Last reviewed 6 August 2026

Privacy policy

This notice explains what personal information Bonsai Digital Ltd uses, why it is used and the choices available to you.

Who is responsible

Bonsai Digital Ltd is the controller for personal information handled through this website and direct business enquiries. We are registered in England and Wales under company number 12259018. Contact us at contact@bonsaidigital.com or at the postal address in the website footer.

Information we collect

Depending on how you use our services, we may collect your name, email address, telephone number, organisation, website address, enquiry, support or website health-check details, where you heard about us, correspondence, newsletter choice and cookie preferences. For authorised website administrators we also process account, authentication, role, permission and security-audit information. When you use the website, limited technical information such as an IP-derived security hash, browser or device information, requested pages and timestamps may also be processed.

How information is collected

We receive information directly when you submit a contact, consulting, support, website health-check or newsletter form, correspond with us, or use an authorised account. If you consent to analytics cookies, we also receive aggregated website-use reporting through Google Analytics 4. Search-performance information may be retrieved from Google Search Console; it reports how the website appears in search and is not used by us to identify individual visitors.

Why we use it

We use information to respond to enquiries and take requested steps before a contract, provide and secure contracted services, administer website content and user access, prevent misuse, maintain audit records, understand how people find and use our services, improve our website, and meet legal obligations. The lawful basis depends on the activity and may be contract, steps requested before a contract, our legitimate interests in operating and protecting the business, legal obligation, or consent. The optional referral answer helps us understand which outreach is effective and is not used for automated decision-making.

Forms and security

Contact, support and website health-check contact fields are encrypted in the application database and are available only to authorised staff. We retain a one-way hash derived from the submitting IP address for form security and rate limiting rather than retaining the address in the form record. We use Google reCAPTCHA v3 on these forms to identify automated abuse. reCAPTCHA processes the verification token, IP address, browser or device signals and interaction data needed to provide a risk score; Google acts as our service provider for this check. Please do not send passwords, payment-card information or other unnecessary sensitive information through a form.

Newsletter and Mailchimp

Newsletter marketing is optional and based on consent. If you subscribe, your name, email address and marketing preference are sent to Mailchimp, which we use to manage and deliver emails. You can unsubscribe using the link in a newsletter or withdraw the consent recorded with an enquiry. Withdrawing newsletter consent does not affect our handling of the original enquiry.

Sharing and international transfers

We share information only with authorised staff and service providers needed to host, secure, communicate, analyse and operate our services. These may include our hosting and email providers, Mailchimp and, where analytics is accepted, Google. Some providers may process information outside the UK. Where required, transfers are protected by UK adequacy regulations or contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses. Service providers may have their own privacy notices.

Retention and deletion

We keep information only for as long as needed for the purpose collected, service continuity, security, dispute handling, legal obligations and legitimate business records. Public website health-check records are deleted after the expiry date shown with the result. Retention periods otherwise depend on the type of record and our relationship with you. Deleting an item from an operational screen may initially soft delete it so authorised audit and recovery processes continue to work; where an approved erasure request applies, personal information will be irreversibly deleted or anonymised unless it must lawfully be retained. Cookie-consent records are retained for the configured consent period and renewed when the policy version changes.

Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction or portability of your information, object to processing, and withdraw consent at any time. You also have the right to complain to the UK Information Commissioner's Office. Contact us first if you would like us to respond to a privacy request.

Changes to this notice

We update this notice when our website or processing changes. The review date above shows when this version was last checked. Legal wording and lawful-basis decisions remain subject to qualified UK legal or privacy review.