1. Who we are
Green Tide is the controller of the personal information described in this policy unless we expressly say otherwise. Our website is greentide.co.uk. Our principal contact address is Essex, United Kingdom, and privacy questions can be sent to hello@greentide.co.uk.
A controller decides why and how personal information is used. In some projects we may process limited information solely on a customer’s instructions, for example when assisting with website content or contact records. In that situation, the customer may be the controller and we may act as its processor under separate contractual terms.
2. Scope of this policy
This policy applies to visitors to our website, people who make an enquiry, prospective and current customers, suppliers, contractors, business contacts, and people who communicate with us by email, phone, social media or another channel.
It does not govern the independent privacy practices of a customer’s own website, a third-party platform or another organisation. Those parties should provide their own privacy information.
3. Personal information we may collect
Depending on your relationship with us, we may collect:
- Identity and contact information: name, job title, business name, postal address, email address, phone number and social-media details.
- Enquiry and project information: messages, requirements, briefs, feedback, approvals, supplied content, meeting notes and correspondence.
- Commercial information: quotations, services purchased, contract records, invoices, payment status and transaction references.
- Account and technical information: usernames, access permissions, IP address, browser type, device details, approximate location, referral source and website activity.
- Marketing information: communication preferences, consent records, campaign interactions and whether you have asked us not to contact you.
- Supplier and contractor information: professional details, tax or payment information, agreements and work records.
- Security and compliance information: records used to prevent fraud, protect accounts, investigate misuse, establish legal claims or meet legal obligations.
Please avoid sending unnecessary confidential, financial, health or other sensitive information through general website forms.
4. Where personal information comes from
We may receive information:
- directly from you when you contact us, request a design, accept a quotation, attend a meeting or buy a service;
- from your employer, colleague, representative or another person involved in a project;
- automatically from your browser or device through server logs, cookies and similar technologies;
- from publicly available sources such as a business website, Companies House, professional directory or social-media profile;
- from service providers, referral partners, payment providers and other organisations where they are permitted to share it; and
- from records created through our relationship with you.
5. Why we use personal information and our lawful bases
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Responding to enquiries and discussing possible work | Identity, contact and enquiry information | Legitimate interests; steps requested before entering a contract |
| Preparing quotations, providing services and managing projects | Contact, project, account and commercial information | Contract; legitimate interests |
| Invoicing, accounting, tax and record keeping | Contact, transaction and payment information | Contract; legal obligation; legitimate interests |
| Hosting, maintaining, securing and improving our website and services | Technical, usage, account and security information | Legitimate interests; consent where required for non-essential cookies |
| Preventing misuse, fraud and security incidents | Technical, account, communication and security information | Legitimate interests; legal obligation where applicable |
| Managing suppliers and professional relationships | Identity, contact, contractual and payment information | Contract; legitimate interests; legal obligation |
| Sending service messages and important administrative updates | Contact and project information | Contract; legitimate interests |
| Sending optional marketing communications | Contact, preference and engagement information | Consent where required; legitimate interests where permitted |
| Handling disputes, complaints and legal claims | Any information relevant to the issue | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, those interests may include operating and improving our business, communicating with customers, protecting systems, recovering debts, maintaining records and promoting relevant services. We consider the necessity of the processing and its effect on individuals before relying on that basis.
6. Special-category and criminal-offence information
We do not normally need special-category personal information, such as health, biometric, political, religious, trade-union or sexual-life information, and we ask you not to provide it unless it is genuinely necessary. If we must use such information, we will identify an appropriate lawful basis and additional legal condition and apply suitable safeguards.
We do not routinely collect criminal-offence information. Where it is necessary for a legal, security or safeguarding reason, we will handle it only where permitted by law.
8. International transfers
Some service providers may store or access information outside the United Kingdom. Where personal information is transferred internationally, we take steps intended to ensure an appropriate level of protection, such as relying on adequacy regulations, approved contractual safeguards or another lawful transfer mechanism.
You may contact us for further information about the safeguards relevant to a particular transfer, subject to reasonable confidentiality and security restrictions.
9. How long we keep personal information
We keep information only for as long as reasonably needed for the purpose for which it was collected, including legal, accounting, tax, security, complaint and dispute requirements. Typical periods are set out below and may be adjusted where a longer or shorter period is justified.
| Record type | Typical retention approach |
|---|---|
| Unsuccessful enquiries | Usually up to 24 months after the last meaningful contact |
| Customer contracts, project and approval records | Usually up to 6 years after the relationship ends |
| Invoices, payment and tax records | Kept for the period required by tax and accounting law, commonly at least 6 years |
| Routine support correspondence | For the active relationship and a reasonable period afterwards |
| Marketing preferences and suppression records | Until consent is withdrawn or the information is no longer needed; suppression records may be retained to respect an opt-out |
| Technical logs and security records | For a period proportionate to operational and security needs |
We may retain information longer where litigation is anticipated, a debt remains outstanding, a regulator requires it, or preservation is otherwise necessary to establish, exercise or defend legal rights. Information may be securely deleted, anonymised or aggregated when it is no longer needed.
10. Security
We use administrative, technical and organisational measures intended to protect personal information against unauthorised access, alteration, disclosure, loss and destruction. Measures may include access controls, authentication, encryption where appropriate, backups, supplier review, software updates and staff or contractor confidentiality obligations.
No internet transmission or storage system is completely secure. You are responsible for protecting passwords and access credentials that you control and for notifying us promptly if you suspect unauthorised access.
11. Marketing communications
We may send relevant information about our services where you have asked for it, consented, or where another lawful basis permits us to do so. You can opt out at any time by using an unsubscribe link or contacting us.
Opting out of marketing does not prevent us from sending necessary service, contract, invoice, security or administrative messages. We may retain a minimal suppression record so that we remember not to send marketing to an address that has opted out.
13. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- ask for confirmation that we use your personal information and obtain a copy;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information in certain circumstances;
- ask us to restrict how information is used in certain circumstances;
- object to processing based on legitimate interests or for direct marketing;
- receive certain information in a structured, commonly used and machine-readable format and transmit it to another controller;
- withdraw consent at any time where processing relies on consent; and
- complain to the Information Commissioner’s Office.
These rights are not absolute and exemptions may apply. We may ask for information to verify your identity and clarify your request. We normally respond within one month, although the law permits extra time for complex or numerous requests. We will tell you if an extension applies.
14. Your right to object
You have an absolute right to object to the use of your personal information for direct marketing. You may also object where we rely on legitimate interests. In that case, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
15. Children
Our website and services are directed at businesses and adults and are not intended for children. We do not knowingly seek personal information from children. A parent or guardian who believes a child has supplied information should contact us so that we can review and, where appropriate, delete it.
16. Third-party websites and services
Our website may link to websites, maps, social-media platforms or other services operated by third parties. Those organisations control their own privacy practices. We recommend reading their notices before providing information or enabling optional content.
17. Questions and complaints
Please contact us first at hello@greentide.co.uk if you have a privacy question or concern. We will investigate and respond as reasonably required.
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom supervisory authority for data protection. Its website is ico.org.uk.
18. Changes to this policy and contact details
We may update this policy when our services, suppliers, technology or legal obligations change. The latest version will be published on this page with a revised date. Material changes may also be brought to your attention by another reasonable method where appropriate.
Privacy requests should be sent to Green Tide at hello@greentide.co.uk or to Essex, United Kingdom. Please include enough detail for us to identify the relevant information and understand your request.

