Legal
How we collect and use personal data across Reddy Apps LTD products and services.
Last updated: 31 July 2026
This Privacy Policy explains how Reddy Apps LTD ("we", "us", "our") collects and uses personal data in connection with our products and services, including the SmashingSite service. We are the data controller.
Reddy Apps LTD, registered in England and Wales, company number 16558403, registered office Unit 82a James Carter Road, Bury St. Edmunds, IP28 7DE.
We are registered with the Information Commissioner's Office (ICO), registration reference ZC172857. You can verify this on the ICO's public register at ico.org.uk.
Contact for privacy matters: info@reddyapps.co.uk.
Where you contact us through a Facebook or Instagram advert, or through Messenger, Meta collects your details on its own platform first and under its own privacy policy, as a separate data controller. We receive those details from Meta and become responsible for them from that point. Meta only makes lead details available to us for 90 days.
We use trusted providers who process data on our behalf:
Meta. Meta (Facebook and Instagram) is not our processor. Where you contact us through an advert or through Messenger, Meta acts as a separate, independent data controller for its own processing on its own platform, under its own privacy policy. We are the controller of your details from the point Meta makes them available to us.
These providers act under contract and only process data as instructed. We do not sell your personal data.
We may add, change or replace these providers from time to time. Any new provider is bound by a written contract to protect your data and use it only as we instruct. An up-to-date list is available on request.
Business transfers. If we sell, transfer or reorganise our business or the SmashingSite service (for example, a sale of the service or its assets to a new owner), we may transfer your personal data to the buyer or successor as part of that transaction. We will only do so on terms that require your data to keep being protected in line with this Policy, and we will tell you if your data moves to a new controller as a result.
Our email provider Resend sends from servers in Ireland but is a United States company; our hosting and database provider Cloudflare is also United States based. Both are certified under the UK Extension to the EU-US Data Privacy Framework, which is the safeguard we rely on for transfers to the United States. Enquiry records themselves are stored in a database constrained to the European Union.
Where we build a sample website for a business we have not yet worked with, we use information that is publicly available about that business, and we may contact the business (for example by email or phone) to show them the sample. We rely on legitimate interests for this business-to-business outreach. A business can ask us at any time to stop contacting them and to delete its data (see section 10).
Our private demo sites use a single functional cookie to remember that a visitor has entered the correct access code, so they do not have to re-enter it. It is not used for tracking or advertising.
When you submit a form we briefly record your IP address, for up to ten minutes, to stop automated abuse of the form. It is not used for anything else and is not kept.
We keep personal data only as long as necessary for the purposes above and to meet legal and accounting obligations. Customer and purchase records are retained for the duration of the subscription and then for 6 years to meet HMRC accounting requirements, after which they are deleted.
Where we hold data about a business we have approached but who has not become a customer, we keep it only for as long as we are actively pursuing that opportunity, and in any event we delete it within 12 months of our last contact, unless the business becomes a customer or asks us to delete it sooner.
Where you contact us about a demo but do not become a customer, we keep your enquiry for 24 months from our last contact with you, or for 12 months from the date you contacted us if we never heard back. After that we remove your name, your contact details and the areas you cover, and keep only an anonymous record that an enquiry was made, which is no longer personal data. If you ask us not to contact you again we keep a minimal, encrypted record of that request indefinitely, so that we can honour it.
We use appropriate technical and organisational measures to keep personal data secure, including encryption in transit, access controls, and the use of reputable providers who maintain their own security standards.
Under UK data protection law you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise any of these, email info@reddyapps.co.uk.
We will respond to any such request within one month, and we do not charge a fee for a valid request (except where the law allows, for example where a request is manifestly unfounded or excessive).
You also have the right to object to direct marketing at any time, and, where we rely on your consent, the right to withdraw that consent at any time (withdrawal does not affect processing carried out before you withdrew).
You have the right to complain to us about how we handle your personal data - see our Privacy Complaints page for how, and what happens next. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint at any time, though we would welcome the chance to put things right first.
We may update this Policy from time to time. The "Last updated" date shows when it last changed.