Privacy Policy
Last updated: 7 September 2026
This policy explains what personal data Refine Media collects, why we collect it, and what rights you have over it. Refine Media Online Ltd (trading as Refine Media) is the data controller for that data. For anything to do with data protection, email hello@refinemedia.co.
It covers two different groups of people, and the sections below make clear which applies to you:
- Visitors and enquirers — people who use this website or contact us.
- Business contacts — people at businesses we approach directly by email or phone, whose details we obtained from public sources rather than from them.
If you were contacted by us and want to know where we got your details, go straight to section 2.
1. Visitors and enquirers
What we collect
We run one form: the free website audit request at /audit. It asks for your business name, your name, your email address, and a description of what is not working on your site. Four fields are optional and clearly marked as such: a phone number, your website address, how you heard about us, and — only if you ask for a live call rather than a recorded walkthrough — the rough time windows that suit you and your timezone. Nothing is pre-ticked, and there is no marketing opt-in. We use what you send to carry out the audit, send it to you, and follow up about it.
That form is protected by Cloudflare Turnstile, a bot check that inspects the request rather than asking you to solve a puzzle. See our Cookie Policy for what it stores.
If you contact us by email instead, we collect whatever you choose to put in that email: typically your name, business name, and what you want to talk about. We keep a record of the correspondence.
Our hosting provider automatically records technical information when you load a page, including your IP address, browser type, the pages you viewed and the time of your visit. This is generated by the server, not by us, and is used for security and to keep the site running.
We also collect limited analytics about how the site is used. See our Cookie Policy for detail.
Why we use it
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and arranging a call | Legitimate interests, or steps towards a contract at your request |
| Providing services if you become a client | Performance of a contract |
| Keeping business and accounting records | Legal obligation |
| Site security, fraud prevention and error monitoring | Legitimate interests |
| Understanding how the site is used | Legitimate interests, or consent where required |
Where we rely on legitimate interests, our interest is in operating and improving a business. We have considered whether this overrides your rights and privacy and concluded that it does not, because the data involved is limited, business-related and used only for the purposes described here. You can object at any time using the contact details above.
We do not
We do not sell your data. We do not use it for automated decision-making or profiling that produces legal or similarly significant effects. We do not add website enquirers to a marketing list without asking.
2. Business contacts we approach directly
If we contacted you and you had not heard of us before, this section explains why.
What we hold
We hold business contact details only. Typically: your name, job title, the name of the business, its address, its website, a business phone number and a business email address. Where the business is a limited company we may also hold information from public company records.
We do not collect or hold special category data, and we do not knowingly hold personal data about you outside your professional capacity.
Where we got it
We obtain these details from sources that are already publicly accessible or commercially available, including:
- Business listings and directories, including search engine business profiles
- Public business websites
- Publicly available trade, licensing and registration records
- Third-party business data providers
We did not obtain your details from a social network, and we did not buy a consumer marketing list.
Why we use it
We use these details to contact you once, and to follow up a small number of times, about services that we believe are relevant to your business. Our lawful basis is legitimate interests: specifically, our interest in marketing business-to-business services to organisations likely to have a use for them.
We have weighed this against your interests. The data is business contact information rather than private information, the contact is relevant to the recipient’s professional role, the volume of contact is limited, and every message includes a way to stop it immediately. On that basis we consider the processing proportionate.
You may disagree, and you have an unqualified right to say so.
How to stop it
Reply to any email from us and say stop, use the unsubscribe link in the message, tell us on a call, or email hello@refinemedia.co. We will remove you and add your details to a suppression list so we do not contact you again. There is no cost and you do not need to give a reason.
We keep the minimum record needed to honour that request, which is the point of a suppression list.
3. Who we share data with
We use third-party providers to run our business. They process data on our instructions under written contracts. They are:
| Provider | What they handle |
|---|---|
| Cloudflare | Website hosting, DNS, security and website analytics |
| Google (Google Workspace) | Email and file storage |
We also work with contractors and remote team members who may access prospect and client records in the course of their work. They are bound by written confidentiality and data protection terms.
We will disclose data where we are legally required to, for example to a regulator, or where necessary to establish or defend a legal claim. We do not sell data to anyone.
4. International transfers
Some of the providers above, and some of the people who work with us, are outside the UK. This includes the United States.
Where we transfer personal data outside the UK, we rely on one of the following safeguards:
- UK adequacy regulations, where the country has been recognised as providing adequate protection
- The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment
You can request a copy of the relevant safeguard by emailing hello@refinemedia.co.
5. How long we keep it
| Data | Retention |
|---|---|
| Website enquiries and audit requests that do not become clients | 24 months from last contact |
| Prospect and outreach records | 24 months from last contact, or until you object |
| Suppression list entries | Indefinitely, so we can honour your objection |
| Client records and project files | Duration of the engagement, then 6 years |
| Accounting records | 6 years, as required by law |
| Server logs | As set by our hosting provider, typically under 30 days |
6. Your rights
Under UK data protection law you have the right to:
- Ask what personal data we hold about you and get a copy
- Have inaccurate data corrected
- Have data erased in certain circumstances
- Restrict how we use your data
- Object to processing based on legitimate interests, including all direct marketing, which is an absolute right in the case of marketing
- Receive certain data in a portable format
- Withdraw consent where we relied on consent
To exercise any of these, email hello@refinemedia.co. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
7. Complaints
If you are unhappy with how we have handled your personal data, tell us first at hello@refinemedia.co. We will acknowledge your complaint within 30 days and tell you the outcome once we have looked into it.
You also have the right to complain directly to the Information Commissioner’s Office at any time:
Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk
8. Security
We use access controls, multi-factor authentication on business accounts, encrypted connections and reputable providers. No system is perfectly secure, and we cannot guarantee that data sent over the internet is safe in transit.
9. Changes
We may update this policy. The date at the top shows when it last changed. Material changes affecting how we use your data will be notified to clients directly.