Legal information
M Frost Digital Privacy Notice
This notice explains how we collect, use, share and protect personal information when you visit our website, contact us, receive business marketing from us, or use our services.
Version 1.1 | Effective and last updated: 1 September 2026
1. Who we are and how to contact us
Maxwell Frost, trading as M Frost Digital, is the controller responsible for the personal information described in this notice and determines why and how that information is used.
- Controller
- Maxwell Frost trading as M Frost Digital
If you make a data-protection rights request or complaint, use the contact details above.
2. What information we collect, why we use it, and our lawful bases
We only collect information that is reasonably necessary for the relevant purpose. The categories below reflect our current services and planned launch configuration.
2.1 Enquiries, quotations and client services
Information we may use:
- Name and business contact details, including email address and telephone number.
- Business name, business address, job title or role, and other relevant business information.
- Enquiry details, selected services, current business situation, challenges, service requirements, website or business information you choose to provide, and related correspondence.
- Proposals, contracts, statements of work, material meeting notes and decisions.
- Service history, invoices, transaction references, amounts, billing information and accounting correspondence. We do not intentionally retain raw payment-card data.
Why we use it: We use this information to respond to enquiries, prepare quotations, take steps at your request before entering a contract, perform and administer client contracts, communicate about services, maintain appropriate business records, troubleshoot issues and improve service reliability.
Lawful basis: Contract or steps taken at your request before entering a contract where you are the contracting party; legitimate interests in administering a prospective or existing relationship with the organisation you represent, securing and improving our services, and maintaining proportionate business records; and legal obligation where records must be kept by law.
2.2 Business-to-business prospecting and marketing
Information we may use:
- Name, work contact details, job title or role, company and relevant public business information.
- The source of the contact information and proportionate observations about the business that help us assess whether our services may be relevant.
- Marketing preferences, opt-in or opt-out status, and the minimum information needed to maintain suppression records.
We may obtain this information from public business sources and use it to identify and communicate with relevant business prospects. Where appropriate, we rely on our legitimate interests in developing the business and promoting relevant B2B services after considering necessity, proportionality and the person's reasonable expectations.
For live marketing calls, we screen numbers against the Telephone Preference Service (TPS), the Corporate Telephone Preference Service (CTPS) where relevant, and our own do-not-contact records. We identify M Frost Digital, display or provide a contact number where required, and honour objections.
PECR generally permits electronic marketing to corporate subscribers without prior consent, but we identify ourselves and provide a valid way to opt out. Sole traders and some partnerships are treated as individual subscribers: we only send unsolicited electronic marketing to them where valid consent or the PECR soft opt-in applies. The soft opt-in is not used for purchased or publicly sourced lists.
If we obtain personal information from another source, we provide the privacy information required by Article 14 at the first communication or, at the latest, within one month, unless a lawful exception applies. You have an absolute right to object to direct marketing at any time. After an objection, we stop the marketing and may retain only the minimum suppression information needed to prevent further contact.
2.3 Website operation, security and technical logs
Information we may use:
- IP address, request timestamps, pages or resources requested, browser and device information, operating system, error logs and security events generated by our hosting or application systems.
Why we use it: We use this information to deliver the website, keep it secure, diagnose faults, prevent abuse, investigate incidents and maintain service reliability.
Lawful basis: Legitimate interests in operating and protecting our website and systems. Storage or access technologies that are strictly necessary for the service may also be used without consent where a PECR exception applies.
2.4 Google Analytics
Information we may use:
- Page views and website interaction events.
- Traffic and referral source information, campaign information where present, browser/device information, approximate geographic information and pseudonymous analytics identifiers.
- For GA4 web properties, Google says IP addresses from UK and EU visitors are used transiently to derive location information and are then discarded before data is logged to an Analytics data centre. Separate hosting or security logs may still contain IP addresses.
Why we use it: With your consent, we use Google Analytics 4 (GA4) to understand how people find and use our website, assess page and campaign performance, and measure actions such as calls-to-action and enquiry-form activity.
Lawful basis: Consent. We do not activate non-essential analytics tracking until the visitor accepts analytics. A visitor can reject analytics and can later withdraw or change that choice through cookie settings. We do not enable Google Signals, user-provided data collection or Google Analytics advertising features.
2.5 Planned AI-assisted enquiry and call handling
No visitor, prospect, enquiry, email, call or client personal information currently reaches OpenAI through this website or our present enquiry process. AI-assisted enquiry or call handling is planned only after a relevant service is activated.
Where enabled, the information processed may include contact details, business and service information, enquiry or communication content, call information, transcripts, classifications, structured summaries and workflow instructions. The exact categories will depend on the approved service configuration.
Possible purposes include helping to handle an enquiry or call, record relevant details, classify or route an opportunity, produce a structured summary and support an approved workflow. Depending on the context, the lawful basis may be contract or steps requested before a contract, legitimate interests after a documented balancing assessment, or consent where required. We will establish and document the final lawful basis, retention period, supplier configuration and transparency information before activation.
We will not record or transcribe calls unless the legal basis and required notice or consent have first been established for the specific service. AI outputs may be incomplete or inaccurate and must be reviewed where appropriate. We do not use AI to make solely automated decisions that produce legal or similarly significant effects on individuals.
2.6 Legal requirements, queries, complaints and claims
Information we may use:
- Name and contact details; relevant client, service and transaction records; correspondence; complaint or enquiry information; and other information reasonably necessary for the matter.
Why we use it: We use this information to comply with legal and regulatory duties, respond to rights requests, answer enquiries, investigate and resolve complaints, and establish, exercise or defend legal claims where necessary.
Lawful basis: Legal obligation; contract where the matter relates to a contract; and legitimate interests in responding fairly to enquiries and complaints, protecting our business and clients, and managing disputes or legal claims.
2.7 Sensitive information and automated decisions
We do not intentionally collect special category personal data or criminal-offence data as part of our ordinary website, prospecting or client-service activities. Please do not include sensitive personal information in an enquiry unless it is genuinely necessary and we have asked for it. We do not currently use personal information to make solely automated decisions that produce legal or similarly significant effects on individuals.
2.8 Children
Our services are business-to-business services and are not directed at children. We do not knowingly collect children's personal information for the purposes described in this notice.
3. Your data-protection rights
Depending on the circumstances and lawful basis, UK data-protection law may give you the following rights:
- Access: ask for a copy of your personal information and information about how it is used.
- Rectification: ask us to correct inaccurate information or complete information that is incomplete.
- Erasure: ask us to delete personal information in circumstances where the right applies.
- Restriction: ask us to limit how we use personal information in circumstances where the right applies.
- Object: object to processing based on legitimate interests. You have an absolute right to object at any time to direct marketing.
- Data portability: ask us to provide or transfer certain information you gave us in a structured, commonly used and machine-readable format where the right applies.
- Withdraw consent: withdraw consent at any time where we rely on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Complain: raise a concern with us or complain to the Information Commissioner's Office.
We will respond to valid rights requests without undue delay and normally within one month, subject to any lawful extension or exemption. You are not normally required to pay a fee. We may ask for information needed to verify your identity or clarify your request.
4. Where we get personal information from
- Directly from you, for example through website forms, email, telephone, meetings, contracts and service communications.
- Publicly available business sources, such as company websites, business directories, public registers and professional or business profiles, where appropriate for B2B prospecting.
- Clients, prospective clients, employees, contractors, authorised representatives, referral partners and other people or organisations who introduce or refer a person or business to us.
- Our service providers and technical systems, which may generate website, security, delivery or analytics information when you interact with our website or communications.
Where Article 14 applies because information was obtained indirectly, we provide the required privacy information at the first communication or within one month at the latest, unless a lawful exception applies.
5. How long we keep personal information
We delete or irreversibly anonymise personal information when it is no longer needed, subject to legal, regulatory, contractual, security or claims-related reasons that may require a longer period. The standard periods below reflect our Data Retention Schedule v1.0.
| Record / data category | Standard retention period |
|---|---|
| Prospective business contacts / outbound prospect data | 24 months after the last meaningful interaction or verification of relevance. If a person objects or opts out, only the minimum suppression information needed to honour that choice is retained. |
| Marketing consent, preferences and suppression records | Consent evidence is retained while relied upon and, where needed to demonstrate compliance, up to 6 years after the last relevant marketing communication. Minimal suppression records are retained for as long as needed to honour an objection or opt-out. |
| Unsuccessful enquiries and contact-form submissions | 12 months after the last meaningful contact, unless the enquiry becomes a client record or is needed for a dispute or claim. |
| Core client contact and service records | For the active client relationship and generally 6 years after it ends for core records relevant to contracts, payments or claims. |
| Contracts, proposals, statements of work and material decisions | 6 years after the contract or client relationship ends, unless a longer period is required because a claim or legal hold remains active. |
| Invoices, transactions and accounting records | Generally 6 years after the end of the relevant tax or accounting period, or longer where applicable law requires. |
| Routine client correspondence and support records | 2 years after the issue is closed or the client relationship ends, whichever is later, unless the communication forms part of a contract record, complaint, claim or legal hold. |
| Complaints, disputes and claims | 6 years after final resolution or closure, or longer while a legal hold, claim or regulatory requirement remains active. |
| Google Analytics event/user-level data | For the period selected in the GA4 property. Standard GA4 properties allow a 2-month or 14-month retention period for user-level and event-level data; the selected setting must be confirmed before analytics is activated. Standard aggregated reports are not governed by the same setting. |
| Website/server technical and security logs | 90 days from collection by default; up to 12 months where an event is retained for a documented security investigation. |
| Cookie and consent-management records | 24 months after the last consent choice or withdrawal, unless a longer period is reasonably necessary to demonstrate compliance. |
| AI-assisted enquiry or call information (where enabled) | A specific retention period will be documented before the relevant AI-assisted service is activated, taking account of the service configuration, purpose, supplier settings and client requirements. |
| Third-party referrals and introductions | If no relationship develops: 12 months after the last meaningful contact. If the person becomes a client, the applicable client-record period applies. |
| Legal, regulatory and data-protection rights-request records | 6 years after closure of the matter unless a different legal or regulatory period applies. |
| System backups containing personal information | Normal rolling backup cycle, targeted at no more than 90 days after deletion from live systems unless technical or legal constraints require otherwise. |
We may delete information earlier where it is no longer needed. Deletion may be paused where information is required for an active complaint, investigation, dispute, legal claim or regulatory request. Residual copies may remain in restricted backups until the normal backup cycle expires and are not restored for ordinary business use.
6. Who we share personal information with
We do not sell personal information. We use a limited number of suppliers to operate the website and business. We only provide information that is reasonably necessary for the relevant service.
OpenAI-powered processing is planned but is not currently active. No visitor, prospect, enquiry, email, call or client personal information currently reaches OpenAI through the website or current enquiry process.
| Provider / category | What they help us do |
|---|---|
| Vercel Inc. | Website hosting, deployment, content delivery, infrastructure, technical security and related platform services. |
| Formagrid Inc. dba Airtable | Cloud database and business-management tools used to receive, organise and manage enquiries, prospect information and client records, including information submitted through website forms. |
| OpenAI and relevant service providers | Where enabled, AI-assisted enquiry processing, call handling, transcription, classification, structured summaries and workflow automation. Relevant enquiry, communication and call information may be processed only when these services are activated. |
| Google Analytics (Google Ireland Limited and relevant Google affiliates) | Website analytics, only after the relevant consent choice. We use GA4 for website measurement and do not enable Google Signals, user-provided data collection or Analytics advertising features. |
| Google Ireland Limited, Google LLC and relevant affiliates, as applicable | Business email and associated communications. |
We may also share relevant information where necessary with accountants, solicitors and other professional advisers; authorities or organisations where disclosure is legally required; authorised representatives, contractors, subcontractors, referral partners or collaborating businesses where needed to provide a service; and a prospective buyer, investor or successor organisation where necessary for a sale, merger, restructuring or transfer of the business.
7. International transfers
Some suppliers are based in, or use infrastructure or subprocessors located in, countries outside the United Kingdom. Where a transfer is a restricted transfer under UK data-protection law, we use an applicable adequacy regulation or appropriate safeguards such as contractual safeguards, as appropriate to the supplier and transfer.
| Provider | Where processing may occur | Transfer protection |
|---|---|---|
| Vercel Inc. | United States and other locations where Vercel or its approved subprocessors operate. | Vercel's published Data Processing Addendum applies to its Pro and Enterprise services and includes transfer mechanisms such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses where applicable. |
| Formagrid Inc. dba Airtable | United States and other locations where Airtable or its approved subprocessors operate. | Where a restricted transfer occurs, appropriate safeguards are used as applicable. Airtable's published Data Processing Addendum includes the UK International Data Transfer Addendum when the DPA has been validly put in place. |
| Google Analytics and Google business email services | Ireland, the United States and other locations where the relevant Google entity, affiliates or subprocessors operate. | Where a restricted transfer occurs, Google's applicable data terms use recognised transfer mechanisms as appropriate, including contractual safeguards such as Standard Contractual Clauses and UK transfer provisions. |
| OpenAI and relevant service providers (only where enabled) | Where OpenAI-powered services are enabled, the United States and other locations used by approved subprocessors. | Where a restricted transfer occurs, appropriate safeguards are used as applicable, including contractual safeguards such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. |
Transfer mechanisms, processing locations and supplier terms can change. We review material changes to our suppliers and safeguards and update this notice where appropriate. You can contact us if you would like more information about the safeguards relevant to a particular transfer.
8. Cookies and similar technologies
Our website may use strictly necessary storage or access technologies to deliver and secure the service. These do not require consent where the applicable PECR exception applies.
We use GA4 analytics technologies only after a visitor gives consent. They help us distinguish browser sessions and understand page views, referral sources, devices and interactions with the website. Analytics remains off if the visitor rejects it. Consent can be withdrawn or changed at any time through cookie settings, without affecting the use of the website.
The exact analytics identifiers, cookie names and durations depend on the final live GA4 and consent configuration. They will be verified and documented before analytics is activated rather than inferred from generic defaults.
Google explains how it uses information from sites and apps using its services here: How Google uses information from sites or apps that use our services.
9. How we protect personal information
We use proportionate technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, alteration and disclosure. These measures include access controls, secure hosting, encrypted network connections, data minimisation, controlled retention, appropriate supplier arrangements and security monitoring. No internet-based service can guarantee absolute security, but we review and improve our controls as the business and processing activities develop.
10. How to complain
If you have a concern about how we use personal information, please contact us first so that we can investigate and respond.
Email: mfrostdigital@gmail.com
If you remain unhappy after raising a complaint with us, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Information Commissioner's OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Make a complaint to the ICO
11. Changes to this privacy notice
We review this notice at least annually and whenever our processing changes materially. In particular, we will review it before introducing material new data sources, client portals, recorded calls, AI voice or autonomous agent services, payment platforms, new analytics or advertising technologies, or materially different services. Where appropriate, we will bring significant changes to the attention of affected individuals.
M Frost Digital - Privacy Notice - Version 1.1 - 1 September 2026
