Legal

Privacy Policy

Last updated: 19 June 2026

This policy explains how Zach Falconer-Barfield ("I", "me", "my") collects, uses, stores and protects personal data through zf-b.com and related email communications. I act as the data controller. This policy is written to comply with the UK GDPR, the Data Protection Act 2018, and the EU GDPR where applicable.

1. Who I am

Zach Falconer-Barfield, sole trader, United Kingdom. For any privacy enquiry, contact privacy@falconer-barfield.com.

2. What data I collect

  • Contact form submissions: name, email address, enquiry topic, and the message you write.
  • Email engagement: if you receive email from me, basic delivery metadata (send, bounce, unsubscribe events) is logged by the sending infrastructure.
  • Server logs: standard request logs (IP address, user agent, timestamp) kept transiently for security and abuse prevention.

I do not run third-party advertising trackers, behavioural profiling, or social-media pixels on this site.

3. Why I use it (lawful basis)

  • Consent (Art. 6(1)(a)): when you submit the contact form, you consent to my using your details to reply.
  • Legitimate interests (Art. 6(1)(f)): to keep the site secure, prevent abuse, and maintain a suppression list of people who have unsubscribed.
  • Legal obligation (Art. 6(1)(c)): to honour unsubscribe requests and respond to data-subject rights requests.

4. How long I keep it

  • Contact form enquiries: up to 24 months, unless an ongoing professional relationship requires longer.
  • Email suppression records: kept indefinitely, because that is the only reliable way to ensure I never email you again after you unsubscribe.
  • Server logs: rotated within 30 days.

5. Who I share it with

I do not sell your data and I do not share it for marketing. I use a small number of processors to operate the site:

  • Hosting and database infrastructure (EU/UK regions where available).
  • Transactional email delivery provider (used only to send the notification of your enquiry to me, and any direct reply).

Each processor is bound by a data-processing agreement and processes data only on my instructions.

6. International transfers

Where data is processed outside the UK/EEA, transfers are protected by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, plus any additional safeguards required.

7. Your rights

Under UK/EU GDPR you have the right to:

  • Access the personal data I hold about you.
  • Correct inaccurate data.
  • Request deletion ("right to be forgotten") where there is no overriding legal basis.
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, including by using the unsubscribe link in any email or visiting /unsubscribe.
  • Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

To exercise any of these rights, email privacy@falconer-barfield.com. I aim to respond within 30 days.

8. Cookies

This site does not set non-essential cookies. Only strictly necessary cookies required for the site to function (e.g. session state) may be used; these do not require consent under PECR.

9. Security

Data is held on encrypted infrastructure with access controls and row-level security. No system is perfectly secure, but I take appropriate technical and organisational measures to protect your data.

10. Children

This site is not directed at children under 16, and I do not knowingly collect data from them.

11. Changes to this policy

I may update this policy as the site evolves. Material changes will be reflected in the "Last updated" date above. The current version always lives at this URL.

Questions? Email privacy@falconer-barfield.com or use the contact form.