Privacy policy

Last updated: 12 September 2026

This policy describes how ESOPRO LTD collects and processes the personal data of visitors to its website, in accordance with the UK GDPR and the EU General Data Protection Regulation.

1. Data controller

The data controller is ESOPRO LTD, a company registered in England and Wales under number 17439003, whose registered office is at Dept 6341, 43 Owston Road, Carcroft, Doncaster DN6 8DA, United Kingdom.

For any question about the protection of your data, you may write to contact@esopro.studio.

2. Data collected

We collect only the data you send us voluntarily. No data is bought, rented or collected from third parties.

2.1 Data submitted through the contact form

  • your first and last name;
  • your company name;
  • your work email address;
  • your phone number, if you choose to provide it;
  • your sector;
  • the content of the message you write;
  • the time of submission.

Mandatory fields are marked on the form. Please do not include in the message field any special category data within the meaning of Article 9 of the GDPR, or personal data relating to third parties.

2.2 Technical data

For security and operational purposes, our hosting provider records technical logs containing, in particular, the connecting IP address, the date and time of the request and the browser type. These logs are kept for a limited period by the hosting provider and are not put to any commercial use by us.

2.3 Cookies

This website uses no advertising cookies and no third-party analytics tools. A single technical cookie, with a lifetime of two minutes, may be set in order to redisplay the contents of a form whose submission failed. That cookie is strictly necessary to provide the service you requested and does not require your prior consent.

3. Purposes and legal bases

  • Responding to your enquiry and corresponding with you — legal basis: your consent, given via the checkbox on the form (Article 6(1)(a) GDPR) and, where applicable, steps taken at your request prior to entering into a contract (Article 6(1)(b)).
  • Preparing a quotation and performing an engagement — legal basis: performance of a contract or of pre-contractual steps (Article 6(1)(b) GDPR).
  • Securing the website and preventing automated submissions — legal basis: our legitimate interest in protecting our infrastructure (Article 6(1)(f) GDPR).
  • Meeting our accounting and legal obligations — legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).

Your data is not used for unsolicited marketing, for profiling, or to train an artificial intelligence model. No automated decision producing legal effects concerning you is taken on the basis of it.

4. Retention periods

  • Enquiry with no commercial follow-up: data is kept for three (3) years from the last contact, then deleted.
  • Enquiry leading to a contractual relationship: data is kept for the duration of the relationship, then archived for the period required by applicable legal and accounting obligations.
  • Accounting records and supporting documents: six (6) years from the end of the financial year concerned.
  • Technical logs: kept by the hosting provider for no more than twelve (12) months.
  • Technical form cookie: two (2) minutes.

5. Recipients

Your data is accessible only to those people at ESOPRO LTD responsible for handling enquiries. It is not sold, rented, or passed to third parties for commercial purposes.

We use the following technical processors, acting on our instructions and bound by confidentiality and security obligations:

  • Vercel Inc. — website hosting and technical logging (United States);
  • Resend — delivery of messages sent from the contact form (United States);
  • our business email provider, for receiving and storing correspondence.

Data may also be disclosed to an administrative or judicial authority where the law requires it.

6. Transfers outside the UK and the EEA

Some of our processors are established in the United States. Those transfers are covered by the appropriate safeguards provided for in Chapter V of the GDPR and in the UK GDPR, namely the standard contractual clauses (together with the UK International Data Transfer Addendum) and, where applicable, the processor's certification under the applicable EU–US and UK–US data protection frameworks. A copy of these safeguards is available on written request.

7. Security

We implement appropriate technical and organisational measures to protect your data against loss, alteration and unauthorised access: encryption of data in transit (HTTPS), strict limitation of access to authorised staff, strong authentication on our tools, and access logging.

8. Your rights

Under the applicable regulations, you have the following rights over your data:

  • Right of access — to confirm whether processing concerning you exists and to obtain a copy of it.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to request deletion of your data, subject to our legal retention obligations.
  • Right to restriction — to request that contested processing be temporarily frozen.
  • Right to object — to object, on grounds relating to your particular situation, to processing based on our legitimate interest.
  • Right to data portability — to receive the data you provided to us in a structured, machine-readable format.
  • Right to withdraw consent — at any time, without affecting the lawfulness of processing carried out beforehand.

These rights may be exercised by email to contact@esopro.studio or by post to the registered office address. We reply within one month of receiving your request. Proof of identity may be requested where there is reasonable doubt as to the identity of the person making the request.

9. Complaints to a supervisory authority

If, having contacted us, you consider that your rights are not being respected, you may lodge a complaint with a supervisory authority:

  • in the United Kingdom, the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk;
  • in France, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr;
  • or with the supervisory authority of your country of residence within the European Union.

10. Data processed on behalf of our clients

When we carry out an audit or automation engagement, we may process personal data on behalf of the client company. In that case we act as a processor within the meaning of Article 28 of the GDPR, under a written agreement specifying the nature, duration and purposes of the processing. Data subjects exercise their rights with the client company, which is the controller.

11. Changes to this policy

This policy may be updated to reflect legal or technical developments. The date of the last update appears at the top of the page. Where a change is substantial, the data subjects whose contact details we hold are informed.