Legal
Privacy Policy
What personal data we collect, why we collect it, who we share it with, how long we keep it and the rights you have over it.
Last updated 1 September 2026 · Effective 1 September 2026
1. Who we are and how to contact us
This privacy policy explains how Jammy Digital Ltd ("we", "us", "our"), trading as SEO Starter Pack, collects, uses, stores and protects personal data when you visit seostarterpack.net, buy the SEO Starter Pack, enquire about our services or subscribe to our emails.
We are the data controller for the personal data described in this policy. That means we decide why and how your data is processed, and we are legally responsible for it.
| Company | Jammy Digital Ltd (registered in England & Wales) |
|---|---|
| Company number | 09283726 |
| VAT number | GB 204 1932 55 |
| Registered address | Steam Mill Business Centre, Steam Mill Street, Chester CH3 5AN, United Kingdom |
| Data protection contact | [email protected] |
| General enquiries | [email protected] |
If you have a question about this policy, or you want to exercise any of the rights described in section 9, email our data protection contact above. We aim to respond within five working days and are required to respond substantively within one month.
2. The personal data we collect
We collect only what we need. The table below sets out each category, what it contains and where it comes from.
| Category | What it includes | Source |
|---|---|---|
| Identity & contact data | Name, business name, email address, telephone number, billing address and country | You, when you buy, enquire or subscribe |
| Transaction data | Products purchased, price paid, VAT treatment, VAT number, invoice records, refund records | You and our payment processor |
| Payment data | Card type, last four digits, expiry, authorisation result. We never receive or store your full card number or security code. | Our payment processor |
| Account data | Login username, hashed password, course progress, downloads, last sign-in | You and our course platform |
| Enquiry content | The message you send us, your website address and what you tell us about your business | You |
| Technical data | IP address, browser type and version, device type, operating system, time zone, referring URL | Automatically, via our hosting and analytics |
| Usage data | Pages viewed, time on page, links clicked, videos watched, files downloaded | Automatically, via analytics (with consent) |
| Marketing preferences | Whether you have consented to marketing email, and any unsubscribe or bounce records | You and our email platform |
Special category data
We do not seek or knowingly collect special category data — that is, data about health, race or ethnicity, religious or political beliefs, sex life, sexual orientation, trade union membership, genetics or biometrics. Please do not include such information in enquiry forms or emails.
Children
Our products are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.
3. How and why we use your data
Under the UK GDPR we must have a lawful basis for each use of personal data. Ours are set out below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Giving you access to a product you bought, and supporting you with it | Identity, contact, account, transaction | Performance of a contract |
| Taking payment and issuing a VAT invoice | Identity, contact, payment, transaction | Performance of a contract; legal obligation |
| Replying to an enquiry or quoting for a service | Identity, contact, enquiry content | Legitimate interests (responding to a request you made) |
| Delivering a service you engaged us for | Identity, contact, enquiry content, website data | Performance of a contract |
| Keeping accounting and tax records | Transaction, identity, contact | Legal obligation (six years, UK tax law) |
| Sending marketing email you asked for | Contact, marketing preferences, usage | Consent (withdrawable at any time) |
| Sending service email to existing customers about similar products | Contact, transaction | Legitimate interests / soft opt-in, with an unsubscribe link in every message |
| Understanding how the site is used so we can improve it | Technical, usage | Consent for analytics cookies; legitimate interests for aggregate server logs |
| Keeping the site secure and preventing fraud and abuse | Technical, transaction | Legitimate interests; legal obligation |
| Enforcing our terms or defending a legal claim | Any relevant data | Legitimate interests; legal obligation |
Where we rely on legitimate interests
Where we rely on legitimate interests, we have considered whether that interest is fair to you, whether you would reasonably expect the processing, and whether it could be achieved in a less intrusive way. You can ask us for a copy of that assessment at any time.
Automated decision-making
We do not make decisions about you by purely automated means that have a legal or similarly significant effect on you. Our payment processor may run automated fraud checks on a transaction; if a payment is declined on that basis you can contact us and we will review it manually.
4. Marketing communications
We send at most one marketing email a month, plus occasional notices about updates to a product you own.
- How you get on the list. By ticking the box on the newsletter form, on the checkout form, or by asking us directly.
- What we send. A summary of what changed in search that month, new guides, and occasionally an offer on our own products. We do not send third-party advertising.
- How to stop. Click "unsubscribe" in any email, or email us. We action unsubscribes immediately and keep a minimal suppression record so that you are not added again by mistake.
- What continues anyway. Transactional email — receipts, licence details, password resets, and notices that materially affect a product you bought. You cannot unsubscribe from these while you hold an account, though you can close the account.
We never sell, rent or share your email address with another organisation for their own marketing.
5. Cookies and similar technologies
We use a small number of cookies. Essential cookies are set automatically because the site cannot work without them; everything else is only set after you consent through the banner.
| Type | Purpose | Consent needed |
|---|---|---|
| Essential | Remembering your cookie choice, keeping you signed in, cart and checkout state, security tokens | No |
| Preference | Remembering filters, your progress through the interactive checklist and similar conveniences | No — stored locally in your browser only |
| Analytics | Aggregate, de-identified statistics about which pages are used | Yes |
| Marketing | Measuring whether an advert led to a purchase | Yes |
The full list, including cookie names, providers and retention periods, plus how to change your mind, is in our cookie policy.
6. Who we share your data with
We do not sell your personal data. We share it only with the service providers we need in order to run the business, and only to the extent each provider needs.
| Recipient type | Why | Location |
|---|---|---|
| Payment processor | Taking card payments, fraud checks, refunds, chargebacks | UK / EU / US |
| Course and membership platform | Hosting your login and the training content | US |
| Email service provider | Sending transactional and marketing email | EU / US |
| Website hosting and CDN | Serving the site and protecting it from attack | EU / US |
| Analytics provider | Aggregate usage statistics, where you have consented | EU / US |
| Accountants and auditors | Statutory accounts and tax returns | UK |
| Professional advisers | Legal advice, insurance, debt recovery where necessary | UK |
| Authorities | Where we are legally required to disclose | UK |
Every provider is bound by a written contract that requires them to process personal data only on our instructions, to keep it secure and confidential, and to delete or return it at the end of the relationship. We review our providers periodically and will name the current ones on request.
Business transfers
If the business is sold or merged, personal data may transfer to the buyer as part of the transaction. We would tell you before that happened and the buyer would remain bound by this policy until it told you otherwise.
7. International transfers
Some of our providers are based outside the United Kingdom, principally in the United States and the European Economic Area. Where personal data leaves the UK we make sure one of the following protections is in place:
- The country has UK adequacy regulations (this includes the EEA and, for certified organisations, the UK Extension to the EU–US Data Privacy Framework).
- The International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, is signed with the provider.
- Additional technical measures such as encryption in transit and at rest, and pseudonymisation where practical.
You can ask us for a copy of the relevant safeguard for any specific transfer by emailing our data protection contact.
8. How long we keep things
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires.
| Data | Retention period | Reason |
|---|---|---|
| Accounting and VAT records (including invoices) | 6 years from the end of the accounting period | UK tax law |
| Customer account and course progress | While your licence is active, then 24 months | Support and licence verification |
| Enquiries that did not become customers | 24 months from last contact | Follow-up and dispute records |
| Marketing list membership | Until you unsubscribe, then a minimal suppression record indefinitely | To honour your objection |
| Service project files and deliverables | 3 years after the project ends | Warranty, reference and dispute resolution |
| Server access logs | Up to 90 days | Security and troubleshooting |
| Analytics data | Up to 14 months, aggregated | Year-on-year comparison |
At the end of the applicable period we delete the data, or anonymise it so it can no longer be linked to you, in which case we may keep the anonymised statistics indefinitely.
9. Your rights
Under UK data protection law you have the following rights. All of them are free to exercise, and you will not be treated less favourably for using them.
- Access. Ask for a copy of the personal data we hold about you, and information about how we use it.
- Rectification. Ask us to correct data that is inaccurate, or complete data that is incomplete.
- Erasure. Ask us to delete your data where we no longer have a good reason to keep it. This does not override our legal duty to retain accounting records.
- Restriction. Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability. Ask for the data you gave us in a structured, commonly used, machine-readable format, or ask us to send it to another controller.
- Objection. Object to processing based on legitimate interests, and object at any time to direct marketing (which we will always honour).
- Withdraw consent. Where we rely on consent — marketing email, analytics cookies — withdraw it at any time, without affecting anything done before you withdrew it.
- Human review. Ask for a human to review any decision that felt automated.
How to make a request
Email [email protected] telling us which right you want to use and what you are asking for. We may ask you to confirm your identity — usually by replying from the address we hold — so that we do not disclose your data to someone else. We will respond within one month, and will tell you if we need up to two further months because the request is complex.
If you are unhappy
Please tell us first; most issues are a misunderstanding we can fix quickly. You also have the right to complain to the UK's supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk
10. How we keep data secure
No system is perfectly secure, but we take proportionate measures for a business of our size:
- HTTPS across the entire website, with modern TLS configuration.
- Card data handled entirely by a PCI-DSS compliant payment processor; we never see or store full card numbers.
- Access to customer data limited to the two directors, on a need-to-know basis, protected by unique accounts and two-factor authentication.
- A password manager for all credentials; no shared logins.
- Encrypted device storage and automatic screen locking.
- Backups held encrypted, with restores tested periodically.
- Written contracts with every processor, and a review of their security posture before we adopt them.
If something goes wrong
We have a breach response procedure. If a breach is likely to result in a risk to your rights and freedoms we will report it to the ICO within 72 hours of becoming aware of it, and if the risk is high we will tell you directly, explaining what happened, what data was involved, what we are doing and what you should do.
11. Third-party links and embedded content
Our guides link out to other websites and sometimes embed content such as video. Following a link means you are subject to that site's own privacy policy, which we do not control, and embedded content may set its own cookies or collect usage data.
Where we embed third-party media we use privacy-enhanced modes where the provider offers them, and we do not load such embeds until you interact with them where that is technically possible.
12. Changes to this policy
We review this policy at least annually and whenever we change how we handle personal data. The date at the top always reflects the current version.
If a change materially affects how we use data you have already given us — for example a new purpose, or a new category of recipient — we will tell you by email before it takes effect, and where the law requires it we will ask for fresh consent.
We keep previous versions for two years and will send you an earlier version on request.