Legal
Privacy policy
How we collect, use and protect personal data, in plain English.
Last updated 1 October 2026
1. Who we are
[COMPANY NAME] Ltd, trading as Aisle. Registered in England and Wales, company number [COMPANY NUMBER]. Registered office: [REGISTERED OFFICE ADDRESS]. VAT number: [VAT NUMBER]. Email: [hello@DOMAIN]. We are the controller of personal data collected through this website and in running our business. For data we handle inside your marketplace, ad or website accounts while providing services to you, we act as your processor under our Data Processing Agreement.
2. What we collect
- Enquiries and audit requests: name, company, email, phone, website or store link, the channels you sell on and your message.
- Clients: contact details of your staff, billing details, and the information needed to deliver the services.
- Website use: IP address, browser and device information, pages visited and the cookies described in our cookie policy.
- Business prospects: business contact details of people at companies we believe may benefit from our services, taken from public sources such as Companies House and company websites.
3. Why we use it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Replying to enquiries and preparing audits and quotes | Legitimate interests; steps before entering a contract |
| Providing services and managing our client relationship | Contract |
| Invoicing, accounting and tax records | Legal obligation |
| Business-to-business marketing to company email addresses | Legitimate interests, with an opt-out in every message |
| Keeping the website secure and working | Legitimate interests |
We only send marketing emails to corporate addresses (limited companies and LLPs). We do not send unsolicited marketing emails to sole traders or partnerships without consent. You can opt out at any time and we will stop.
4. Who we share it with
We use carefully chosen suppliers who process data on our behalf under contract: cloud hosting (Amazon Web Services, EU/UK regions), website security and delivery (Cloudflare), email and office tools (Google Workspace), our CRM, accounting software, and business-grade AI services that do not use your data to train their models. We never sell personal data.
5. International transfers
Some suppliers may process data outside the UK. Where they do, we rely on UK adequacy regulations or approved safeguards such as the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses.
6. How long we keep it
- Enquiries that don't become clients: up to 24 months.
- Client records and invoices: 6 years after the relationship ends, for legal and tax reasons.
- Marketing suppression list: indefinitely, so we never contact you again after you opt out.
7. How we protect it
Encrypted connections, access restricted to people who need it, multi-factor authentication on our systems, encrypted storage of credentials, logging of access to client accounts and regular backups.
8. Your rights
You can ask to access, correct, delete or restrict your data, object to our processing (including marketing), and ask for data portability. Email [hello@DOMAIN] and we will reply within one month.
9. Complaints
Please contact us first. You also have the right to complain to the UK data protection regulator, the Information Commission (formerly the Information Commissioner's Office), at ico.org.uk.
10. Changes
We will update this policy when our practices change and show the date at the top.