Fimolo's privacy notice
This privacy notice tells you what to expect us to do with your personal information.
Last updated on 24th July 2026
Contact details
Fimolo Ltd is the controller responsible for the personal information described in this privacy notice.
Company registration number
16289738
What information we collect, use, and why
We collect or use the following information to provide and improve products and services for clients:
Names and contact details
Business, billing and correspondence addresses where relevant
Company name, occupation and professional role
Information clients provide about their employees, representatives, customers, suppliers or other people involved in a project
Transaction data, including details of payments, purchases and services
Information about how people use our website, products and services
Enquiries, feedback, compliments and complaints
Records of meetings, decisions and project communications
Audio or video recordings of meetings where we have told participants that recording is taking place
Account identifiers, permissions, security information and access logs
Technical and website-use information, including browser, device and IP information
Project information and materials provided by clients, including briefs, business information, website content, brand assets, photographs, testimonials, correspondence and documents
We may use approved artificial intelligence tools to help us research, organise, summarise, draft, analyse, generate or edit content and creative materials. This may involve limited personal information contained in project files, correspondence, meeting notes, transcripts or images. We minimise the information used, remove identifiers where practical and review AI-assisted outputs before using them.
We collect or use the following personal information for the operation of client or customer accounts:
Names and contact details
Addresses
Purchase or service history
Account information, including registration details
Information used for security purposes
Marketing preferences
Technical data, including information about browser and operating systems
We collect or use the following personal information for the prevention, detection, investigation or prosecution of crimes:
Names and contact information
Client accounts and records
Financial information eg for fraud prevention or detection
Account security information, including login activity, IP addresses, device information, failed login attempts, suspected misuse and payment or chargeback references provided by our payment providers.
We collect or use the following personal information for information updates or marketing purposes:
Names and contact details
Profile information
Marketing preferences
Purchase or account history
Website user journey information
IP addresses
Information about responses to our marketing, including email opens, link clicks, event registrations, survey responses and social media interactions.
Approved testimonials, reviews, names, professional roles, company names, logos, screenshots, images and case-study information
We collect or use the following personal information to comply with legal requirements:
Name
Contact information
Client account information
Any other personal information required to comply with legal obligations
We collect or use the following personal information for dealing with queries, complaints or claims:
Names and contact details
Addresses
Account information
Purchase or service history
Relevant information from previous investigations
Customer or client accounts and records
Financial transaction information
Correspondence
Project files, screenshots, technical records and other evidence provided or collected in connection with a query, complaint or claim.
We collect or use the following personal information to manage our business relationships, projects, suppliers and contractors:
Names and contact details
Company name, occupation and professional role
Business and correspondence addresses
Bank and payment information required to pay suppliers or contractors, excluding full payment-card details handled by payment providers
Contract, project and supplier records
Records of meetings, decisions, communications and approvals
Information about services, deliverables, invoices and payments
Information about relevant employees, representatives or subcontractors involved in the relationship.
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
Your right to erasure - You have the right to ask us to delete your personal information. Read more about the right to erasure.
Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.
Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.
Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.
Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.
If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:
Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
We have a legitimate interest in managing and improving our products and services, maintaining service quality, understanding how clients use them, keeping our systems secure and developing improvements based on client needs and feedback. We only use personal information that is reasonably necessary for these purposes. This benefits our clients by helping us provide reliable, relevant and secure services. The information used is limited, handled proportionately and would normally be expected within an existing or prospective client relationship. We do not use it where the person’s rights, interests or freedoms outweigh our business interests.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:
Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
We have a legitimate interest in operating, maintaining and securing client and customer accounts. This includes protecting accounts from unauthorised access or misuse, troubleshooting technical issues, maintaining accurate account records and improving account functionality. Using limited account, technical and usage information is necessary to provide a reliable and secure service. It benefits customers by protecting their access, purchases and account activity. We limit the information used, apply appropriate security measures and do not use it where the person’s rights and interests outweigh our legitimate interests.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Our lawful bases for collecting or using personal information for the prevention, detection, investigation or prosecution of crimes are:
Recognised legitimate interests - our pre-approved purpose for collecting or using personal information for the prevention, detection, investigation or prosecution of crimes:
We need to prevent, detect, or investigate a crime, including the apprehension and prosecution of offenders (the ‘crime condition’).
Our lawful bases for collecting or using personal information for information updates or marketing purposes are:
Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
We have a legitimate interest in keeping existing and prospective clients, customers and relevant business contacts informed about products, services, resources and business updates that may be useful to them, where the law allows us to do so. This processing helps us promote and develop our business while providing relevant information based on a person’s relationship with us, interests or previous purchases. We use limited personal information, avoid excessive or unexpected marketing and provide a clear way to opt out at any time. We do not rely on legitimate interests where consent is required, or where the person’s rights and interests outweigh our own.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Where the Privacy and Electronic Communications Regulations require consent for electronic marketing, we will obtain that consent before sending the communication.
Our lawful bases for collecting or using personal information to comply with legal requirements:
Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
We have a legitimate interest in responding to and investigating queries, complaints and claims, resolving disputes, keeping appropriate records and establishing, exercising or defending our legal rights. Using relevant personal information is necessary so we can understand what happened, communicate with the people involved, reach a fair outcome and retain evidence where a claim may arise. This benefits clients and customers by helping us handle concerns properly and consistently. We limit the information used to what is relevant, restrict access where appropriate and do not retain it for longer than necessary. We consider the potential impact on the people involved and do not rely on our legitimate interests where their rights and interests outweigh ours.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Our lawful bases for collecting or using personal information to To manage our business relationships, projects, suppliers and contractors are:
Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
We have a legitimate interest in managing our relationships and day-to-day dealings with clients, prospective clients, suppliers, contractors and their representatives. This includes communicating about projects and services, keeping appropriate records, coordinating work, managing contracts and maintaining effective business relationships. Using limited contact, professional, project and relationship information is necessary so we can communicate with the relevant people, manage work efficiently and keep accurate records. This benefits everyone involved by supporting clear communication, reliable delivery and appropriate accountability. We only use information that is relevant to the relationship, limit access where appropriate and do not retain it for longer than necessary. The processing is generally within the reasonable expectations of people dealing with us in a professional capacity, and we do not rely on our interests where their rights and interests outweigh ours.
For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.
Where we get personal information from
Directly from you
Audio or video recordings of meetings where recording has been disclosed
Publicly available sources
Suppliers and service providers
Clients, customers, business partners, online marketplaces, account platforms and payment providers, including information they provide about employees, representatives or other people involved in a project or transaction.
How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, to meet our legal and regulatory obligations, and to establish, exercise or defend legal claims.
Our usual retention periods are:
Enquiries and prospective-client records: normally for up to 24 months after our last meaningful contact.
Client, customer, contract and project records: for the duration of the relationship and normally for up to six years after it ends.
Customer-account records: while the account remains active. Core purchase, contract and transaction records may be retained for up to six years after the account closes.
Financial, invoice, tax and accounting records: normally for six years from the end of the financial year to which they relate, or for longer where required by law.
Marketing records: until you unsubscribe, object or we determine that the information is no longer relevant. We may retain a minimal suppression record so that we can respect an opt-out request.
Meeting recordings: normally deleted within 120 days after any required notes or transcript have been confirmed, unless the recording is needed for an ongoing project, complaint, dispute or legal requirement.
Website analytics information: according to the retention settings applied within our analytics systems, normally for no longer than 14 months where information remains linked to an identifier.
Security and access logs: normally for up to 12 months, unless they are needed to investigate suspected fraud, misuse or a security incident.
Complaints and claims: normally for up to six years after the matter has been resolved, or longer where legal proceedings or another legal requirement applies.
Supplier and contractor records: for the duration of the relationship and normally for up to six years after it ends.
We may retain information for longer where required by law, where a dispute or investigation is ongoing, or where it is necessary to establish, exercise or defend legal rights. We securely delete or anonymise information when it is no longer required.
Who we share information with
Data processors
Website-building, hosting and content-management service providers based in the UK and internationally, including the EEA, United States and other countries where the provider or its approved subprocessors operate.
This data processor does the following activities for us: They host and operate our website, store website content and form submissions, and provide the technical infrastructure needed to publish and maintain our online services.
Cloud email, document storage and workplace productivity providers based in the UK and internationally, including the EEA, United States and other countries where the provider or its approved subprocessors operate.
This data processor does the following activities for us: They provide business email, cloud storage, document creation and collaboration services, and store communications, client records and project files on our behalf.
Website analytics and cookie-management service providers based in the UK and internationally, including the EEA, United States and other countries where they or their approved subprocessors operate.
They help us understand how people use our website, measure performance, manage cookie choices and identify technical or usability improvements.
Specialist creative, technical and administrative subcontractors based primarily in the UK and EEA, and occasionally in other countries where appropriate safeguards are in place.
They may process limited client, project or customer information on our instructions when helping us deliver design, development, technical support or administrative services.
Others we share personal information with
Professional or legal advisors
Organisations we’re legally obliged to share personal information with
Publicly on our website, social media or other marketing and information media
Suppliers and service providers
Artificial intelligence and machine-learning service providers, including text, image, audio and video generation, editing, transcription, summarisation and analysis services.
Sharing information outside the UK
Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.
For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.
Framer B.V.
Category of recipient:
Website-building, hosting and content-management service provider
Country the personal information is sent to:
Netherlands
How the transfer complies with UK data protection law:
The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.
Google Cloud EMEA Limited
Category of recipient:
Cloud email, document storage, workplace productivity and collaboration service provider for Google Workspace
Country the personal information is sent to:
Ireland
How the transfer complies with UK data protection law:
The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.
Google Ireland Limited
Category of recipient:
Website analytics and measurement service provider for Google Analytics
Ireland
How the transfer complies with UK data protection law:
The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.
We may use a range of artificial intelligence tools from time to time to help research, draft, edit or generate content and creative materials. These tools are typically operated by providers based in the United States or elsewhere, acting as independent data controllers or processors depending on the tool. Where personal information is transferred outside the UK, we rely on the destination being covered by adequacy regulations, or on Standard Contractual Clauses and the UK Addendum being in place with the relevant provider.
Where necessary, our data processors will share personal information outside of the UK. When doing so, they must comply with the UK GDPR and make sure that appropriate safeguards are in place.
For further information or to obtain details or a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.
Amazon Web Services, Inc.
Category of recipient
Cloud hosting, infrastructure and data-storage provider used by Framer
Country the personal information is sent to
United States
How the transfer complies with UK data protection law
The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.
Google LLC
Category of recipient
Cloud infrastructure, hosting, technical support, analytics and subprocessing provider for Google Workspace and Google Analytics
Country the personal information is sent to
United States
How the transfer complies with UK data protection law
The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.
The organisations listed above may use approved subprocessors in other countries. Where this happens, the relevant organisation is required to use an appropriate transfer mechanism, which may include Adequacy Regulations or a UK data bridge, the International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses.
How to complain
If you have any concerns about our use of your personal information, you can make a data protection complaint to us:
Email: hello@fimolo.com
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline number: 0303 123 1113