PRIVACY

Your data, plainly.

What we collect, why, who else sees it, and how to make us delete it. UK GDPR and PECR. Last updated 5 September 2026.

Who we are

SCOTT&YOUNG LTD (company no. 16697821, registered in England & Wales, based in Thame, Oxfordshire) is the data controller for this website and for the services described on it.

Our registration with the Information Commissioner’s Office (ICO) is being completed and our registration number will be published here as soon as it is issued.

We are a one-person company and are not required to appoint a Data Protection Officer. Every data protection question comes to the same place: hello@scottnyoung.co.uk. If you would prefer to write to us by post, email us and we will give you a postal address — we do not publish one because it is a private residence.

The short version

We collect only what you type into a form. This website sets no cookies whatsoever — none, not even “essential” ones. We run no advertising pixels, no cross-site tracking, and no third-party analytics. Nothing on the page is loaded from another company without you clicking first. We never sell your data, and we never use it to train AI models.

What we collect, why, and our lawful basis

WhatWhyLawful basis
Contact form
your name, business name, email, message
To read your enquiry and reply to it. Consent (you tick the box), and legitimate interest in replying to people who contact us.
Visibility Audit request
company name, website address, email, your reference code
To produce your free audit and email it to you. Consent.
Thame Pledge application
your name, organisation, email, what you need
To assess and administer applications for a free community build. Consent.
Newsletter
your email address
To send you the newsletter you asked for. Consent (explicit opt-in only).
Security log
your IP address, the page requested, time
To keep the site online and defend against attacks and abuse. Legitimate interest in the security of our service.
Traffic statistics
page requested, time, referring site, browser type — no IP address, no identifier
To see which pages people find useful. Legitimate interest. This log contains no personal data, so it identifies nobody.

Providing any of this is entirely voluntary. There is no statutory or contractual obligation to give us anything — but if you do not complete a form, we cannot reply to you or produce your audit.

Cookies

This website sets no cookies. Not for advertising, not for analytics, not for anything. Our typefaces are served from our own server rather than from Google, so no request goes to Google when you visit.

There is one third party on the site: the booking calendar on our contact page, provided by Cal.com. We do not load it automatically. It sits behind a button, and nothing is requested from Cal.com — and no cookies are set by them — unless you choose to press it. If you never press it, Cal.com never learns you were here. If you press it, Cal.com will receive your IP address and may set its own cookies, under their privacy policy.

Because we set no cookies and store nothing on your device, we do not need to show you a cookie banner, and we have not built one.

Analytics

We count visits with GoatCounter, open-source analytics software that runs on our own server. It is not a third-party service: nothing about your visit leaves our server, and it sets no cookies and stores no identifier on your device.

For each page you view it records the page, the page you came from if your browser sends one, your screen size, browser and operating-system family, your country, and which links you press. To count how many different people visited, it derives a short-lived hash from your IP address and browser signature, salted with a value that changes regularly and is never kept. The IP address itself is not stored, the hash cannot be reversed, and it cannot be used to follow you from one day to the next. There is no cross-site tracking and no advertising use, and we never join this data to anything you type into a form.

Our lawful basis is legitimate interest in knowing which pages and links are useful. To opt out in your browser, open any page on this site with #toggle-goatcounter at the end of the address; that sets a single “do not count me” flag in your browser’s local storage and nothing else.

Your free Visibility Audit — exactly what happens

When you request an audit we take three things: your company name, your website address and your email address. With your consent we then:

A human reviews every finding before anything reaches you.

When we audit or work on another business’s data

If you are a client and we audit your business, produce content for you, or run your marketing, we may handle personal data that belongs to your business — for example the names and work contact details of your staff shown on your own website, or enquiries that come through a site we built for you.

Who else sees your data

We keep the number of suppliers deliberately small. These are all of them:

SupplierWhat they doWhere
HetznerHosts this website and its logsGermany (EU)
SupabaseStores form submissionsIreland (EU)
BrevoSends our emailFrance (EU)
Cal.comBooking calendar — only if you press the buttonUnited States

International transfers. Our EU suppliers are covered by the UK’s adequacy regulations for the EEA, so your data is protected to UK standards. Cal.com is in the United States; if you choose to load the calendar, that transfer relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. You can avoid that transfer entirely by not pressing the button and emailing us instead.

We will also disclose data if we are legally required to — for example by a court order. We will tell you if that happens unless we are forbidden from doing so.

How long we keep things

WhatHow long
Enquiries, audit requests, audit reports and Pledge applications24 months from your last contact with us, then deleted
Newsletter subscriptionUntil you unsubscribe
Security log containing your IP address14 days, then automatically deleted
Traffic statistics (no IP, no identifier)13 months
Records we must keep by law, such as invoices6 years, as HMRC requires

Marketing email

We only email marketing to people who have explicitly asked for it. No pre-ticked boxes, no adding you because you once enquired, no buying lists. We record when and how you consented. Every marketing email carries a one-click unsubscribe, and we act on it immediately. Replying to an enquiry or sending your audit is not marketing, and you can ask us to stop at any time.

Automated decisions and our use of AI

We use AI tools to help produce audits, content and code. Your Visibility Audit is scored partly by automated analysis — but a human reviews every finding before it reaches you, and the score has no legal or similarly significant effect on you. We do not make solely automated decisions about people, and we do not profile you.

We never put your data into a public AI tool in a way that allows it to be used for training, and we never train models on your data or your customers’ data.

Keeping it safe, and what happens if something goes wrong

Data is encrypted in transit (HTTPS everywhere) and stored in access-controlled databases where the public can write to a form but nobody can read the contents back. Access is limited to the one person who runs the company.

If a breach ever occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly and without undue delay if the risk to you is high.

Children

This is a business-to-business service and is not directed at children. We do not knowingly collect data about anyone under 18. If you believe we hold a child’s data, email us and we will delete it.

Your rights

Under UK GDPR you have the right to:

Withdrawing consent. Where we rely on your consent you can withdraw it at any time, and it is as easy to withdraw as it was to give: email us. Withdrawing does not affect anything we did lawfully before you withdrew.

Email hello@scottnyoung.co.uk to exercise any of these. It is free, and we will respond within one month.

Complaining

If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain directly to the regulator at any time:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint

Changes to this notice

If we change how we handle your data we will update this page and change the date at the top. Material changes affecting you will be told to you directly where we hold your contact details.