Privacy Policy
What we hold about you, why we hold it, and what you can ask of us.
This policy is for everyone we deal with: visitors to our website, people who contact us, clients and their teams, suppliers, and the businesses we approach, in the UK and in the EU. It says plainly what we hold about you, why, who sees it, how long we keep it, and how to ask us to change or delete it. We wrote it to be read in one sitting, in plain words. We keep little, we say why, and we answer when you ask.
Who we are and how to contact us
We are Blue Ocean Social Ltd, a marketing company registered in England and Wales (company number 15021733), registered office 128 City Road, London, EC1V 2NX. We are the controller of the personal data described in this policy, and we are registered with the UK Information Commissioner’s Office.
For anything about your data, email privacy@blueoceansocial.co.uk or use the contact form on our website. We aim to acknowledge any request within five working days, and we respond within the time the law allows, normally one month.
This policy covers our website, blueoceansocial.co.uk, and our dealings with clients, prospective clients, suppliers and the people who work for them, in the UK and in the EU. UK data protection law applies to us. Where the EU GDPR applies to people in the EU, we comply with it too. Marketing and cookie rules differ by country, so we follow the rules of the recipient’s or visitor’s country.
The short version
We work with businesses. The information we hold is professional: names, roles, business contact details and the messages we exchange.
Our website sets no cookies today. We count visits ourselves, in aggregate, and you can switch that off. When advertising arrives, it will ask before it runs.
If we contact your business without a prior relationship, it is because public sources suggested our services are relevant to your role. You can object at any time and we stop the same day.
We never sell personal data, and we never share it for anyone else’s marketing.
You can ask what we hold, have it corrected or deleted, and complain to a regulator. Section 14 explains how.
When you contact us or book a call
If you email us, use a form on our site, message us or book a call, we keep your name, company, contact details and what you tell us, so we can reply, prepare a proposal and follow up; section 4 explains how the contact form itself works. We may use AI tools to help us read and organise enquiries; any such use supports a decision by a person and never replaces one. Please do not send us sensitive information, such as health details, through the website; we do not need it and would rather not hold it.
Legal basis. Our legitimate interest in answering your enquiry, preparing a proposal and working with the contacts your organisation chooses; where you would enter the contract personally, for example as a sole trader, taking steps at your request before that contract. You do not have to give us this information, but without it we may be unable to reply. If we end up working together, section 6 applies. If we do not, we delete your details 12 months after our last contact, or sooner if you ask.
When you visit our website
Our website places almost nothing on your device. It sets no cookies today, none at all. The one thing it may keep there is your decision to switch our visitor counting off, if you make it, so we can honour it.
Advertising, coming soon. No advertising technology runs on our site today. We plan to introduce the Google Ads tag and the Meta Pixel and, when we do, our consent banner will ask first: neither will run unless you accept, and you will be able to change your mind at any time from that same banner. Once introduced, and only with your permission, they will record that you visited our site and which pages, together with online identifiers and browser, device, referrer, time and IP-derived information, so we can measure our advertising and show relevant ads on Google, Facebook and Instagram to people who have visited. For the Meta Pixel, we and Meta will be jointly responsible for collecting that data and sending it to Meta; Meta publishes the terms that set out that shared responsibility (its Controller Addendum, facebook.com/legal/controller_addendum), and you will be able to exercise your rights against either of us. What Meta does with such data is described in Meta’s own privacy policy. Google and Meta may process this data in the United States under the safeguards in section 11. You can also limit personalised advertising in your Google and Meta account settings. We will update this policy before any of that starts.
Your choices. Nothing on our site asks you to accept cookies today, because it sets none. The visitor counting described below runs unless you switch it off, and its switch, the “Analytics Toggle” link, sits in the footer of every page and on this one. When advertising arrives, a consent banner will ask before anything runs, and it will list each cookie in use, who sets it and how long it lasts. Either way, saying no changes nothing about how the site works for you.
Server logs. Our own web server keeps no record of who visited which page. The company whose infrastructure our server runs on may keep its own network-level connection logs under its own policy.
The contact form. The form on our website asks for your name, your business name, your email address and your message. When you press send, the message becomes an email to us, carried to our inbox by an email delivery provider that acts on our instructions. Nothing is stored on the website itself: there is no database of submissions, and the only copy is the email in our inbox. Before the form sends, Cloudflare runs a check in your browser to confirm that a person is sending it and not a machine; for that, Cloudflare processes technical details such as your IP address and browser characteristics. Our website’s own logs record only whether a submission went through and how long each field was, never your name, email address or message.
Links to other sites. Our site links to other websites, including the social platforms where we publish and the website of our sister company, White Sand Intelligence. Their own privacy policies apply there.
Visitor statistics. We count visits to our website with software we run ourselves, on our own server in the United Kingdom, and the numbers stay there: no analytics company receives them. We count which pages were looked at and how many times; how many people visited, as distinct from how many page views; which country a visit came from; which browser and operating system, by name only; and which page someone arrived from if they followed a link, together with campaign tags from a written list. That is the whole list. When the link came from another website, we keep that site and the path of the page it sat on, so we can tell which article or post sent you. When it came from one of our own pages, we keep the path only. In neither case do we keep what follows a question mark or a hash in the address, because that part can carry search terms or details about a person. None of it tells us who you are.
What we never do. We hold counts, not a record per person. Nothing follows you to any other website, we build no profiles or audience segments, and the numbers are never used to target or measure advertising or to make a decision about anyone. Location stops at country, because the software carries no finer database. Screen size and language preference are not collected. The numbers are never sold or shared.
One exception, said plainly. The counting software keeps a short, separate record of visits it judges to be automated: bots, crawlers and scrapers. That record holds the page requested, the browser’s self-description, the time and a code saying why the visit was judged automated. It holds no IP address, it applies only to visits judged automated, and it deletes itself after 30 days. Bot detection is imperfect, so a real person can occasionally be judged automated by mistake; if that happens, their browser string and the page they read sit in that record for up to 30 days.
Your choice. Counting is on unless you switch it off. The “Analytics Toggle” link, in the footer of every page and on this page, opens a small panel with one switch, and switching it off stops the counting on that browser at once, until you turn it back on. If your browser sends a Do Not Track or Global Privacy Control signal, we treat that as switched off, and you need do nothing. Nothing is stored on your device except that off switch itself, if you use it, and nothing about it is sent to us. Because it lives on the device, it works per browser: another browser, another device, or clearing this site’s data, and counting starts again.
How long we keep the numbers. Aggregate statistics for 25 months, long enough to compare a month with the same month a year earlier; the record of automated visits for 30 days.
Legal basis. Our legitimate interest in running a secure, working website, which covers the anti-spam check and the contact form logs described above; and, for the visitor statistics, our legitimate interest in understanding how the site is used so we can improve it. UK law allows statistics of this kind without asking for consent, because they serve no other purpose, we describe them here, and you can switch them off at any time. Advertising cookies, when they arrive, will rest on your consent instead.
When we contact your business
This section is our privacy notice for business contacts. Every message we send to a business we have not worked with before links here.
Why you might hear from us. We occasionally introduce our marketing services to businesses we believe could genuinely benefit from them. If we have contacted you, it is because your company’s public profile suggested our services are relevant to your role. We contact businesses in the UK and in some EU countries, including Sweden and Finland, by email, post or telephone, and only where the recipient’s country allows it. Before any UK call we screen the Telephone Preference Service, the Corporate Telephone Preference Service and our own do-not-call list. In Denmark we use post and telephone only.
What information we hold. Only limited professional personal data: your name, job role, business email address or business phone number, and facts about your company (what it does, where it is, its size), together with where we found each fact and when, our contact history with you, and any objection you have made. Nothing private, nothing sensitive.
Where it came from. Public sources only: official business registers such as Companies House and its equivalents in other countries, your company’s own website, and published trade directories. We record where every piece of information came from, and when.
Our legal basis. Legitimate interests (Article 6(1)(f) UK GDPR and EU GDPR): introducing relevant business services to businesses, in a professional context, with minimal data. We have documented this assessment and will provide it on request.
What we never do. We never sell or share your details for anyone else’s marketing. We make no automated decisions about you. We do not collect private contact details or sensitive information.
Who handles it. An email outreach platform sends our emails for us, and postal and telephone providers carry our letters and calls. They act on our instructions and see only what they need.
How long we keep it. If we do not end up working together, your details are deleted 12 months after our last message or call to you, or reduced to company-level facts with your name removed. If you ask us to stop contacting you, we keep only your contact route, the date and the channel on a suppression list, so we never contact you again.
Your rights. You can object to hearing from us at any time, and we will stop the same day: reply to any message from us, or email privacy@blueoceansocial.co.uk. You also have the right to see the information we hold about you, correct it, or have it deleted, and to complain to the UK Information Commissioner’s Office or your local data protection authority. Section 14 has the details.
When you are a client, or work for one
When your business becomes a client, we hold the names, roles and contact details of the people we work with; our correspondence by email, in the WhatsApp Business group chats we set up, and through our client portal; your approvals and instructions; the materials you share with us; and the invoicing and payment records the law requires us to keep. We use this to deliver the services, keep an accurate record of what was agreed, run our business and keep our systems secure.
Legal basis. Where the contract is with you personally, performing that contract; where you work for a client company, our legitimate interest in working with the contacts your employer chooses, and you can ask us to use a different contact at any time. Also our legal obligations for accounting and tax records, and our legitimate interests in keeping records, maintaining quality and protecting our systems. Some of this information is needed to start or run the service; without it we may be unable to continue.
Where client data sits. Personal data about a client’s own customers, leads or staff that arrives inside messages, recordings or materials stays under the client’s data processing agreement, including its six-month rule and its return-or-delete rule at the end of the contract. What we keep as our own record is the commercial correspondence, approvals and recordings of our own meetings described here.
Our client portal. The portal is a way to share materials, review work and communicate with us. It may include an AI assistant to help you find information quickly. Conversations with the assistant may be reviewed by our team for quality and, with personal data removed first, used in anonymised form to improve the platform.
Payments. Our payment providers collect Direct Debit and card payments under their own terms and privacy notices. We see that a payment was made, never your full card details.
Case studies. We may describe the results of our work in anonymised form in proposals, on our website and in our marketing, with names, logos and anything that would identify a client removed, and with any figures drawn from data that has had personal data removed. Naming a client, or quoting them, happens only with their written approval each time.
Recorded calls and meetings
We may record and transcribe video calls and meetings using an AI note-taking service, so we can capture details accurately without asking you to repeat yourself. We tell participants at the start of every call and explain the purpose. Anyone who prefers not to be recorded can ask us not to record, or communicate with us by email instead. The service acts on our instructions under a data processing agreement.
Legal basis. Our legitimate interest in keeping an accurate record of what was discussed and agreed. Recordings and transcripts of client calls are kept until 12 months after our relationship with that client ends, because they are our record if a question about the work ever arises. Recordings of calls with people who do not become clients are deleted 12 months after our last contact.
When we work on a client’s behalf
When we deliver services, we sometimes handle personal data about a client’s own customers, contacts and audience on that client’s behalf: for example sales and enquiry data shared for performance analysis, or data we can see in a client’s advertising accounts. There, the client decides why and how that data is used, and we act only on their instructions under the data processing agreement that forms part of every client contract. The client’s own privacy notice describes that use.
If you are a customer of one of our clients and have a question about your data, contact that business; we will help them answer you. We ask clients to share data without names or identifiers wherever possible, we delete personal data used for an analysis once the analysis is complete, and we never keep it longer than six months from receipt.
Suppliers, freelancers and applicants
If you supply us with services, work with us as a freelancer, or apply to work with us, we hold your name, contact details, the contract or application, and the records needed to pay you. Some of this information is needed to contract with you and pay you; without it we may be unable to engage you.
Legal basis. Performing our contract with you, our legal obligations for accounting and tax, and our legitimate interest in running the business. We keep contract and payment records for six years after the relationship ends. Unsuccessful applications are deleted after six months.
Who we share data with
We share personal data only with people and companies who need it to do something for us, and only what they need. Our service providers act under written terms that require them to protect it. Some recipients, such as payment providers, advertising and social platforms, professional advisers and public authorities, act under their own legal duties or terms; if we introduce the Meta Pixel described in section 4, Meta and we will act as joint controllers for that limited activity. They are:
our email and file storage providers, and our file sharing, delivery and e-signature providers;
our web hosting providers, including a UK-based provider for the websites we host for clients;
AI providers we hold data processing agreements with, configured so that our data is never used to train their models, for organising enquiries, analysis, removing personal data from datasets and, where enabled, the client portal assistant;
an AI note-taking service, for the recorded calls described in section 7;
business messaging and call-booking providers, for the WhatsApp Business groups and call bookings described above;
a social media scheduling tool, and the advertising and social platforms (Google Ads, Meta Business Suite, Facebook, Instagram) where a client gives us access to their own accounts;
an email outreach platform, and postal and telephone providers, for the business contacts described in section 5;
our payment providers, and the freelancer platforms through which we engage contractors;
Cloudflare, for the anti-spam check on our contact form, and an email delivery provider that carries form submissions to our inbox, both described in section 4;
Google and Meta, for the advertising cookies described in section 4, once those are introduced;
professional advisers such as our accountant or solicitor, bound by their own duties of confidentiality, including where they verify that anonymised results we publish are accurate;
public authorities, regulators or courts, where the law requires.
We never sell personal data, and we never share it for anyone else’s marketing.
Transfers outside the UK and the EU
We are based in the United Kingdom, so information about people in the EU is handled in the UK; the European Commission recognises the UK as providing adequate protection under the EU GDPR (decisions renewed on 19 December 2025). Some of the providers above also process data in the United States or other countries. Whenever personal data leaves the UK or the EU, we make sure a lawful safeguard is in place first: for data from the UK, the UK-US Data Bridge where the recipient is certified under it, or the UK International Data Transfer Agreement or UK Addendum; for data from the EU, the EU-US Data Privacy Framework where the recipient is certified, or the EU standard contractual clauses. You can ask us for a copy of the safeguards that apply to your data.
How long we keep data
We keep personal data only as long as we have a reason to, and then we delete it or anonymise it so that it no longer identifies anyone.
Website cookies: none today. When advertising cookies arrive, each will last for the period shown in the cookie settings panel, and your consent choice will stay on your own device until you change it or clear your browser’s site data. Our own server keeps no record of who visited which page; our hosting provider may keep connection logs under its own policy.
Visitor statistics: aggregate counts for 25 months; the record of visits judged automated for 30 days; your off switch, if you use it, stays on your own device until you change it or clear your browser’s site data.
Enquiries that do not lead to work: 12 months after our last contact. A contact form submission exists only as the email it becomes, so the same rule applies; the website keeps no copy.
Business contacts we approach: 12 months after our last message or call if no relationship follows; after an objection, only a suppression record (contact route, date and channel), kept so we never contact you again.
Client commercial records and correspondence: normally the relationship and six years afterwards, where needed for accounting, legal claims and an accurate record of what was agreed; sooner where those purposes no longer justify it. Personal data about a client’s customers inside those records follows the client’s data processing agreement instead.
Invoices, payments and accounting records: the period tax and company law require, normally six years from the end of the financial year they belong to.
Recordings and transcripts: 12 months after the client relationship ends; otherwise 12 months after our last contact.
Client portal accounts: the life of the account and 12 months afterwards.
Data handled on a client’s behalf: deleted after each analysis and never kept more than six months from receipt; returned or deleted at the client’s choice when the contract ends.
Suppliers, freelancers and applicants: six years after the relationship ends; unsuccessful applications six months.
How we protect data
We take reasonable security precautions: secure password management, two-factor authentication wherever it is available, access limited to the people who need it, and providers chosen with their security in mind. Everyone with access is bound by confidentiality.
If a personal data breach ever affects you, we will investigate, contain it, tell you and the regulator without undue delay where the law requires it, and cooperate fully.
Your rights and how to complain
Under UK GDPR and EU GDPR, depending on the circumstances, you can:
ask for a copy of the personal data we hold about you;
ask us to correct it, or to delete it;
ask us to restrict how we use it;
receive the data you gave us in a portable format;
object to our use of your data where we rely on legitimate interests, and object at any time to direct marketing, which we always honour;
withdraw consent, for example for cookies, without affecting anything done before.
Some rights have legal limits, for example where we must keep a tax record or protect another person’s rights. Your right to object to direct marketing has no such limit: once you object, we stop. We make no decisions about you by automated means that have legal or similarly significant effects.
To exercise a right, email privacy@blueoceansocial.co.uk. We may need to confirm who you are. We acknowledge within five working days and respond within one month; if a request is complex or you make several, the law allows up to two further months, and we will tell you within the first month if that applies.
If you are unhappy with how we have handled your data, we would welcome the chance to put it right first. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or to your local data protection authority: in Sweden, the Swedish Authority for Privacy Protection (imy.se); in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi); in Denmark, Datatilsynet (datatilsynet.dk).
Children
Our website and services are for businesses. We do not knowingly collect personal data about anyone under 18. If you believe we hold such data, email us and we will delete it.
Changes to this policy
We review this policy whenever our services, tools or the law change, and at least once a year. The version number and effective date at the top of this page tell you which version you are reading. Where a change matters to you, for example a new purpose for using your data, we will tell you directly where we can.
This is Version 08/26, effective 29 August 2026. For any question about this policy or your personal data, email privacy@blueoceansocial.co.uk, use the contact form, or write to us at the registered address below.
Blue Ocean Social Ltd · Registered in England & Wales · Company No. 15021733 · 128 City Road, London, United Kingdom, EC1V 2NX · privacy@blueoceansocial.co.uk · blueoceansocial.co.uk