Back to Legal

Legal

Privacy Policy

Last updated: 2026-06-25 · Contact: legal@solentrahouse.xyz

1. Controller and contact

Solentra House ("Solentra House", "we", "us", "our") is the data controller for personal data processed through https://solentrahouse.xyz and during client engagements.

  • Company number: 17289559 (United Kingdom (England and Wales))
  • Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
  • Privacy contact: legal@solentrahouse.xyz

A Data Protection Officer is not appointed because our processing does not meet the thresholds of UK GDPR Article 37(1) or EU GDPR Article 37(1). The legal@solentrahouse.xyz mailbox is monitored for all privacy matters.

2. Categories of personal data we collect

  • Identification and contact data you submit through the contact form, registration form, or service request form: full name, email address, phone number, company name (optional), and message content.
  • Account data created when you register: name, email, phone, securely hashed password (we never see the plain text), account creation timestamp.
  • Purchase data received from Gumroad after a completed transaction: order number, product purchased, price paid, sale timestamp, and the email address used at checkout.
  • Communication and engagement data: records of emails, briefs, deliverables, and meeting notes created during the engagement.
  • Analytics data (only with consent): aggregated page views, session interactions, device and browser type, country derived from IP, collected by Google Analytics 4 and Microsoft Clarity with IP anonymisation.
  • Technical data required to serve the site: IP address (for security and captcha verification) and strictly necessary cookies.

We do not knowingly collect special category data (health, religious belief, biometric data, sexual orientation) or data about children under the age of 18.

3. Lawful bases and purposes

  • Performance of a contract (UK/EU GDPR Article 6(1)(b)): to respond to enquiries, deliver services, manage your account, process payments, send transactional emails (welcome, password reset, purchase confirmations).
  • Legal obligation (Article 6(1)(c)): to keep accounting and tax records, to respond to lawful requests from authorities, to comply with sanctions screening.
  • Consent (Article 6(1)(a)): to load analytics scripts, to send any optional newsletter.
  • Legitimate interest (Article 6(1)(f)): to protect the site from abuse via captcha, rate limiting, and basic server logs; to keep records needed to defend or bring legal claims. We have weighed these interests against your rights and freedoms.

4. Retention periods

  • Contact form submissions: 24 months from receipt.
  • Account data: for the lifetime of the account, plus 30 days after a verified deletion request.
  • Purchase, invoicing, and accounting records: 6 years from the end of the financial year (UK statutory retention).
  • Engagement deliverables and notes: 6 years from the end of the engagement.
  • Analytics data: 14 months in Google Analytics 4 standard retention.
  • Server logs containing IP addresses: 30 days.
  • Marketing consent records (if any): until consent is withdrawn plus 3 years.

5. Processors and recipients

We share personal data with the following processors, each bound by a data processing agreement:

  • Vercel Inc. (United States) - hosting and content delivery for the site.
  • Supabase, Inc. (United States, EU hosting region) - authentication and database for account and engagement records.
  • Resend Inc. (United States) - transactional email delivery (contact form, welcome, password reset, purchase confirmations).
  • Cloudflare, Inc. (United States, edge in EU) - captcha verification (Turnstile), DNS, and DDoS protection.
  • Gumroad, Inc. (United States) - payment processing. Gumroad is an independent controller for the card and billing data it collects at checkout.
  • Google Ireland Limited - Google Analytics 4 (only with consent).
  • Microsoft Ireland Operations Limited - Microsoft Clarity (only with consent).

We do not sell personal data and do not share it with marketing or advertising partners.

6. International transfers

Some of our processors are established in the United States. Where personal data is transferred outside the United Kingdom or the European Economic Area, we rely on one or more of the following safeguards as applicable to the destination:

  • The UK International Data Transfer Agreement (IDTA).
  • The UK Addendum to the EU Standard Contractual Clauses.
  • The European Commission Standard Contractual Clauses (2021/914).
  • The EU-US Data Privacy Framework, where the processor is certified.

You can request a copy of the relevant safeguards by emailing legal@solentrahouse.xyz.

7. Security measures

We apply organisational and technical measures appropriate to the risk, including:

  • TLS 1.2 or higher for all data in transit between your browser, our site, and our processors.
  • Encryption at rest for the account and engagement database (managed by Supabase under their AWS-region infrastructure).
  • Row-Level Security policies that restrict each authenticated user to their own records.
  • Authentication is provided by Supabase. Passwords are hashed using bcrypt with a per-user salt by Supabase's authentication service; plain-text passwords are never accessible to Solentra House.
  • Card data is never stored or processed by us. All payment card data is handled by Gumroad (PCI DSS Level 1) or by the receiving bank for SEPA / wire-transfer invoices.
  • Principle of least privilege for staff and contractor access, reviewed periodically.
  • Captcha and rate limiting on public forms to deter automated abuse.
  • Backups and disaster recovery handled by our hosting and database processors under their own controls.

8. Personal data breach

Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by Article 33 UK/EU GDPR. Where the risk is high, we will also notify affected data subjects without undue delay.

9. Automated decision-making and profiling

We do not subject personal data to any automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

10. Your rights

Subject to applicable conditions you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete personal data.
  • Request erasure of personal data, subject to legal retention requirements.
  • Restrict our processing in defined circumstances.
  • Receive a portable copy of your data in a structured, commonly used, machine-readable format.
  • Object to processing carried out on the basis of legitimate interest or for direct marketing.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint with the Information Commissioner's Office (ICO) (https://ico.org.uk) if you are in the United Kingdom, or with your national supervisory authority if you are in the EEA.

11. How to exercise your rights

Email legal@solentrahouse.xyz with a clear description of your request and the email address you used with us. We respond within 30 calendar days. For complex requests we may extend this by up to a further 60 days and will tell you within the first 30 days if we do. We may ask for proof of identity before acting on the request, strictly to protect your data.

12. Cookies

For the categories of cookies we use, their purposes, durations, and how to control them, see the Cookie Policy.

13. Changes to this policy

We update this policy when our processing changes. Material changes are notified to account holders by email at least 14 days before they take effect. The current version is identified by the "Last updated" date at the top of this page.