Privacy policy

Last updated 7 October 2026

This policy explains what personal information Courageous Design collects, why, and what your rights are. It is written to meet UK data protection law: the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations (PECR).

Who I am

Courageous Design is run by Stephen Edwards, a sole trader based in Central Scotland. For the information described here I am the data controller. I have applied to register with the Information Commissioner's Office (ICO); my registration reference is C2053669. You can contact me at info@courageousdesign.co.uk or on 07910 483 378.

Visiting this website

This website sets no cookies and uses no analytics, tracking or advertising tools. Fonts and images are served from this site, so your browser does not contact any other company when you visit. Like all websites, the server keeps short-lived technical logs (such as IP address and pages requested) to keep the site secure; these are deleted after 30 days.

When you contact me

If you email or phone me, I receive your name, contact details and whatever you choose to tell me. I use it only to reply and, if we work together, to provide the service. The lawful basis is legitimate interests (answering your enquiry) or taking steps towards a contract. I keep enquiries that don't lead to work for 12 months, then delete them. I never add you to a mailing list or pass your details on for marketing.

Clients and the client portal

If your organisation is a client, I hold contact details for the people I work with, account details for anyone given a client portal login (name, email address and a securely hashed password), invoices and support requests. The lawful basis is the contract with your organisation, and legal obligation for financial records, which I keep for six years as HMRC requires. Portal accounts are removed when the client relationship ends.

The client portal uses one strictly necessary cookie to keep you signed in. Under PECR this does not need consent, and it is deleted when you sign out or close your browser.

Websites I host for clients

When I build or host a website for a client, any personal data collected through that website belongs to the client, who is the data controller. I act as their data processor, under a written data processing agreement, and only handle that data on their instructions. Questions about those websites should go to the organisation that runs them.

Who else handles your data

I use FastComet for web hosting and maintenance services. If any personal data is processed outside the UK, the transfer is protected by UK adequacy regulations or the ICO's approved contract terms. I will never sell your data.

Keeping it safe

Data is encrypted in transit, logins are protected against guessing, passwords are never stored in readable form, and files are kept outside the public web space. Backups are encrypted and restores are tested.

Your rights

You can ask for a copy of the personal information I hold about you, ask me to correct or delete it, object to or restrict how I use it, or ask for it in a portable format. There is no charge, and I will reply within one month. Just email me.

Complaints

If you are unhappy with how I have handled your information, please tell me first. I will acknowledge your complaint within 30 days and put it right where I can. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

Changes

If this policy changes, the new version will be posted here with a new date.