Privacy Policy
Last updated · 6 July 2026
This policy explains what personal data WFK Digital collects, why, how it’s protected, and the rights you have over it — written as plainly as the subject allows.
Who we are
WFK Digital (“WFK”, “we”, “us”) is a trading name of Anthony Key, an independent consultant based in the United Kingdom. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), WFK is the data controller for the personal data described below.
You can reach us at hello@wfk.digital for anything in this policy, including to exercise any of your rights.
The data we collect
We only collect what we need to do the work and stay in touch. That falls into a few groups:
- When you make an enquiry — your name, email address, and whatever you tell us about your business, team size, timeline, budget, and the problem you want help with.
- When you complete the audit — your email address, your answers to the questions, and your consent to store them. Your answers describe your organisation’s practices; treat them as you would any working notes about your business.
- When you become a client with a portal login — your name, email address, a password (stored only as a secure one-way hash — we never see it), and the reports we deliver to you.
- Technical data — standard server logs and security data (such as IP address and request information) generated when you use the site, used to keep it running and to prevent abuse.
Why we use it, and our lawful basis
- To respond to you and provide our services — on the basis of your consent (for the audit), our legitimate interests in responding to enquiries and running the business, and the performance of a contract once you’re a client.
- To send you your audit result and occasional relevant follow-up about your enquiry — on the basis of consent and legitimate interests. You can opt out at any time.
- To keep the site secure and working — on the basis of our legitimate interests in protecting the service.
Your confidentiality
The information you share with us — your enquiry, your audit answers, and anything discussed during an engagement — is treated as confidential. We use it only to respond to you, produce your result, and deliver the work you’ve asked for. We don’t sell it, we don’t share it with other clients, and we don’t publish anything that identifies you or your organisation without your explicit permission. Where we describe our work publicly, we use anonymised or composite examples unless you’ve agreed otherwise in writing.
Who we share it with
We don’t sell your data or share it for advertising. We do use a small set of trusted service providers (“processors”) to run the business — each only processes your data on our instructions and under contract:
- Vercel — website hosting and secure serverless functions.
- Neon — the database where enquiries, audit results, and client records are stored.
- Resend — sending transactional email (such as your audit result and replies to your enquiry).
- Anthropic — an AI provider (Claude) we may use to help summarise and triage inbound enquiries. Where used, it processes only the enquiry content, under a business agreement that prohibits training on your data.
- Our email host — for the mailbox behind hello@wfk.digital.
We may also disclose data if the law requires it, or to establish, exercise, or defend legal claims.
International transfers
Some of these providers are based outside the UK (including in the United States). Where your data is transferred internationally, we rely on appropriate safeguards recognised under UK law — such as the UK’s International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses), or a UK adequacy decision — so your data keeps a similar level of protection.
How long we keep it
We keep personal data only for as long as we need it for the purposes above, then delete or anonymise it. Enquiry and audit data is kept while there’s a realistic prospect of working together and for a reasonable period afterwards; client and financial records are kept for as long as we’re legally required to (for example, for tax purposes). You can ask us to delete your data at any time (see “Your rights”).
Cookies
We use only strictly-necessary cookies — the ones that keep you logged in to the client portal and secure the site. We don’t use advertising or analytics tracking cookies. See our Cookie Policy for detail.
Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“the right to be forgotten”);
- restrict or object to how we process it;
- ask for a copy of your data in a portable format;
- withdraw consent at any time, where we rely on consent.
To exercise any of these, email hello@wfk.digital. We’ll respond within the timeframes the law requires (usually within one month).
How we protect it
We take reasonable technical and organisational measures to protect your data: encrypted connections, access controls that keep client documents private to each client, passwords stored only as secure hashes, and confidential documents kept off any public URL. No system is perfectly secure, but we treat your information with the care our whole business is built on.
Children
Our services are for businesses. They’re not directed at children, and we don’t knowingly collect children’s data.
Changes to this policy
We may update this policy from time to time. The “last updated” date at the top always reflects the current version.
Complaints
If you’re unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.
Draft boilerplate — before relying on this with paying clients, confirm the highlighted details (legal name / trading structure, business address, ICO registration number) and have it reviewed. This is a starting point, not legal advice.