Privacy Policy
Your privacy matters to me. This policy explains what personal information I collect, why I collect it, how I use it, and what rights you have in relation to it. It is written in plain English — because you deserve to understand it without needing a law degree.
If you have any questions about this policy or how I handle your data, please get in touch at hollyscottdigital@gmail.com.
1. Who I Am
Holly Scott Digital is a sole trader providing digital marketing services including social media management, brand design, copywriting, content creation, and paid advertising support. For the purposes of UK GDPR, I am the data controller for the personal data I collect.
2. What Information I Collect
I may collect the following types of personal information:
Your name and business name
Your email address and phone number
Your social media handles or website URL
Information you share about your business, goals or marketing needs
Payment information (processed securely via third-party platforms — I do not store card details)
Any other information you choose to share with me via enquiry forms, emails or discovery calls
If you fill in a Meta (Facebook or Instagram) lead form:
I collect only the information you submit in the form — typically your name, email address, business name and a brief description of your marketing needs. This information is used solely to follow up on your enquiry and arrange a discovery call.
3. How I Use Your Information
I use your personal information to:
Respond to your enquiry and arrange a discovery call
Provide the services you have requested
Send invoices and manage our working relationship
Keep you updated on relevant services or offers (only where you have consented)
Improve my website and marketing materials
4. My Lawful Basis for Processing Your Data
Under UK GDPR, I rely on the following lawful bases:
Consent — when you submit an enquiry form or Meta lead form, you are giving your consent for me to contact you about my services.
Contract — when we have agreed to work together, I need to process your data to deliver the services outlined in our agreement.
Legitimate Interests — for example, keeping records of our correspondence and invoices for a reasonable period.
5. How I Share Your Information
I will never sell your personal data. I will never share it with third parties for marketing purposes. Your information stays with me.
I may share your data only in the following limited circumstances:
With trusted tools and platforms I use to deliver my services (such as invoicing software, scheduling tools, or project management platforms) — these are bound by their own privacy policies and GDPR-compliant agreements
With Meta Platforms, where data is collected via lead forms — subject to Meta's own privacy policy
Where required by law or a regulatory authority
6. How Long I Keep Your Data
I keep your data only for as long as necessary:
Enquiry data (not converted to clients) — up to 6 months
Client records including invoices and correspondence — up to 6 years (as required by HMRC)
Meta lead form data — downloaded promptly and stored securely; deleted when no longer needed
7. Your Rights
Under UK GDPR, you have the following rights:
The right to access — you can request a copy of the personal data I hold about you
The right to rectification — you can ask me to correct any inaccurate data
The right to erasure — you can ask me to delete your data (the 'right to be forgotten')
The right to restrict processing — you can ask me to limit how I use your data
The right to data portability — you can request your data in a commonly used format
The right to object — you can object to me processing your data in certain circumstances
The right to withdraw consent — where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, please contact me at hollyscottdigital@gmail.com. I will respond within 30 days.
8. Cookies
My website may use cookies to improve your browsing experience and to understand how visitors use the site (for example, via Google Analytics). You can control cookie settings through your browser at any time. Where cookies require your consent, I will ask for it. A full cookie policy will be provided separately on the website.
9. Third-Party Links
My website and social media profiles may contain links to third-party websites (such as Instagram, Facebook or LinkedIn). I am not responsible for the privacy practices of those sites and encourage you to read their privacy policies separately.
10. Data Security
I take the security of your data seriously. I store personal data securely and limit access to it. While no method of electronic storage is 100% secure, I take all reasonable steps to protect your information from unauthorised access, loss or disclosure.
11. Changes to This Policy
I may update this privacy policy from time to time. When I do, I will update the date at the top of this page. I encourage you to check back periodically. Continued use of my website or services after changes are made constitutes your acceptance of the updated policy.
12. Contact
If you have any questions, concerns or requests relating to this privacy policy or how I handle your data, please contact me.