Last updated: 22 July 2026
Who is responsible?
James Elliot Smith, trading as Vitalflow Creative, is the controller for personal data collected through this website and its contact forms. Contact: james@vitalflowcreative.com, 8 Toppesfield Road, Great Yeldham, United Kingdom.
What we collect
When you contact us, we collect the details you choose to provide, such as your name, work email, business type, and message. We do not ask for sensitive personal data. The website may also process essential technical data needed to deliver and secure the service.
Why we use it
We use enquiry data to respond to your request and, where relevant, prepare for a conversation. The legal basis is Article 6(1)(b) UK GDPR / GDPR where your request is to take steps before a contract, or Article 6(1)(f) for legitimate business communication. We use consent where consent is specifically requested. We do not sell enquiry data or use it for unrelated marketing without permission.
Analytics and cookies
We use essential local storage to remember your cookie choice. With your explicit consent, we use Umami analytics to understand aggregate website use, including pages visited, referring pages, device and browser information, and approximate location inferred from IP address. Umami is not loaded until you opt in. We exclude URL search and hash values from analytics and do not send contact-form contents or other directly identifying information to Umami.
The analytics legal basis is your consent under Article 6(1)(a) UK GDPR / GDPR. You can accept, reject, or change your choice at any time through . Withdrawal does not affect processing before it was withdrawn.
Service providers
Contact form messages are sent through Resend, our email delivery provider. If you consent to analytics, Umami processes analytics data on our behalf. We may also use hosting and infrastructure providers necessary to operate this website. See Umami’s privacy policy and Resend’s privacy policy.
Retention and security
We keep enquiry data only as long as needed to handle the request and any resulting relationship, then delete or securely archive it according to our retention process. Analytics data is retained only for as long as needed to understand and improve the site, then deleted or aggregated. We use data minimisation, server-side secrets, input validation, rate limiting, origin checks, anti-bot controls, and encrypted HTTPS transport. No online service can promise absolute security.
Your rights
Subject to UK GDPR / GDPR conditions, you can ask for access, correction, deletion, restriction, portability, or object to processing. Where processing relies on consent, you can withdraw it at any time. You can also complain to your local supervisory authority; in the UK, this is the ICO, and in Germany, the competent Landesdatenschutzbehörde.
International transfers
Some providers may process data outside the UK or EEA. Where this happens, we use a valid UK GDPR / GDPR transfer mechanism and appropriate safeguards, such as an adequacy decision or standard contractual clauses, as applicable.