Privacy Policy
What we hold about you, why we hold it, and what you can ask of us.
This policy is for everyone we deal with: visitors to our website, people who contact us, clients and their teams, suppliers, and the businesses we approach, in the UK and in the EU. It says plainly what we hold about you, why, who sees it, how long we keep it, and how to ask us to change or delete it. We wrote it to be read in one sitting, in plain words. We keep little, we say why, and we answer when you ask.
Who we are and how to contact us
We are Blue Ocean Social Ltd, a marketing company registered in England and Wales (company number 15021733), registered office 128 City Road, London, EC1V 2NX. We are the controller of the personal data described in this policy, and we are registered with the UK Information Commissioner’s Office.
For anything about your data, email privacy@blueoceansocial.co.uk or use the contact form on our website. We aim to acknowledge any request within five working days, and we respond within the time the law allows, normally one month.
This policy covers our website, blueoceansocial.co.uk, and our dealings with clients, prospective clients, suppliers and the people who work for them, in the UK and in the EU. UK data protection law applies to us. Where the EU GDPR applies to people in the EU, we comply with it too. Marketing and cookie rules differ by country, so we follow the rules of the recipient’s or visitor’s country.
The short version
We work with businesses. The information we hold is professional: names, roles, business contact details and the messages we exchange.
Our website sets advertising cookies only if you accept them, and you can change your mind at any time.
If we contact your business without a prior relationship, it is because public sources suggested our services are relevant to your role. You can object at any time and we stop the same day.
We never sell personal data, and we never share it for anyone else’s marketing.
You can ask what we hold, have it corrected or deleted, and complain to a regulator. Section 14 explains how.
When you contact us or book a call
If you email us, use a form on our site, message us or book a call, we keep your name, company, contact details and what you tell us, so we can reply, prepare a proposal and follow up; section 4 explains how the contact form itself works. We may use AI tools to help us read and organise enquiries; any such use supports a decision by a person and never replaces one. Please do not send us sensitive information, such as health details, through the website; we do not need it and would rather not hold it.
Legal basis. Our legitimate interest in answering your enquiry, preparing a proposal and working with the contacts your organisation chooses; where you would enter the contract personally, for example as a sole trader, taking steps at your request before that contract. You do not have to give us this information, but without it we may be unable to reply. If we end up working together, section 6 applies. If we do not, we delete your details 12 months after our last contact, or sooner if you ask.
When you visit our website
Our website uses cookies and similar technologies. Some are essential: they keep the site working and remember your cookie choices. The rest run only if you accept them when the cookie banner appears, and you can change your choice at any time from “Cookie settings” in the footer of every page.
Advertising. With your permission, the Google Ads tag and the Meta Pixel record that you visited our site and which pages, together with online identifiers and browser, device, referrer, time and IP-derived information, so we can measure our advertising and show relevant ads on Google, Facebook and Instagram to people who have visited. For the Meta Pixel, we and Meta are jointly responsible for collecting that data and sending it to Meta; Meta publishes the terms that set out that shared responsibility (its Controller Addendum, facebook.com/legal/controller_addendum), and you can exercise your rights against either of us. What Meta does with the data afterwards is described in Meta’s own privacy policy. Google and Meta may process this data in the United States under the safeguards in section 11. You can also limit personalised advertising in your Google and Meta account settings.
Your choices. The cookie settings panel lists each cookie in use, who sets it and how long it lasts, and lets you switch advertising cookies on or off. Rejecting them changes nothing about how the site works for you.
Server logs. The provider that hosts our website records IP addresses and basic request details in security logs for up to 30 days. We use these only to keep the site secure and working.
The contact form. The form on our website asks for your name, your business name, your email address and your message. When you press send, the message becomes an email to us, carried to our inbox by an email delivery provider that acts on our instructions. Nothing is stored on the website itself: there is no database of submissions, and the only copy is the email in our inbox. Before the form sends, Cloudflare runs a check in your browser to confirm that a person is sending it and not a machine; for that, Cloudflare processes technical details such as your IP address and browser characteristics. Our website’s own logs record only whether a submission went through and how long each field was, never your name, email address or message.
Legal basis. Your consent for advertising cookies; our legitimate interest in running a secure, working website for essential cookies, server logs and the anti-spam check on the contact form.
Links to other sites. Our site links to other websites, including the social platforms where we publish and the website of our sister company, White Sand Intelligence. Their own privacy policies apply there.
When we contact your business
This section is our privacy notice for business contacts. Every message we send to a business we have not worked with before links here.
Why you might hear from us. We occasionally introduce our marketing services to businesses we believe could genuinely benefit from them. If we have contacted you, it is because your company’s public profile suggested our services are relevant to your role. We contact businesses in the UK and in some EU countries, including Sweden and Finland, by email, post or telephone, and only where the recipient’s country allows it. Before any UK call we screen the Telephone Preference Service, the Corporate Telephone Preference Service and our own do-not-call list. In Denmark we use post and telephone only.
What information we hold. Only limited professional personal data: your name, job role, business email address or business phone number, and facts about your company (what it does, where it is, its size), together with where we found each fact and when, our contact history with you, and any objection you have made. Nothing private, nothing sensitive.
Where it came from. Public sources only: official business registers such as Companies House and its equivalents in other countries, your company’s own website, and published trade directories. We record where every piece of information came from, and when.
Our legal basis. Legitimate interests (Article 6(1)(f) UK GDPR and EU GDPR): introducing relevant business services to businesses, in a professional context, with minimal data. We have documented this assessment and will provide it on request.
What we never do. We never sell or share your details for anyone else’s marketing. We make no automated decisions about you. We do not collect private contact details or sensitive information.
Who handles it. An email outreach platform sends our emails for us, and postal and telephone providers carry our letters and calls. They act on our instructions and see only what they need.
How long we keep it. If we do not end up working together, your details are deleted 12 months after our last message or call to you, or reduced to company-level facts with your name removed. If you ask us to stop contacting you, we keep only your contact route, the date and the channel on a suppression list, so we never contact you again.
Your rights. You can object to hearing from us at any time, and we will stop the same day: reply to any message from us, or email privacy@blueoceansocial.co.uk. You also have the right to see the information we hold about you, correct it, or have it deleted, and to complain to the UK Information Commissioner’s Office or your local data protection authority. Section 14 has the details.
When you are a client, or work for one
When your business becomes a client, we hold the names, roles and contact details of the people we work with; our correspondence by email, in the WhatsApp Business group chats we set up, and through our client portal; your approvals and instructions; the materials you share with us; and the invoicing and payment records the law requires us to keep. We use this to deliver the services, keep an accurate record of what was agreed, run our business and keep our systems secure.
Legal basis. Where the contract is with you personally, performing that contract; where you work for a client company, our legitimate interest in working with the contacts your employer chooses, and you can ask us to use a different contact at any time. Also our legal obligations for accounting and tax records, and our legitimate interests in keeping records, maintaining quality and protecting our systems. Some of this information is needed to start or run the service; without it we may be unable to continue.
Where client data sits. Personal data about a client’s own customers, leads or staff that arrives inside messages, recordings or materials stays under the client’s data processing agreement, including its six-month rule and its return-or-delete rule at the end of the contract. What we keep as our own record is the commercial correspondence, approvals and recordings of our own meetings described here.
Our client portal. The portal is a way to share materials, review work and communicate with us. It may include an AI assistant to help you find information quickly. Conversations with the assistant may be reviewed by our team for quality and, with personal data removed first, used in anonymised form to improve the platform.
Payments. Our payment providers collect Direct Debit and card payments under their own terms and privacy notices. We see that a payment was made, never your full card details.
Case studies. We may describe the results of our work in anonymised form in proposals, on our website and in our marketing, with names, logos and anything that would identify a client removed, and with any figures drawn from data that has had personal data removed. Naming a client, or quoting them, happens only with their written approval each time.
Recorded calls and meetings
We may record and transcribe video calls and meetings using an AI note-taking service, so we can capture details accurately without asking you to repeat yourself. We tell participants at the start of every call and explain the purpose. Anyone who prefers not to be recorded can ask us not to record, or communicate with us by email instead. The service acts on our instructions under a data processing agreement.
Legal basis. Our legitimate interest in keeping an accurate record of what was discussed and agreed. Recordings and transcripts of client calls are kept until 12 months after our relationship with that client ends, because they are our record if a question about the work ever arises. Recordings of calls with people who do not become clients are deleted 12 months after our last contact.
When we work on a client’s behalf
When we deliver services, we sometimes handle personal data about a client’s own customers, contacts and audience on that client’s behalf: for example sales and enquiry data shared for performance analysis, or data we can see in a client’s advertising accounts. There, the client decides why and how that data is used, and we act only on their instructions under the data processing agreement that forms part of every client contract. The client’s own privacy notice describes that use.
If you are a customer of one of our clients and have a question about your data, contact that business; we will help them answer you. We ask clients to share data without names or identifiers wherever possible, we delete personal data used for an analysis once the analysis is complete, and we never keep it longer than six months from receipt.
Suppliers, freelancers and applicants
If you supply us with services, work with us as a freelancer, or apply to work with us, we hold your name, contact details, the contract or application, and the records needed to pay you. Some of this information is needed to contract with you and pay you; without it we may be unable to engage you.
Legal basis. Performing our contract with you, our legal obligations for accounting and tax, and our legitimate interest in running the business. We keep contract and payment records for six years after the relationship ends. Unsuccessful applications are deleted after six months.
Who we share data with
We share personal data only with people and companies who need it to do something for us, and only what they need. Our service providers act under written terms that require them to protect it. Some recipients, such as payment providers, advertising and social platforms, professional advisers and public authorities, act under their own legal duties or terms; Meta and we act as joint controllers for the limited Pixel activity described in section 4. They are:
our email and file storage providers, and our file sharing, delivery and e-signature providers;
our web hosting providers, including a UK-based provider for the websites we host for clients;
AI providers we hold data processing agreements with, configured so that our data is never used to train their models, for organising enquiries, analysis, removing personal data from datasets and, where enabled, the client portal assistant;
an AI note-taking service, for the recorded calls described in section 7;
business messaging and call-booking providers, for the WhatsApp Business groups and call bookings described above;
a social media scheduling tool, and the advertising and social platforms (Google Ads, Meta Business Suite, Facebook, Instagram) where a client gives us access to their own accounts;
an email outreach platform, and postal and telephone providers, for the business contacts described in section 5;
our payment providers, and the freelancer platforms through which we engage contractors;
Cloudflare, for the anti-spam check on our contact form, and an email delivery provider that carries form submissions to our inbox, both described in section 4;
Google and Meta, for the website cookies described in section 4;
professional advisers such as our accountant or solicitor, bound by their own duties of confidentiality, including where they verify that anonymised results we publish are accurate;
public authorities, regulators or courts, where the law requires.
We never sell personal data, and we never share it for anyone else’s marketing.
Transfers outside the UK and the EU
We are based in the United Kingdom, so information about people in the EU is handled in the UK; the European Commission recognises the UK as providing adequate protection under the EU GDPR (decisions renewed on 19 December 2025). Some of the providers above also process data in the United States or other countries. Whenever personal data leaves the UK or the EU, we make sure a lawful safeguard is in place first: for data from the UK, the UK-US Data Bridge where the recipient is certified under it, or the UK International Data Transfer Agreement or UK Addendum; for data from the EU, the EU-US Data Privacy Framework where the recipient is certified, or the EU standard contractual clauses. You can ask us for a copy of the safeguards that apply to your data.
How long we keep data
We keep personal data only as long as we have a reason to, and then we delete it or anonymise it so that it no longer identifies anyone.
Website cookies: each cookie lasts for the period shown in the cookie settings panel; your consent choice is kept for 12 months; our website’s security logs are kept for up to 30 days.
Enquiries that do not lead to work: 12 months after our last contact. A contact form submission exists only as the email it becomes, so the same rule applies; the website keeps no copy.
Business contacts we approach: 12 months after our last message or call if no relationship follows; after an objection, only a suppression record (contact route, date and channel), kept so we never contact you again.
Client commercial records and correspondence: normally the relationship and six years afterwards, where needed for accounting, legal claims and an accurate record of what was agreed; sooner where those purposes no longer justify it. Personal data about a client’s customers inside those records follows the client’s data processing agreement instead.
Invoices, payments and accounting records: the period tax and company law require, normally six years from the end of the financial year they belong to.
Recordings and transcripts: 12 months after the client relationship ends; otherwise 12 months after our last contact.
Client portal accounts: the life of the account and 12 months afterwards.
Data handled on a client’s behalf: deleted after each analysis and never kept more than six months from receipt; returned or deleted at the client’s choice when the contract ends.
Suppliers, freelancers and applicants: six years after the relationship ends; unsuccessful applications six months.
How we protect data
We take reasonable security precautions: secure password management, two-factor authentication wherever it is available, access limited to the people who need it, and providers chosen with their security in mind. Everyone with access is bound by confidentiality.
If a personal data breach ever affects you, we will investigate, contain it, tell you and the regulator without undue delay where the law requires it, and cooperate fully.
Your rights and how to complain
Under UK GDPR and EU GDPR, depending on the circumstances, you can:
ask for a copy of the personal data we hold about you;
ask us to correct it, or to delete it;
ask us to restrict how we use it;
receive the data you gave us in a portable format;
object to our use of your data where we rely on legitimate interests, and object at any time to direct marketing, which we always honour;
withdraw consent, for example for cookies, without affecting anything done before.
Some rights have legal limits, for example where we must keep a tax record or protect another person’s rights. Your right to object to direct marketing has no such limit: once you object, we stop. We make no decisions about you by automated means that have legal or similarly significant effects.
To exercise a right, email privacy@blueoceansocial.co.uk. We may need to confirm who you are. We acknowledge within five working days and respond within one month; if a request is complex or you make several, the law allows up to two further months, and we will tell you within the first month if that applies.
If you are unhappy with how we have handled your data, we would welcome the chance to put it right first. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or to your local data protection authority: in Sweden, the Swedish Authority for Privacy Protection (imy.se); in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi); in Denmark, Datatilsynet (datatilsynet.dk).
Children
Our website and services are for businesses. We do not knowingly collect personal data about anyone under 18. If you believe we hold such data, email us and we will delete it.
Changes to this policy
We review this policy whenever our services, tools or the law change, and at least once a year. The version number and effective date at the top of this page tell you which version you are reading. Where a change matters to you, for example a new purpose for using your data, we will tell you directly where we can.
This is Version 08/26, effective 29 August 2026. For any question about this policy or your personal data, email privacy@blueoceansocial.co.uk, use the contact form, or write to us at the registered address below.
Blue Ocean Social Ltd · Registered in England & Wales · Company No. 15021733 · 128 City Road, London, United Kingdom, EC1V 2NX · privacy@blueoceansocial.co.uk · blueoceansocial.co.uk