This explains what personal data I collect through this website and in the course of doing work for clients, why I hold it, and what you can ask me to do about it.
Who is responsible
Harrison Ratcliffe, trading as Ask Harrison is the data controller for the personal data described here.
You can reach me about anything on this page at harrison@askharrison.co.uk. I work from a home address, so I don't publish it. I'll provide it in writing on request if you need it for a formal complaint or a contract.
What I collect through this website
When you email me
If you contact me using the address on this site, I receive whatever you put in the message: typically your name, your email address, your company, and details of the website or server you want help with. That message sits in my mailbox.
Analytics
I use Plausible Analytics, which I host myself rather than using a third-party service. It sets no cookies, and it does not collect or store personal data. It records aggregate counts of page views, referring sites, country, and general device type. Individual visitors are not identified and cannot be tracked between sites or across visits.
Because no personal data is processed, there is nothing here that identifies you and no consent banner is needed.
Server and network logs
The site is hosted on Vercel and DNS is handled by Cloudflare. Both automatically generate technical logs that can include your IP address, the time of your request, and your browser's user agent. These exist for security and for keeping the site running, and they're held for the short retention periods those providers apply. I don't use them to build any profile of you.
Cookies
This site sets no cookies of its own, and no advertising or tracking cookies are used. Cloudflare may set a strictly necessary cookie for security and bot filtering where its protection is enabled.
Data I handle when working for clients
Doing migrations, upgrades and recovery work means I'm given access to systems that contain other people's personal data: website databases, customer records, order details, mailing lists, email accounts. I need this access to do the job, but I'm not using that data for my own purposes.
In this situation I act as a processor, not a controller. The client (or their agency) decides what happens to that data; I act only on their instructions and only to complete the work agreed. I'm happy to sign a data processing agreement, and I'll work under a client's own agreement where they have one.
Where I hold credentials, access keys or database copies for a job, I keep them only while the work is live and delete them once it's signed off. Any backups or staging copies I make are removed at the same time unless the client asks me to keep them.
Why I'm allowed to hold this data
| Data | Purpose | Lawful basis |
|---|---|---|
| Enquiry emails | Replying to you and quoting for work | Legitimate interests: you contacted me about a service |
| Client contact details | Carrying out the work and communicating about it | Performance of a contract |
| Invoices and accounts | Bookkeeping and tax | Legal obligation |
| Server and site access | Doing the technical work requested | Performance of a contract (as processor for the client) |
| Server logs | Security and site availability | Legitimate interests: keeping the site working and secure |
How long I keep it
- Enquiries that don't turn into work: deleted within 12 months.
- Client project records and correspondence: kept for the duration of the relationship, then up to 6 years.
- Invoices and financial records: 6 years after the end of the accounting period, as tax law requires.
- Credentials, database copies and staging environments: deleted once the job is complete.
- Server logs: as long as Vercel and Cloudflare retain them, which is short.
Who else sees it
I don't sell personal data or share it for marketing. It reaches these providers only because I use them to run the business:
| Provider | What for |
|---|---|
| Apple (iCloud Mail) | |
| Vercel | Website hosting |
| Cloudflare | DNS and network protection |
| Sage | Accounting and invoicing |
Security
Accounts are protected with strong unique passwords and two-factor authentication. Credentials are held in an encrypted password manager, never in plain text or email. Client data is transferred over encrypted connections and copies are deleted when a job ends.
Your rights
Under UK GDPR you can ask me to:
- tell you what personal data I hold about you, and give you a copy;
- correct anything inaccurate;
- delete it, where I have no continuing reason to keep it;
- restrict or stop a particular use of it;
- object to processing I'm doing on the basis of legitimate interests;
- transfer it to you or someone else in a portable format.
Email me and I'll respond within one month. There's no charge. If the data belongs to a website I worked on for a client, the client is the controller and I'll pass your request to them.