Privacy notice
Slashturn Studios
Last updated: 27 July 2026
Version: slashturn-privacy-v0.1-draft
How did you get my email address?
That is almost certainly why you are here, so we will answer it first and we will answer it honestly.
We found your business on Google Maps. Our software reads Google Maps business listings in a web browser, the same listings you can look at yourself, and it looks for businesses that do not appear to have a website of their own. If yours came up, we then needed a way to contact you. Your email address reached us in one of three ways, and we record which one it was for every single business we contact:
- It was published on your Google Maps listing, or on a page linked from it.
- It was published somewhere else on the open web, and a service called Hunter.io found it for us and told us where it was published.
- Hunter.io worked it out. In this case your address was not published anywhere. Hunter knows the pattern that other email addresses at your domain follow, for example firstname@yourbusiness.co.uk, and produced a likely address for you. It then checked with your mail server that an address in that form exists.
We want to be straight about the third one, because it is the one people find surprising. If your address reached us that way, then nobody published it. We inferred it. We do not describe an inferred address as “your published business contact”, because it is not.
If you want to know which of the three applies to you, ask us and we will tell you. We record the exact source against your record. Email privacy@slashturn.com and we will send you what we hold, including the source.
Why did you email me?
Because our search suggested your business has no website, and we build websites for small businesses at a fixed price. We wrote to tell you what one would cost and, if you replied, to build you a real working one so you could see it before deciding.
That is the whole reason. We are not selling your details to anyone, we are not adding you to a mailing list that goes on forever, and we do not send you anything after you tell us to stop.
Who we are
The company responsible for your information (the “controller”, in the language of the law) is:
The Creative Clan Group Ltd
Registered in England and Wales, company number 13472488
Registered office: 3 Bakehouse Mews, London TW12 2NL
VAT registration number GB 436810691
Slashturn Studios is a trading name of The Creative Clan Group Ltd. It is not a separate
company. When you deal with Slashturn Studios you are dealing with The Creative Clan Group
Ltd. We use two web addresses: slashturnstudios.com, which sends our email, and
slashturn.com, which hosts our site, the previews we build and our payment pages. Both are
us.
How to contact us about your information:
- Email: privacy@slashturn.com
- Named contact: Ross Walker, director. If you would rather write to a person by name, write to Ross Walker at the registered office above, or email ross@creativeclan.net.
We do not have a Data Protection Officer. We are a small company and the law does not require us to appoint one. We are telling you this rather than leaving a gap, because the law requires us to give you a DPO’s details if we have one. Ross Walker is the person accountable for this, and the address above reaches him.
What we do with your information, and what allows us to do it
| What we do | What allows us to do it |
|---|---|
| Find businesses on Google Maps that appear to have no website, and record their public listing details | Our legitimate interests (see below) |
| Find or work out a contact email address for that business, and check it is a real working address | Our legitimate interests |
| Send you one cold pitch email and a short sequence of follow-ups if you do not reply | Our legitimate interests |
| Read and classify your reply, and keep the correspondence | Our legitimate interests |
| Build you a preview website and send you the link, if you tell us you are interested | Our legitimate interests, and then taking steps at your request before entering a contract |
| Take payment and deliver what you bought | Performance of our contract with you |
| Keep records of sales, VAT and tax | A legal obligation we are under |
| Keep a permanent record of anyone who has told us to stop, so we never contact them again | A legal obligation, and our legitimate interest in not breaking the law twice |
| Keep a record of what we showed you and what you confirmed at checkout, and of the IP address and time when someone confirms an unsubscribe | Our legitimate interest in being able to prove what happened, and a legal obligation |
The legitimate interests we actually rely on
The law lets us use “legitimate interests” as our reason, but only if we say what those interests are and only if they do not override your rights. Here they are, specifically.
- We are a new business and we need customers. Cold email to other businesses is how we intend to find our first ones.
- We only write to businesses that our search suggested have no website of their own. We think a plumber, a garage or a salon with no website is more likely than most people to want to know what one would cost. That makes the message commercially relevant to you rather than random.
- We want to tell you once, briefly, at a stated price, and, if you are interested, show you a real working site built for your business rather than a sales deck.
- We want to keep a permanent record of everyone who has said no, so that we can guarantee we never contact them a second time.
Why we think this does not override your rights
- We write to you in your business capacity, about your business, at a business address.
- We do not hold anything sensitive about you. No health data, no beliefs, no finances beyond what you pay us if you buy something.
- The volume is small and the sequence is short and capped. We are not sending you a newsletter for years.
- Stopping us takes one click and costs you nothing, and we act on it immediately rather than within the ten days the law allows.
- We never sell, rent, share or licence your details to anyone else for their marketing.
What we do NOT rely on
We do not say that because your details were public, you must be happy to receive marketing. The Information Commissioner’s Office has said plainly that the public availability of someone’s information is not agreement to direct marketing, and we agree with that. Putting a phone number on a Google listing so customers can book a boiler service is not an invitation to receive sales email. So being public is how we found you. It is not our justification for writing to you. Our justification is set out above and it stands or falls on its own.
Exactly what we hold about you
Some of this is about your business rather than about you personally, but we are listing all of it, because a one-person business and the person running it are often the same thing.
From the Google Maps listing:
- business name
- your name, where the listing or the website shows it
- postal address of the business
- telephone number
- business category, for example “plumber” or “hair salon”
- the geographic coordinates of the business and the timezone it sits in (we use the timezone so we only email you during your own working hours)
- the number of reviews the listing has and its star rating
- whether the listing showed a website, and if so whether that site was reachable
Contact details:
- email address
- how we got that email address, recorded per address as one of the three routes described at the top of this page
- whether the address was verified as deliverable, and the result of that check
About our dealings with you:
- which of our three price offers you were shown (we run three, and each business is assigned one at random and keeps it)
- every message we have sent you, and when
- whether a message was opened, where our mail system can tell us that
- your replies, in full
- our automated classification of your replies, for example “interested”, “not interested”, “asked a question”, “asked us to stop”
- your engagement state and where you sit in our process, for example “contacted, no reply yet”, “replied”, “preview site built”, “customer”, “expired”
- whether you are on our suppression list, and why, and when you went on it
If you unsubscribe:
- the IP address and the date and time recorded when you confirmed the unsubscribe
If you buy from us, we keep a record of the checkout itself. This is our evidence of what you agreed to, when, and on what terms, and the law effectively requires us to be able to prove it. It is a fuller record than most people expect, so here is all of it, grouped:
- What you agreed to: the version number of the terms you accepted, a digital fingerprint (a hash) of the exact terms file that was published at the time, a digital fingerprint of the block of information shown on screen immediately above the order button, and the exact wording that was on the order button itself. The two fingerprints let us show what you were actually shown, rather than asking you to take our word for it.
- The four separate confirmations you ticked, and the time you ticked each one: that you agreed to the terms; that you understood placing the order meant you had to pay us; that you asked us to start work straight away; and that you consented to us supplying the website immediately.
- What you bought: our internal reference for your record, which of our three offers you were on, the price, the currency, and whether that price included VAT.
- When, and from where: the date and time of the order, and the IP address you placed it from.
- The confirmation email: the date and time we sent it, and its message identifier. That email is the moment your contract with us starts, so we keep proof that it went.
We do not hold your card details. If you buy, your billing details are handled by Stripe rather than held by us.
Who else sees it
We use other companies to run our business. Here is every one of them that can see your information, what they do, and where they are.
| Who | What they do with it | Where they are |
|---|---|---|
| Microsoft | Runs our email. Every message to and from you sits in a Microsoft 365 mailbox. | United States and Ireland, with UK data centres for mailbox storage |
| Hunter.io | Finds, verifies and enriches email addresses. We send them a business domain or name and they return an address and a confidence score. | European Union, with some United States infrastructure |
| HubSpot | Our customer records system. Holds your contact record, the correspondence history and where you are in our process. | United States, with an EU hosting region |
| Cloudflare | Runs our domain names, hosts our website and hosts the preview sites we build. | United States, with a global network including the UK |
| Stripe | Takes payment if you buy from us. Stripe decides for itself how it uses payment data for fraud checks and its own legal duties, so for that data Stripe is responsible in its own right and not just working for us. | United Kingdom and United States |
| Anthropic | Provides the AI models that read and classify your reply and help draft our copy. Your reply text is sent to their model to be classified. | United States |
Google is not on that list, because we do not send Google anything. Google is where we found your listing, not somewhere we send your data.
We may also have to hand your information to our accountants, our lawyers, our insurers, or a public authority such as HMRC or the Information Commissioner’s Office, if we are legally required to or if we need advice. We do not sell your information, we do not rent it, and we do not pass it to anyone else for their own marketing.
Does my information leave the UK?
Yes, some of it does. Most of the companies above are American or have American parts. UK law allows that, but only if the information stays protected. Here is the basis for each one.
| Who | Where it goes | What protects it |
|---|---|---|
| Microsoft | Ireland and the United States | UK adequacy regulations for the United States (the UK Extension to the EU-US Data Privacy Framework), where Microsoft’s US entity is certified under that scheme, together with Microsoft’s standard data protection terms which incorporate the UK International Data Transfer Addendum |
| Hunter.io | European Union, some United States processing | UK adequacy regulations for the EEA. For any United States element, the UK International Data Transfer Addendum in Hunter’s data processing agreement |
| HubSpot | United States | UK adequacy regulations for the United States, where HubSpot’s US entity is certified, together with the UK International Data Transfer Addendum in HubSpot’s data processing agreement |
| Cloudflare | United States and a global network | UK adequacy regulations for the United States, where Cloudflare is certified, together with the UK International Data Transfer Addendum in Cloudflare’s data processing agreement |
| Stripe | United Kingdom and United States | Our UK contract is with Stripe’s UK entity. Onward transfer to the United States is covered by Stripe’s own transfer safeguards, which include the UK International Data Transfer Addendum |
| Anthropic | United States | UK adequacy regulations for the United States, where Anthropic is certified, together with the UK International Data Transfer Addendum in Anthropic’s commercial terms |
In plain terms there are two protections in play. The first is that the UK government has decided that American companies which sign up to a scheme called the Data Privacy Framework give personal information enough protection, so transfers to those companies are allowed. The second, which we use as well as or instead of the first, is a standard UK government contract called the International Data Transfer Addendum, which legally binds the receiving company to protect your information to a UK standard.
You can have a copy. Email privacy@slashturn.com and ask for the transfer safeguards, and we will send you the relevant clauses. We may redact commercial pricing, because that is not about you.
How long we keep it
We keep different things for different lengths of time. Here is the whole picture.
| What | How long | Why |
|---|---|---|
| A business we found but never contacted | 90 days from the day we found it, then deleted | If we have not written to you in three months we are not going to, and there is no reason to keep the record |
| A business we contacted that never replied | 12 months from the last message we sent | Long enough to stop us contacting you again by accident, short enough not to be a permanent file on you |
| Your replies and our correspondence, if you did not become a customer | 12 months from the last message either way | So we can answer a question or a complaint about what we said to you |
| Automated classifications, engagement state and offer variant | Deleted with the record they belong to | They are notes about the correspondence, not a separate file |
| Records of anyone who told us to stop, or who bounced, or who said no | Permanently | See the note below |
| Unsubscribe links and the ability to use them | At least 30 days after the last message we sent you, and in practice 12 months | The law requires the opt-out to keep working. We keep it working for far longer than the minimum |
| The IP address and time recorded at an unsubscribe | 6 years | So that if anyone ever says we did not honour an opt-out, we can prove we did |
| The whole checkout record described above, including the IP address, the time, the terms version and hash, the four consent confirmations, the button wording and the confirmation email details | 6 years from the end of the contract | This is our evidence of what you agreed to and when. Six years is the period in which a contract claim can be brought in England and Wales |
| Customer contracts, invoices, VAT and accounting records | 6 years after the end of the financial year they relate to | We are legally required to keep these |
| Anything we host for you as a customer | For as long as we host it, and deleted on request or within 30 days of the service ending | It is your data, not ours |
Why the suppression list is permanent
This is the one thing we keep forever, and we want to explain it rather than bury it.
If you tell us to stop, or your address bounces, or you tell us you are not interested, we put a record of your email address on a suppression list. Every single message we send is checked against that list first. Nothing gets through it, ever, in any campaign.
That record has to be permanent, because the moment we delete it we lose the only thing that guarantees we will never write to you again. If we deleted it and then found your business on Google Maps a year later, we would have no way of knowing you had already said no. Keeping the record is how we honour your objection, not a way around it.
So we keep it, and we keep it as small as we can. After 12 months we strip the record down to an irreversible scrambled version of your email address plus the date and the reason. That is still enough for our system to check “is this address suppressed?” before every send. It is no longer enough for a human being to read your address off the list.
If you would rather we did not do that, say so, and we will discuss it with you. But be aware that the alternative is that we cannot promise never to contact you again.
YOUR RIGHT TO TELL US TO STOP
You have an absolute right to object to us using your personal information for direct marketing. You do not have to give a reason. We do not get to weigh it against our own interests. We cannot refuse.
This is separate from every other right on this page, and the law requires us to bring it to your attention explicitly and separately, which is what this block is for.
Three ways to use it. Any one of them is enough.
- Click the unsubscribe link at the foot of any email we send you. One click. No form, no login, no reason, no “are you sure”.
- Reply to any email from us and say stop. Those words are enough. You do not need to be polite about it.
- Email privacy@slashturn.com.
What happens then:
- We stop emailing you immediately. Not within ten days, which is all the law requires. Immediately.
- Your address goes on our permanent suppression list, so no future campaign can reach you.
- We delete the rest of what we hold about you within 30 days, keeping only the minimum suppression record described above.
- You get no confirmation email, because you have told us to stop emailing you and we take that literally. The web page confirms it instead.
You can also object to anything else we do with your information, not just the marketing. That right is not absolute in the same way: we have to stop unless we can show compelling legitimate grounds that override your interests. Tell us and we will look at it properly and answer you.
Your other rights
Each of these is a right you have under UK data protection law. To use any of them, email privacy@slashturn.com. We will respond within one month, and it is free.
- The right to be told what we hold. You can ask for a copy of the personal information we hold about you, including the exact source of your email address.
- The right to have it corrected. If anything we hold about you is wrong or incomplete, tell us and we will fix it.
- The right to have it deleted. You can ask us to delete your information, and where we are relying on our own legitimate interests rather than a legal duty we will normally do so.
- The right to have us pause. You can ask us to stop using your information while we deal with a dispute about whether it is accurate or whether we should be using it at all.
- The right to take it with you. This one has limits. It only applies where we are using your information because you consented or because we have a contract with you, so it applies to your customer data if you buy from us, and it does not apply to the outreach data we gathered before you had any dealings with us.
- The right to object. Set out in full in the block above.
- The right to withdraw consent. We do not rely on consent for our outreach, so there is usually nothing to withdraw. Where we do ask for consent, for example for non-essential cookies, you can withdraw it at any time and it is as easy to withdraw as it was to give.
Complaining about us
If you are unhappy with how we have handled your information, please tell us first. Email privacy@slashturn.com. We would rather fix it than have you go elsewhere.
You do not have to come to us first, though. You can complain directly to the UK regulator at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Online: https://ico.org.uk/make-a-complaint/
The ICO’s online complaint form takes about five minutes. The ICO cannot award you compensation, but it can look at what we did and tell us to change it. If you want compensation, that is a claim you would bring in court, and you should take your own advice before doing that.
Automated systems and AI
We are telling you this because you should know, not because we have to bury it in a footnote.
Almost all of this is automated. Software, not a person:
- decides which businesses to contact, by looking for Maps listings with no website
- assigns each business one of our three price offers, at random and permanently
- decides when to send, so that the message arrives during your working hours
- writes the message from a fixed, pre-approved template with your business details merged in
- reads your reply and classifies it, for example as interested, not interested, a question or an opt-out
- decides whether to send a follow-up, and when to stop
- decides whether to build you a preview site and send you a payment link
Sophie is an AI assistant, not a person. She is operated by Slashturn Studios and her messages are our messages. If you would rather deal with a human being at any point, reply and ask for one, and Ross Walker will pick it up. Some things always go to a human: anything that looks like a complaint, a negotiation, a legal question, or a request we have not planned for.
The logic, in plain terms. There is no scoring of you as a person and no profile of your character. The system looks at whether your listing shows a website, what category of business you are, where you are, and whether we can find a working email address. The price offer you see is assigned at random, as part of a test of which of our three offers works best, and it is not based on anything about you. The consequence of all this is that you receive an email, or you do not. Nothing else happens to you either way.
Does the law’s special protection for automated decisions apply here? From 5 February 2026, the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D. Those rules give you extra rights where a decision is made about you entirely by machine and it has a legal effect on you, or an effect that is similarly significant.
Our honest view is that they do not apply to what we do, because sending you a marketing email and quoting you one of three prices does not have a legal or similarly significant effect on you. You can ignore it. You can say no. Nothing follows.
We have written that reasoning down rather than assuming it, because it is a judgement and not a certainty. If you think a decision our system made about you was significant and you want a human being to look at it again, ask, and a human will.
Do you have to give us anything?
No. You did not give us your details in the first place, so there is nothing you are required to provide and no consequence if you provide nothing. You can ignore our email entirely and nothing happens. If you decide to buy something from us, we will need your billing details in order to take payment and deliver, and if you do not give them we cannot sell you anything, which is the only consequence.
Cookies, and the websites we build
This page and our outreach. This notice covers our cold outreach and the people we contact. The site you are reading it on uses only the cookies that are strictly necessary to serve the page. We do not run advertising trackers on it and we do not need your consent for strictly necessary cookies.
Preview sites we build for you. If we build you a preview at yourbusiness.slashturn.com, that site is ours until you buy it, it is covered by this notice, and it carries no advertising or third-party tracking cookies. We can see basic hosting logs for it, including IP addresses, which our hosting provider keeps for security and which we keep for no longer than 90 days.
Sites we host for you as a customer. Once you are a customer and we are hosting your site, the position flips. You become responsible for the personal information your own visitors give you, and we are simply following your instructions as your supplier. That is dealt with in the data processing terms in your contract with us, not in this notice, and you will need your own privacy notice for your visitors. We will tell you that at the time.
Changes to this notice
If we change how we use your information, we will update this page and change the version number at the top. Every version is kept, so you can see what the notice said on the day we wrote to you. If we make a change that materially affects people we are still in contact with, we will tell them.
Contact us
- Email: privacy@slashturn.com
- Post: Ross Walker, The Creative Clan Group Ltd, 3 Bakehouse Mews, London TW12 2NL
- Regulator: Information Commissioner’s Office, https://ico.org.uk/make-a-complaint/, 0303 123 1113
Version slashturn-privacy-v0.1-draft. Page generated 2026-07-28. Every version of this document is kept, so you can see what it said on the day we wrote to you. The version string and a hash of the published file are at /legal/versions.json.