Home · Privacy

Privacy policy

Last updated: January 2026

The short version: We only collect information you give us when you fill in our contact form or email us. We use it to respond to your enquiry and nothing else. We don't sell your data, we don't send unsolicited marketing, and we don't share it with third parties except where needed to run the business (like email hosting). You can ask us to delete your data at any time.

1. Who we are

OwlPoint is a UK-based business that helps small businesses remove operational bottlenecks by putting practical systems in place for calls, enquiries, bookings, invoices and follow-ups. We are the data controller for the personal information described in this policy.

Contact: hello@owlpoint.co.uk

2. What information we collect

We collect personal information only in the following situations:

How collectedWhat we collect
Contact form on our websiteName, business name, email address, phone number (optional), the part of the business taking too much time, and the message you write
Emailing us directlyYour email address and any personal information you include in the email
Phone or video callInformation you share verbally during a conversation
Becoming a clientBusiness details, billing information, and any information needed to deliver the agreed service

We do not use cookies for tracking or analytics. We do not run advertising on our website. We do not collect data about you passively.

3. Why we use your information

PurposeLegal basis (UK GDPR)
Responding to your enquiryLegitimate interests — you contacted us, so responding is a reasonable expectation
Delivering the service you've paid forPerformance of a contract
Sending invoices and managing paymentsPerformance of a contract; legal obligation
Keeping records as required by lawLegal obligation

We do not use your information for automated decision-making or profiling. We do not send marketing emails to people who have not specifically asked to hear from us.

4. Who we share your information with

We do not sell, rent, or trade your personal data. We may share it in the following limited circumstances:

  • Email service providers — your enquiry passes through standard email infrastructure (currently hosted email). These providers process data only as needed to deliver the email service.
  • Professional advisers — our accountant or legal advisers if required, under professional confidentiality obligations.
  • Legal requirements — if we are required to disclose information by law, court order, or to protect our legal rights.

All third parties we work with are required to handle your data securely and in compliance with UK data protection law.

5. How long we keep your information

Type of dataHow long we keep it
Enquiries that did not lead to work12 months from the date of your enquiry, then deleted
Client contact details and communications6 years from the end of our engagement (to comply with standard UK business record requirements)
Financial records (invoices etc.)6 years from the end of the tax year they relate to, as required by HMRC

6. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Access — you can ask us for a copy of the personal data we hold about you.
  • Correction — you can ask us to correct any inaccurate information.
  • Deletion — you can ask us to delete your data where we no longer have a legal basis to keep it.
  • Restriction — you can ask us to restrict how we use your data in certain circumstances.
  • Objection — you can object to us processing your data on the basis of legitimate interests.
  • Portability — where data is processed by automated means, you can request it in a commonly used format.

To exercise any of these rights, email us at hello@owlpoint.co.uk with the subject line "Data request". We will respond within one month.

If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk or call 0303 123 1113.

7. Data security

We take reasonable steps to protect your personal information from loss, misuse, and unauthorised access. These include using password-protected systems, limiting access to personal data to people who need it to do their job, and using reputable, UK-compliant email and storage providers.

If we become aware of a data breach that is likely to affect your rights or freedoms, we will notify the ICO within 72 hours and inform you directly where required by law.

8. International transfers

We aim to keep your data within the UK or the European Economic Area (EEA). If any of our service providers are based outside the UK/EEA, we will only use them where appropriate safeguards are in place (such as UK adequacy decisions or standard contractual clauses).

9. Children

Our services are directed at businesses and their representatives. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. When we do, we will update the "last updated" date at the top of the page. We encourage you to review this page periodically. For significant changes, we will notify active clients directly.

Questions about your data?

If you want to know what information we hold about you, ask us to delete it, or have any other questions about this policy — just get in touch.

Email us about privacy