Privacy Policy
Updated: Friday 13 February 2026
CONTACT DETAILS
If you have any questions about this privacy policy or how we handle your personal data, please contact us:
Telephone: (+44) 0330 133 6113
Email: dpo@y17.group
WHAT INFORMATION WE COLLECT, USE, AND WHY
We collect or use personal information for specific business purposes. The types of data we collect and our reasons for doing so are outlined below.
To provide and improve products and services for clients. Types of data collected:
Names and contact details
Addresses
Occupation
Payment details (including card or bank information for transfers and direct debits)
Transaction data (details of products/services purchased)
Usage data (how you interact with our website and services)
Audio recordings (e.g., calls) and records of meetings
Website user information
For the operation of client or customer accounts. Types of data collected:
Names and contact details
Addresses
Purchase or service history
Account registration details and security information
Marketing preferences
For information updates or marketing purposes. Types of data collected:
Names and contact details
Marketing preferences
Purchase or account history
Website and app user journey information
For dealing with queries, complaints, or claims. Types of data collected:
Names and contact details
Addresses
Account information and service history
Call recordings and correspondence history
Financial transaction information
OUR LAWFUL BASES FOR PROCESSING
Under UK data protection law (UK GDPR), we must have a "lawful basis" for collecting and using your personal information.
Providing and Improving Products & Services. We rely on the following lawful bases:
Contract: We need to process your information to enter into or carry out a contract with you.
Consent: Where we have asked for your permission explicitly.
Legitimate Interests:
Production & Fulfillment Logistics: Processing contact details, shipping manifests, and visual content is necessary to design, manufacture, and distribute physical and digital marketing assets.
Asset Management & Archival Integrity: We retain long-term records of project files and digital assets to ensure business continuity, restoration of lost data, and brand consistency.
Agency Promotion & Portfolio: We may display completed work to evidence professional capability and past performance.
Operation of Client Accounts. We rely on:
Contract: Necessary to manage your account and fulfill orders.
Legal Obligation: To comply with tax and accounting laws.
Legitimate Interests: For managing production logistics and maintaining accurate business records.
Marketing Purposes
We rely on consent. We will usually ask for your consent before sending direct marketing communications. You have the right to withdraw this at any time.
Dealing with Queries, Complaints, or Claims. We rely on:
Legal Obligation: To comply with laws regarding consumer rights.
Legitimate Interests: To maintain high service standards, resolve disputes amicably, and defend our legal rights.
HOW LONG WE KEEP INFORMATION
We retain personal data only for as long as necessary to provide our services and in accordance with statutory retention periods.
Client Project Archives (Photos, Video, Design Files etc)
Retention Period: Indefinite / Permanent - to facilitate future file recovery, re-prints, and maintain brand history for the client. Stored in secure/cold storage after active use.Financial Records (Invoices, POs, Bank Info)
Retention Period: 7 Years - to fulfil statutory requirements (HMRC) and defence of legal claims.Contracts & Agreements
Retention Period: 7 Years - to reference terms in case of legal disputes (Limitation Act 1980).Prospective Enquiries (Emails, Contact Forms)
Retention Period: 7 Years - to allow for follow-up on long lead-time projects.Portfolio Work (Website, Case Studies)
Retention Period: Indefinite - legitimate interest in marketing our agency’s past work and expertise.
At the end of the retention period, or upon a valid request for erasure, data is securely destroyed or anonymised.
WHO WE SHARE INFORMATION WITH
We may share your personal information with:
Service Providers & Suppliers: Third parties helping deliver our products (e.g., commercial printers, couriers, and IT support).
Professional Advisers: Lawyers, bankers, auditors, and insurers.
Legal Authorities: HM Revenue & Customs or other regulators if required by law.
WHERE WE GET PERSONAL INFORMATION FROM
Directly from you: When you contact us, place an order, or set up an account.
Suppliers and service providers: From third parties involved in the supply chain or lead generation.
YOUR DATA PROTECTION RIGHTS
Under UK data protection law, you have rights including:
Your right of access: To ask us for copies of your personal information.
Your right to rectification: To ask us to correct or delete information you think is inaccurate.
Your right to erasure: To ask us to delete your personal information.
Your right to restriction of processing: To ask us to limit how we use your data.
Your right to object to processing: To object to the processing of your data.
Your right to data portability: To ask that we transfer the information to another organisation or to you.
Your right to withdraw consent: To withdraw permission at any time.
HOW TO COMPLAIN
If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice. You can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AFHelpline number: 0303 123 1113
Website: www.ico.org.uk/make-a-complaint