Your data, handled properly
We build systems that capture leads and hold customer data, so trust is part of the product. Here is exactly how we protect your information, secure our platform and operate as a legitimate business.
Data handling & privacy
Built to UK GDPR practice
We handle personal data in line with UK GDPR and the Data Protection Act 2018 — collecting only what we need to scope and deliver your work, and publishing exactly who processes it.
Where your data is processed
Customer data is stored in Appwrite Cloud (Frankfurt). Website hosting, AI replies and enquiry email are processed outside the UK/EEA — Vercel, Anthropic (Claude), OpenAI, Groq, Resend — under Standard Contractual Clauses with the UK Addendum. The full list is in our [Privacy Policy](/privacy).
A Data Processing Agreement with every processor
We keep the number of companies that touch your data to a minimum, and each one processes it under a Data Processing Agreement — the contract that binds them to protect it and use it only as we instruct. No processor is used without one.
Encrypted in transit
Every page and API call is served over HTTPS/TLS, so data moving between your browser and our systems is encrypted end to end.
We never sell your data
We do not sell, rent or share your personal data with third parties for marketing — ever.
Your rights, on request
You can ask us to access, correct or delete your data at any time and we respond within 30 days. See our Privacy Policy for the detail.
Clear data retention
Enquiry data is retained for up to two years after last contact and then deleted. You can request earlier deletion at any point.
Security practices
HTTPS everywhere
The whole site runs on TLS with a global CDN, so there is no unencrypted path to our systems.
Secure session handling
The client portal uses HttpOnly, secure session cookies — login credentials are never exposed to browser scripts.
Least-privilege access
Admin areas are role-gated; only authorised accounts can reach the portal, leads and customer data.
Reputable infrastructure
We build on vetted providers — Vercel, Appwrite Cloud, Anthropic (Claude), OpenAI, Groq, Resend — each maintaining its own security and compliance posture.
No third-party ad cookies
We use privacy-friendly analytics and set no third-party advertising or tracking cookies.
Defensive engineering
Form inputs are validated and spam-protected, and we keep dependencies current to limit exposure to known issues.
Company & legitimacy
- Trading name
- Neubor
- Based in
- Stoke-on-Trent, United Kingdom
Full company registration, VAT and insurance details are available on request — just ask and we'll send them over.
Questions about security, data processing or compliance? Email kieran@neubor.co.uk and we'll answer plainly.