Company: X7X
Effective Date: September 01, 2025
1. Introduction
X7X (“we,” “us,” or “X7X”), a sole trader entity duly registered and operating under the laws of the United Kingdom, is unwaveringly committed to protecting the privacy and security of personal data. This Privacy Policy (“the Policy”) delineates, with exhaustive detail, the principles, procedures, and legal frameworks governing the collection, storage, processing, sharing, protection, and erasure of personal data in connection with our provision of digital services. These services encompass website development (including extensive use of the WordPress platform), application development, custom software solutions, search engine optimisation (SEO), web hosting, virtual private servers (VPS), dedicated server management, and ancillary digital services.
This Policy is meticulously crafted to ensure full compliance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) 2003, and, where applicable, the European Union General Data Protection Regulation (EU GDPR) for cross-border processing activities. It is designed to provide maximum transparency to all stakeholders, including but not limited to website visitors, current and prospective clients, contractors, freelancers, suppliers, job applicants, employees, and marketing subscribers. The document is structured to withstand rigorous regulatory scrutiny, legal audits, and to serve as a definitive resource for understanding our data protection practices.
X7X unequivocally declares that it does not sell, rent, lease, or otherwise monetise personal data for commercial gain. Personal data is processed solely for the purposes of fulfilling contractual obligations, delivering high-quality services, ensuring compliance with legal obligations, and maintaining robust security measures. This commitment underscores our dedication to ethical data handling and client trust.
The Policy is comprehensive, addressing all facets of our operations, including the use of third-party platforms such as WordPress, payment processors, hosting providers, and analytics tools. It is intended to be accessible to individuals regardless of their familiarity with legal or technical terminology, with each section accompanied by detailed explanations and practical examples to elucidate its application. Where WordPress is used, specific considerations (e.g., plugins, themes, or user accounts) are addressed to ensure clarity.
This Policy was last updated on September 12, 2025, and is subject to periodic review to reflect changes in legal requirements or our operational practices. Significant updates will be communicated via our website and, where appropriate, directly to affected data subjects.
2. Definitions
To ensure precision and clarity, the following terms, as defined under Article 4 of the UK GDPR, are used throughout this Policy:
- Personal Data: Any information relating to an identified or identifiable natural person (“data subject”), including but not limited to names, email addresses, telephone numbers, postal addresses, IP addresses, payment details, or other identifiers that, alone or in combination, can identify an individual.
- Special Category Data: Personal data revealing racial or ethnic origins, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health, or data concerning a person’s sex life or sexual orientation, which is subject to heightened safeguards under UK GDPR Article 9.
- Processing: Any operation or set of operations performed on personal data, whether by automated or manual means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, or erasure.
- Data Subject: A natural person whose personal data is processed by X7X.
- Controller: X7X, as the entity determining the purposes and means of processing personal data.
- Processor: A third-party entity processing personal data on behalf of X7X under strict contractual obligations compliant with UK GDPR.
- Data Breach: A security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
- Consent: A freely given, specific, informed, and unambiguous indication of the data subject’s agreement to the processing of their personal data, typically obtained through an affirmative action.
- Legitimate Interests: A lawful basis for processing where X7X’s interests are balanced against the data subject’s rights and freedoms, as assessed under UK GDPR Article 6(1)(f).
- Cookies: Small text files stored on a user’s device to facilitate website functionality, user preferences, analytics, or marketing purposes, as further detailed in Section 18 (Cookie Policy).
- WordPress-Specific Terms: References to plugins (add-on tools), themes (design templates), user accounts (logins for site management), or other functionalities associated with the WordPress content management system, which X7X utilises extensively for website development.
These definitions align with UK GDPR and are provided to ensure a consistent understanding throughout this Policy.
3. Scope of the Policy
This Policy governs the processing of personal data across all interactions with X7X’s services and operations. It applies to the following categories of individuals and activities:
- Website Visitors: Individuals accessing our primary website (e.g., www.x7x.co.uk), client-hosted websites managed by X7X, or any web-based interfaces developed or maintained by us, including WordPress-based sites.
- Current and Prospective Clients: Individuals or entities engaging with X7X for services such as website development, WordPress site management, application development, SEO, web hosting, VPS, or dedicated server administration.
- Contractors, Freelancers, and Suppliers: Third parties providing services or resources to X7X, such as graphic designers, developers, or hosting providers.
- Job Applicants and Employees: Individuals applying for roles with X7X or currently employed or contracted by us.
- Marketing Subscribers: Individuals who have provided explicit consent to receive promotional communications, such as newsletters or updates on services.
The Policy encompasses all mediums of interaction, including but not limited to:
- Website forms, chatbots, or plugins (e.g., WordPress contact forms, e-commerce plugins).
- Email correspondence, telephone communications, or video conferencing (e.g., Zoom for project consultations).
- Contracts, invoices, and payment processing systems.
- Software platforms developed or managed by X7X, including custom applications or WordPress dashboards.
- Analytics tools tracking website performance or user behaviour (e.g., Google Analytics integrated with WordPress).
- Hosting environments, VPS logs, and server access records.
For WordPress-based services, this Policy extends to data processed through plugins, themes, or user accounts created for site administration or visitor interactions. Where X7X acts as a processor (e.g., managing a client’s WordPress site), the client, as the controller, is responsible for their own privacy policy governing visitor data. X7X ensures compliance with processor obligations under UK GDPR Article 28.
Exclusions: This Policy does not cover personal data processed independently by clients on services we provide (e.g., customer data collected via a client’s WordPress e-commerce site). Such data is governed by the client’s privacy policy, though X7X can provide guidance on compliance best practices.
4. Categories of Personal Data Collected
X7X adheres to the UK GDPR principle of data minimisation, collecting only the personal data necessary for specified, explicit, and legitimate purposes. The following subcategories detail the types of data collected, the methods of collection, the purposes, the legal bases, and illustrative examples, with specific attention to WordPress-related processing.
4.1 Contact and Identification Data
Data Collected: Full name, job title, company name, email address, telephone number, postal address, billing details, client identifiers (e.g., account numbers), and WordPress user account details (e.g., usernames for site administration).
Method of Collection: Directly from data subjects via website forms, email submissions, contractual agreements, telephone inquiries, or in-person interactions; indirectly through WordPress user account creation or client-provided data for service delivery.
Purpose of Collection: To facilitate communication, manage client relationships, deliver contracted services, provide technical support, and ensure accurate invoicing. For WordPress sites, this includes creating and managing user accounts for site administration or content management.
Examples:
- A client submits a contact form on www.x7x.co.uk requesting a quote for a WordPress website; their name and email are recorded.
- A business provides billing details for a recurring VPS hosting plan.
- A WordPress site administrator is assigned a secure username for managing content updates.
Legal Basis: Processing is necessary for the performance of a contract (UK GDPR Article 6(1)(b)) or, in pre-contractual stages, based on legitimate interests (UK GDPR Article 6(1)(f)) to respond to inquiries and manage client relationships.
4.2 Payment Data
Data Collected: Payment method tokens (e.g., generated by third-party processors), bank account details for direct debits or wire transfers, transaction histories, VAT numbers, and billing addresses.
Method of Collection: Collected securely via third-party payment processors (e.g., Stripe, PayPal, or TakePayments) during invoicing or checkout processes.
Purpose of Collection: To process payments, issue refunds, maintain financial records, and comply with tax and accounting obligations under UK law.
Examples:
- Processing a credit card payment for a WordPress site maintenance package, with only a token stored by X7X.
- Recording a client’s VAT number for compliance with HMRC regulations.
- Issuing a refund for an overpayment on SEO services.
Legal Basis: Processing is necessary for the performance of a contract (UK GDPR Article 6(1)(b)) and to comply with legal obligations (UK GDPR Article 6(1)(c)), such as tax reporting under the Data Protection Act 2018.
4.3 Technical and Usage Data
Data Collected: IP addresses, browser types and versions, device information (e.g., mobile or desktop), operating systems, referral sources, server logs, cookies, session identifiers, analytics identifiers (e.g., from Google Analytics or WordPress plugins), page views, clickstreams, and error reports.
Method of Collection: Automatically collected via website servers, WordPress plugins (e.g., Jetpack, Yoast SEO), hosting management tools, or analytics platforms.
Purpose of Collection: To monitor and optimise service performance, troubleshoot technical issues, enhance user experience, detect and prevent security threats, and ensure system integrity. For WordPress sites, this includes monitoring plugin performance or visitor interactions.
Examples:
- Logging an IP address to investigate a security incident on a VPS server.
- Using WordPress analytics to identify high-traffic pages for SEO optimisation.
- Reviewing server logs to diagnose a WordPress plugin conflict.
Legal Basis: Legitimate interests (UK GDPR Article 6(1)(f)), balanced against data subjects’ rights through a documented Legitimate Interests Assessment (LIA).
4.4 Marketing Data
Data Collected: Email addresses, subscription preferences, interaction histories (e.g., email opens or clicks), and records of event participation.
Method of Collection: Collected via opt-in forms on our website, during client onboarding, or at events, with explicit consent.
Purpose of Collection: To deliver consented marketing communications, such as newsletters, promotional offers, or educational content related to our services, including WordPress tips or hosting updates.
Examples:
- Sending a newsletter with best practices for securing WordPress sites.
- Tracking email engagement to refine content for future campaigns.
- Inviting subscribers to a webinar on SEO strategies.
Legal Basis: Consent (UK GDPR Article 6(1)(a)), which data subjects may withdraw at any time.
4.5 Recruitment Data
Data Collected: Curriculum vitae (CVs), cover letters, application forms, interview notes, qualifications, professional certifications, work history, references, background check results (where applicable), and voluntary diversity monitoring information.
Method of Collection: Directly from applicants via email, recruitment platforms, or in-person submissions.
Purpose of Collection: To evaluate candidates, make informed hiring decisions, and comply with employment law requirements.
Examples:
- Reviewing a candidate’s CV for a WordPress developer position.
- Verifying references for an SEO specialist role.
- Collecting voluntary diversity data to monitor recruitment fairness.
Legal Basis: Processing is necessary for the performance of a contract or steps taken prior to entering a contract (UK GDPR Article 6(1)(b)); legitimate interests (UK GDPR Article 6(1)(f)) for screening processes.
4.6 Third-Party Data
Data Collected: Information provided by clients or third parties, such as login credentials for migrations, API keys, or data from integrated platforms (e.g., WordPress plugins connecting to external services like Mailchimp).
Method of Collection: Directly from clients or authorised third parties during project execution.
Purpose of Collection: To perform contracted services, such as website migrations, integrations, or custom development.
Examples:
- Receiving WordPress admin credentials to perform a site audit.
- Obtaining API keys to integrate a client’s WordPress site with an external CRM.
- Migrating hosting data using credentials from a previous provider.
Legal Basis: Processing is necessary for the performance of a contract (UK GDPR Article 6(1)(b)).
4.7 Special Category Data
Data Collected: In exceptional circumstances, data such as health information, biometric data, or other sensitive categories, only when required for specific client projects (e.g., a custom health application).
Method of Collection: Directly from data subjects or clients with explicit consent.
Purpose of Collection: To fulfill specific contractual requirements, with stringent safeguards in place.
Examples:
- Processing health data for a WordPress-based wellness app, with explicit client consent.
- Handling biometric data for a custom authentication module.
Legal Basis: Explicit consent (UK GDPR Article 9(2)(a)) or necessity for contractual performance with appropriate safeguards.
5. Purposes of Processing Personal Data
X7X processes personal data for the following specific, explicit, and legitimate purposes, each aligned with a lawful basis under UK GDPR:
- Service Delivery: To provide contracted services, including website development (e.g., WordPress site creation), application development, SEO, hosting, VPS, and server management. Example: Using client contact details to coordinate WordPress site updates.
- Client Communication: To respond to inquiries, provide project updates, and offer technical support. Example: Emailing a client about VPS downtime resolution.
- Payment Processing: To facilitate secure transactions, issue invoices, and manage financial records. Example: Processing a payment for a WordPress hosting plan via Stripe.
- Marketing Communications: To send consented promotional content, such as newsletters or event invitations. Example: Emailing subscribers about new WordPress security features.
- Legal Compliance: To meet obligations under tax, accounting, employment, or data protection laws. Example: Retaining transaction records for HMRC audits.
- Security and Fraud Prevention: To protect systems, detect unauthorised access, and prevent fraudulent activities. Example: Monitoring server logs for suspicious activity on a WordPress site.
- Service Improvement: To analyse usage data for optimising performance and enhancing user experience. Example: Using WordPress analytics to improve site navigation.
- Recruitment: To assess candidates and manage hiring processes. Example: Reviewing CVs for a WordPress developer role.
Each purpose is mapped to a legal basis, documented internally, and subject to regular review to ensure compliance with UK GDPR Article 5.
6. Lawful Bases for Processing
X7X processes personal data under the following lawful bases, as defined in UK GDPR Article 6:
- Contractual Necessity (Article 6(1)(b)): Processing required to perform a contract or take steps at the data subject’s request prior to entering a contract. Example: Collecting billing details for a WordPress site maintenance contract.
- Legal Obligation (Article 6(1)(c)): Processing necessary to comply with legal requirements, such as tax reporting or employment law. Example: Retaining financial records for HMRC compliance.
- Legitimate Interests (Article 6(1)(f)): Processing necessary for X7X’s legitimate interests, provided they do not override data subjects’ rights, as assessed via a Legitimate Interests Assessment. Example: Analysing server logs to enhance security.
- Consent (Article 6(1)(a)): Processing based on the data subject’s explicit, informed consent, revocable at any time. Example: Sending marketing emails to subscribers.
- Explicit Consent for Special Category Data (Article 9(2)(a)): Required for processing sensitive data, with additional safeguards. Example: Handling health data for a custom app.
Each processing activity is documented with its corresponding lawful basis in our internal Data Protection Register.
7. Sharing of Personal Data
X7X does not sell, rent, lease, or otherwise monetise personal data. Data sharing is strictly limited to the following scenarios, each governed by UK GDPR-compliant agreements:
- Third-Party Processors: Trusted service providers, such as payment processors (e.g., Stripe, PayPal), hosting providers, or analytics platforms (e.g., Google Analytics for WordPress sites), process data under strict Data Processing Agreements (DPAs) compliant with UK GDPR Article 28. Example: Sharing payment tokens with Stripe for transaction processing.
- Client-Designated Controllers: When acting as a processor, X7X shares data as instructed by clients (e.g., transferring WordPress site data during a migration).
- Legal Authorities: Data may be disclosed to comply with legal obligations, such as court orders or regulatory requests. Example: Providing financial records to HMRC during an audit.
- Business Transfers: In the event of a merger, acquisition, or sale, data may be shared with potential acquirers under strict confidentiality agreements. Example: Sharing client contract details during due diligence, with safeguards.
All third-party processors are vetted for compliance, and data sharing is minimised to the extent necessary.
8. Data Retention
X7X retains personal data only for as long as necessary to fulfill the purposes for which it was collected, in accordance with UK GDPR Article 5(1)(e). The table below outlines retention periods and justifications:
| Data Type | Retention Period | Justification |
|---|---|---|
| Financial Records | 6 years | Compliance with HMRC tax obligations |
| Contract/Project Data | Duration of contract + 6 years | Contractual and legal purposes |
| Recruitment Data | 6 months post-application | Fair recruitment; legal compliance |
| Marketing Data | Until consent is withdrawn | Respecting data subject’s preferences |
| Technical Logs | 30–180 days | Security and troubleshooting |
| Special Category Data | Project duration or as consented | Strict necessity and compliance |
Data is securely erased or anonymised upon expiration of the retention period, using industry-standard methods (e.g., secure deletion protocols).
9. Data Subject Rights
Under UK GDPR Chapter III, data subjects have the following rights, which X7X upholds rigorously:
- Right of Access: Obtain confirmation of processing and a copy of personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of data where no longer necessary or lawful to retain.
- Right to Restrict Processing: Limit processing under specific circumstances.
- Right to Data Portability: Receive data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Revoke consent at any time, without affecting prior processing.
- Right to Complain: Lodge a complaint with the Information Commissioner’s Office (ICO).
To exercise these rights, data subjects may contact X7X at [email protected]. Requests are verified for identity and processed within one month, extendable for complex cases per UK GDPR Article 12. No fees are charged unless requests are manifestly unfounded or excessive.
10. Security Measures
X7X implements robust technical and organisational measures to protect personal data, in accordance with UK GDPR Article 32:
- Access Controls: Role-based access to systems, ensuring only authorised personnel handle data.
- Encryption: Data encrypted in transit (e.g., TLS 1.3) and at rest (e.g., AES-256).
- Network Security: Firewalls, intrusion detection systems, and regular vulnerability scans.
- Secure Development: WordPress sites and custom software built with security best practices (e.g., OWASP guidelines).
- Backups and Recovery: Encrypted backups with disaster recovery plans tested annually.
- Staff Training: Regular data protection training and contractual confidentiality obligations.
- Audits: Annual security audits and penetration testing to identify vulnerabilities.
These measures ensure the confidentiality, integrity, and availability of personal data.
11. International Data Transfers
Where personal data is transferred outside the UK, X7X ensures compliance with UK GDPR Chapter V through:
- Adequacy Decisions: Transfers to countries with recognised adequate protection.
- International Data Transfer Agreement (IDTA): Standard contractual clauses for non-adequate jurisdictions.
- Client Instructions: Transfers authorised by clients for specific purposes (e.g., hosting on international servers).
Example: Transferring WordPress site data to a US-based hosting provider under an IDTA.
12. Data Breach Notification
In the event of a personal data breach, X7X follows a structured protocol compliant with UK GDPR Article 33:
- Containment and Assessment: Immediate action to mitigate the breach and assess its scope.
- Notification to ICO: Reporting to the Information Commissioner’s Office within 72 hours if the breach is likely to result in a risk to data subjects’ rights.
- Notification to Data Subjects: Informing affected individuals without undue delay if the breach poses a high risk.
- Documentation: Maintaining a breach register and implementing remediation measures.
Example: Notifying clients of a compromised WordPress site and coordinating password resets.
13. Third-Party Integrations
X7X utilises trusted third-party services to deliver its offerings, each vetted for UK GDPR compliance:
- Payment Processors: Stripe, PayPal, TakePayments for secure transactions.
- Hosting Providers: Providers for web hosting, VPS, and dedicated servers.
- Analytics Tools: Google Analytics, Jetpack for WordPress usage insights.
- WordPress Plugins: Tools like Yoast SEO, WooCommerce, or security plugins.
- Project Management: Platforms like GitHub or Trello for collaboration.
All integrations are governed by Data Processing Agreements, ensuring third parties meet UK GDPR standards.
14. Children’s Data
X7X’s services are not intended for individuals under 16 years of age. We do not knowingly collect or process personal data from children, in compliance with UK GDPR Article 8. If such data is inadvertently collected, it is promptly deleted upon discovery.
15. Policy Updates
This Policy is reviewed annually or upon significant changes in law or practice. Updates are published on our website (www.x7x.co.uk) and, where necessary, communicated directly to affected data subjects. A version history is maintained for audit purposes.
16. Contact Information
For inquiries, data subject rights requests, or complaints, contact:
- Email: [email protected]
- Website: www.x7x.co.uk
Data subjects may also contact the Information Commissioner’s Office (ICO) at www.ico.org.uk or via their helpline: 0303 123 1113.
17. Data Consumer Policy Statement
X7X reaffirms its commitment to ethical data handling. We do not sell, rent, lease, or otherwise monetise personal data for commercial purposes. Personal data is processed exclusively to:
- Fulfill contractual obligations (e.g., delivering WordPress sites or hosting services).
- Comply with legal requirements (e.g., tax reporting).
- Protect our systems and clients (e.g., security monitoring).
- Provide consented communications (e.g., newsletters).
Data is shared only with vetted third parties under strict contractual terms, and international transfers are safeguarded by appropriate mechanisms. This commitment is embedded in all our processes, ensuring trust and compliance.