This part is important for understanding when we act as a processor rather than a controller.
What we collect and how
To manage the client relationship, we process the business-contact details of our clients’ personnel (name, role, business email and phone, and billing-contact details), together with account-management and project records – for which we act as a controller. This information is held in our CRM and business systems (for example, HubSpot and Google Workspace).
Separately, to deliver our services we process personal data on the client’s behalf and on its documented instructions, as a processor. Most of this is aggregated or pseudonymised campaign and analytics data rather than directly identifying information. What we process depends on the service line:
| Service line |
Personal data typically processed (as processor) |
| Paid Search |
Mostly aggregated, pseudonymised performance data (impressions, clicks, spend, conversions) from ad platforms (Google Ads, Microsoft Advertising) and analytics. Conversion tracking uses online identifiers such as cookies and ad-click IDs (for example, GCLID). May process client-supplied customer lists (email/phone) that are hashed before upload for audience matching (for example, Customer Match). No special-category data. |
| Paid Social |
Aggregated campaign performance and audience insights from platform pixels and SDKs across social platforms (for example, Meta, TikTok, LinkedIn, Pinterest, Snap, X). Custom and lookalike audiences may use hashed customer lists provided by the client; pixel and Conversions API events capture pseudonymised user actions. No special-category data. |
| Programmatic |
Pseudonymised online identifiers (cookies, mobile advertising IDs, IP-derived location), contextual and audience-segment data, and impression/click/conversion logs, through demand-side platforms (for example, DV360). Third-party audience segments are accessed via the platform. No directly identifying or special-category data is processed by us. |
| SEO |
Mostly aggregated, non-personal data: crawl data, rankings, and aggregated search-query and impression data (for example, from Google Search Console), plus site analytics. Any user-level analytics is pseudonymised. |
| Content |
Largely non-personal. May include contributor or contact details, and any personal data contained in client-supplied source material or assets. Performance is measured on aggregated engagement metrics. |
| Analytics and measurement |
Website and app behavioural data via analytics tags (GA4, server-side tagging, Tag Manager): online identifiers, device and browser data, IP (often truncated), on-site events and conversions. Processed within the client’s analytics properties and our reporting/warehouse environments, pseudonymised and configured to exclude directly identifying data unless agreed. May ingest client first-party data for attribution or modelling on documented instructions. |
| Conversion rate optimisation (CRO) |
Behavioural and interaction data from testing and session tools (online identifiers, device data, on-site behaviour, session recordings and heatmaps). Session recordings may incidentally capture data you enter; tools are configured to mask sensitive fields. Pseudonymised. |
| Influencer |
Personal data of creators and influencers (name, contact details, social handles, audience and engagement metrics, and commercial terms), and payment details for contracted creators, processed to manage relationships and contracts under formal agreements and NDAs. Campaign performance is reported in aggregate. |
Client first-party data, tracking and account access
- First-party customer data – Clients may provide first-party customer data (such as CRM or email lists) for audience matching (for example, Google Customer Match, Meta Custom Audiences and LinkedIn Matched Audiences). This is received through secure transfer mechanisms (such as secure Google Drive links or encrypted email), stored in our secure Google Workspace environment hosted in Europe, and encrypted in transit and at rest; lists are hashed for audience matching.
- Tracking and tags – Where instructed, we implement tracking tags, pixels, server-side tracking (for example, Conversions API and Enhanced Conversions) and SDKs on client websites and apps. These are configured at project inception following a privacy by design process, with access restricted to authorised project teams on a role-based basis.
- Account access – Access to a client’s advertising and analytics accounts is normally granted through delegated or managed access rather than shared credentials. We do not routinely use client-issued credentials to access client production systems; where credentials are ever issued, they are held in a project-specific vault, shared only with the relevant team, and deleted at the end of the project or contract.
- Creative assets – Where a client provides creative assets (such as photographs, video or testimonials) that feature identifiable individuals, we handle them as a processor. Assets are stored securely within our corporate Google Workspace environment, which is hosted in European data centres and encrypted in transit and at rest.
- No cross-client use – We do not share one client’s personal data with another client, and we do not use it for cross-client benchmarking.
Healthcare and other regulated-sector clients
For clients in healthcare and other regulated sectors, our work is standard digital marketing (such as SEO and paid media). We do not access, ingest or interface with electronic health records, clinical systems or patient databases. Any content we use (for example, a customer testimonial or case study) is pre-cleared and provided to us by the client. We treat all client operational data as confidential by default and limit access through role-based permissions.
Why we use it and our legal basis
- For our own management of the client relationship (client-contact records, account management, billing) – Article 6(1)(b) and Article 6(1)(f) of the UK GDPR, and Article 6(1)(c) of the UK GDPR for tax and accounting records.
- For personal data we process as a processor on the client’s behalf, the client is the controller and is responsible for identifying the lawful basis and for obtaining all necessary permissions, consents and usage rights (including for customer-match lists, for tracking and, where relevant, for testimonials or content featuring individuals). We process it only under our data processing agreement with the client and on the client’s documented instructions, in line with Article 28 of the UK GDPR. We do not use client data for our own purposes, and we do not use it to train, fine-tune or improve any artificial-intelligence models (see Section 7).
- We do not carry out automated decision-making or profiling that has a legal or similarly significant effect on individuals (such as personalised pricing or eligibility/exclusion audiences) in delivering our services.
Who we share it with
The group companies and personnel who need it to deliver the engagement (systems are operated consistently across our entities), and our vetted sub-processors – including cloud hosting and infrastructure (primarily Google Workspace, and Google Cloud Platform, including BigQuery, and Vercel for applications in development), collaboration tools (such as Slack), advertising and analytics platforms, and reporting and creative-production tools. Where we act as a processor, we engage sub-processors only as permitted by our agreement with the client, under equivalent data-protection obligations.