Privacy policy

Joro Services Ltd (company number 14079588) is the data controller for personal data collected through this website and in the course of our services. Contact: info@joroservices.org. Last updated: 25 July 2026.

What we collect and why

Processing summary
DataPurposeLawful basisRetention
Enquiry details (name, email, phone, business, message) Answering your enquiry and preparing quotes Legitimate interests / steps towards a contract 24 months from last contact, then deleted
Booking details Scheduling calls you request Steps towards a contract 24 months from last contact
Payment records Taking payments and accounting Contract and legal obligation 6 years (HMRC requirement)
Client project data Delivering contracted services Contract Duration of engagement plus agreed handover period

Who we share data with

Only processors needed to run the service, under contract: our hosting provider (Vercel), our email delivery provider (Resend) for enquiry notifications and acknowledgements, and Stripe for payments. Your card details go to Stripe directly and never touch our systems. We do not sell personal data, and we do not share it for third-party marketing.

Analytics and cookies

This site is designed to run without advertising trackers and without setting non-essential cookies, which is why you do not see a consent banner. The details, including what would change if that ever changed, are in the cookie policy.

International transfers

Our processors may store data outside the UK; where they do, transfers rely on UK-recognised safeguards such as adequacy decisions or the UK International Data Transfer Agreement.

Your rights

Under UK GDPR you can request access to, correction of, or deletion of your personal data; object to or restrict processing; and request portability. Email info@joroservices.org and we respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk).

Security

Data is encrypted in transit, access is restricted and logged, and our own practice follows the same standards we sell: MFA everywhere, least-privilege access, and tested backups.