Privacy Policy
How Witty Content Writers collects, uses, shares, secures and retains personal data — including legal bases, retention periods, international transfers and your GDPR and CCPA rights.
Last updated: 15 September 2026 · Effective date: 1 October 2026 · Version 3.0
Witty Content Writers (“Witty Content Writers”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains what we collect, why we collect it, how we use and protect it, who we share it with, how long we keep it, and the rights you have over it.
This policy applies to https://wittycontentwriters.com and to every service, proposal, form, email and project we deliver. It does not apply to third-party websites we link to, which operate their own policies.
If you do not agree with this policy, please do not use the website or submit information through it.
1. Who we are (data controller)
For the purposes of the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679) and comparable legislation, the data controller is:
| Entity | Witty Content Writers |
|---|---|
| Registered address | 2261 Market Street, Suite 5514, San Francisco, CA 94114, USA |
| [email protected] | |
| Telephone | +1 (415) 555-0134 |
| Privacy contact | [email protected] |
We have not appointed a statutory Data Protection Officer because we are not required to do so, but our privacy contact above is responsible for data protection matters and monitors that inbox directly.
2. The personal data we collect
2.1 Information you give us
- Contact and enquiry data — first name, last name, work email address, telephone number, company name, website, the service you are interested in, budget range and the content of your message.
- Project data — anything you share with us during an engagement: briefs, brand guidelines, customer research, analytics exports, credentials you choose to share (we ask that you use least-privilege access rather than account passwords), and feedback on drafts.
- Newsletter data — the email address you submit and your subscription status.
- Billing data — company billing address, VAT or tax identifier, purchase order references and payment confirmations. Card details are processed by our payment provider and never reach our servers.
- Correspondence — emails, call notes, and messages exchanged in shared workspaces.
2.2 Information we collect automatically
- Technical data — IP address (truncated where analytics permits), browser type and version, operating system, device type, screen size and referring URL.
- Usage data — pages visited, time on page, scroll depth, links clicked, downloads and the path taken through the site.
- Cookie data — see our Cookie Policy for the full inventory and your controls.
2.3 Information from third parties
- Publicly available business information (company website, LinkedIn company page) used to prepare a proposal.
- Analytics and search data about your domain where you have granted us access to your own accounts.
- Referral information when an existing client or partner introduces you.
2.4 Data we do not want
We do not knowingly collect special category data (health, ethnicity, religion, political opinions, biometric or genetic data, sexual orientation), criminal offence data, or data relating to children under 16. Please do not send such information through our forms. If you do, we will delete it as soon as we become aware.
3. Why we use your data and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to an enquiry and preparing a proposal | Contact, enquiry, technical | Steps at your request prior to a contract; legitimate interests |
| Delivering the services you have engaged us for | Contact, project, correspondence | Performance of a contract |
| Invoicing, accounting and tax records | Billing, contact | Legal obligation; performance of a contract |
| Sending the monthly newsletter | Email address | Consent (withdrawable at any time) |
| Improving the website and measuring content performance | Technical, usage, cookie | Consent for optional analytics cookies; legitimate interests for aggregate, non-identifying measurement |
| Security, fraud prevention and abuse detection | Technical, usage | Legitimate interests; legal obligation |
| Establishing, exercising or defending legal claims | Any relevant data | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest in operating and improving a professional services business does not override your rights and freedoms. You may object at any time (see section 8).
4. Marketing communications
We send one newsletter a month and occasional project-related updates. We will only send marketing email where you have subscribed, or where you are an existing client and the message concerns services similar to those you have purchased.
Every marketing email contains a one-click unsubscribe link. You can also email [email protected] with “unsubscribe” in the subject line. Unsubscribing from marketing does not stop transactional messages about an active project, invoices or legal notices.
We do not sell, rent or trade your personal data, and we do not share it with third parties for their own marketing purposes. Ever.
5. Who we share data with
We share personal data only with the categories of recipients below, and only to the extent necessary:
- Service providers (processors) — website hosting, email delivery, analytics, cloud document storage, project management tooling, accounting software and payment processing.
- Professional advisers — accountants, auditors, insurers and lawyers, where necessary and under duties of confidentiality.
- Subcontracted writers and editors — vetted freelance specialists who work under written confidentiality and data protection terms. They receive only the project data needed for the work assigned.
- Authorities — where we are required to disclose by law, court order or a valid regulatory request.
- A successor entity — if our business is sold or merged, subject to the buyer honouring this policy.
Every processor is bound by a written data processing agreement requiring appropriate technical and organisational measures, confidentiality, assistance with data subject requests and deletion or return of data at the end of the engagement.
6. International transfers
We are based in the United States and work with clients and contractors worldwide, so your data may be transferred outside your country of residence — including to the United States, the United Kingdom and the European Economic Area.
Where personal data originating in the EEA or UK is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by a transfer risk assessment and, where appropriate, additional measures such as encryption in transit and at rest and least-privilege access controls.
You may request a copy of the safeguards applying to a specific transfer by writing to our privacy contact.
7. How long we keep data
| Category | Retention period | Reason |
|---|---|---|
| Enquiries that do not become projects | 24 months from last contact | Follow-up and dispute evidence |
| Client project files and correspondence | 7 years after the engagement ends | Contractual, tax and professional liability |
| Invoices and accounting records | 7 years | Statutory accounting obligations |
| Newsletter subscriber data | Until you unsubscribe, plus 12 months of suppression data | Consent management and honouring opt-outs |
| Analytics and cookie data | Up to 14 months | Year-on-year measurement |
| Server and security logs | 12 months | Security and abuse investigation |
At the end of a retention period we delete data or irreversibly anonymise it. Backups are overwritten on a rolling 90-day cycle, so deleted data may persist in encrypted backups for a short period after deletion from live systems.
8. Your rights
Depending on where you live, you may have the following rights:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion where we no longer have a lawful reason to keep it.
- Restriction — to limit processing while a dispute about accuracy or legitimacy is resolved.
- Portability — to receive data you provided in a structured, machine-readable format.
- Objection — to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Withdraw consent — at any time, without affecting processing already carried out.
- Complaint — to your supervisory authority (in the UK, the Information Commissioner's Office; in the EEA, your national authority).
8.1 California residents
Under the CCPA as amended by the CPRA you additionally have the right to know the categories of personal information collected, disclosed or sold; the right to delete; the right to correct; the right to opt out of sale or sharing; and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CPRA, and we do not process sensitive personal information for inferring characteristics.
8.2 How to exercise a right
Email [email protected] stating the right you wish to exercise. We will acknowledge within five business days and respond substantively within one month (extendable by two further months for complex requests, with notice). We may ask for information to verify your identity; we will not use that information for any other purpose. Exercising your rights is free unless a request is manifestly unfounded or excessive.
9. How we protect your data
We maintain technical and organisational measures appropriate to the risk, including:
- TLS encryption for all data in transit and encryption at rest with our cloud providers
- Multi-factor authentication on every business system that supports it
- Role-based, least-privilege access, reviewed quarterly and revoked on the day a contract ends
- A password manager for all shared credentials; no credentials in email or chat
- Written confidentiality and data protection terms with every contractor
- Annual security review, device encryption and automatic screen locking
- An incident response procedure with notification to affected individuals and regulators where required (within 72 hours of becoming aware of a reportable breach)
No system is perfectly secure. If you believe your data has been compromised, contact our privacy address immediately.
10. Children's privacy
Our services are intended for businesses and their representatives. The website is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects. We use tooling to score keyword opportunities and to prioritise content recommendations, but every recommendation and commercial decision is reviewed by a person.
12. Third-party links and embedded content
Our website links to third-party sites (for example our social media profiles) and may embed content from third parties. Clicking those links or loading that content means the third party may collect data about you under its own policy. We are not responsible for the privacy practices of external sites and encourage you to read their policies.
13. Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle your data, we will notify you by email where we hold your address, or by a prominent notice on the site, at least 14 days before the change takes effect.
14. How to contact us
Questions, requests or complaints about this policy:
- Email: [email protected]
- General email: [email protected]
- Post: Witty Content Writers, 2261 Market Street, Suite 5514, San Francisco, CA 94114, USA
- Telephone: +1 (415) 555-0134
We aim to resolve every concern directly. If you remain dissatisfied you may complain to your data protection supervisory authority.