Replace the square-bracketed legal name, address and registration details below. Confirm that every listed email address exists and that the retention periods match the final service configuration.
1. Policy overview
This privacy policy explains how WOWLeads collects and uses personal data when someone visits our website, books a call, contacts us, buys or uses our services, receives our business marketing, or interacts with a system we operate for a client. It also explains your rights under UK data-protection law.
“Personal data” means information relating to an identified or identifiable person. It does not include genuinely anonymous information. This policy should be read with our Terms of Service, Payments, Cancellations and Refunds Policy, and any client order form or data-processing terms.
2. Who we are and how to contact us
The controller for our own website, sales, account, billing and support activities is:
[INSERT LEGAL BUSINESS NAME], trading as WOWLeads Marketing
[INSERT POSTAL ADDRESS]
[INSERT COMPANY NUMBER IF APPLICABLE] · [INSERT VAT NUMBER IF APPLICABLE]
You can also use the routes on our contact page. If we appoint a data-protection officer or UK representative, we will update this section.
3. When we are a controller and when we are a processor
Our own business data
We act as a controller when we decide why and how to use personal data for our website, sales, bookings, contracts, billing, support, security, service improvement and our own marketing.
Data handled for a client
When a home-service business uses WOWLeads to manage its enquiries or customer communications, that business will normally be the controller and we will normally act as its processor. We use that data only on the client's documented instructions, subject to the service agreement and data-processing terms. Requests about a particular trade business or job should normally be sent to that business first. We will assist the client where required.
Some activities may involve separate or joint controller roles depending on the facts. If that applies, the relevant order form or notice will explain the allocation.
4. Personal data we may collect
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Name, role, business, postal address, email, telephone number | You, your employer or client |
| Account and contract | Login identifiers, permissions, plan, order form, acceptance records, preferences | You, an authorised account owner |
| Enquiry and job context | Service requested, postcode or service area, property/job details, timescale, preferred contact route | You or a client-operated enquiry journey |
| Communications | Emails, messages, support tickets, call notes and—where clearly notified—recordings or transcripts | You, our staff, service channels |
| Transaction | Invoices, payment status, amount, currency, tax information and limited payment identifiers | You and payment providers; we do not need your full card number |
| Technical and usage | IP address, device/browser, timestamps, pages or features used, error and security logs, cookie choices | Your device and service systems |
| Marketing and source | Campaign/source, interests, communication preference, opt-out and suppression records | You, public business sources, referrals, interactions |
| Feedback and outcomes | Survey answers, review status, complaint details, enquiry stage and reason codes | You, our clients or service use |
We do not intentionally ask for special-category data (such as health, ethnicity, religion, biometrics or sexual orientation) or criminal-offence data. Please do not provide it unless it is genuinely necessary and the controller has supplied appropriate instructions and safeguards. Free-text fields can contain unexpected data; access is restricted and unnecessary content may be removed.
We may create aggregated or anonymised statistics that no longer identify anyone. We can use those statistics for analysis and improvement.
5. Purposes and lawful bases
We use personal data only where we have a valid purpose and lawful basis. The basis depends on the context:
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Respond to enquiries and book calls | Contact, business and booking details | Steps at your request before a contract; legitimate interests in answering business enquiries |
| Provide and administer services | Account, contract, usage and communications | Contract; legitimate interests for authorised business-user contacts |
| Process payments and keep tax records | Transaction, contact and invoice data | Contract; legal obligation; legitimate interests in debt administration |
| Support, complaints and service messages | Contact, account, communications and technical data | Contract; legal obligation; legitimate interests in resolving issues |
| Secure and prevent abuse | Technical, account, audit and communication data | Legitimate interests; legal obligation where applicable |
| Improve the service and understand performance | Usage, feedback and aggregated outcomes | Legitimate interests; consent where required for non-essential tracking |
| Send relevant business marketing | Business contact, source, preference and engagement | Legitimate interests or consent, alongside applicable electronic-marketing rules |
| Establish or defend legal claims | Relevant contract, transaction and communication data | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we consider the purpose, necessity and impact on the individual, including reasonable expectations and safeguards. You may object in relevant circumstances. Where we rely on consent, you can withdraw it at any time without affecting earlier lawful use.
If required data is not provided, we may be unable to respond, enter into a contract, process a booking or deliver a requested service. We will identify mandatory fields where practical.
6. Automation and artificial intelligence
WOWLeads may use rules and assisted technologies to acknowledge enquiries, ask relevant questions, classify a request, suggest a response, route work, create summaries or prompt follow-up. These tools can be wrong. They are not authorised to make emergency, safety-critical, legal, credit, employment or similarly significant decisions about a person.
We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects. Where a workflow could materially affect someone, we configure human review and an escalation route. A person can ask for review through the relevant business or contact us.
We and our service providers may process prompts, messages and outputs to deliver the contracted function. Client data is not used to train general-purpose models unless the relevant controller has expressly authorised that use and a lawful, transparent basis exists.
7. Direct marketing
We may contact corporate business addresses about services relevant to the recipient's professional role where electronic-marketing rules permit and our legitimate-interests assessment supports it. Rules can differ for sole traders, some partnerships and individual subscribers; consent may be required. Telephone marketing also depends on applicable preference-service registrations and prior objections.
Every direct-marketing message will identify the sender and provide a simple way to object or unsubscribe. You can opt out at any time by using that route or emailing [email protected]. We may retain the minimum information needed on a suppression list so we do not contact you again. Service, security, invoice and contract messages are not marketing and may still be sent where necessary.
Our clients are responsible for the lawfulness, audience, content and instructions for marketing they send through the service. We may suspend activity that appears unlawful, misleading or contrary to provider rules.
10. Security and data incidents
We use proportionate technical and organisational controls such as access restriction, authentication, encryption where appropriate, backups, logging, supplier review, staff confidentiality and incident procedures. No internet service can be guaranteed completely secure.
Clients must manage authorised users, remove access promptly, use strong unique credentials, protect devices and report suspected compromise. Security concerns should be sent to [email protected]. Where a personal-data breach triggers a legal notification duty, the relevant controller will notify the regulator and affected people within the required timeframe.
11. How long we keep data
We keep personal data only as long as reasonably necessary for the purpose, legal duties, disputes and security. The following are working defaults and may be shortened or extended where the context, contract, legal hold or controller instruction requires:
| Record | Typical period | Reason |
|---|---|---|
| Pre-sales enquiries and booking records | Up to 24 months after the last meaningful contact | Respond, follow up appropriately and understand the relationship |
| Contracts, core account records and invoices | Usually 7 years after the relevant financial year or contract end | Tax, accounting and legal claims |
| Routine support tickets and service correspondence | Usually 3 years after closure | Continuity, quality and disputes |
| Call recordings or transcripts, where used | Normally up to 12 months, unless a shorter notice states otherwise | Training, quality, evidence and follow-up |
| Security, access and web logs | Normally up to 12 months | Security investigation, resilience and abuse prevention |
| Optional analytics identifiers | Normally up to 14 months | Trend analysis, subject to consent/settings |
| Client enquiry/customer data | As instructed in the service agreement; export or deletion normally begins within 30–90 days after termination | Processor obligations and controlled offboarding |
| Marketing suppression record | As long as needed to honour the objection | Avoid sending unwanted marketing |
Backups may retain encrypted residual copies for a limited rotation period. Such copies are protected, not routinely accessed and removed through the normal cycle unless legally preserved.
12. Your data-protection rights
Depending on the circumstances, you may have the right to:
- be informed about use of your personal data;
- request access to your personal data and supplementary information;
- have inaccurate data corrected and incomplete data completed;
- request deletion where the law applies;
- restrict processing in specified situations;
- receive certain data in a portable format;
- object to direct marketing at any time and object to some legitimate-interest processing;
- withdraw consent at any time;
- seek safeguards relating to solely automated significant decisions; and
- complain to us and to the Information Commissioner's Office.
Send a request to [email protected]. State which right you are exercising and give enough information to locate the relevant records. We may request proportionate proof of identity or authority, particularly where disclosure could affect another person. We normally respond within one month, subject to lawful extensions for complex or multiple requests. Rights are not absolute; if an exemption or refusal applies, we will explain it where permitted.
If we process data only for a client, we may refer the request to that client and assist them. We will not disclose another person's confidential information merely because it appears in the same record.
13. Data-protection complaints
Email [email protected] with “Data protection complaint” in the subject. Explain what happened, the relevant dates and the outcome you seek. We will:
- provide a way to make the complaint without unreasonable barriers;
- acknowledge it within 30 days;
- take appropriate steps to investigate and respond without undue delay;
- keep you informed of progress; and
- tell you the outcome and, where appropriate, any action taken.
You can also complain to the Information Commissioner's Office. We would appreciate the opportunity to address the issue first, but this does not limit your right to approach the regulator.
14. Children, third-party links and policy changes
Our services are designed for business users, not children. We do not knowingly offer them directly to anyone under 18. If a workflow could collect information about a child, the relevant client must ensure an appropriate lawful basis, notice and safeguards.
Our pages may link to third-party services. Their operators control their own privacy practices, and their policies should be reviewed separately.
We may update this policy when services, providers or law change. Material changes will be highlighted by an updated date and, where appropriate, a direct notice. Earlier versions can be requested from the privacy contact.