub-Processor Operational Purpose Processing Location & Safeguards
Cloudflare Inc. Edge web hosting, Turnstile bot security, and Cloudflare R2 media storage optimization. UK / EU / US (Standard Contractual Clauses & UK Addendum)
Google Generative AI Google Gemini API content extraction and portfolio description generation. UK / EU / US (Data Processing Addendum & UK IDTA)
Meta Platforms Ireland Ltd WhatsApp Cloud API intake routing and authorized Facebook/Instagram social posting. EU / US (UK GDPR Compliant DPA)
Stripe Payments Europe Payment processing, subscription billing, and fraud mitigation. EU (PCI-DSS Level 1 Compliant)

6. Cookies and Local Storage

site2.uk operates a privacy-centric approach to tracking technologies. We deploy minimal, strictly necessary cookies and local storage items required exclusively for session authentication (magic-link state) and bot prevention (Cloudflare Turnstile verification). We do not deploy intrusive third-party cross-site advertising tracking scripts without prior explicit consent.

7. International Data Transfers

Where personal data is transferred or accessed outside the United Kingdom, we ensure appropriate safeguards are implemented in accordance with UK GDPR Chapter V. Transfers to third-party sub-processors rely upon UK Adequacy Decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.

8. Data Retention & Security

We enforce technical safeguards including AES-256 encryption at rest for Cloudflare R2 storage, TLS 1.3 encryption in transit, strict access control policies, and anonymized folder structures. Passwordless magic links eliminate credential theft risks. Account data is retained for the active duration of the Subscriber’s subscription. Following account closure, personal data is archived or deleted within ninety (90) days, except where longer retention is mandated by UK tax or statutory legislation.

9. Data Subject Rights Under UK GDPR

Under UK data protection laws, individuals possess statutory rights regarding their personal information:

To exercise any of these rights, please submit a request via our Contact Form selecting "Privacy" as the heading. We will evaluate and respond to all requests within one (1) calendar month. You also retain the right to lodge a complaint directly with the UK Information Commissioner's Office (ICO) at ico.org.uk.