Highrise Digital Ltd
Privacy Policy
Last updated: 4 August 2026
This Privacy Policy explains how Highrise Digital Ltd collects, uses, shares and protects Personal Data when acting as a Controller.
Highrise Digital Ltd is registered in England and Wales under company number 09989726. Our registered-office and other corporate details are available on our Company Information page.
In this policy, Highrise Digital Ltd is referred to as “Highrise Digital”, “we”, “us” or “our”.
Who this policy applies to
We operate a web development agency that provides services including WordPress development, consultancy, website hosting, maintenance and support. We also provide products and services under our RecPress trading name.
This policy applies to Personal Data we collect about people who:
- visit highrise.digital, recpress.com or another website operated by Highrise Digital;
- contact us about our products or services;
- are customers, prospective customers or representatives of customers;
- purchase or use one of our products;
- receive marketing communications from us;
- work with us as a supplier, contractor or business contact; or
- otherwise interact with Highrise Digital in a business capacity.
In this policy, our websites, development work, consultancy, products, hosting, maintenance and support are collectively referred to as the “Services”.
When we act as a Processor
When we host, maintain, migrate or work on a customer’s website or system, we may process Personal Data on that customer’s behalf. In those circumstances, the customer is normally the Controller and Highrise Digital acts as its Processor.
That processing is governed by our Data Processing Agreement and the Customer’s instructions. Questions about Personal Data controlled by one of our customers should normally be directed to that customer.
This Privacy Policy principally covers processing for which Highrise Digital decides why and how Personal Data is used and therefore acts as the Controller.
Personal Data we collect
We collect Personal Data only where we have a reason to do so, such as providing a Service, responding to an enquiry, meeting a legal obligation, protecting our systems or improving our business.
Information you provide to us
The Personal Data you provide depends on how you interact with us and may include:
- Enquiry information – your name, email address, telephone number, organisation and the information included in an enquiry or contact form.
- Customer and business contact information – your name, job title, organisation, postal address, email address, telephone number and relevant company information.
- Project information – communications, instructions, specifications, feedback, files and other information needed to deliver a project or provide support.
- Account information – your name, contact details, username, product licences, account preferences and purchase history.
- Billing and transaction information – billing address, organisation details, VAT information, invoice records and information about payments and purchases.
- Payment information – information needed to process a payment. Full payment-card details are collected and processed by our payment provider and are not stored directly by Highrise Digital.
- Access credentials – website, hosting, server, WordPress, SFTP, SSH or other credentials you provide so that we can perform agreed work.
- Website and system copies – files, databases or backups supplied to us for migration, development, testing or troubleshooting.
- Marketing information – your name, email address, communication preferences and information about your interaction with our communications.
- Correspondence – emails, support requests, meeting notes and other communications between you and Highrise Digital.
Please do not provide special-category, criminal-offence or other highly sensitive Personal Data unless it is necessary for the relevant Service and you are authorised to provide it.
Information collected automatically
When you use our websites or online Services, we may automatically collect:
- Technical information – your IP address, approximate location, browser type, operating system, device type and language.
- Log information – the date and time of access, pages or resources requested, error information and other security or diagnostic records.
- Website statistics – aggregated information about visits, pages viewed and how visitors arrive at our websites. We use Fathom Analytics, which does not use cookies or create persistent profiles of individual visitors.
- Cookie and similar-technology information – information used for secure payments, authentication, fraud prevention and protecting forms against spam or automated abuse.
More information is available in our Cookie Policy.
Information obtained from other sources
We may receive Personal Data from:
- your employer, colleague or another representative of your organisation;
- a customer who asks us to communicate or work with you;
- referral partners and professional contacts;
- payment, accounting, fraud-prevention and identity-verification providers;
- public sources, including business websites, professional profiles and Companies House; and
- service providers that help us operate and secure our Services.
How and why we use Personal Data
UK data protection law requires us to have a lawful basis for each purpose for which we process Personal Data.
Responding to enquiries and preparing proposals
We use contact and enquiry information to respond to questions, discuss potential work and prepare proposals or quotations.
Our lawful basis is taking steps at your request before entering into a contract or our legitimate interest in responding to business enquiries and developing our business.
Providing products and Services
We use customer, project, account, credential and communication information to:
- deliver agreed work;
- manage projects and customer relationships;
- provide products, accounts and licences;
- provide hosting, maintenance and support;
- communicate about the Services; and
- handle renewals, changes and termination.
Our lawful basis is performing our contract with you. Where the customer is an organisation rather than an individual, we rely on our legitimate interests in performing the contract and communicating with the customer’s personnel and representatives.
Billing, payments and financial records
We use customer, transaction and billing information to process payments, issue invoices, manage our accounts, recover debts and meet tax, accounting and company-law obligations.
Our lawful bases are performing our contract, complying with legal obligations and our legitimate interests in administering our business and recovering amounts owed to us.
Security, fraud prevention and service reliability
We use technical, log, account and transaction information to:
- protect our websites, systems, products and customers;
- authenticate users;
- detect and prevent fraud, spam and abuse;
- investigate errors, security events and complaints; and
- maintain the availability and reliability of our Services.
Our lawful bases are our legitimate interests in protecting our business, customers and systems and, where applicable, compliance with our legal security obligations.
Improving our Services
We use feedback, support information and aggregated website statistics to understand how our Services are used and to improve their usability, reliability and relevance.
Our lawful basis is our legitimate interest in understanding and improving our Services. We do not use this information to create behavioural advertising profiles.
Marketing communications
We may use your contact details to send information about relevant products, Services, updates or events.
We rely on consent where consent is required. In other circumstances, we may rely on our legitimate interests in promoting relevant Services to existing customers and business contacts where the law permits this.
You can opt out at any time by using the unsubscribe link in a marketing email or by contacting us. Opting out of marketing will not prevent us from sending necessary service, account, transaction or legal communications.
Portfolio and business promotion
We may identify customer organisations and display examples of completed work in our portfolio where this is permitted by our agreement with the customer or separately agreed.
We will not intentionally publish confidential information or Personal Data about an identifiable individual as part of a case study or testimonial without an appropriate basis and, where necessary, permission.
Legal obligations and claims
We may use Personal Data to comply with law, respond to lawful requests from public authorities, enforce our agreements and establish, exercise or defend legal claims.
Our lawful bases are compliance with legal obligations and our legitimate interests in protecting our legal rights and business.
When we share Personal Data
We do not sell Personal Data.
We may share Personal Data with the following recipients where reasonably necessary:
- Personnel and contractors who need the information to provide the Services and who are subject to appropriate confidentiality obligations.
- Hosting and infrastructure providers used to operate websites, applications, staging environments, databases and backups.
- Cloud storage and document providers used to store project files and business records.
- Email and communication providers used to send, receive and store business communications.
- Project-management and support providers used to organise work, communicate with customers and manage support requests.
- Accounting, time-recording and invoicing providers used to administer projects, transactions and financial records.
- Payment and fraud-prevention providers, including Stripe, where required to process and secure payments.
- Analytics providers, including Fathom Analytics, used to provide aggregated website statistics.
- Professional advisers, including accountants, solicitors, insurers and consultants.
- Public authorities, regulators, courts and law-enforcement bodies where disclosure is required or permitted by law.
- Potential purchasers, investors or advisers involved in a proposed merger, restructuring, investment or sale of all or part of our business, subject to appropriate confidentiality safeguards.
Where a recipient processes Personal Data on our behalf, we require it to provide appropriate contractual, organisational and technical protections.
International transfers
Some of our service providers may process Personal Data outside the United Kingdom.
Where a transfer is restricted under applicable Data Protection Laws, we will ensure that it is protected by an appropriate legal mechanism. This may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- applicable EU Standard Contractual Clauses; or
- another safeguard or exception recognised by applicable law.
Where required, we will undertake a transfer risk assessment or other applicable data protection test and implement additional safeguards.
You may contact us for further information about the safeguards used for a particular transfer.
How long we keep Personal Data
We keep Personal Data only for as long as reasonably necessary for the purpose for which it was collected, including satisfying legal, accounting, security and reporting requirements.
Our normal retention periods and criteria include:
- Unsuccessful enquiries – normally up to one year after our last substantive communication.
- Customer and project records – for the duration of the customer relationship and normally up to seven years afterwards where required for contractual, legal or record-keeping purposes.
- Invoices and transaction records – normally seven years to support tax, accounting and company record-keeping obligations.
- Account and product information – while the account, product or licence remains active and afterwards where necessary to maintain transaction, licensing or support records.
- Marketing information – until you withdraw consent, object or unsubscribe, or until we determine that the information is no longer needed. We may retain a minimal suppression record so that we can respect an opt-out.
- Credentials – only while reasonably necessary to perform the relevant work or provide continuing support, after which they will be deleted or access will be removed where practicable.
- Development, migration and website copies – for the period required to perform the work and according to the deletion terms in the applicable Service Agreement or Data Processing Agreement.
- Technical and security logs – for a period proportionate to their operational and security purpose, or longer where required to investigate an incident.
- Legal disputes – for as long as reasonably necessary to establish, exercise or defend legal claims.
We may retain information for longer where required by law, a regulator, a court, an insurer or an active legal claim. We may also anonymise information so that it can no longer be associated with an identifiable person.
Security
We use appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the nature of the information and Service, these measures may include:
- access controls based on role and business need;
- unique credentials and secure credential-management tools;
- multi-factor authentication where supported and appropriate;
- encryption in transit and at rest where appropriate;
- device encryption and automatic screen locking;
- software maintenance and risk-based security updates;
- backups and restoration arrangements;
- confidentiality obligations for personnel and contractors;
- security and data protection guidance; and
- procedures for identifying, investigating and responding to security incidents.
No method of transmission or storage can be guaranteed to be completely secure. We review our measures in response to changes in technology, risk and the Services.
Personal Data Breaches
If a Personal Data Breach occurs, we will take reasonable steps to contain and investigate it, assess the risks to affected people, mitigate potential harm and record the incident.
Where legally required, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where a breach is likely to result in a high risk to an affected person’s rights and freedoms, we will also inform that person without undue delay unless an applicable legal exception applies.
Your data protection rights
Depending on the circumstances, you may have the right to:
- Access the Personal Data we hold about you and receive information about how it is used.
- Rectify inaccurate or incomplete Personal Data.
- Erase your Personal Data where there is no lawful reason for us to continue using it.
- Restrict how we use your Personal Data in certain circumstances.
- Object to processing based on legitimate interests and to direct marketing.
- Receive or transfer certain Personal Data in a structured, commonly used and machine-readable format.
- Withdraw consent at any time where we rely on consent. Withdrawal does not affect processing already carried out lawfully.
- Complain about how we have handled your Personal Data.
These rights are subject to legal conditions and exceptions. For example, we may need to retain information to comply with law, perform a contract or establish or defend legal claims.
You can exercise your rights by completing our data request form or by emailing support@highrise.digital.
We may ask for information needed to confirm your identity and understand your request. We will respond within the period required by applicable Data Protection Laws.
Data protection complaints
If you are concerned about how we have handled your Personal Data, you can make a complaint by emailing support@highrise.digital, using our contact form or writing to our registered office shown on our Company Information page.
We will acknowledge a data protection complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office. Information about making a complaint is available on the ICO website.
Automated decision-making
We do not use Personal Data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Children’s information
Our websites and Services are primarily intended for businesses and are not directed at children. We do not knowingly collect Personal Data directly from children through our own websites except where necessary and lawful.
We may process information about children on behalf of a customer where it is contained in a customer-controlled website or system. In those circumstances, the customer is normally responsible for determining the lawful basis and providing appropriate privacy information.
Information required to provide the Services
Some Personal Data is required so that we can enter into or perform a contract, process a payment, meet a legal obligation or provide a requested Service.
If required information is not provided, we may be unable to respond to an enquiry, enter into a contract, process a transaction or continue providing the relevant Service. We will explain where providing particular information is mandatory.
Changes to this policy
We may update this Privacy Policy when our Services, processing activities or legal obligations change. The latest version will be published on our website with its revision date shown above.
If a change materially affects how we use Personal Data, we will take reasonable steps to bring it to the attention of affected people where required.
How to contact us
Highrise Digital Ltd is the Controller responsible for the processing described in this policy.
Our registered-office and corporate details are available on our Company Information page.
Email: support@highrise.digital
You can also contact us using our contact form.