Fimolo's privacy notice

This privacy notice tells you what to expect us to do with your personal information.

Last updated on 24th July 2026

Contact details

Fimolo Ltd is the controller responsible for the personal information described in this privacy notice.

Company registration number

16289738

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details

  • Business, billing and correspondence addresses where relevant

  • Company name, occupation and professional role

  • Information clients provide about their employees, representatives, customers, suppliers or other people involved in a project

  • Transaction data, including details of payments, purchases and services

  • Information about how people use our website, products and services

  • Enquiries, feedback, compliments and complaints

  • Records of meetings, decisions and project communications

  • Audio or video recordings of meetings where we have told participants that recording is taking place

  • Account identifiers, permissions, security information and access logs

  • Technical and website-use information, including browser, device and IP information

  • Project information and materials provided by clients, including briefs, business information, website content, brand assets, photographs, testimonials, correspondence and documents

We may use approved artificial intelligence tools to help us research, organise, summarise, draft, analyse, generate or edit content and creative materials. This may involve limited personal information contained in project files, correspondence, meeting notes, transcripts or images. We minimise the information used, remove identifiers where practical and review AI-assisted outputs before using them.

We collect or use the following personal information for the operation of client or customer accounts:

  • Names and contact details

  • Addresses

  • Purchase or service history

  • Account information, including registration details

  • Information used for security purposes

  • Marketing preferences

  • Technical data, including information about browser and operating systems

We collect or use the following personal information for the prevention, detection, investigation or prosecution of crimes:

  • Names and contact information

  • Client accounts and records

  • Financial information eg for fraud prevention or detection

  • Account security information, including login activity, IP addresses, device information, failed login attempts, suspected misuse and payment or chargeback references provided by our payment providers.

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details

  • Profile information

  • Marketing preferences

  • Purchase or account history

  • Website user journey information

  • IP addresses

  • Information about responses to our marketing, including email opens, link clicks, event registrations, survey responses and social media interactions.

  • Approved testimonials, reviews, names, professional roles, company names, logos, screenshots, images and case-study information

We collect or use the following personal information to comply with legal requirements:

  • Name

  • Contact information

  • Client account information

  • Any other personal information required to comply with legal obligations

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details

  • Addresses

  • Account information

  • Purchase or service history

  • Relevant information from previous investigations

  • Customer or client accounts and records

  • Financial transaction information

  • Correspondence

  • Project files, screenshots, technical records and other evidence provided or collected in connection with a query, complaint or claim.

We collect or use the following personal information to manage our business relationships, projects, suppliers and contractors:

  • Names and contact details

  • Company name, occupation and professional role

  • Business and correspondence addresses

  • Bank and payment information required to pay suppliers or contractors, excluding full payment-card details handled by payment providers

  • Contract, project and supplier records

  • Records of meetings, decisions, communications and approvals

  • Information about services, deliverables, invoices and payments

  • Information about relevant employees, representatives or subcontractors involved in the relationship.

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

    • We have a legitimate interest in managing and improving our products and services, maintaining service quality, understanding how clients use them, keeping our systems secure and developing improvements based on client needs and feedback. We only use personal information that is reasonably necessary for these purposes. This benefits our clients by helping us provide reliable, relevant and secure services. The information used is limited, handled proportionately and would normally be expected within an existing or prospective client relationship. We do not use it where the person’s rights, interests or freedoms outweigh our business interests.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

    • We have a legitimate interest in operating, maintaining and securing client and customer accounts. This includes protecting accounts from unauthorised access or misuse, troubleshooting technical issues, maintaining accurate account records and improving account functionality. Using limited account, technical and usage information is necessary to provide a reliable and secure service. It benefits customers by protecting their access, purchases and account activity. We limit the information used, apply appropriate security measures and do not use it where the person’s rights and interests outweigh our legitimate interests.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for the prevention, detection, investigation or prosecution of crimes are:

  • Recognised legitimate interests - our pre-approved purpose for collecting or using personal information for the prevention, detection, investigation or prosecution of crimes:

  • We need to prevent, detect, or investigate a crime, including the apprehension and prosecution of offenders (the ‘crime condition’).

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

    • We have a legitimate interest in keeping existing and prospective clients, customers and relevant business contacts informed about products, services, resources and business updates that may be useful to them, where the law allows us to do so. This processing helps us promote and develop our business while providing relevant information based on a person’s relationship with us, interests or previous purchases. We use limited personal information, avoid excessive or unexpected marketing and provide a clear way to opt out at any time. We do not rely on legitimate interests where consent is required, or where the person’s rights and interests outweigh our own.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Where the Privacy and Electronic Communications Regulations require consent for electronic marketing, we will obtain that consent before sending the communication.

Our lawful bases for collecting or using personal information to comply with legal requirements:

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

    • We have a legitimate interest in responding to and investigating queries, complaints and claims, resolving disputes, keeping appropriate records and establishing, exercising or defending our legal rights. Using relevant personal information is necessary so we can understand what happened, communicate with the people involved, reach a fair outcome and retain evidence where a claim may arise. This benefits clients and customers by helping us handle concerns properly and consistently. We limit the information used to what is relevant, restrict access where appropriate and do not retain it for longer than necessary. We consider the potential impact on the people involved and do not rely on our legitimate interests where their rights and interests outweigh ours.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information to To manage our business relationships, projects, suppliers and contractors are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

    • We have a legitimate interest in managing our relationships and day-to-day dealings with clients, prospective clients, suppliers, contractors and their representatives. This includes communicating about projects and services, keeping appropriate records, coordinating work, managing contracts and maintaining effective business relationships. Using limited contact, professional, project and relationship information is necessary so we can communicate with the relevant people, manage work efficiently and keep accurate records. This benefits everyone involved by supporting clear communication, reliable delivery and appropriate accountability. We only use information that is relevant to the relationship, limit access where appropriate and do not retain it for longer than necessary. The processing is generally within the reasonable expectations of people dealing with us in a professional capacity, and we do not rely on our interests where their rights and interests outweigh ours.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Where we get personal information from

  • Directly from you

  • Audio or video recordings of meetings where recording has been disclosed

  • Publicly available sources

  • Suppliers and service providers

  • Clients, customers, business partners, online marketplaces, account platforms and payment providers, including information they provide about employees, representatives or other people involved in a project or transaction.

How long we keep information

We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, to meet our legal and regulatory obligations, and to establish, exercise or defend legal claims.

Our usual retention periods are:

  • Enquiries and prospective-client records: normally for up to 24 months after our last meaningful contact.

  • Client, customer, contract and project records: for the duration of the relationship and normally for up to six years after it ends.

  • Customer-account records: while the account remains active. Core purchase, contract and transaction records may be retained for up to six years after the account closes.

  • Financial, invoice, tax and accounting records: normally for six years from the end of the financial year to which they relate, or for longer where required by law.

  • Marketing records: until you unsubscribe, object or we determine that the information is no longer relevant. We may retain a minimal suppression record so that we can respect an opt-out request.

  • Meeting recordings: normally deleted within 120 days after any required notes or transcript have been confirmed, unless the recording is needed for an ongoing project, complaint, dispute or legal requirement.

  • Website analytics information: according to the retention settings applied within our analytics systems, normally for no longer than 14 months where information remains linked to an identifier.

  • Security and access logs: normally for up to 12 months, unless they are needed to investigate suspected fraud, misuse or a security incident.

  • Complaints and claims: normally for up to six years after the matter has been resolved, or longer where legal proceedings or another legal requirement applies.

  • Supplier and contractor records: for the duration of the relationship and normally for up to six years after it ends.

We may retain information for longer where required by law, where a dispute or investigation is ongoing, or where it is necessary to establish, exercise or defend legal rights. We securely delete or anonymise information when it is no longer required.

Who we share information with

Data processors

  • Website-building, hosting and content-management service providers based in the UK and internationally, including the EEA, United States and other countries where the provider or its approved subprocessors operate.

    This data processor does the following activities for us: They host and operate our website, store website content and form submissions, and provide the technical infrastructure needed to publish and maintain our online services.

  • Cloud email, document storage and workplace productivity providers based in the UK and internationally, including the EEA, United States and other countries where the provider or its approved subprocessors operate.

    This data processor does the following activities for us: They provide business email, cloud storage, document creation and collaboration services, and store communications, client records and project files on our behalf.

  • Website analytics and cookie-management service providers based in the UK and internationally, including the EEA, United States and other countries where they or their approved subprocessors operate.

    They help us understand how people use our website, measure performance, manage cookie choices and identify technical or usability improvements.

  • Specialist creative, technical and administrative subcontractors based primarily in the UK and EEA, and occasionally in other countries where appropriate safeguards are in place.

    They may process limited client, project or customer information on our instructions when helping us deliver design, development, technical support or administrative services.

Others we share personal information with

  • Professional or legal advisors

  • Organisations we’re legally obliged to share personal information with

  • Publicly on our website, social media or other marketing and information media

  • Suppliers and service providers

  • Artificial intelligence and machine-learning service providers, including text, image, audio and video generation, editing, transcription, summarisation and analysis services.

Sharing information outside the UK

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Framer B.V.

Category of recipient:

Website-building, hosting and content-management service provider

Country the personal information is sent to:

Netherlands

How the transfer complies with UK data protection law:

The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.

Google Cloud EMEA Limited

Category of recipient:

Cloud email, document storage, workplace productivity and collaboration service provider for Google Workspace

Country the personal information is sent to:

Ireland

How the transfer complies with UK data protection law:

The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.

Google Ireland Limited

Category of recipient:

Website analytics and measurement service provider for Google Analytics

Country the personal information is sent to:

Ireland

How the transfer complies with UK data protection law:

The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.

We may use a range of artificial intelligence tools from time to time to help research, draft, edit or generate content and creative materials. These tools are typically operated by providers based in the United States or elsewhere, acting as independent data controllers or processors depending on the tool. Where personal information is transferred outside the UK, we rely on the destination being covered by adequacy regulations, or on Standard Contractual Clauses and the UK Addendum being in place with the relevant provider.

Where necessary, our data processors will share personal information outside of the UK. When doing so, they must comply with the UK GDPR and make sure that appropriate safeguards are in place.

For further information or to obtain details or a copy of the appropriate safeguard for any of the transfers below, please contact us using the contact information provided above.

Amazon Web Services, Inc.

Category of recipient

Cloud hosting, infrastructure and data-storage provider used by Framer

Country the personal information is sent to

United States

How the transfer complies with UK data protection law

The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.

Google LLC

Category of recipient

Cloud infrastructure, hosting, technical support, analytics and subprocessing provider for Google Workspace and Google Analytics

Country the personal information is sent to

United States

How the transfer complies with UK data protection law

The country or sector has been assessed as providing adequate protection to data subjects, also known as Adequacy Regulations or UK data bridge.

The organisations listed above may use approved subprocessors in other countries. Where this happens, the relevant organisation is required to use an appropriate transfer mechanism, which may include Adequacy Regulations or a UK data bridge, the International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses.

How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us:

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline number: 0303 123 1113

© 2026 Fimolo

© 2026 Fimolo

Fimolo Ltd is a company registered in England and Wales (No.16289738).
Our address is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ