Legal

Privacy policy

Plain-English information about our website, services and how we handle data.

Last updated: 11 August 2026

1. Who is responsible for your information?

Rework Studio is responsible for the personal information described in this policy. This is sometimes called being the “controller”. Privacy questions can be sent to sales@rework-studio.com.

2. Information we collect

We may collect information you provide, including your name, business name, email address, optional telephone number, website address, service requirements, preferred contact method and messages. If you become a client, we may also process proposal, contract, billing, payment, project, support and approval records.

Our hosting and security providers may automatically process limited technical data such as IP address, device or browser information, request time, requested page and security logs.

3. Why we use it and our lawful bases

  • Enquiries and proposals: to take steps at your request before entering a contract and for our legitimate interest in responding to genuine business enquiries.
  • Projects and support: to perform a contract, manage scope, deliver work and provide agreed support.
  • Administration and legal records: to meet legal obligations and our legitimate interests in accounting, preventing disputes and enforcing agreements.
  • Security: for our legitimate interests in protecting the website, clients and business against abuse, fraud and cyber incidents.
  • Optional marketing: only where permitted by law and, where required, with consent that can be withdrawn.

4. Sharing and processors

Information may be shared only where reasonably necessary with providers supporting hosting, email delivery, cloud storage, project administration, accounting, security and professional advice. It may also be disclosed where required by law, to establish or defend legal claims, or as part of a properly managed business sale or restructuring.

Providers acting as processors are expected to use information only on documented instructions, keep it secure and meet applicable data-protection obligations.

5. International transfers

Some providers may process information outside the United Kingdom. Where this happens, we will use an approved safeguard where required, such as UK adequacy regulations, the UK International Data Transfer Agreement or an approved UK addendum to standard contractual clauses.

6. Retention

Unsuccessful enquiry records are normally kept for no longer than 24 months after the last meaningful contact. Client contracts, approvals and financial records are normally kept for up to seven years after the relationship ends where needed for tax, accounting or legal purposes. Routine technical logs are retained only for the provider’s configured security and operational period. Records may be kept longer where a dispute, legal hold or statutory requirement applies.

7. Security

We use proportionate organisational and technical measures intended to protect personal information, including access controls, secure providers, software updates, backups and restricted administrative access. No internet service can be guaranteed completely secure.

8. Your rights

Depending on the circumstances, you may have rights to receive a copy of your information, correct it, have it deleted, restrict or object to its use, receive portable data, and withdraw consent where consent is the lawful basis. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

9. Children

Our services are intended for businesses and are not directed at children. We do not knowingly request personal information from children through this website.

10. Cookies and changes

Cookie use is described in our cookie policy. We may update this policy when our services, providers or legal obligations change and will update the date above.