Privacy Policy
Effective Date: June 2026
Last Reviewed: June 2026
1. Introduction
This Privacy Policy explains the manner in which personal data is collected, processed, stored, transmitted, disclosed, retained, and otherwise handled by Josh Veazey ("we", "us", "our"), the owner and operator of joshvz.com (the "Website").
We recognise the importance of protecting personal data and are committed to conducting all processing activities in accordance with applicable data protection legislation, including but not limited to the United Kingdom General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and any other applicable legislation governing privacy, electronic communications, information security, and data protection.
This Privacy Policy applies to all visitors, users, prospective clients, clients, contractors, and other individuals whose personal information may be collected through the Website or in connection with enquiries submitted through the Website.
By accessing, browsing, or otherwise interacting with the Website, you acknowledge that you have read and understood the contents of this Privacy Policy.
2. Identity of the Data Controller
For the purposes of applicable data protection legislation, the data controller responsible for determining the purposes and means of processing personal data collected through this Website is:
Josh Veazey
Website: joshvz.com
Email: hello@joshvz.com
References throughout this Privacy Policy to "personal data", "special category data", "processing", "controller", "processor", "data subject", "recipient", "cross-border transfer", and related terminology shall have the meanings prescribed under applicable data protection legislation.
3. Scope of Processing Activities
The Website primarily operates as a professional services website for the purpose of presenting information regarding services offered by Josh Veazey and facilitating communication with prospective clients.
The Website does not provide direct e-commerce functionality, does not facilitate user account creation, and does not provide public user-generated content functionality such as comments, forums, or member areas.
Personal data processing activities are generally limited to:
- Responding to enquiries;
- Assessing potential projects and service requests;
- Communicating with prospective clients;
- Delivering contracted services;
- Website administration;
- Security monitoring;
- Website analytics and performance measurement;
- Compliance with legal, regulatory, taxation, and contractual obligations.
4. Categories of Personal Data Collected
Information Submitted Voluntarily
Where visitors complete and submit forms hosted via Tally, we may collect and process information including:
- Full name;
- Email address;
- Telephone number;
- Company or business information;
- Website information;
- Project requirements;
- Service requirements;
- Budget information;
- Timescale information;
- Communications and correspondence;
- Any other information voluntarily submitted by the individual.
The precise categories of information collected may vary depending upon the nature of the enquiry and the information voluntarily disclosed by the individual.
Technical Information
When visitors access the Website, certain technical information may be collected automatically, including:
- Internet Protocol (IP) address;
- Browser type and browser version;
- Operating system information;
- Device type and device identifiers;
- Language preferences;
- Screen resolution information;
- Referring and exit URLs;
- Geographic location data derived from IP addresses;
- Session duration metrics;
- Clickstream data;
- Time zone settings;
- Date and time of access;
- Website navigation behaviour.
Analytical Information
Analytical and statistical information may be collected relating to how visitors interact with the Website, including:
- Page views;
- Entry and exit pages;
- User journeys;
- Session duration;
- Bounce rates;
- Engagement metrics;
- Traffic acquisition sources;
- Conversion-related interactions;
- Device and browser performance data.
Communication Data
Where communications occur through email or other business communication channels, we may maintain records of:
- Correspondence history;
- Attachments;
- Meeting notes;
- Project documentation;
- Client instructions;
- Service delivery records.
5. Lawful Bases for Processing
Personal data is processed only where an appropriate lawful basis exists under Article 6 of the UK GDPR.
Legitimate Interests
Pursuant to Article 6(1)(f) UK GDPR, processing may be undertaken where necessary for the purposes of legitimate interests pursued by us, including:
- Responding to enquiries;
- Assessing suitability for potential projects;
- Managing business relationships;
- Website administration;
- Information security management;
- Fraud prevention;
- Service improvement;
- Business continuity planning;
- Network and system monitoring;
- Internal administrative purposes.
Where processing is based upon legitimate interests, a balancing assessment is undertaken to ensure that such interests do not override the rights and freedoms of the individual concerned.
Consent
Where required by law, personal data may be processed on the basis of consent pursuant to Article 6(1)(a) UK GDPR.
Examples include:
- Non-essential cookies;
- Website analytics technologies;
- Similar tracking technologies where consent is legally required.
Individuals may withdraw consent at any time without affecting the lawfulness of processing undertaken prior to withdrawal.
Contractual Necessity
Where an individual requests services or enters into a contractual relationship, processing may be undertaken pursuant to Article 6(1)(b) UK GDPR where necessary:
- To take steps prior to entering into a contract;
- To administer contractual arrangements;
- To deliver requested services;
- To manage project communications.
Legal Obligations
Processing may occur where necessary to comply with legal obligations, including obligations relating to taxation, accounting, regulatory compliance, dispute resolution, law enforcement requests, or court orders.
6. Analytics, Measurement, and Performance Monitoring
The Website utilises Google Analytics to facilitate the collection and analysis of aggregated statistical information concerning visitor interactions.
Google Analytics assists in evaluating:
- Website performance;
- User engagement;
- Visitor demographics;
- Device usage patterns;
- Traffic acquisition channels;
- Content effectiveness;
- Website optimisation opportunities.
Data collected through Google Analytics is generally pseudonymised and used for statistical, analytical, operational, and business intelligence purposes.
Although Google Analytics is not ordinarily used to identify individual visitors, certain technical identifiers may constitute personal data under applicable legislation.
Analytics processing shall only occur where the required consent mechanisms have been satisfied.
7. Cookies and Similar Technologies
The Website utilises cookies, pixels, tags, local storage technologies, and similar tracking mechanisms.
Cookies may be deployed for the following purposes:
- Essential website functionality;
- Security and fraud prevention;
- Consent management;
- Website performance optimisation;
- Traffic analysis;
- User preference management;
- Diagnostic and troubleshooting activities.
Cookie consent preferences are administered through Complianz.
Visitors may manage, modify, or withdraw cookie preferences through the consent management interface made available on the Website.
The continued availability of certain functionality may be affected where cookies are disabled.
8. Third-Party Processors and Service Providers
In connection with the operation of the Website and the delivery of services, personal data may be disclosed to carefully selected third-party service providers acting as processors or independent controllers where appropriate.
These may include:
- SiteGround (hosting infrastructure);
- Tally (form processing services);
- Google Analytics (analytics services);
- Complianz (cookie consent management);
- Professional advisers;
- Accountants;
- Legal advisers;
- Information technology service providers;
- Cloud infrastructure providers;
- Security service providers.
All third-party providers are expected to maintain appropriate technical and organisational measures designed to protect personal information.
9. Service Delivery, Contractors, and Professional Collaborators
Where an enquiry progresses into a client relationship, personal data and project-related information may be disclosed to trusted professional collaborators, subcontractors, consultants, developers, designers, technical specialists, or other service providers engaged in the fulfilment of the requested services.
Such disclosures are undertaken only where reasonably necessary for:
- Project delivery;
- Technical implementation;
- Design services;
- Content production;
- Website development;
- Quality assurance;
- Technical support;
- Maintenance activities;
- Project administration.
Information may be exchanged through secure business communication channels and collaboration systems, including:
- Email;
- Cloud-based file storage platforms;
- Project management systems;
- Documentation systems;
- Collaboration software;
- Secure file-sharing environments.
All recipients are expected to be bound by contractual, professional, or confidentiality obligations appropriate to the nature of the information being processed.
Personal information is not sold, rented, licensed, or otherwise disclosed to third parties for unrelated marketing purposes.
10. International Transfers of Personal Data
Certain service providers utilised by the Website may process personal data outside the United Kingdom.
Where international transfers occur, appropriate safeguards shall be implemented in accordance with Chapter V of the UK GDPR.
Such safeguards may include:
- Adequacy Regulations;
- International Data Transfer Agreements (IDTAs);
- Standard Contractual Clauses;
- Supplementary security measures;
- Other legally recognised transfer mechanisms.
11. Data Retention and Records Management
Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected.
Retention periods are determined having regard to:
- The nature of the information;
- Contractual obligations;
- Legal obligations;
- Accounting requirements;
- Regulatory requirements;
- Potential dispute resolution requirements;
- Business continuity considerations.
Upon expiry of the applicable retention period, information may be securely deleted, anonymised, archived, or otherwise disposed of in accordance with recognised information governance practices.
12. Information Security Measures
Appropriate technical and organisational security measures are implemented to mitigate risks associated with unauthorised access, disclosure, alteration, destruction, loss, misuse, or unlawful processing of personal data.
Such measures may include:
- SSL/TLS encryption;
- Access controls;
- Authentication mechanisms;
- Principle-of-least-privilege permissions;
- Security monitoring;
- Malware protection;
- Backup and recovery procedures;
- Hosting infrastructure protections;
- Administrative safeguards.
Whilst reasonable efforts are undertaken to safeguard information, no electronic transmission system or storage environment can be guaranteed to be entirely secure.
13. Rights of Data Subjects
Subject to applicable legal limitations, individuals may have the right to:
- Access personal data;
- Request rectification;
- Request erasure;
- Request restriction of processing;
- Object to processing;
- Request data portability;
- Withdraw consent;
- Request information regarding processing activities;
- Lodge a complaint with a supervisory authority.
Requests relating to the exercise of data subject rights should be submitted to:
Reasonable evidence of identity may be requested before responding to any request.
14. Third-Party Websites and External Services
The Website may contain links to third-party websites, applications, payment providers, resources, or external services.
We do not control and are not responsible for the privacy practices, security arrangements, or content of third-party websites.
Users are encouraged to review the privacy policies of any external services they choose to access.
15. Amendments and Policy Updates
This Privacy Policy may be amended, revised, supplemented, or otherwise updated from time to time in order to reflect operational, legal, regulatory, technological, or organisational developments.
The most current version shall always be published on this Website and shall supersede any previous versions.
16. Contact Information
Questions, concerns, or requests relating to this Privacy Policy or personal data processing activities should be directed to:
Josh Veazey
Email: hello@joshvz.com
Website: joshvz.com
Individuals also have the right to lodge a complaint with the UK Information Commissioner's Office ("ICO") if they believe their personal data has been processed unlawfully or in a manner inconsistent with applicable data protection legislation.