Website Privacy Notice

1. INTRODUCTION
Welcome to the privacy notice of Julia Cartwright. We value your privacy and are committed to protecting your personal data. This notice explains how we collect, use, and safeguard your information when you visit our website, https://juliacartwright.com/

Julia Cartwright, trading as Julia Cartwright, is the data controller responsible for your personal data, referred to as "we," "us," or "our" in this notice.

Contact Details
For any questions or concerns about your data, please reach out to us:
• Full Name of Legal Entity: Julia Cartwright T/A Julia Cartwright
• Email Address: info@Juliacartwright.com
• Contact: Due to security, please email for details

It's crucial that the information we hold about you is accurate and current. If your personal data changes, please notify us by emailing info@Juliacartwright.com

2. WHAT DATA DO WE COLLECT ABOUT YOU, FOR WHAT PURPOSE, AND ON WHAT GROUND WE PROCESS IT

Personal data refers to any information that can identify an individual. Anonymised data is not included.

Categories of Personal Data We Process:
1. Communication Data: This includes any messages you send us via our website's contact form, email, text, social media, or other communication channels. We process this data to communicate with you, maintain records, and manage legal claims. Our lawful basis for this processing is our legitimate interests, specifically to respond to communications, keep records, and handle legal claims.
2. Customer Data: This includes information related to your purchases, such as your name, title, billing address, email, phone number, contact details, purchase details, and card information. We process this data to deliver the goods/services you've purchased and maintain transaction records. Our lawful basis is the performance of a contract with you or steps taken at your request to enter into such a contract.
3. User Data: This includes data about your website usage and any content you post. We process this data to operate our website, ensure security, maintain backups, and manage our online services. Our lawful basis is our legitimate interests in administering our website and business effectively.
4. Technical Data: This includes your IP address, browser type, time zone settings, and page interaction data, collected via analytics and advertising tools like Google Analytics and the Meta Pixel. We process this data to understand website performance, enhance user experience, and evaluate marketing effectiveness. Our lawful basis is our legitimate interests in maintaining and growing our business.
5. Marketing Data: This includes your marketing preferences and communication choices. We process this data to engage you in promotions, deliver relevant content, and assess advertising effectiveness. Our lawful basis is our legitimate interests in understanding customer use of our products/services, developing them, and shaping our marketing strategy.
6. Consultation Data: This includes notes or information from consultations, questionnaires, or project inquiries. We process this data to understand your needs and provide tailored advice or services. Our lawful basis is the performance of a contract and our legitimate interests in ensuring quality client service.
7. Sensitive Data: We do not collect sensitive data, such as details about race, ethnicity, religious beliefs, or health information.
Important Considerations:
• If we are legally required to collect personal data and you do not provide it, we may not be able to deliver our services. We will inform you if this affects your service.
• We will only use your personal data for its collected purpose or a compatible purpose if necessary. For unrelated new purposes, we will notify you and explain the legal grounds for processing.
• We may process your data without your knowledge or consent where required or permitted by law.
• We do not engage in automated decision-making or profiling.













3. HOW WE COLLECT YOUR PERSONAL DATA
Direct Interactions: We collect personal data directly from you when you engage with us. This includes filling out forms on our website, subscribing to our newsletter, booking consultations, or contacting us via email or social media.


Automated Technologies: As you navigate our website, we automatically collect certain data using cookies, analytics, and similar tracking tools. This data includes information about your device, browsing patterns, and interactions with our content. For further details, please refer to our Cookie Policy.
https://juliacartwright.com/cookie-policy

Third-Party Sources: We may receive data from third parties, including analytics providers like Google, advertising networks such as Facebook, and providers of technical, payment, and delivery services. These third parties may be based outside the UK and/or the EU.

Public Sources: We also obtain data from publicly available sources, such as Companies House and the Electoral Register, which may be located inside or outside the UK and/or the EU.

We do not engage in buying, renting, or selling personal data from third parties.
4. MARKETING COMMUNICATIONS
Our lawful basis for processing your personal data for marketing purposes is either your consent or our legitimate interests, specifically aimed at growing our business.
We send marketing emails only when you have actively opted in, such as by subscribing through our website or downloading a free resource. You can withdraw your consent at any time by clicking the unsubscribe link in any of our emails.

In accordance with the Privacy and Electronic Communications Regulations (PECR), we may also contact you if you have previously made an enquiry or purchase from us, provided you have not opted out of communications.
We may also collect publicly available information from sources such as Companies House or the Electoral Register within or outside the UK and EU where it is lawful to do so.

In line with the PECR, we may send you marketing communications if you have either: (i) made an enquiry or purchase from us, or (ii) opted in to receive updates from us and have not unsubscribed since.

You can opt out of receiving marketing emails at any time by clicking the unsubscribe link in our emails or by contacting us at info@Juliacartwright.com

We will never share your personal data with third parties for their own marketing purposes without your explicit consent.

Please note that opting out of marketing messages does not affect the processing of personal data related to other business activities, such as client agreements, payments, or project records.
5. DISCLOSURES OF YOUR PERSONAL DATA
We may share your personal data with selected third parties to ensure the smooth operation of our business.

These parties include:
• Trusted Service Providers: These are entities that assist us with IT systems, website management, email marketing platforms, cloud storage, and administrative support.
• Professional Advisers: This includes lawyers, accountants, bankers, and insurers who provide us with professional services.
• Regulatory or Government Authorities: We may disclose personal data to these bodies when legally required to do so.
• Third Parties in Business Transactions: In the event of a sale, transfer, or restructuring of our business or assets, we may share your data with relevant third parties.

We ensure that all third parties with whom we share your data respect its security and handle it in compliance with the law. These parties are only permitted to process your personal data for specified purposes and must adhere to our instructions.
6. INTERNATIONAL TRANSFERS
For Individuals in the United Kingdom:
We adhere to the UK General Data Protection Regulation (UK GDPR), ensuring your personal data is protected. When we work with trusted third-party providers with servers outside the UK or the European Economic Area (EEA)—such as Google, Dropbox, Showit, Meta (Facebook/Instagram), Kajabi, Shopify, Flodesk, or ConvertKit—we implement appropriate safeguards to maintain the same level of data protection as within the UK or EEA.
To achieve this:
• We may transfer your personal data to countries deemed by UK regulatory authorities to provide an adequate level of data protection.
• If using US-based providers that are part of a UK regulator-approved privacy framework, we may transfer data to them, as they have equivalent safeguards in place.
• For service providers outside the UK, we may use specific contracts, codes of conduct, or certification mechanisms approved by UK regulators to ensure your data receives the same protection as in the UK.

If none of these safeguards are available, we will seek your explicit consent for the specific transfer, and you have the right to withdraw this consent at any time.

For Individuals in the EEA:
We comply with the EU General Data Protection Regulation (GDPR) to protect your personal data. When transferring your data to third parties outside the EEA, we ensure certain safeguards are in place to maintain a similar level of security for your personal data.

To ensure this:
• We may transfer your personal data to countries that the European Commission has approved as providing an adequate level of data protection.
• If using US-based providers that are part of an EU-approved privacy framework, we may transfer data to them, as they have equivalent safeguards in place.
• For service providers outside the EEA, we may use specific contracts, codes of conduct, or certification mechanisms approved by EU regulators to ensure your data receives the same protection as in the EEA.

If none of these safeguards are available, we will seek your explicit consent for the specific transfer, and you have the right to withdraw this consent at any time.
7. DATA SECURITY
We have implemented robust security measures to protect your personal data from accidental loss, unauthorized use, alteration, disclosure, or access. Access to your personal data is restricted to employees and partners who require it for legitimate business purposes. They are instructed to process your personal data strictly according to our guidelines and are obligated to maintain its confidentiality.
8. DATA RETENTION
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including meeting any legal, accounting, or reporting obligations.

When determining the appropriate retention period, we consider the data's volume, nature, and sensitivity, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, whether these purposes can be achieved by other means, and any applicable legal requirements.

For tax purposes, we are legally required to retain basic customer information (including Contact, Identity, Financial, and Transaction Data) for six years after they cease to be customers.

In certain circumstances, we may anonymise your personal data for research or statistical purposes, allowing us to use this information indefinitely without further notice to you.
9. YOUR LEGAL RIGHTS
Under data protection law, you have several rights regarding your personal data, including the right to:
• Request Access: Obtain a copy of the personal data we hold about you.
• Request Correction: Amend any inaccurate or incomplete data.
• Request Erasure: Delete your data where there is no lawful reason for us to continue processing it.
• Restrict or Object: Limit or oppose the processing of your data in certain situations.
• Request Data Portability: Transfer your data to another party.
• Withdraw Consent: Revoke consent where processing is based on consent.

For more information about your rights under UK law, visit the Information Commissioner’s Office (ICO): ICO Individual Rights.
To exercise any of these rights, please contact us at info@Juliacartwright.com. You will not be charged a fee to access your data or exercise your rights unless your request is clearly unfounded, repetitive, or excessive. In such cases, we may charge a reasonable fee or refuse to comply.

We may need to request specific information from you to confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any unauthorized person. We may also contact you for further information regarding your request to expedite our response.

We aim to respond to all legitimate requests within one month. Occasionally, it may take longer if your request is particularly complex or you have made multiple requests. In such cases, we will notify you.

If you are within the UK and are dissatisfied with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would appreciate it if you contacted us first with any complaints so we can attempt to resolve them for you.

If you are within the EU and are dissatisfied with any aspect of how we collect and use your data, you have the right to complain to the data protection authority of your country. We would appreciate it if you contacted us first with any complaints so we can attempt to resolve them for you.

10. THIRD-PARTY LINKS
Our website may contain links to third-party websites, plug-ins, and applications. By clicking on these links or enabling these connections, you may allow third parties to collect or share data about you. We do not have control over these third-party websites and are not responsible for their privacy policies. When you leave our website, we strongly recommend that you read the privacy notice of every website you visit to understand how they handle your personal data.
11. COOKIES
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see https://juliacartwright.com/cookie-policy


Last updated [20 Jan 2026]