Legal

Privacy Policy

Last updated: 15 August 2026

1. Who we are

This policy explains how Jacombs Enterprises Ltd (“Jacombs”, “we”, “us”, “our”) collects, uses and protects your personal data, and the rights you have over it. We are the data controller for the personal data described here.

  • Company: Jacombs Enterprises Ltd, registered in England & Wales, company number 12571887.
  • Registered office: One Mayfair Place, London, W1J 8AJ.
  • Contact: team@jacombsenterprises.com.

We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information we collect

We collect only what we need to run our studio and serve our clients. Depending on how you interact with us, this may include:

  • Contact details you give us — your name, email, company and the content of your enquiry when you complete our contact form or email us.
  • Client and project information — details about your organisation, its people and its data needed to deliver a brand, website or AI engagement, agreed in each contract.
  • Correspondence — records of our communications with you.
  • Technical and usage data — limited information about how you use our website, such as pages visited and general device information, via standard analytics where enabled.

Where we process personal data on behalf of a client as part of a project, that client is usually the controller and we act as a processor under our engagement terms.

3. How and why we use it

We use personal data to:

  • respond to your enquiries and provide the information you ask for;
  • deliver, manage and improve our brand, web and AI services;
  • manage our relationship with clients and suppliers, including administration and billing;
  • keep our own records and meet legal and regulatory obligations;
  • maintain the security and performance of our website and systems;
  • send occasional updates about our work where you have asked to receive them.

4. Our lawful bases

We rely on one or more of the following lawful bases under UK GDPR:

  • Consent — e.g. where you opt in to receive updates. You can withdraw it at any time.
  • Contract — where processing is necessary to enter into or perform a contract with you or your organisation.
  • Legitimate interests — to respond to enquiries, run and grow our studio and keep our systems secure, balanced against your rights.
  • Legal obligation — where we must process data to comply with the law.

5. Who we share it with

We do not sell your personal data. We share it only where necessary:

  • with trusted service providers who help us operate — hosting, email, analytics, design and productivity tools — under contracts that require them to protect your data;
  • with professional advisers such as accountants and lawyers where needed;
  • with authorities or regulators where legally required; and
  • in connection with a business reorganisation or transfer, subject to appropriate safeguards.

6. AI tools and processors

Because our work involves artificial intelligence, we may use third-party AI platforms and model providers to deliver services. Where personal data is involved, we choose providers with appropriate security and data-protection commitments, put processing agreements in place, and configure tools so client data is not used to train third-party models unless expressly agreed. The specific tools used on any engagement are set out with the client in advance.

7. International transfers

Some providers are based outside the UK. Where personal data is transferred internationally, we ensure it is protected by an appropriate safeguard recognised under UK data-protection law — such as UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses).

8. How long we keep it

We keep personal data only as long as we need it for the purposes above, or as required by law. Enquiry correspondence is typically retained for up to 24 months; client and financial records for the periods required by law (generally at least six years for financial records). When data is no longer needed, we securely delete or anonymise it.

9. Your rights

Under UK GDPR you have the right to be informed; to access your data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to certain processing; to data portability where applicable; and to withdraw consent at any time where we rely on it.

To exercise any of these, email team@jacombsenterprises.com. We will respond within one month.

10. Cookies

Our website uses only the cookies necessary to make it work and, where enabled, privacy-friendly analytics to understand how the site is used. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; blocking some may affect how the site functions.

11. Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access — including access controls, encryption in transit, and supplier due diligence. No system is perfectly secure, but we work hard to keep your data safe and to respond quickly if anything goes wrong.

12. Children

Our website and services are intended for businesses and adults. We do not knowingly collect personal data from children under 13. If you believe we have, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. The latest version will always be on this page, with the “last updated” date at the top. Material changes will be highlighted where appropriate.

14. Contact & complaints

Questions or requests about your data? Email team@jacombsenterprises.com or write to Jacombs Enterprises Ltd, One Mayfair Place, London, W1J 8AJ.

If you are unhappy with how we have handled your data, you can complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk. We’d appreciate the chance to put things right first, so please do contact us.