Privacy Policy

This policy explains what personal data CanMarket Limited collects, why we collect it, who we share it with and what rights you have. Please read it carefully.

Last updated: 12 August 2026. This version replaces all previous versions.

Who we are

CanMarket Limited is the data controller for the personal data described in this policy and for this website. We are a company registered in England and Wales (company number 07212058) with our registered office at 168 Old Dover Road, Canterbury, Kent, England, CT1 3EX. We are registered with the Information Commissioner’s Office under reference ZA695814.

Where this policy says “CanMarket”, “we”, “us” or “our”, it means CanMarket Limited.

You can contact us about anything in this policy:

  • By email: [email protected]
  • By post: Data Protection, CanMarket Limited, 168 Old Dover Road, Canterbury, Kent, England, CT1 3EX
  • Using the form on our contact page

We are not required to appoint a Data Protection Officer and have not appointed one. Enquiries about data protection are handled by the director.

The law that applies

We handle personal data in accordance with the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, together with the Privacy and Electronic Communications Regulations 2003 (PECR) where those apply to cookies and electronic marketing. Our supervisory authority is the Information Commissioner’s Office (ICO).

Who this policy applies to

This policy applies to you if you:

  • visit this website;
  • contact us with an enquiry, whether through our contact form, by email, by phone or on social media;
  • are a client of ours, or work for one;
  • supply goods or services to us, or work for a supplier; or
  • receive marketing from us.

Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal data relating to anyone under 18.

What we collect, why, and our legal basis

If you visit this website

We automatically collect technical information: your IP address, browser type and version, device and operating system, time zone, the pages you view, how you arrived at the site and how you move through it, and the dates and times of your visit. Some of this comes from our web server logs and some from cookies and similar technologies, which are covered in the next section.

Why: to keep the site running, secure and free from abuse, to diagnose faults, and to understand how the site is used so we can improve it.

Legal basis: our legitimate interests in operating and securing our website and understanding how it performs. Where this involves cookies or similar technologies that are not strictly necessary, we rely on your consent under PECR, given through our cookie banner.

If you make an enquiry

Our contact form collects your first name, last name, email address, telephone number and the content of your message. If you email, call or message us directly we will hold whatever you choose to tell us, along with a record of the correspondence.

Why: to answer your enquiry, to discuss whether we can help you, and to keep a record of what was said. When you use our contact form, the details you send are emailed to us and stored on this website so that an enquiry is not lost if the email fails to arrive.

Legal basis: taking steps at your request before entering into a contract, and our legitimate interests in responding to people who approach us and in keeping proper records of our business dealings.

The tick box on our contact form confirms you have seen this policy. It is not the legal basis on which we process your enquiry, and ticking it does not give us permission to market to you.

If you are a client, or work for one

We hold your name, job title, employer, email address, telephone number, postal address, the correspondence between us, the records of the work we do for you, and our invoicing and payment records. We do not take card payments and we do not hold card details. Clients pay us by bank transfer, so we hold the bank details you give us for that purpose.

Why: to provide our services, to manage the relationship, to invoice and get paid, to keep accounting records, and to deal with any dispute.

Legal basis: performance of our contract with you or with your employer; compliance with our legal obligations, particularly under tax and company law; and our legitimate interests in managing our business and defending our legal position.

If you are a supplier, partner or professional contact

We hold your name, job title, employer, contact details, the correspondence between us and our records of what was supplied and paid. We may also look at publicly available information about you and your business, such as your website, Companies House and your professional social media profile.

Why: to buy in the goods and services we need, to manage those relationships and to keep accounting records.

Legal basis: performance of a contract, compliance with legal obligations, and our legitimate interests in running our business.

If we market to you

We hold your name, business email address, employer and your marketing preferences, including any request to stop.

Why: to tell you about our services where we think they are relevant to your work.

Legal basis: our legitimate interests in promoting our services to business contacts, or your consent where we have asked for it. We always comply with PECR, which is explained under “Marketing” below.

Cookies and similar technologies

This site uses cookies and similar technologies. Some are strictly necessary to make the site work and to keep it secure, and these do not require your consent. Others, including our analytics and any third-party content, are only set if you agree through the cookie banner when you first arrive.

The services we use that may set cookies or send data to a third party are:

  • Google Analytics and Google Tag Manager, to measure how the site is used;
  • Google reCAPTCHA, to stop our forms being abused by automated software. This works by analysing your interaction with the page and is subject to Google’s privacy policy and terms of service;
  • Google Fonts, which serves the typefaces used on this site;
  • Cloudflare, which delivers and protects the site;
  • LinkedIn, where we embed or link to content on that platform.

You can change or withdraw your cookie choices at any time using the cookie preferences link on this site, and you can block or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of the site working. Our cookie policy sets out each cookie, what it does and how long it lasts.

When we act for our clients

When we deliver marketing services, we sometimes have access to personal data belonging to a client, for example the data in their advertising accounts, analytics, CRM or mailing lists. In that situation the client is the data controller and we act as their processor. We only act on that client’s documented instructions, under a written contract that meets the requirements of Article 28 of the UK GDPR.

If you want to know how a particular business handles your personal data, you should contact that business directly. If you contact us instead, we will pass your request on to them and tell you that we have done so.

Who we share your personal data with

We do not sell your personal data. We share it only where we need to, and only the minimum needed. The categories of recipient are:

  • Our website host, which stores the site and its server logs;
  • Cloudflare, Inc., which provides our content delivery network and security filtering, and therefore processes the traffic to this site;
  • Google, for website analytics, reCAPTCHA, fonts and our business email;
  • Capsule CRM, operated by Zestia Limited, a company registered in England and Wales, where we manage our client and business contact records;
  • Automattic, Inc., which provides the security, statistics and spam filtering tools built into our website platform;
  • Our professional advisers, including our accountant, our bank and, if needed, our solicitors and insurers;
  • HM Revenue & Customs and other authorities and regulators, where the law requires us to report or disclose;
  • A buyer or prospective buyer, if we ever sell or reorganise the business, on terms that require them to use your personal data only as described in this policy.

We will also disclose personal data where we are required to by law, or where we need to in order to establish, exercise or defend legal claims.

Where a third party acts as our processor, we have a written contract with them that requires them to keep your personal data secure, to use it only on our instructions and never for their own purposes.

Sending personal data outside the UK

Some of the providers listed above are based outside the United Kingdom, principally in the United States. When we transfer personal data out of the UK we make sure it is protected to the standard required by UK law, by relying on one of the following:

  • UK adequacy regulations, where the Secretary of State has decided the country in question provides adequate protection;
  • the UK Extension to the EU-US Data Privacy Framework, where the recipient is a US organisation certified under it; or
  • the ICO’s International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, supported by a transfer risk assessment and any additional safeguards that assessment shows are needed.

If you would like more detail about the safeguards we use for a particular transfer, please email us.

How long we keep personal data

WhatHow long
Website server logsUp to 12 months
Analytics dataUp to 14 months, then deleted automatically
Enquiries that do not lead to work24 months from our last contact with you
Client records, correspondence and deliverables7 years after the end of the engagement
Accounting and tax records7 years, as required by law
Supplier records7 years after the end of the relationship
Marketing preferences and opt-out recordsFor as long as we market, and opt-out records indefinitely so we do not contact you again by mistake

We will keep personal data for longer where the law requires it, or where it is relevant to legal proceedings, in which case we keep it until those proceedings and any enforcement have finished. Where we no longer need to identify you, we may anonymise the data instead of deleting it and keep the anonymised version.

How we protect personal data

We use appropriate technical and organisational measures to protect personal data, including encryption of the connection to this website, access controls and multi-factor authentication on the accounts that hold personal data, kept-up-to-date software, and restricting access to those who need it.

No transmission over the internet is completely secure, and we cannot guarantee the security of data you send us over the internet. We have procedures for dealing with any suspected personal data breach and will notify you and the ICO where the law requires us to.

We will never ask you to send us your bank details, passwords or card numbers by email or text message. If you receive a message that appears to be from us and asks for these, please do not respond and tell us straight away.

Marketing

We may send you information about our services by email where you have asked us to, where you have engaged us before, or where you are a business contact and the message is relevant to your work. We comply with PECR, which sets the rules for electronic marketing in the UK.

You can tell us to stop at any time. Every marketing email has an unsubscribe link, or you can email us and we will act on it. If you opt out, we keep a record of your email address on a suppression list so that we do not contact you again by mistake. Opting out of marketing does not stop us sending you messages we need to send about work we are doing for you.

We will not share your personal data with any third party for that third party’s own marketing purposes.

Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not carry out profiling of that kind.

Your rights

You have the following rights in relation to the personal data we hold about you:

  • Access. To be told whether we hold personal data about you and to receive a copy of it, together with information about how we use it.
  • Rectification. To have inaccurate personal data corrected and incomplete data completed.
  • Erasure. To ask us to delete personal data, in the circumstances where that right applies.
  • Restriction. To ask us to limit our use of your personal data to storage only, in certain circumstances.
  • Objection. To object to processing based on our legitimate interests. You can also object to direct marketing at any time, and that is an absolute right.
  • Portability. To receive certain personal data in a machine-readable format, or to have it sent to another provider.
  • Withdrawing consent. Where we rely on your consent, to withdraw it at any time. That does not affect anything we did before you withdrew it.

To exercise any of these rights, email [email protected] or write to us at the address above.

There is no charge. We may ask you for information to confirm your identity, so that we do not disclose personal data to the wrong person. We will respond within one month of receiving your request. If your request is complex, or you have made several, we may extend that by up to two further months, and we will tell you if we do and explain why. We may refuse a request, or charge a reasonable fee, if it is manifestly unfounded or excessive, and we will explain our reasons if we do.

Please keep us informed if your contact details change.

How to complain

If you are unhappy with how we have handled your personal data, please tell us first so we have the chance to put it right. Email [email protected] or write to Data Protection, CanMarket Limited, 168 Old Dover Road, Canterbury, Kent, England, CT1 3EX. You can also use the form on our contact page. Please tell us what has happened and what you would like us to do.

We will acknowledge your complaint within 30 days of receiving it. We will then look into it and keep you informed, and we will tell you the outcome as soon as we can, normally within three months. If we cannot meet that timescale we will explain why and tell you when to expect our response.

If you are not satisfied with our response, or if we do not respond, you can complain to the Information Commissioner’s Office:

  • Online: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • By post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Links to other websites

This site contains links to other websites, including social media platforms. We are not responsible for the content of those sites or for how they handle your personal data. Please read their own privacy policies before giving them any personal data.

Changes to this policy

We review this policy regularly and will update it when our practices change or the law changes. The date at the top shows when it was last updated. If we make a significant change, we will draw attention to it on this page, and we will tell you directly where we are required to.