Home / Privacy Policy
Privacy Policy
Last updated: 8 September 2026
[BRACKETED] placeholder
with your real details and have a qualified adviser confirm it against the laws that
apply to your business and customers (for example UK GDPR, EU GDPR, PECR, CCPA/CPRA).
1. Who we are
This website is operated by [REGISTERED BUSINESS NAME] ("Mr. Comet", "we", "us"), a business registered in [COUNTRY/STATE] under number [COMPANY/REG NUMBER], with its registered address at [FULL REGISTERED ADDRESS]. We are the data controller for the personal data described in this policy.
For any privacy question or request, contact us at mr.cometwebsites@gmail.com.
2. The short version
- This site sets no cookies and runs no advertising trackers. It uses privacy-friendly, cookie-free page-view analytics from Vercel. See our Cookie Policy.
- All fonts and scripts are served from our own domain. No data is sent to third-party content networks when you browse the site.
- We only receive personal data when you choose to send it to us — for example by emailing us or becoming a client.
- We do not sell personal data and we do not use it for automated decision-making or profiling.
3. What we collect and why
a) When you visit the website
We use Vercel Web Analytics to count page views and see which pages are visited. It sets no cookies, does not track you across other sites, and does not build a profile of you. Our hosting provider automatically processes standard server logs (your IP address, request time, page requested, user agent) to deliver pages and protect the service against abuse. These logs are held by the hosting provider for a short period and then deleted.
Lawful basis (GDPR): legitimate interests — operating and securing the website.
b) When you contact us
If you email us or send an enquiry, we process the contact details and message content you provide so we can reply and, where relevant, prepare a proposal. This data reaches us through our email provider.
Lawful basis: steps taken at your request prior to entering a contract, and our legitimate interest in responding to enquiries.
c) When you become a client
To design, build, host and maintain your website we process business and contact details, billing information, domain and DNS records, login credentials you share with us, and any content you provide for your site. Some of this may include personal data about your own staff or customers, for which you are the controller and we act as your processor under the data-processing terms in our Terms of Service.
Lawful basis: performance of our contract with you, and compliance with legal obligations (for example tax and accounting records).
4. Service providers (sub-processors)
We share personal data only with the providers we need to run the service:
| Provider | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Website and email hosting, server logs | [REGION] |
| [EMAIL PROVIDER] | Business email and enquiry handling | [REGION] |
| [DOMAIN REGISTRAR] | Domain registration and DNS | [REGION] |
| [PAYMENT / INVOICING PROVIDER] | Invoicing and payment collection | [REGION] |
| [ACCOUNTANT / BOOKKEEPING] | Statutory accounting | [REGION] |
We put a written data-processing agreement in place with each provider. We do not authorise them to use your data for their own purposes.
5. International transfers
Where a provider processes data outside [YOUR COUNTRY / THE UK / THE EEA], we rely on an approved transfer mechanism such as an adequacy decision or the applicable Standard Contractual Clauses / UK International Data Transfer Addendum, together with appropriate safeguards.
6. How long we keep data
- Enquiries that do not become projects: up to [12] months, then deleted.
- Client records: for the life of the engagement and up to [6/7] years afterwards to meet tax and legal requirements.
- Server logs: retained by the hosting provider for [its standard period, e.g. 14–30 days].
7. Your rights
Depending on where you live, you may have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected, or incomplete data completed;
- ask us to delete data, or restrict or object to how we use it;
- ask for a portable copy of data you provided to us;
- withdraw consent where we relied on it, without affecting prior processing;
- for California residents: know, delete, correct, and opt out of "sale"/"sharing" (we do neither), without discrimination for exercising these rights.
To exercise any right, email mr.cometwebsites@gmail.com. We respond within one month. If you are in the UK or EEA and are unhappy with our response, you can complain to your supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk).
8. Security
We use HTTPS across the site, keep software and dependencies patched, limit access to client systems to the people who need it, use unique credentials and multi-factor authentication where available, and hold off-site encrypted backups. No method of transmission or storage is completely secure, but we take these measures seriously and review them regularly.
9. Children
This site and our services are aimed at businesses and are not directed to children under 16. We do not knowingly collect their personal data.
10. Changes to this policy
We will post any changes on this page and update the date above. Material changes affecting clients will also be sent by email.
11. Contact
[REGISTERED BUSINESS NAME]
[FULL REGISTERED ADDRESS]
mr.cometwebsites@gmail.com