Privacy policy
Last updated: 9 October 2026
This policy explains how Clume (“Clume”, “we”, “us”) collects and uses personal data when you visit clume.co.uk, get in touch, request a quote, book a call, or work with us as a client. We process personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
Clume is the trading name of Clume Ltd, a company registered in Scotland (company number SC903242), with its registered office at 19 Dundas Road, North Berwick, EH39 4EQ. For the personal data described here, Clume Ltd is the data controller. You can contact us about this policy or your data at hello@clume.co.uk.
What we collect
Information you give us
- Contact form: your name and email address, and, if you choose to give them, your company, phone number, the services you are interested in and your message.
- Quotes: if you use “Lock-in my quote”, the services you selected and the monthly total shown, alongside your contact details.
- Booking a call: if you book through our scheduling tool, the details you enter there (such as your name, email address and any notes) and the time you choose.
- Correspondence and calls: what you tell us by email, on calls or during an engagement.
- Clients: business contact details for the people we work with, billing details, and the information we need to deliver the work (see “When we act for our clients” below).
Information collected automatically
- Analytics and advertising measurement: only if you accept cookies, Google Analytics 4 and the Meta Pixel collect usage data such as the pages you view, the links you click, your device and browser, and your approximate location. When you submit the form with cookies accepted, we also send a hashed (scrambled) copy of your email address and, if given, your phone number and first name to Meta so it can measure our advertising. Nothing of this kind is collected or sent unless you have accepted. See our cookie policy.
- Campaign links: if you arrive from an advert or campaign link, we record its UTM parameters and the referring page with your enquiry, so we know which channels work.
- Technical data: our hosting provider processes your IP address and browser details to deliver the site and keep it secure, and we use them to limit form spam.
How and why we use it
We rely on these lawful bases under UK GDPR:
- Legitimate interests: to reply to your enquiry or quote, arrange and prepare for calls, follow up on a conversation you started, keep records of our business, keep the site secure and prevent spam, and improve our services. We balance these interests against your rights, and you can object at any time.
- Contract: where you engage us, or ask us to take steps before doing so (such as preparing a proposal), to provide and administer our services.
- Consent: for analytics and advertising cookies and the measurement data described above, and for any marketing emails you opt into. You can withdraw consent at any time.
- Legal obligation: to keep the records we must keep, such as for tax and accounting.
We do not sell your personal data, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
When we act for our clients
When we deliver work for a client, we may handle personal data that belongs to that client, such as data in its advertising, analytics or CRM accounts, or customer lists it asks us to use for advertising audiences. In that work we act as the client’s data processor: we use the data only on the client’s instructions and under our agreement with it, and the client’s own privacy policy explains how it uses that data. If you are a customer of one of our clients, please contact that business about your data.
How we use AI
We use AI tools to help our experts work faster, for example to analyse campaign data or draft copy for a human to review. A person directs and checks the work. Where personal data passes through an AI service, the provider processes it on our behalf under contract, and we use business services whose terms do not allow our inputs to be used to train their models. We do not use AI to make decisions about you.
Who we share it with
We share personal data only with organisations that help us run Clume, under contract and only for that purpose:
- Apopo AI Limited, a company under common ownership with Clume Ltd, which provides some of our operational systems (including the CRM where enquiries are stored) and processes personal data on our behalf.
- Notion: our CRM, where enquiries and client records are kept.
- Resend: sending the confirmation and notification emails when you get in touch.
- Vercel: website hosting and infrastructure.
- Calendly: scheduling, when you book a call.
- Our email provider: sending and receiving email.
- AI service providers: as described above.
- Google (Analytics) and Meta: analytics and advertising measurement, only where you have consented.
- Professional advisers such as our accountants and lawyers, and authorities where the law requires it.
International transfers
Some of these providers store or access data outside the UK, including in the United States. Where they do, we rely on UK adequacy regulations (including the UK–US data bridge where the provider is certified) or on appropriate safeguards such as the UK International Data Transfer Agreement or the UK addendum to the EU Standard Contractual Clauses.
How long we keep it
- Enquiries and quotes that do not lead to an engagement: up to 24 months from our last contact, so we have the context if you come back to us, unless you ask us to delete them sooner.
- Client records: for the length of the engagement and then up to six years, to meet our legal and accounting obligations and to deal with any claims.
- Data we process for clients: deleted or returned when the engagement ends, as our agreement with the client sets out.
- Analytics data: according to the provider’s retention settings (for Google Analytics, 14 months).
Keeping it secure
We protect personal data with access controls, multi-factor authentication on our business accounts, encryption in transit, and by giving access only to the people and providers who need it.
Your rights
Under UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing, including any direct marketing;
- data portability; and
- withdraw your consent at any time, without affecting processing before you withdrew it.
To exercise any of these, email hello@clume.co.uk. We will respond within one month. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we would appreciate the chance to put things right first.
Marketing
If you get in touch, we will reply about your enquiry. We will only send you marketing emails if you are a client and the emails are about similar services, or if you have opted in. Every marketing email includes a way to unsubscribe.
Children
Our services are for businesses. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
We may update this policy from time to time. The “last updated” date above shows when it last changed, and the version published here is the one in force.