SiteRise Studio resources
Privacy & GDPR information
How SiteRise Studio handles enquiries, website projects and portal access.
This sheet describes the current service. The legal controller name and business address, confirmed retention schedule and provider-specific international-transfer arrangements must be completed as part of our privacy information. It is not a GDPR certification.
Contact
For privacy requests, contact SiteRise Studio at alexfilsell@googlemail.com. Full legal business identity and postal address: pending confirmation.
Information used
Enquiry name, email and business details; briefing and development conversations; project files and images; project status and approval records; portal membership and sign-in/security information; and payment/subscription references and billing status. Payment card details are handled by Stripe checkout rather than stored in the project portal. Team information can be supplied by a project owner inviting you.
Why it is used
To respond to enquiries and take requested steps before a contract; deliver and administer agreed website services; manage portal access, approvals and billing; and protect the service against misuse. Contract-related processing is intended to rely on contract or pre-contract steps; security and operational administration on legitimate interests, subject to assessment. Optional marketing, if introduced, needs a separate appropriate basis and preferences. Completing a brief is not a newsletter opt-in.
Providers and AI
Cloudflare supports hosting, security, project data and files; OpenAI supports AI-assisted briefing and development requests; GitHub supports website code and change records; Stripe supports payments; Resend supports emails. Relevant content may be sent to providers to deliver the requested function. Do not upload unnecessary sensitive personal data, payment-card details, passwords or confidential information about children or other people.
Providers may process data outside the UK. The applicable processing terms, destinations and transfer safeguards still need to be confirmed for the configured accounts; request details using the contact above. We do not describe every provider as UK-only or claim safeguards have been verified where they have not.
Retention
Retention is assessed according to whether an enquiry remains active, the project is ongoing, records are needed for support or handover, and legal/accounting obligations or disputes require preservation. Financial and essential audit records may need retention after a project is archived. Archiving is not deletion. The detailed schedule and review process are pending confirmation; no automatic deletion period is promised by this information sheet.
Your rights
You can request access, correction, deletion, restriction or portability where applicable. You can object to processing based on legitimate interests. Where consent is used, you can withdraw it. Rights and exceptions depend on the circumstances; we may verify identity before releasing project information. Contact us using the email above. You can complain to the Information Commissioner’s Office.
Security and browser storage
Sign-in, session and security mechanisms support portal access and bot protection. The site may use browser storage and third-party security services. This update does not introduce advertising trackers or analytics. We use AI assistance for website workflows; this does not replace team review of scope or customer approval of launch.
Client websites
A client is responsible for the privacy and cookie information on their own website. A contact form is not automatically a complete compliance solution. If we process personal data on a client’s behalf, the roles and any necessary processing agreement must be confirmed in the proposal.
Version 1 · 14 September 2026. Save a copy with your proposal; later website changes do not amend an accepted proposal.