Privacy Policy

Last updated: 18 April 2026

This policy explains how SFS Models collects, uses, and protects personal data when you visit sfsmodels.org or purchase one of our products. We are committed to handling your data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

SFS Models (“we”, “us”, “our”) is the trading name of [BUSINESS NAME / COMPANY NUMBER], with a correspondence address at [BUSINESS ADDRESS, LONDON, UK]. We are the data controller responsible for your personal data. For any questions about this policy or how we handle your data, contact us at sfsmodels362@gmail.com.

2. What Personal Data We Collect

We collect only the data we need to deliver our products and respond to enquiries:

  • Enquiry data — when you submit the contact form or custom-model request form: name, email address, business name, sector, role, and the content of your message.
  • Transaction data — when you purchase a model: name, email address, billing country, and order details. Payment is processed by our payment provider (Lemon Squeezy); we do not receive or store your card details.
  • Sample-download data — when you request a free sample: name and email address.
  • Technical data — when you browse the site: IP address, browser type, operating system, referring URL, pages viewed, and session duration. This is collected via standard server logs and, where enabled, Google Analytics (see Section 8).

We do not knowingly collect data from anyone under 18. Our products are intended for business use by finance professionals.

3. Why We Collect It (Lawful Basis)

Under UK GDPR, we rely on the following lawful bases:

  • Contract — to process your order, deliver your download, and provide support. We need your name and email to fulfil these obligations.
  • Legitimate interests — to respond to enquiries, prevent fraud, secure the website, and improve our products. We have balanced these interests against your rights and consider our use reasonable.
  • Legal obligation — to retain transaction records for tax and accounting purposes (HMRC requires records to be kept for six years).
  • Consent — where we use non-essential cookies or send marketing communications. You can withdraw consent at any time.

4. How Long We Keep It

  • Transaction records — six years from the end of the tax year in which the sale occurred, to meet HMRC requirements.
  • Enquiry and support emails — up to two years from the last contact, then deleted.
  • Sample-download records — up to two years from the download request.
  • Server logs and analytics — retained for up to 14 months.

5. Who We Share It With

We do not sell your personal data. We share it only with the third-party service providers we use to run the business:

  • Lemon Squeezy — payment processing and order fulfilment (merchant of record). See lemonsqueezy.com/privacy.
  • Google (Analytics) — aggregated website analytics, where enabled. See policies.google.com/privacy.
  • Email provider — for delivering download links and responding to enquiries.
  • Hosting provider — for serving the website and storing server logs.

We may also disclose personal data where required by law, court order, or to protect our legal rights.

6. International Transfers

Some of our service providers (including Lemon Squeezy and Google) are based outside the UK. Where personal data is transferred outside the UK, we rely on safeguards approved under UK GDPR, including the UK International Data Transfer Agreement, Standard Contractual Clauses, or transfers to jurisdictions with UK adequacy decisions.

7. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), access controls, and using reputable third-party providers with recognised security standards. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

8. Cookies and Analytics

We use a small number of cookies and similar technologies:

  • Strictly necessary cookies — required for the website to function (e.g. remembering you have dismissed a notice). These do not require consent.
  • Analytics cookies — Google Analytics 4 (GA4), where enabled, to understand how the site is used in aggregate. GA4 uses cookie-less measurement by default, but may set cookies depending on configuration.

You can control or delete cookies through your browser settings. Blocking cookies may affect some functionality of the site.

9. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where we no longer have a lawful basis to keep it.
  • Restriction — ask us to pause processing of your data in certain circumstances.
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — withdraw any consent you have previously given.

To exercise any of these rights, email us at sfsmodels362@gmail.com. We will respond within one month. There is no charge for exercising your rights in most cases.

10. Complaints

If you believe we have handled your data unlawfully, you have the right to complain to the UK Information Commissioner's Office (ICO). You can contact the ICO at ico.org.uk or by phone on 0303 123 1113. We would appreciate the chance to address your concerns first, so please contact us before approaching the ICO where possible.

11. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. The “Last updated” date at the top of the page will be revised. Material changes will be highlighted on the site for a reasonable period.

12. Contact

For any privacy-related question, data request, or concern, contact us at sfsmodels362@gmail.com.