Privacy policy
Joro Services Ltd (company number 14079588) is the data controller for personal data collected through this website and in the course of our services. Contact: info@joroservices.org. Last updated: 25 July 2026.
What we collect and why
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Enquiry details (name, email, phone, business, message) | Answering your enquiry and preparing quotes | Legitimate interests / steps towards a contract | 24 months from last contact, then deleted |
| Booking details | Scheduling calls you request | Steps towards a contract | 24 months from last contact |
| Payment records | Taking payments and accounting | Contract and legal obligation | 6 years (HMRC requirement) |
| Client project data | Delivering contracted services | Contract | Duration of engagement plus agreed handover period |
Who we share data with
Only processors needed to run the service, under contract: our hosting provider (Vercel), our email delivery provider (Resend) for enquiry notifications and acknowledgements, and Stripe for payments. Your card details go to Stripe directly and never touch our systems. We do not sell personal data, and we do not share it for third-party marketing.
Analytics and cookies
This site is designed to run without advertising trackers and without setting non-essential cookies, which is why you do not see a consent banner. The details, including what would change if that ever changed, are in the cookie policy.
International transfers
Our processors may store data outside the UK; where they do, transfers rely on UK-recognised safeguards such as adequacy decisions or the UK International Data Transfer Agreement.
Your rights
Under UK GDPR you can request access to, correction of, or deletion of your personal data; object to or restrict processing; and request portability. Email info@joroservices.org and we respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk).
Security
Data is encrypted in transit, access is restricted and logged, and our own practice follows the same standards we sell: MFA everywhere, least-privilege access, and tested backups.