00Home01Services02Work03Field Notes04About05Contact

Legal

Privacy Policy

We hate privacy-policy legalese as much as you do. So here's the honest version: what actually happens to your data when you get in touch, in words a human can read.

Last updated: 4 July 2026

The short version

If you contact us — through the form, by email, or by phone — we collect only what we need to reply to you and, if it goes somewhere, to run the work. We store it on our own server in the UK/EU. We don't sell it, we don't rent it, we don't feed it into ad networks, and we don't sign you up to anything. A handful of trusted suppliers help us run the plumbing (spam-blocking, email, voicemail, website hosting) and nothing more. You can ask us to show you what we hold or delete it at any time, and we'll do it.

The longer version, because you deserve the detail:

Who we are

This site is run by Automancer Ltd, a company registered in England and Wales (company no. 17060907). We're the "data controller" — the ones responsible for your data and the ones you hold accountable for it. The sole director is Waseem Ilyas. We're registered with the UK's data protection regulator, the Information Commissioner's Office (ICO), under registration number ZC180569.

Automancer Ltd
62 Beckfield Road, Bingley, BD16 1QS
Questions about your data? Email waseem@automancer.uk — it reaches Waseem directly.

What we collect, and why

When you fill in the contact form

The form asks for, and we store:

  • Your name and email — so we know who you are and can reply.
  • Your business name and team size (optional) — context, so the reply is useful.
  • What you wrote — the message itself, about what you're trying to fix.
  • Your IP address — recorded with the submission, purely to spot and block spam and abuse. It isn't used to profile or track you.
  • An anti-bot token — a one-time token from the security check on the form (see "Cookies and the security check" below), used only to confirm you're a person.

When you hit send, the form posts straight to our own server (at api.automancer.uk) and lands in our own database. There's no third-party form service in the middle — no Formspree, no Typeform, no Google Forms. We then send ourselves an email notification so we don't miss you. That's the entire journey.

When you email us

If you email waseem@automancer.uk, we keep the email and anything you send with it, for as long as we need it to help you. Our email runs on Google Workspace (more on that below).

When you call us

Calls to our published number are forwarded to us. If you leave a voicemail, it may be recorded and automatically transcribed into text so we can pick it up reliably and get back to you. We keep the recording and transcript only for as long as we need to respond and handle your enquiry. The voicemail and transcription is handled for us by Vonage (see below).

When you just browse the site

Almost nothing. This site is static — there's no analytics, no tracking pixels, no advertising tags, no "people who viewed this also viewed" machinery. Our fonts are served from our own site, so your browser doesn't call out to Google or anyone else to load them. The one thing we can't avoid: the site is hosted on GitHub Pages, and like any web host, GitHub's servers keep standard technical logs (including visitor IP addresses) to serve the pages and keep the service secure. That's GitHub's infrastructure doing its job, not us watching you.

Our lawful bases

Under UK GDPR we need a lawful reason to process your data. Ours are:

  • Legitimate interests — the main one. When you get in touch, it's in both our interests for us to read your message, reply, and take the conversation forward. We also have a legitimate interest in keeping the form and our systems free of spam and abuse.
  • Contract — if we go on to work together, we process what's needed to deliver the work, quote, invoice, and keep proper records.
  • Legal obligation — some records (e.g. tax and accounting) we're required by law to keep.
  • Consent — where we ever genuinely need it, we'll ask for it plainly, and you can withdraw it just as easily. We don't do marketing emails, so this rarely comes up.

Where your data lives

Enquiries you send through the form live in our own database, on our own server — a VPS hosted in the UK/EU (with OVH). It's not sitting in some third-party marketing platform. A few suppliers (below) process specific slices of data on our behalf; where any of them operate outside the UK/EU, that transfer is covered by the appropriate safeguards (such as the UK's International Data Transfer Agreement or adequacy decisions).

Who else touches your data (our processors)

We keep this list short on purpose. These are suppliers that process data for us, under contract, only to do the job we've hired them for. We never sell your data, and we never share it for anyone else's marketing.

  • Cloudflare (Turnstile) — the "security check" on the contact form. It tells spam-bots apart from people so our inbox doesn't drown. Used purely for security and anti-fraud.
  • Vonage — handles call forwarding, and records and transcribes voicemails so we can respond to them.
  • Google Workspace — our email. If you email us, or we email you, it passes through Google's Workspace service (business plan, not the ad-funded consumer one).
  • GitHub (Pages) — hosts and serves this website. Its servers hold standard technical access logs, as any web host does.

Cookies and the security check

We don't use tracking or analytics cookies, so there's no cookie banner — because there's nothing to consent to. We checked this empirically: loading the site sets no cookies and stores nothing in your browser.

The one exception is the security check (Cloudflare Turnstile) on the contact page. To do its job — telling a real person apart from an automated bot — it may set a strictly-necessary cookie while it's actively defending the form. Under UK law (PECR), cookies that are strictly necessary for security and to deliver a service you've asked for are exempt from consent requirements, which is why you don't get a pop-up for it. It's there to protect the form, not to track you, and it only comes into play on the contact page.

How long we keep it

We keep enquiry data for as long as it's relevant to a potential or actual engagement — long enough to have the conversation, do the work, and keep the records we're legally required to keep. When it's no longer needed, we delete it. And if you ask us to delete your data sooner, we will (unless the law requires us to hold onto a specific record).

Your rights

Under UK GDPR, you have the right to:

  • Access — ask for a copy of the data we hold about you.
  • Rectification — have anything wrong or out of date corrected.
  • Erasure — ask us to delete your data ("the right to be forgotten").
  • Restriction — ask us to pause processing while something's sorted out.
  • Objection — object to processing we base on legitimate interests.
  • Portability — get your data in a portable format, where that applies.
  • Withdraw consent — where we relied on it, at any time.

To exercise any of these, just email waseem@automancer.uk. No special form, no hoops. We'll respond within one month, and there's normally no charge.

Complaints

We'd always rather you came to us first so we can put things right — email waseem@automancer.uk. But you also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.

Work we don't take on

For everyone's protection, we steer clear of certain high-risk engagements — for example, work heavy on patient data, or highly confidential government/military systems — unless it's explicitly agreed and set up properly first.

Changes to this policy

If we change how we handle data, we'll update this page and the "last updated" date at the top. For anything significant, we won't bury it.