Privacy Policy & Cookie Notice
Version 2.0 · Effective 8 June 2026
This policy explains what personal data we collect about you, how and why we use it, who we share it with, how we look after it, and the rights you have over it. It applies to visitors to this website, prospective and paying clients, attendees of our workshops, and recipients of our communications.
1. Who we are (the controller)
The data controller is James Edwards, trading as Tailored Tools (sole trader), Orchard House, 16 Pear Tree Lane, Maidstone, Kent, ME15 9QY, United Kingdom. Email [email protected]. The same controller also operates The Sonic Sanctuary; where the data is collected through that brand, it is handled under separate notice specific to that practice.
Tailored Tools is registered with the UK Information Commissioner’s Office (ICO) as a data controller.
2. What personal data we collect
2.1 From website visitors
- Technical data sent automatically by your browser to GitHub Pages (our hosting provider): IP address, user agent, request paths, timestamps. Used by GitHub for security and infrastructure operation; we do not access these server logs.
- Information you submit via forms (e.g., the free AO Score form): business name, business type, website URL, email address, optional message.
- If you email us: your name, email address, and the content of your message.
2.2 From AO Audit clients and prospects
- Billing details processed by Stripe (we do not store full card numbers; only the last four digits and confirmation tokens).
- Business contact details, website URLs, and any information you share with us during scoping or delivery.
- Publicly available business information we analyse during the audit (website HTML, schema markup, Google Business Profile, publicly visible reviews).
2.3 From Custom Platform engagements
The specific personal data we process depends on what the platform does for you. This will be set out in a Data Processing Agreement (DPA) signed before processing begins.
2.4 Special category data (UK GDPR Article 9)
Where a client engagement involves biometric data, health data, or other special category data, we process it only on the explicit consent and lawful basis declared by the controller in writing. Special category data is not collected through this website.
3. Lawful bases under UK GDPR Article 6
We rely on the following lawful bases:
- Contract (Article 6(1)(b)), to perform paid services for you (AO Audits, Custom Platforms, Workshops, Retainers).
- Legitimate interests (Article 6(1)(f)), to operate and improve our website, respond to enquiries, and conduct AO scans of publicly available business information. Our legitimate interest is operating a B2B consultancy; we balance this against your rights and freedoms.
- Consent (Article 6(1)(a)), for any marketing communications, for the use of non-essential cookies, and where required for special category data (combined with Article 9(2)(a) explicit consent).
- Legal obligation (Article 6(1)(c)), to comply with tax, accounting, regulatory and reporting requirements.
4. Who we share your data with (processors and third parties)
We use the following data processors and service providers:
- GitHub Pages, website hosting. Operated by GitHub Inc. (US). GitHub privacy statement.
- Cloudflare, DNS, CDN, security in front of this site (US/EU/UK edge). Cloudflare privacy policy.
- Stripe, payment processing for paid services. Operated by Stripe Payments Europe Ltd / Stripe Inc. (Ireland / US). Stripe privacy policy.
- Resend, transactional email delivery (including AO Score form submissions and audit results) via the
send.tailored-tools.comsubdomain. The free AO Score form posts to a Cloudflare Worker we operate, which calls Resend to email the submission to us, no third-party form embeds. Operated by Resend Inc. (US). Resend privacy policy. - IONOS, inbound email hosting for
[email protected]. Operated by IONOS SE (Germany). IONOS privacy policy. - Google Fonts, web fonts loaded from
fonts.googleapis.com. Operated by Google Ireland Ltd / Google LLC (US). Google privacy policy. - HMRC and our accountant, for tax, accounting, and self-assessment reporting.
We do not sell your data, share it for advertising, or use it to train third-party AI models.
5. International transfers
Some of the processors above are based in or transfer data to the United States, where data protection laws differ from the UK. Where such transfers occur, we rely on (i) the UK extension to the EU–US Data Privacy Framework where the processor is certified, (ii) the UK International Data Transfer Agreement / Standard Contractual Clauses where not, or (iii) your explicit consent where neither applies. You can request copies of the safeguards in place.
6. Cookies and tracking
This website uses a small number of cookies and equivalent technologies. None are used for advertising or cross-site tracking.
6.1 Essential
- Cloudflare may set the
__cf_bmbot-management cookie for security purposes (session lifetime).
6.2 Third-party fetches (no embeds, no cookies)
- Google Fonts: when your browser fetches our typeface from
fonts.googleapis.com, Google receives your IP address per its policy. No cookies are set by Google Fonts itself.
This site has no third-party form embeds. The free AO Score form is hosted on our own domain and submits directly to a Cloudflare Worker we operate, no iframes, no third-party JavaScript, no consent banner required.
7. How long we keep your data
- Enquiries and email correspondence: up to 24 months after our last interaction, unless you ask us to delete it sooner.
- Free AO Score form submissions: 12 months from submission.
- Paid client records (engagement files, deliverables, communications): 6 years from the end of the engagement, to meet UK accounting and tax retention obligations.
- Billing records (Stripe receipts, invoices): 6 years (HMRC requirement).
- Special category data: deleted or returned at engagement end unless contracted otherwise.
8. Security
We protect personal data with measures appropriate to its sensitivity: full-disk encryption on all devices, password manager and unique strong credentials, two-factor authentication on all business accounts, encrypted backups, and access controls so only the controller can read client files. We will notify you and the ICO of any personal data breach likely to result in a risk to you, within the timescales required by UK GDPR.
9. Your rights under UK GDPR
You have the right to:
- be informed about how we use your data (this notice);
- access the personal data we hold about you (Subject Access Request);
- correct inaccurate data;
- request deletion ("right to be forgotten") where applicable;
- restrict or object to certain processing;
- request data portability;
- withdraw consent at any time (without affecting prior lawful processing);
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects (we do not currently make such decisions).
To exercise any right, email [email protected]. We respond within one month. If you are unhappy with our handling, you can complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint or 0303 123 1113.
10. Children
Our services are sold to businesses. We do not knowingly collect personal data from anyone under 18 through this website. If you believe a child has submitted personal data to us, email us and we will delete it.
11. Marketing
We will only send you marketing communications if you have explicitly opted in. You can unsubscribe at any time using the link in any marketing email or by emailing us.
12. Changes to this policy
We may update this policy as our services or the law change. The "Effective" date at the top reflects the current version. Material changes will be communicated to active clients by email.
13. Contact
Questions about this policy or how we handle your data: [email protected].