SmartServe Websitesby SmartServe AI

Legal

Privacy Policy

How SmartServe AI Ltd handles information submitted through the SmartServe Websites site.

Last updated: 21 July 2026

1. Scope of this policy

This policy explains how SmartServe AI Ltd ("SmartServe", "we", "us" or "our") collects, uses, stores and protects personal information when you visit websites.smartserveai.uk, submit a website enquiry or contact us about web-design and website-management services.

It does not describe information handled through the separate SmartServe restaurant-booking and guest-marketing platform. That service has its own privacy information on the main SmartServe AI website.

2. Who we are

SmartServe Websites is a service operated by SmartServe AI Ltd, a private limited company registered in England and Wales. SmartServe AI Ltd is the data controller for the information covered by this policy.

Legal name
SmartServe AI Ltd
Company number
16770812
Registered office
2 Henry Street, Cockermouth, United Kingdom, CA13 0AT
Privacy contact
gdrimmie@smartserveai.uk

3. Information we collect

Depending on how you contact us, we may collect:

  • Enquiry details: your name, business name, email address, optional telephone number and the message you submit.
  • Correspondence and project details: information you provide during follow-up emails, calls, quotations or discussions about a possible website project.
  • Technical and security information: IP address, browser and device information, request timestamps and routine server or security logs.

Please do not put passwords, payment-card details or unnecessary sensitive or confidential information into the enquiry form.

4. How we receive information

We receive information:

  • directly from you when you submit the enquiry form;
  • when you contact us by email, telephone or another agreed channel;
  • during discussions about a quotation, project or support request; and
  • automatically through essential hosting, server and security logs when the website is accessed.

5. How and why we use information

We may use personal information to:

  • receive, review and respond to your enquiry;
  • discuss your requirements and prepare a quotation or proposal;
  • keep an appropriate record of business correspondence;
  • operate, troubleshoot and protect the website and enquiry service;
  • prevent spam, fraud, misuse and security incidents; and
  • meet legal obligations or establish, exercise or defend legal claims.

Depending on the circumstances, our lawful bases are taking steps at your request before entering a contract, performing a contract, complying with a legal obligation and our legitimate interests in responding to prospective customers, maintaining business records and protecting our systems.

Submitting an enquiry does not add you automatically to a general marketing mailing list. If we send direct marketing, we will do so only where permitted by law and will provide a clear way to opt out.

6. Enquiry storage and email notifications

When you submit the enquiry form, the information is sent securely to SmartServe's application service and stored in our PostgreSQL enquiry database. Access is limited to authorised people who need it to respond or manage the resulting business relationship.

The form also generates an email notification to an authorised SmartServe inbox so that we know an enquiry has arrived. Our email-delivery provider processes the enquiry details and relevant email addresses only as needed to deliver that notification.

The public website is hosted by Vercel. The enquiry application and database are hosted through Render and our PostgreSQL infrastructure, and notification emails are delivered through Twilio SendGrid. These providers may create routine operational and security records when supplying their services.

7. Who we share information with

We do not sell personal information. We disclose it only where reasonably necessary to:

  • Vercel, Render, our PostgreSQL provider and Twilio SendGrid, which provide hosting, storage and email-delivery services;
  • professional advisers, insurers or contractors who reasonably need the information and are subject to suitable duties of confidence;
  • regulators, courts, law-enforcement bodies or public authorities where disclosure is required by law; or
  • a buyer or successor if the business is sold, reorganised or transferred.

8. International transfers

Some of our service providers operate internationally, so technical or email information may be processed or accessed outside the United Kingdom.

Where UK data-protection law restricts an international transfer, we use providers offering an appropriate legal mechanism, such as UK adequacy regulations, an approved UK transfer agreement or another safeguard permitted by law. Contact us if you would like more information about relevant safeguards.

9. How long we keep information

We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected. We review enquiry records and delete or anonymise information when it is no longer relevant to an active enquiry, potential project, customer relationship, legal requirement or dispute.

  • Enquiry and correspondence records are kept for as long as needed to respond, follow up appropriately and maintain proportionate business records.
  • If an enquiry becomes a client relationship, relevant proposal, contract, payment and project records may be kept longer to meet contractual, accounting, tax and legal requirements.
  • Technical and security logs are kept only as long as needed for security, troubleshooting and legal compliance.

10. Cookies and analytics

This website does not currently use advertising cookies, behavioural tracking, Vercel Analytics or other non-essential analytics tools.

Our hosting and security providers may still generate routine technical request logs required to deliver and protect the site. If we introduce non-essential analytics or tracking, we will update this policy and provide consent controls where required.

11. How we protect information

We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. These measures include encryption in transit, access controls, secure hosting, logging and limiting access to people and providers who require it.

No online service can guarantee absolute security. Please contact us promptly if you believe information submitted through this website has been compromised.

12. Your UK data-protection rights

Depending on the circumstances and our lawful basis, you may have the right to:

  • request access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • request deletion of your information;
  • ask us to restrict how information is used;
  • object to certain processing;
  • receive certain information in a portable format; and
  • withdraw consent where processing relies on consent.

You may object at any time to the use of your personal information for direct marketing.

These rights are not absolute and may depend on why the information is being processed. To make a request, email gdrimmie@smartserveai.uk. We may need to confirm your identity before completing a request.

13. Automated decision-making

We do not use enquiry information to make solely automated decisions that produce legal or similarly significant effects about you.

14. Complaints

Please contact us first if you have concerns about how your information has been handled so that we can try to resolve them.

You also have the right to complain to the Information Commissioner's Office, the UK data-protection regulator. Visit ico.org.uk/make-a-complaint.

15. Changes to this policy

We may update this policy when the website, our providers or our legal obligations change. The latest version will be published on this page with an updated revision date.