Privacy Policy

This website is operated by Exposure Ninja (“we”, “us”, “our”). We are the data controller responsible for your personal data.

If you have any questions about this policy or how we use your data, you can contact us at: [email protected]

The Data We Collect

We may collect and process the following personal data:

Information you provide directly:

  • Name (first and last)
  • Email address
  • Phone number (if provided)
  • Company name
  • Business information (e.g. marketing goals, turnover where relevant).

Information collected automatically:

  • IP address
  • Usage data (pages visited, time on site, interactions).

Depending on how you interact with us, we may also collect and process:

  • call recordings, meeting recordings, meeting notes and transcripts where calls or meetings are recorded;
  • account access details, permissions and information from platforms such as Google Analytics, Google Ads, Meta Ads, CRM systems, CMS platforms, hosting environments and reporting tools;
  • information contained in client platforms, reports, dashboards, briefs, forms, uploads, emails and other materials made available to us in connection with our services.

Sensitive data

We do not intentionally collect sensitive personal data (e.g. health, religion, political views).

How We Use Your Data

We only process your data where we have a lawful basis under UK GDPR. You can withdraw consent at any time by clicking “unsubscribe” in emails or contacting us.

Purpose

Data Used

Legal Basis

Provide marketing reviews or services

Contact details, business info

Contract

Send marketing emails and training content

Name, email

Consent

Respond to enquiries

Contact details

Legitimate interest

Improve website performance

Usage data, IP

Legitimate interest

Manage client relationships

Client data, login info

Contract

We may also use personal data to:

  • record calls or meetings for training, quality, note-taking, project delivery, dispute resolution and record-keeping;
  • access, review, analyse and report on client accounts, platforms and systems where this is necessary to provide our services;
  • manage client relationships, deliver services, respond to enquiries, provide support, maintain records and comply with legal or regulatory obligations.

 

International Transfers

Where personal data is transferred outside the UK, we use appropriate safeguards where required, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.

Where we use service providers based outside the UK, or where data may be accessed from outside the UK, we take steps designed to ensure that personal data continues to receive appropriate protection in accordance with applicable Data Protection Laws.

How We Share Your Data

We only share your data where necessary, including with trusted service providers such as:

  • Cloud storage providers (e.g. Google Drive)
  • CRM systems
  • Email marketing platforms
  • Project management and communication tools.

All third parties are required to process your data securely and in line with data protection law.

We do not sell your personal data.

International Data Transfers

Some of our service providers and staff may access data outside the UK.

Where this happens, we ensure appropriate safeguards are in place, such as:

  • UK-approved Standard Contractual Clauses (SCCs)
  • Transfers to countries with adequacy decisions.

Data Retention

We only keep your data for as long as necessary:

  • Leads: up to 24 months from last interaction
  • Clients: up to 6 years (for legal and accounting purposes)
  • Marketing data: until you withdraw consent.

We securely delete or anonymise data when no longer needed.

Your Rights

Under UK data protection law, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent at any time.

To exercise your rights, contact: [email protected]

You also have the right to lodge a complaint with the UK regulator, the Information Commissioner’s Office (ICO):
https://ico.org.uk

Data Security

We take appropriate technical and organisational measures to protect your data, including:

  • Secure cloud-based storage
  • Access controls and authentication measures
  • Staff training on data protection
  • Regular password updates.

While no system is completely secure, we actively work to protect your information and respond quickly to any incidents.

Data Breaches

If a data breach occurs, we will:

  • Investigate and contain the issue
  • Assess the risk to individuals
  • Notify affected users where required
  • Report to regulators where legally necessary.

Cookies and Tracking

We use cookies and similar technologies to:

  • Improve website performance
  • Understand user behaviour.

You can control cookies through your browser settings.

Our website may contain links to third-party websites.
We are not responsible for their privacy practices, and we encourage you to review their policies.

Changes to This Policy

We may update this policy from time to time.
The latest version will always be published on this page.

Contact and Complaints

If you have concerns about how we use your data, please contact us first so we can resolve the issue.

You can also raise a complaint with the ICO if you are not satisfied with our response.

Our Approach to Data Responsibility

We are committed to:

  • Collecting only the data we genuinely need
  • Being transparent about how it is used
  • Giving you control over your information
  • Handling data in a secure and responsible way.

Any requests for access to data, requests to be forgotten, reports of a breach, or any other matter relating to the management of or access to personal data should be immediately passed to Charlie Marchant at [email protected].

Policy reviewed and updated: April 2026.