Privacy Policy
How Dark Alchemy Creative collects, uses and protects personal information.
Last updated 24 July 2026
The short version
We collect only the information needed to respond to enquiries, arrange calls, deliver our services, run the business and keep the website secure. We do not sell personal information. You can ask us about your information or object to marketing at any time.
1. Who we are
Dark Alchemy Creative (referred to as “we”, “us” or “our” in this policy) is a UK creative agency providing branding, website design and development, marketing, content and related creative services.
For personal information collected through this website or in connection with our own business activities, Dark Alchemy Creative is the data controller. This means we decide why and how that information is used.
You can contact us about this policy or your personal information at:
Email: contact@darkalchemycreative.com
Website: www.darkalchemycreative.com
2. What this policy covers
This policy explains how we handle personal information when you visit our website, contact us, book a call, become a client or supplier, receive business-to-business communications from us, or otherwise deal with Dark Alchemy Creative.
It does not govern websites or services operated by other organisations. Where our website links to another service, such as Cal.com, LinkedIn or Instagram, that organisation will also handle information under its own privacy policy.
3. Personal information we collect
Depending on how you interact with us, we may collect:
Identity and contact details, such as your first and last name, email address, telephone number, job title, company name and professional social media details.
Enquiry and project information, including your message, service interests, goals, budget, timings, references, files and any other information you choose to provide.
Booking information, such as meeting preferences, availability, time zone and information supplied through Cal.com.
Client and supplier records, including proposals, contracts, statements of work, project communications, approvals, deliverables and relationship history.
Financial and transaction information, such as billing details, invoices, payments and accounting records. We do not intentionally store full payment-card details.
Marketing information, including your communication preferences, whether you have opted out, and your response to relevant business communications.
Website and technical information, such as IP address, browser and device type, pages viewed, approximate location, referral source, timestamps, security logs, and cookie or consent choices.
Information contained in content or assets supplied for a project, which may include photographs, video, audio, testimonials, customer data or social media material.
Please do not send sensitive personal information through the contact form unless it is genuinely necessary. If a project requires us to handle sensitive information, we will agree appropriate safeguards with you first.
4. How we collect information
We collect personal information:
directly from you, for example when you complete the contact form, email us, book a call, sign a contract or work with us;
from your organisation, colleagues, representatives or a person who refers you to us;
from publicly available professional sources, such as a company website, Companies House, LinkedIn or another public business directory, where relevant to business development;
automatically through website hosting, security, server logs, cookies or similar technologies; and
from service providers that help us operate the website, schedule calls, communicate, invoice, store files or deliver projects.
5. How and why we use personal information
UK data protection law requires us to have a lawful basis for each use of personal information. We use information for the following purposes:
To respond to enquiries and arrange calls. We use your contact details, message and booking information to understand what you need, respond, prepare for a discovery call and take steps at your request before entering a contract. Our lawful bases are steps before a contract and our legitimate interests in responding to potential clients.
To provide and manage services. We use client, project and communication records to plan, create, review, deliver and support agreed work. Our lawful bases are performance of a contract and our legitimate interests in managing projects and client relationships.
To administer the business. We use relevant information for proposals, contracts, invoicing, payments, bookkeeping, tax, insurance, complaints and legal claims. Our lawful bases are contract, legal obligation and legitimate interests.
To operate, protect and improve the website. We use technical and usage information to deliver pages, prevent abuse, diagnose faults, understand performance and improve usability. Our lawful bases are legitimate interests, and consent where required for optional cookies or similar technologies.
For relevant business-to-business marketing. We may contact organisations or professional contacts about services we reasonably believe may be relevant. We rely on legitimate interests under data protection law and comply with the Privacy and Electronic Communications Regulations, including obtaining consent where the law requires it. You can object or opt out at any time.
To showcase work. We may publish a case study, testimonial or project example only where we have an appropriate lawful basis and the permissions required by our agreement with the client or the people concerned.
Where we rely on legitimate interests, we consider the benefit to our business and clients, whether the use is necessary, what a person would reasonably expect, and the possible impact on their rights. We do not rely on legitimate interests where those rights override our interests.
6. Marketing and outreach
We may use professional contact information that you provide, that your organisation provides, or that has been made publicly available for business purposes to send limited and relevant business communications.
Every recipient can ask us to stop. You can opt out by replying to the message or emailing contact@darkalchemycreative.com. We may keep a minimal suppression record so that we do not contact you again by mistake.
We do not sell personal information. We do not share contact details with unrelated organisations so they can run their own marketing.
7. Contact forms and call bookings
Contact form
Our contact form currently asks for your first name, last name, email address, telephone number and message. We use this information only to assess and respond to your enquiry, keep an appropriate record of the conversation, and take any next steps you request.
Cal.com
If you use our booking link, Cal.com processes the information needed to arrange the meeting. Cal.com acts under its own privacy terms for its platform and may also process information on our behalf. Please review Cal.com’s privacy information before submitting a booking.
8. Cookies and similar technologies
Our website may use cookies, server logs, scripts or similar technologies. Some are strictly necessary for the website to function, remain secure or remember a choice you make. Others, such as analytics or advertising technologies, are optional.
Where consent is legally required, optional technologies will not be activated until you choose to accept them. Any cookie controls displayed on the website provide the current categories, purposes, providers and expiry periods, and allow you to change your choices.
You can also control cookies through your browser. Blocking strictly necessary technologies may cause parts of the website to stop working correctly.
9. Who we share information with
We share personal information only where it is reasonably necessary. Recipients may include:
website hosting, maintenance, security, backup, form and email providers, including WPMU DEV where its services are used;
Cal.com for discovery-call and meeting bookings;
cloud storage, document collaboration, communication and project-management providers;
accounting, invoicing and payment-service providers;
freelancers, contractors or specialist partners working under confidentiality and only where needed to deliver agreed work;
professional advisers such as accountants, insurers, solicitors or auditors;
regulators, courts, law-enforcement bodies, tax authorities or other parties where disclosure is required by law or needed to protect legal rights; and
a buyer, investor or successor if all or part of our business is reorganised, sold or transferred, subject to appropriate confidentiality safeguards.
Service providers acting as processors may use personal information only on our documented instructions, for the agreed service, and with appropriate security and confidentiality obligations.
10. When we process information for a client
Some creative, website, social media or marketing projects require us to handle personal information supplied or controlled by a client. In those circumstances, the client may be the data controller and Dark Alchemy Creative may act as its data processor.
Where we act as a processor, we use that information only on the client’s documented instructions and under the relevant contract or data processing terms. Requests about that information should normally be directed to the client that controls it.
11. International transfers
Some service providers may store or access personal information outside the United Kingdom. Where this creates a restricted international transfer, we use a lawful transfer mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law.
You can contact us if you would like more information about the safeguards relevant to your information.
12. How long we keep information
We keep personal information only for as long as it is needed for the purpose collected, including:
Enquiries that do not become projects: normally up to 24 months after the last meaningful contact.
Client, contract and project records: normally for the engagement and up to 6 years after it ends, where needed for tax, accounting, insurance or legal claims.
Invoices and accounting records: normally 6 years or any longer period required by law.
Marketing records: until you opt out or the information is no longer relevant. We may retain a minimal suppression record after an opt-out.
Website security and server logs: normally up to 12 months, unless a longer period is needed to investigate an incident.
Cookie and consent records: for the period shown in the website’s cookie controls or as otherwise required to demonstrate your choices.
We may keep information for longer where a dispute, legal claim, regulatory enquiry or contractual obligation requires it. When information is no longer needed, we delete it securely or anonymise it.
13. How we protect information
We use reasonable technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, alteration or disclosure. These measures include access controls, secure accounts, updates, backups, confidentiality requirements and limiting information to people who need it.
No online service is completely risk-free. Please avoid sending confidential or sensitive information through an ordinary website form or unencrypted email unless we have agreed an appropriate method.
14. Your data protection rights
Depending on the circumstances, you may have the right to:
ask for a copy of the personal information we hold about you;
ask us to correct inaccurate or incomplete information;
ask us to delete information in certain circumstances;
ask us to restrict how information is used;
object to processing based on legitimate interests;
object at any time to the use of your information for direct marketing;
ask to receive information you provided in a portable format where the right applies;
withdraw consent at any time where we rely on consent, without affecting earlier lawful processing; and
complain to the Information Commissioner’s Office.
These rights are not absolute and an exemption may apply. We may need to verify your identity before acting on a request. We normally respond within one calendar month and do not charge a fee unless a request is manifestly unfounded or excessive.
Your absolute right to stop direct marketing
You can object to direct marketing at any time. Email contact@darkalchemycreative.com or reply to the message you received. We will stop the marketing and keep only the minimum information needed to honour your request.
15. Complaints
If you are concerned about how we use personal information, please contact us first at contact@darkalchemycreative.com so we can investigate.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection. Its current contact information is available at www.ico.org.uk.
16. Children
Our website and services are intended for businesses and adults. We do not knowingly collect personal information from children through this website. If you believe a child has provided information to us, please contact us so we can review and, where appropriate, delete it.
17. Automated decision-making
We do not use personal information collected through this website to make decisions about you solely by automated means that produce legal or similarly significant effects.
18. Changes to this policy
We may update this policy when our services, website technology, suppliers or legal obligations change. The latest version will be published on this page with a revised “last updated” date. If a change materially affects how we use information, we will take reasonable steps to bring it to the attention of affected people.
19. Contact
Privacy enquiries and rights requests can be sent to:
Dark Alchemy Creative
Email: contact@darkalchemycreative.com
Website: www.darkalchemycreative.com
