Privacy

How we handle personal information, and the difference between the two roles we play.

Last updated 18 August 2026

Who we are

The Keep is a trading name of Brave New Studio Ltd, registered in England, company number 15236743, registered office 6 Roads Place, London N19 4TA. We are registered with the Information Commissioner’s Office, registration number ZB829531.

For anything about this policy or your data, email enquiries@thekeepwebsites.co.uk.

Two different roles

When you contact us or use this website, we are the data controller. This policy covers that.

When we build and look after a website for your church, your PCC or parish is the data controller and we act as your data processor. That relationship is governed by the data processing agreement we sign with you before work starts, not by this page.

What we collect

Our hosting provider keeps standard server logs, which include IP addresses, for security and to keep the site running. We do not read them unless something has gone wrong.

If you fill in the contact form, that is handled by Formspree, who pass it to us by email. They act on our instructions and do not use it for anything else. If you book a call, that is handled by Cal.com, who need your name and email to send you the invitation.

Why we hold it, and on what basis

We use enquiry details to reply to you and to quote for work. Our lawful basis is legitimate interests, specifically responding to someone who has contacted us about our services.

We use client details to deliver the service, to invoice, and to keep the records the law requires us to keep. Our lawful basis is performance of a contract, and legal obligation for accounting records.

We do not sell your data, we do not share it for advertising, and we do not use it to train anything.

Special category data

Information that reveals religious belief is special category data under UK GDPR, and a church website touches it more often than people expect. We design on that assumption: we collect as little as possible, keep it no longer than necessary, and keep our clients’ websites and their content on servers in the United Kingdom.

Who else sees it

We use a small number of suppliers who handle data on our behalf. As of 18 August 2026 these are:

Each is bound by a contract that limits what they may do with the data, and none of them use it for their own purposes. We will tell clients before adding or changing any supplier who processes their data.

Everything on our clients’ websites stays in the United Kingdom. The contact form and the booking service are provided by companies based in the United States, so if you choose to use either of those, your details are processed there under the UK Extension to the EU–US Data Privacy Framework. If you would rather they were not, email us directly instead.

How long we keep it

Keeping it safe

Credentials are held in an encrypted password manager and never sent by email. Two-factor authentication is enforced on every account we control. Access is limited to the people who need it. Backups are encrypted and stored separately from the live systems.

Your rights

You can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, object to how we are using it, or ask for it in a portable format. Email us and we will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first so we can put it right.

Changes

If we change this policy, we will update the date at the top. Where the change affects clients materially, we will tell you directly rather than expecting you to notice.