Privacy notice
What we collect, why we have it, who else sees it, and how to make us delete it. This site sets no cookies, runs no analytics and tracks nobody — so most of what a notice like this usually covers doesn't apply here.
Last updated 9 August 2026.
Who is responsible for your information
Kieran Smith, trading as Wardith, is the data controller. That means the decisions about your information are one person's, and the person is named.
- Email hello@wardith.co.uk
- Address Lytchett House, 13 Freeland Park
Wareham Road
Poole
Dorset
BH16 6FA - ICO registration C1995412 — checkable on the Information Commissioner's public register
Visiting this website
No cookies. No analytics. No tracking pixels. Nothing on these pages watches what you read, and nothing follows you to another site. We couldn't tell you how many people visited this page today, and we've decided we'd rather not know than build the thing that would tell us.
Two ordinary exceptions, both worth naming rather than glossing over. Our host, Netlify, keeps short-lived server logs including IP addresses, as every web host does — that's what serving a page involves. And the site loads its typefaces from Google Fonts, which means your browser asks Google for them and Google sees your IP address in the process. Neither is used to identify or profile you by us, and we'd rather you knew about the second one than found it in the page source.
Getting in touch, or ordering
If you email us, we have your email address and whatever you wrote. If you order the audit, the form asks for your business name, your email address, your website, the services you want to be found for, the area you serve, and — optionally — what people usually ask you and what a new customer is worth. That's the whole list, and every field on it is there because the report needs it.
Why we're allowed to hold it: because you asked us to do something. For an enquiry that's our legitimate interest in replying to people who write to us; for an order it's performing the contract you've entered into.
Order form submissions go through Netlify Forms, so they sit in Netlify's system before they reach our inbox. Payments are taken by Revolut, who handle your card details — we never see or hold them.
If you become a client
We keep a record of the work: your business name, contact name and email, website, what you want to be found for, the area you serve, which plan you're on and what you've paid, what we did and when, the results of each check, and any access you've given us. It is held by us, on our own encrypted computer, in the United Kingdom.
Invoices and payment records go through Zoho Books and our bank, Revolut. Email is Zoho Mail, on their European servers.
The part that is specific to what we do
An audit works by asking other companies' AI assistants about you. To find out how they answer, we have to ask them — so your business name, your website and questions about what you do are typed into systems run by OpenAI, Google, Perplexity and Microsoft, and those companies process them under their own terms. We use business API accounts where the provider offers one, which by default keeps the queries out of model training, and for the two assistants that have to be checked by hand we use the ordinary consumer apps.
For most clients this is information about a company and not about a person at all. For a sole trader whose business carries their own name, it is both. Either way, we would rather write this paragraph than leave you to work it out.
We never send these providers your customers' details, your files, or anything from your website beyond what is already published on it.
If we contact you first
We sometimes approach businesses that look like a good fit. Where we do, we hold the business name, a contact, where we found you, what we said and what came back — on the basis of our legitimate interest in finding customers. Say "don't contact me again" and we record that permanently, which is the only way to be sure it's honoured.
Who else sees your information
Only the companies above, and only for the job each one does. We do not sell your information, rent it, or share it for anyone else's marketing. Nobody makes automated decisions about you.
We'd disclose information if the law required it — a court order, a tax investigation — and not otherwise.
Some of these companies are based outside the UK, mostly in the United States. Where information goes overseas it is covered by the safeguards UK data protection law requires, which in practice means the UK extension to the EU–US Data Privacy Framework or the standard contractual clauses.
How long we keep it
- Enquiries Twelve months, if they don't turn into work.
- Client records For as long as we're working together, and twelve months after that. A client who comes back inside a year is much better served by us still having their baseline; past that it's stale data held for no reason.
- Invoices and payments As long as tax law requires — currently at least five years after the 31 January submission deadline for the relevant tax year. This one isn't our choice.
- Do-not-contact requests Permanently. Deleting the request would defeat its purpose.
Keeping it safe
Accounts carry two-factor authentication where the provider offers it, records are encrypted at rest, and access is limited to one person because there is only one person. Client records are never put in our public code repository — a rule written down precisely so that nobody has to remember it. No system is perfect; if something went wrong that affected you, we'd tell you, and we'd tell the ICO where the law requires it.
What you can ask for
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable format, or object to us holding it at all. Email hello@wardith.co.uk and we'll answer within one month. It's free, and you don't have to give a reason.
In practice this is one person opening a spreadsheet, so a deletion request usually takes minutes rather than the month the law allows.
If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd rather you told us first and gave us the chance to fix it, but it's your right either way and you don't need our permission to use it.
Changes to this notice
The date at the top is when this was last changed. If something material changes — a new company handling your information, a longer retention period — we'll say so here rather than quietly amend it, and we'll email current clients.