Who is responsible for your data
Oakstone Digital is the data controller for information collected through https://oakstone.digital. We are a remote-first studio with senior staff in New York and London, and we work with clients across the United States, United Kingdom, UAE, Canada and Australia.
For anything in this policy — including access, correction and deletion requests — the route is jonathan@oakstone.digital. A person reads that inbox; there is no ticketing maze between you and an answer.
Information you give us deliberately
The contact form asks for your name, email address, company and a description of what you are trying to solve. The company field and the focus selector are optional; the rest is what we need in order to reply usefully.
If an engagement follows, we hold ordinary business contact details for the people we work with, plus whatever project material you choose to share with us. Project material is covered by the confidentiality terms in the engagement agreement, which take precedence over this policy where the two overlap.
- Lawful basis for enquiries: legitimate interest in responding to a request you initiated.
- Lawful basis for client records: performance of a contract, and legal obligation for invoicing records.
- Lawful basis for analytics: legitimate interest in understanding which pages are useful, using data that cannot identify you.
Information collected automatically
Every page on this site is prerendered static HTML served from a CDN. Serving it produces ordinary server logs — IP address, user agent, requested URL, timestamp — which exist for security and abuse prevention and are discarded on the provider’s rolling schedule.
We measure readership with privacy-preserving, cookieless analytics: a page view, a referrer and a coarse country, aggregated on collection. There is no cross-site identifier, no device fingerprint, no advertising pixel and no session recording. We cannot tell that the person reading a capability page on Tuesday is the person who sent an enquiry on Thursday, and we have not tried to build that link.
Third parties who process data for us
We keep the list deliberately short, and every processor on it is bound by a data processing agreement that prevents them using your data for their own purposes.
- Hosting and CDN — serves this site and retains short-lived request logs.
- Email — receives and stores enquiry correspondence.
- Analytics — aggregate, cookieless page measurement with no personal identifiers.
- Fonts and imagery — a font provider and an image CDN serve assets to your browser, which necessarily discloses your IP address to them as part of the request.
International transfers
We are a distributed team, so information you send may be read in the United States, the United Kingdom or the European Economic Area. Transfers out of the UK and EEA rely on adequacy regulations where they exist and on Standard Contractual Clauses where they do not.
Where a client’s regulatory position requires data to stay in a particular region, we architect the engagement that way — regional hosting, regional backups, and processors chosen to match. That is a build decision we make with you, not an afterthought.
How long we keep things
Enquiries that do not become engagements are deleted twenty-four months after the last exchange. Enquiries that do become engagements are retained for the life of the relationship and for six years afterwards, which is the period we are required to keep financial records against.
Server logs follow the hosting provider’s rolling retention. Aggregate analytics carry no personal data and are kept indefinitely because there is nothing in them to expire.
Your rights
Depending on where you live, you have some or all of the rights below. We apply them to everyone regardless of jurisdiction, because operating two standards would cost more than operating the higher one.
- Access — ask what we hold about you and receive a copy.
- Rectification — have inaccurate details corrected.
- Erasure — ask us to delete what we hold, subject to records we are legally required to keep.
- Restriction and objection — ask us to stop a particular use, including any processing based on legitimate interest.
- Portability — receive your data in a structured, machine-readable format.
- Complaint — raise the matter with your supervisory authority, such as the ICO in the United Kingdom.
Security
The site is served over TLS with a strict transport policy and a content security policy. Access to the enquiry inbox and to client systems requires multi-factor authentication, and access is granted per engagement rather than held permanently by everyone.
No system is beyond incident. If a breach affects your data and creates a real risk to you, we will tell you and the relevant regulator inside the statutory window, with what happened and what we did — not a euphemism about an unauthorised third party.
Children
This is a business-to-business site. It is not directed at children, and we do not knowingly collect information from anyone under sixteen. If you believe a child has sent us information, email us and we will remove it.
Changes to this policy
When this policy changes materially, we update the effective date at the top and describe what changed rather than quietly reissuing the document. Continuing to use the site after a change means the current version applies.
Asking us about this
Requests under this policy, questions about a clause, or a disagreement with something in it all go to the same place and are answered by a person within thirty days — usually considerably sooner.