CloseDeck Limited

Privacy notice for closedeck.co.uk

Version
2.0
In effect from
30 July 2026
Applies to
closedeck.co.uk only

What this notice covers. This notice covers the website closedeck.co.uk and the consultation calls you book through it. CloseDeck Limited also operates a separate product, setpal.io, which has its own privacy notice because it processes personal data in a materially different way. Personal data collected through closedeck.co.uk is not combined or cross-referenced with personal data held in setpal.io, and the two are kept in separate systems. If you use both, you are two separate records to us.

1. Who we are

CloseDeck Limited is the data controller for the personal data described in this notice. We are a company registered in England and Wales, company number 17187412, with a registered office at Suite Ra01, 195–197 Wood Street, London, E17 3NU.

For anything in this notice, including any request about your rights, email eric@closedeck.co.uk. CloseDeck is a one-person business, so that address reaches the person who makes the decisions about your data. We have not appointed a Data Protection Officer; we are not required to.

We are registered with the Information Commissioner's Office, the UK data protection regulator.

2. Who this notice is about

This notice is for people who visit closedeck.co.uk, book a consultation call with us, or email us. Our clients are businesses and sole traders rather than consumers, but data protection law protects you as an individual regardless of the hat you are wearing, so this notice applies to you whether you are contacting us for your company or for yourself.

3. What we collect, why, and on what basis

3.1 Visiting the website

The website itself sets no cookies and stores nothing on your device. It runs no analytics, no advertising pixels, no session recording and no chat widget. Fonts are served from our own domain, so no third party learns that you visited.

Our hosting provider, Vercel, keeps technical logs of requests to the site for 24 hours, which include your IP address, the page requested, the time, and your browser's user-agent string. After a day they are deleted, and we never take a copy. We use these only to keep the site running and secure. Our lawful basis is our legitimate interests (UK GDPR Article 6(1)(f)) in operating a working, secure website. We do not use these logs to build a profile of you or to identify you.

3.2 Reaching the booking calendar

Our calendar is run by Calendly, a company in the United States. We do not embed it. There is a link to it, and a link is not a download: nothing of Calendly's is loaded onto our page, so nothing of theirs reaches your device unless you decide to click through.

We used to embed it, and stopped in July 2026. Embedding meant Calendly's code and cookies arrived on your device as a consequence of visiting our page, which is a decision we were effectively making on your behalf. A link puts the decision back where it belongs.

If you click through, you are on Calendly's site. Calendly sets its own cookies there and shows you its own cookie banner, and that is a matter between you and Calendly under their privacy notice. We receive nothing from those cookies.

You never have to go there at all. Email eric@closedeck.co.uk with a couple of times that suit you and we will confirm one by return: same call, same audit, no third party. We do not treat that route as second best.

3.3 Booking a consultation call

The booking form asks for this, and nothing else:

  • Your name. Required.
  • Your email address. Required.
  • Your answer, if you give one, to "Please share anything that will help prepare for our meeting." A free-text box, and optional. Write as much or as little as you like, including nothing. Please do not put anything sensitive in it: we do not need it, and section 3.4 explains why.
  • Whether you are happy for the call to be recorded. Both answers are fine and neither affects whether you can book. See section 3.4.
  • Guests, if you add any. Calendly lets you invite colleagues by entering their email addresses. If you do, we receive those addresses from you rather than from them, and Calendly emails them the invitation. We use them only to hold the meeting, we keep them for the same twelve months as the rest of the booking, and we do not add them to anything. If you are a guest reading this because you were added by someone else, this notice is your privacy information, and you can ask us to delete your details at any time using the address in section 1.

Alongside those, the booking itself records:

  • your time zone, which Calendly detects from your browser;
  • the date and time you picked, and any later change, cancellation or no-show.

On Calendly's own site, once you have clicked through, Calendly runs three further things worth naming, because each involves a company other than us receiving information about your device. None of them runs on our site, none of them is our choice, and we see nothing they collect. We mention them because we sent you there.

  • Google reCAPTCHA, on the step where you enter your name and email, to stop automated abuse. Google receives technical information about your device and how you interact with the page in order to judge whether you are a person. Covered by Google's privacy policy. We never see the result beyond the booking succeeding or failing.
  • A bot-detection script of Calendly's own, served from Calendly's servers under a deliberately unmemorable filename, which gathers signals about your device and browser and sends them back to Calendly for the same anti-abuse purpose.
  • Stripe.js, which Calendly loads across its booking pages and which is why two Stripe cookies appear. Nothing is being paid for here, we never ask you for card details, and this site takes no payments at all.

We use this to arrange the call, to send you the confirmation and any reminder, to hold the call, and to write and send you the audit you asked for. Our lawful basis is performance of a contract, and steps taken at your request before entering into one (UK GDPR Article 6(1)(b)): you have asked us for a specific thing and we cannot deliver it without knowing who you are and how to reach you.

Afterwards, we keep the booking record for twelve months so that we can remember the conversation if you come back to us, and so that we have a record of what we advised. Our lawful basis for that period is our legitimate interests (Article 6(1)(f)) in maintaining business records and being able to follow up on a conversation you started. You can object to that retention at any time and we will delete the record unless we have to keep it for tax or legal reasons.

3.4 Recording, transcribing and summarising the call

We sometimes use an AI notetaker called Fathom on consultation calls. When it is running it records the call, produces a written transcript, and generates a summary and action points. That means your voice, your image if your camera is on, and what you say about your business are recorded and processed by a third party.

We ask you when you book, not when the call starts. The booking form asks whether you are happy for the call to be recorded, so you can decide unhurried and in your own time rather than being put on the spot by a stranger. Our lawful basis is your consent (UK GDPR Article 6(1)(a)). In practice:

  • if you answer no, we switch the recorder off before the call begins and nothing is recorded. The call goes ahead exactly as it would otherwise and you get the same audit. Nothing about the service you receive depends on agreeing;
  • both answers let you book. The question is not a condition of getting a call, and we will not ask you to justify a no;
  • we confirm your answer out loud at the start of the call, so you can change your mind before anything is captured;
  • if someone else joins with you, we ask them too, because your answer cannot speak for them. If anyone objects, we do not record;
  • you can change your mind at any point during the call. We stop immediately and delete what has been captured;
  • you can ask afterwards for the recording, transcript and summary to be deleted, and we will do it, without asking you why.

Your answer is kept with the booking record for the same twelve months, so that we can show what you were asked and what you said. It records the fact and the date, not the conversation.

If we ever record you when you had said no, that is our mistake and not something you need to police. Tell us, or just email eric@closedeck.co.uk, and we will delete the recording, the transcript and the summary straight away and confirm when it is done.

We keep recordings, transcripts and summaries for twelve months from the call, then delete them.

Please do not use the call to tell us about anyone's health, religion, ethnicity, political opinions, trade union membership, sex life, sexual orientation, biometrics or criminal record, whether yours or an employee's. We do not need any of it, we do not ask for it, and we do not rely on any condition in UK GDPR Article 9 or 10 that would allow us to process it. If something like that comes up in passing, tell us and we will remove it from the transcript and notes.

3.5 Emailing us

If you email us, we hold that correspondence in our mailbox so that we can reply and keep a record of what was agreed. Our lawful basis is our legitimate interests (Article 6(1)(f)) in answering the people who contact us. We keep correspondence that relates to a booking for twelve months in line with the booking record above; where an email becomes part of a paid engagement, see section 3.6.

3.6 If you become a paying client

If you go on to engage us for paid work, we keep the contract, invoices and the records that sit behind them for six years after the end of the relationship. Our lawful basis is legal obligation (Article 6(1)(c)) for the tax and accounting records we are required to keep, and legitimate interests (Article 6(1)(f)) for keeping enough of a file to deal with a dispute inside the limitation period. This website does not take payments; if that changes we will update this notice before it does.

3.7 Marketing

We do not currently send marketing email. Booking a call does not put you on a list, because there is no list. If we start sending marketing, we will ask you to opt in, every message will carry a working one-click unsubscribe, and we will update this notice first.

4. Who else sees your data

We do not sell your personal data, we do not share it for advertising, and we do not disclose it to anyone except the service providers below, each of which acts on our instructions under a written contract that meets UK GDPR Article 28. This is the complete list.

Who What they do for us What they get Where
Calendly LLC Runs the booking calendar and sends confirmations Your name, email, time zone, your answer to the preparation question, any guest email addresses you add, meeting times, and the technical data its widget collects (IP address, device and browser information, cookies) United States
Google, as reCAPTCHA, engaged by Calendly Stops automated abuse of the booking form Technical information about your device and how you interact with the booking step, used to judge whether you are a person United States
Fathom Video, Inc. Records, transcribes and summarises calls, with your consent The call recording, the transcript, and the summary generated from them United States
Google (Google Workspace) Our email, our calendar, and the spreadsheet we keep booking records in Your name, email, the content of any correspondence, the calendar entry for the call, and the booking record European Union and United States, depending on the service and where data is at rest
Vercel Inc. Hosts the website Technical request logs, including your IP address United States, with the site served from edge locations including London

Calendly acts on our instructions for your booking details: we decide what is collected and why, and Calendly processes it for us. Calendly's own terms treat it as an independent controller for cookies it sets through an embedded calendar, which is one of the reasons we no longer embed one. Because you reach Calendly by your own click, anything its site does once you are there is Calendly's responsibility to explain, and it does.

The video conferencing platform we use for the call itself (for example Google Meet or Zoom, depending on what suits you) will also process the call. We will tell you which one we are using when we send the invitation.

We may also disclose personal data where we are legally required to, for example to a regulator, a court, or HM Revenue & Customs.

5. Sending data outside the UK

Calendly, Fathom, Vercel and Google are United States companies, so booking and call data is transferred to the United States. Each of them is certified under the EU–US Data Privacy Framework and the UK Extension to it. Since 12 October 2023 the UK Government has recognised the UK Extension as providing an adequate level of protection, which is the transfer mechanism we rely on. Where a provider also offers the UK International Data Transfer Addendum or the EU Standard Contractual Clauses in its data processing terms, those apply as a fallback if its certification ever lapses.

You can ask us for a copy of the relevant transfer paperwork by emailing eric@closedeck.co.uk.

6. How long we keep things

What How long
Booking record (name, email, time zone, your answer, times) 12 months from the call
Call recording, transcript and AI summary 12 months from the call, or sooner if you ask
The written audit we send you 12 months from the call
Email correspondence about a booking 12 months
Contracts, invoices and accounting records for paid work 6 years after the end of the engagement
Website request logs held by our host 1 day. Vercel deletes runtime logs after 24 hours on our plan. We keep no copy

7. Your rights

Under UK data protection law you have the right to:

  • be told what we hold about you, and get a copy of it;
  • have anything inaccurate corrected;
  • have your data deleted, where we have no overriding reason to keep it;
  • restrict what we do with it while a dispute is resolved;
  • object to processing we do on the basis of legitimate interests, including our twelve-month retention of your booking record;
  • receive your data in a portable, machine-readable form where we relied on consent or on a contract;
  • withdraw consent at any time, for the booking calendar and for call recording, without it affecting anything we did before you withdrew.

Email eric@closedeck.co.uk and we will respond within one month. There is no charge. We may ask you a question to confirm you are who you say you are, but no more than we need.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113. You can complain to the ICO without coming to us first, though we would rather have the chance to put it right.

8. If you are in the European Economic Area

closedeck.co.uk is aimed at businesses in the United Kingdom and the United States. We do not target the EEA: we do not advertise there, we do not price in euros, and we do not offer the site in another language. On that basis we do not consider EU GDPR Article 3(2) to apply to this website and we have not appointed an Article 27 representative in the EU. If someone in the EEA books a call, we handle their data exactly as described above, to the same standard. If we start marketing into the EEA we will appoint a representative and name them here first.

9. If you are in the United States

We do not sell your personal information and we do not share it for cross-context behavioural advertising. There is no "Do Not Sell or Share My Personal Information" link on this site because there is nothing to opt out of: no advertising trackers, no data brokers, no ad networks.

Our website contains no advertising or analytics technology, so there is nothing for a Global Privacy Control signal to switch off. We honour the signal by design rather than by configuration, and if we ever add anything that a GPC signal would apply to, we will detect and respect that signal automatically.

We believe we fall below the thresholds that make the California Consumer Privacy Act apply to a business. We nevertheless extend the substance of these rights, which are to know, to delete, to correct, to opt out, and not to be discriminated against for exercising them, to everyone who contacts us, wherever they are. Use the same email address in section 7.

10. Keeping it safe

The website is static, has no login and no database, and is served only over HTTPS. Access to our email, calendar and booking spreadsheet is protected by a strong unique password and multi-factor authentication, and only the founder has that access. Nobody else at CloseDeck, and no contractor, has access to booking records or call recordings.

If a breach happens that is likely to result in a risk to your rights, we will report it to the ICO within 72 hours and tell you if the risk to you is high.

11. Automated decisions and AI

We do not make any decision about you by automated means alone, and we do not profile you. The AI notetaker described in section 3.4 summarises what was said; it does not decide anything about you. The audit we write is written by a person.

We do not use your call recordings, transcripts or booking details to train any AI model, and we have not authorised any of our providers to do so.

Fathom uses a number of specialist AI companies to produce the transcript and summary, rather than doing all of it itself. We checked their published list on 30 July 2026, and every AI provider handling meeting content is contractually forbidden from training on it. Their current list is at trust.fathom.video, and we check it rather than assume it.

12. Children

This is a business-to-business service and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you think a child has given us data, email us and we will delete it.

13. Changes to this notice

If we change what we do with personal data, we will update this notice and change the version number and date at the top before the change takes effect. Where the change is significant and we hold your email address, we will tell you directly.