Privacy
This site does not collect anything.
Most privacy policies are long because the site behind them is doing a lot. This one is short for the opposite reason: there is no analytics, no tracking, no cookies and no form. What follows is the detail, plus what changes if you become a client.
In effect from
Who this notice is from
This site is operated by Premark Lab Limited, a company registered in England and Wales under number 17391216, trading as SEO for Therapists. For the purposes of the UK GDPR and the Data Protection Act 2018, that company is the data controller for the information described below.
Premark Lab Limited71-75 Shelton StreetCovent GardenLondonWC2H 9JQUnited KingdomThat is a registered office, not a walk-in address. Everything is done remotely, and the way to reach anyone is hello@seofortherapists.org.
What this website collects
Nothing. There is no analytics on this site, no advertising or conversion pixels, no session recording, no A/B testing tool, no newsletter signup, no accounts and no contact form. The fonts are served from this domain rather than a font CDN, so loading a page here does not tell a third party that you did.
The contact page is an email address and a booking link rather than a form, and that is the reason: a form would mean collecting and storing what you typed, and there is no need for it when a reply has to come by email anyway.
Server logs
The site is hosted by Vercel Inc. Like every web host, its servers record the technical detail of each request in order to deliver pages, keep the site up and defend it from abuse: IP address, timestamp, the URL requested, the referring page and the browser user-agent string. This happens at the infrastructure layer and is not something a website can opt out of and still be reachable.
No visitor-analytics product is enabled on this project, so there is no report anywhere of who visited, from where, or how often. Vercel holds these logs under its own terms, which are set out in the Vercel privacy notice.
Where this site sends you
Two things on this site take you somewhere else, and neither is tracked on the way out.
- Booking a call goes to Calendly. If you book, you give Calendly your name, email address and a chosen time, and that is processed under the Calendly privacy notice. The booking details then come through to me so that the call can happen. Calendly is linked rather than embedded, so nothing loads from it unless you click.
- Email links open your own mail application. Whatever you then send is handled by your mail provider and mine.
If you become a client
Doing the work needs more than an email address, so this is what gets handled once an engagement starts:
- Business contact and billing details — practice name, your name, email, phone, and the invoicing details needed to charge you.
- Delegated access to your own systems — website admin, Google Search Console, Google Business Profile, and any analytics you run yourself. Access is granted by you, is scoped to what the work needs, and is revoked at the end.
- Payment details — handled by Stripe, not by me. Card numbers never reach this business; what comes back is the last four digits, the card type and whether the payment succeeded. Stripe’s handling is covered by the Stripe privacy policy.
Nothing identifying the people you treat appears in that list, and nothing ever will. The next section sets out what that rules out in full, and what happens when a system you are about to hand over holds both kinds of thing at once.
Health data, and why none of it is here
Information about someone’s mental or physical health is special category data under Article 9 of the UK GDPR. It carries a higher bar than ordinary personal data, tighter breach consequences, and for a therapy practice it is the single thing most worth protecting.
This business does not process special category data, and the service is built so that it never needs to. SEO work operates on public-facing pages, search listings and directory profiles. None of that requires knowing who your clients are.
Concretely, the following are never requested and are refused if offered:
- Client or patient lists, in any format
- Intake forms, assessments or completed questionnaires
- Session notes, treatment records or case files
- Appointment calendars containing client names
- Practice-management or EHR system access
- Billing or insurance records that identify individuals
- Inbox access where client correspondence is held
If access to a system is needed and that system also holds any of the above, the access is scoped down to what the work requires or declined outright. Where a platform cannot separate the two, the task gets done a different way or does not get done. If something identifying a client arrives here by accident — forwarded in an email, visible in a screenshot, sitting in an export — it is deleted rather than filed, and you are told.
Who else touches any of it
Four services are involved, each doing one job. There is no data broker, no advertising network, no enrichment tool and no offshore subcontractor.
- Vercel — hosts this website. Sees request logs: IP address, timestamp, URL, referrer, user-agent. Privacy notice
- Stripe — takes payments. Sees your card details and billing information directly; they do not pass through this business. Privacy policy
- Calendly — books calls, and only if you click the booking link. Sees the name, email and time you enter. Privacy notice
- The mail provider behind hello@seofortherapists.org — carries and stores email correspondence, in the same way your own provider carries yours.
If that list ever grows — an analytics tool, a CRM, an email platform — this section changes before the tool goes live, not afterwards.
Why this is lawful
- Performance of a contract — Article 6(1)(b). Doing the work you are paying for, invoicing it and supporting it.
- Legitimate interests — Article 6(1)(f). Serving and securing this website, and replying to an inquiry you sent. The interest is running a business that answers its email and stays online; it is hard to see how that overrides anybody’s rights, and if you disagree you can object.
- Legal obligation — Article 6(1)(c). Keeping the accounting records UK company and tax law requires.
How long anything is kept
- Inquiries that go nowhere — deleted once the conversation has clearly ended.
- Client records — kept for the engagement, then for the six years UK tax law requires accounting records to be retained. That applies to invoices and the correspondence behind them, not to system access.
- Access to your systems — handed back or revoked when the engagement ends, as described in the terms.
- Server logs — held by the host for its own retention period, which is set by Vercel rather than by this business.
Transfers outside the UK
Vercel, Stripe and Calendly are United States companies, so information reaching any of them leaves the UK. Each publishes the safeguards it relies on for UK and EU transfers — standard contractual clauses with the UK Addendum, and the EU-US Data Privacy Framework and its UK extension. No other transfer happens: there is no offshore contractor, no data-broker relationship and nothing sold to anyone.
Your rights
Under the UK GDPR you can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be erased, ask for processing to be restricted, object to processing carried out under legitimate interests, and ask for the data you provided in a portable format. Email hello@seofortherapists.org and it gets handled. There is no charge and the law allows one month to respond.
If the answer is unsatisfactory you can complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk. You do not have to raise it here first, though it is usually quicker.
Changes to this notice
If what this site or this business does with data changes, this page changes with it and the date at the top moves. There is no mailing list to notify, so the date is the version marker — if it has not moved, nothing has.