Highrise Digital Ltd

Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how Highrise Digital Ltd collects, uses, shares and protects Personal Data when acting as a Controller.

Highrise Digital Ltd is registered in England and Wales under company number 09989726. Our registered-office and other corporate details are available on our Company Information page.

In this policy, Highrise Digital Ltd is referred to as “Highrise Digital”, “we”, “us” or “our”.

Who this policy applies to

We operate a web development agency that provides services including WordPress development, consultancy, website hosting, maintenance and support. We also provide products and services under our RecPress trading name.

This policy applies to Personal Data we collect about people who:

In this policy, our websites, development work, consultancy, products, hosting, maintenance and support are collectively referred to as the “Services”.

When we act as a Processor

When we host, maintain, migrate or work on a customer’s website or system, we may process Personal Data on that customer’s behalf. In those circumstances, the customer is normally the Controller and Highrise Digital acts as its Processor.

That processing is governed by our Data Processing Agreement and the Customer’s instructions. Questions about Personal Data controlled by one of our customers should normally be directed to that customer.

This Privacy Policy principally covers processing for which Highrise Digital decides why and how Personal Data is used and therefore acts as the Controller.

Personal Data we collect

We collect Personal Data only where we have a reason to do so, such as providing a Service, responding to an enquiry, meeting a legal obligation, protecting our systems or improving our business.

Information you provide to us

The Personal Data you provide depends on how you interact with us and may include:

Please do not provide special-category, criminal-offence or other highly sensitive Personal Data unless it is necessary for the relevant Service and you are authorised to provide it.

Information collected automatically

When you use our websites or online Services, we may automatically collect:

More information is available in our Cookie Policy.

Information obtained from other sources

We may receive Personal Data from:

How and why we use Personal Data

UK data protection law requires us to have a lawful basis for each purpose for which we process Personal Data.

Responding to enquiries and preparing proposals

We use contact and enquiry information to respond to questions, discuss potential work and prepare proposals or quotations.

Our lawful basis is taking steps at your request before entering into a contract or our legitimate interest in responding to business enquiries and developing our business.

Providing products and Services

We use customer, project, account, credential and communication information to:

Our lawful basis is performing our contract with you. Where the customer is an organisation rather than an individual, we rely on our legitimate interests in performing the contract and communicating with the customer’s personnel and representatives.

Billing, payments and financial records

We use customer, transaction and billing information to process payments, issue invoices, manage our accounts, recover debts and meet tax, accounting and company-law obligations.

Our lawful bases are performing our contract, complying with legal obligations and our legitimate interests in administering our business and recovering amounts owed to us.

Security, fraud prevention and service reliability

We use technical, log, account and transaction information to:

Our lawful bases are our legitimate interests in protecting our business, customers and systems and, where applicable, compliance with our legal security obligations.

Improving our Services

We use feedback, support information and aggregated website statistics to understand how our Services are used and to improve their usability, reliability and relevance.

Our lawful basis is our legitimate interest in understanding and improving our Services. We do not use this information to create behavioural advertising profiles.

Marketing communications

We may use your contact details to send information about relevant products, Services, updates or events.

We rely on consent where consent is required. In other circumstances, we may rely on our legitimate interests in promoting relevant Services to existing customers and business contacts where the law permits this.

You can opt out at any time by using the unsubscribe link in a marketing email or by contacting us. Opting out of marketing will not prevent us from sending necessary service, account, transaction or legal communications.

Portfolio and business promotion

We may identify customer organisations and display examples of completed work in our portfolio where this is permitted by our agreement with the customer or separately agreed.

We will not intentionally publish confidential information or Personal Data about an identifiable individual as part of a case study or testimonial without an appropriate basis and, where necessary, permission.

Legal obligations and claims

We may use Personal Data to comply with law, respond to lawful requests from public authorities, enforce our agreements and establish, exercise or defend legal claims.

Our lawful bases are compliance with legal obligations and our legitimate interests in protecting our legal rights and business.

When we share Personal Data

We do not sell Personal Data.

We may share Personal Data with the following recipients where reasonably necessary:

Where a recipient processes Personal Data on our behalf, we require it to provide appropriate contractual, organisational and technical protections.

International transfers

Some of our service providers may process Personal Data outside the United Kingdom.

Where a transfer is restricted under applicable Data Protection Laws, we will ensure that it is protected by an appropriate legal mechanism. This may include:

Where required, we will undertake a transfer risk assessment or other applicable data protection test and implement additional safeguards.

You may contact us for further information about the safeguards used for a particular transfer.

How long we keep Personal Data

We keep Personal Data only for as long as reasonably necessary for the purpose for which it was collected, including satisfying legal, accounting, security and reporting requirements.

Our normal retention periods and criteria include:

We may retain information for longer where required by law, a regulator, a court, an insurer or an active legal claim. We may also anonymise information so that it can no longer be associated with an identifiable person.

Security

We use appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the nature of the information and Service, these measures may include:

No method of transmission or storage can be guaranteed to be completely secure. We review our measures in response to changes in technology, risk and the Services.

Personal Data Breaches

If a Personal Data Breach occurs, we will take reasonable steps to contain and investigate it, assess the risks to affected people, mitigate potential harm and record the incident.

Where legally required, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Where a breach is likely to result in a high risk to an affected person’s rights and freedoms, we will also inform that person without undue delay unless an applicable legal exception applies.

Your data protection rights

Depending on the circumstances, you may have the right to:

These rights are subject to legal conditions and exceptions. For example, we may need to retain information to comply with law, perform a contract or establish or defend legal claims.

You can exercise your rights by completing our data request form or by emailing support@highrise.digital.

We may ask for information needed to confirm your identity and understand your request. We will respond within the period required by applicable Data Protection Laws.

Data protection complaints

If you are concerned about how we have handled your Personal Data, you can make a complaint by emailing support@highrise.digital, using our contact form or writing to our registered office shown on our Company Information page.

We will acknowledge a data protection complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office. Information about making a complaint is available on the ICO website.

Automated decision-making

We do not use Personal Data to make solely automated decisions that produce legal or similarly significant effects on individuals.

Children’s information

Our websites and Services are primarily intended for businesses and are not directed at children. We do not knowingly collect Personal Data directly from children through our own websites except where necessary and lawful.

We may process information about children on behalf of a customer where it is contained in a customer-controlled website or system. In those circumstances, the customer is normally responsible for determining the lawful basis and providing appropriate privacy information.

Information required to provide the Services

Some Personal Data is required so that we can enter into or perform a contract, process a payment, meet a legal obligation or provide a requested Service.

If required information is not provided, we may be unable to respond to an enquiry, enter into a contract, process a transaction or continue providing the relevant Service. We will explain where providing particular information is mandatory.

Changes to this policy

We may update this Privacy Policy when our Services, processing activities or legal obligations change. The latest version will be published on our website with its revision date shown above.

If a change materially affects how we use Personal Data, we will take reasonable steps to bring it to the attention of affected people where required.

How to contact us

Highrise Digital Ltd is the Controller responsible for the processing described in this policy.

Our registered-office and corporate details are available on our Company Information page.

Email: support@highrise.digital

You can also contact us using our contact form.