Sellable Marketing Agency ("SMA", "we", "us", or "our") respects your privacy and is committed to protecting personal information. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website, submit enquiries or applications, use our services, access our platforms, or otherwise interact with us.
This Privacy Policy applies to personal information collected through our website, application forms, landing pages, client portals, dashboards, communications, and services, including the Sellable LaunchPad Programme.
1. Who We Are
Sellable Marketing Agency is the organisation responsible for deciding how and why personal information is processed in connection with our website, business operations, and many of our services.
If you have questions about this Privacy Policy or our handling of personal information, you can contact us at hello@sellablemarketing.com.
2. The Information We Collect
We may collect personal information necessary to provide, operate, maintain, improve, and secure our services.
The information we collect may include:
- name
- email address
- telephone number
- company name
- billing address
- business information
- application details
- communication records
- support enquiries
- project materials
- files, documents, images, creative assets, and other content you upload, submit, or share with us
We may also collect account-related and operational information, including:
- login credentials or encrypted authentication data
- account settings and preferences
- login timestamps
- platform usage records
- user actions within client portals, dashboards, or other systems
- file upload history
- communication and collaboration records
- permission and role activity
- access timestamps and related technical logs
Where payments are made for our services, payment information is processed securely by authorised third-party payment providers. We do not store complete debit card or credit card details.
We may also collect technical and usage information, including:
- browser type
- device information
- IP address
- pages visited
- session information
- website interactions
- duration of visits
- referral information
- diagnostic and performance information
We use cookies, analytics tools, session technologies, and similar tracking technologies to enhance user experience, maintain functionality, analyse performance, remember preferences, support security, and improve our services.
3. Information Collected in Relation to the LaunchPad Programme
If you apply for or participate in the Sellable LaunchPad Programme, we may collect and process personal information and business information relating to:
- your identity and contact details
- your business name, registration details, and supporting verification information
- your website, domain, hosting, and online presence
- information submitted through the application form
- onboarding responses, brand assets, content, and project materials
- communications relating to selection, onboarding, delivery, support, handover, and ongoing services
We use this information to assess eligibility, administer the Programme, communicate with applicants, deliver websites and related services, provide support, manage handover, improve the Programme, and protect our legal and operational interests.
4. How We Use Personal Information
We may use personal information to:
- provide and manage our services
- review enquiries and programme applications
- verify business eligibility and suitability
- process transactions and send billing information
- communicate updates, notices, service information, and support messages
- provide customer service and respond to enquiries
- customise user experiences and project outcomes
- deliver websites, content, support, hosting, profiles, and related services
- manage accounts, portals, dashboards, permissions, and user access
- maintain platform security, authentication, and operational integrity
- monitor system performance, detect suspicious activity, and prevent fraud, misuse, or abuse
- maintain audit logs and operational records for compliance and security purposes
- improve workflows, automation systems, service functionality, and user experience
- comply with legal obligations and regulatory requirements
- establish, exercise, or defend legal claims
- send marketing communications where permitted by law
We do not sell, rent, lease, or trade personal information to unaffiliated third parties for their own independent marketing purposes.
5. Legal Bases for Processing
Where applicable under data protection laws, including the UK GDPR and EU GDPR, we process personal information on one or more of the following legal bases:
- Performance of a contract
- where processing is necessary to provide requested services, manage accounts, process transactions, or fulfil contractual obligations.
- Legitimate interests
- where processing is necessary to operate, improve, secure, administer, market, and develop our business and services, provided those interests are not overridden by the rights and freedoms of the individual.
- Legal obligation
- where processing is required to comply with applicable laws, regulations, court orders, lawful requests, tax obligations, or regulatory requirements.
- Consent
- where you have given clear consent for a specific purpose, such as certain marketing communications or optional cookies.
- Vital interests
- where processing is necessary to protect someone’s vital interests or to help prevent fraud, serious harm, or unlawful activity.
6. Artificial Intelligence and Automation
We may use artificial intelligence tools, automation systems, and similar technologies to support aspects of our business operations and service delivery, including content structuring, workflow management, research support, quality assurance, operational efficiency, and internal administration.
Where AI-assisted tools are used, they are used as support technologies within our workflow and do not replace appropriate human oversight where such oversight is required or appropriate.
7. Cookies and Tracking Technologies
We use cookies, session technologies, analytics tools, and similar tracking technologies to:
- maintain secure user sessions
- improve website functionality
- remember user preferences
- analyse website and platform usage
- enhance user experience
- monitor performance and reliability
- support authentication, account access, and security operations
You may disable cookies through your browser settings. However, parts of the website, client portal, or platform may not function properly if you do so.
For more information about how we use cookies and similar technologies, please refer to our separate Cookie Policy, where available.
8. Children and Minors
Our services are not directed to individuals under the age of eighteen (18), and we do not knowingly collect personal information from children.
If we become aware that personal information has been collected from a child without appropriate consent where required by law, we will take reasonable steps to delete that information.
Parents or guardians who believe that a child has provided personal information to us may contact us using the details set out in this Privacy Policy.
9. Sharing Personal Information
We may share personal information where reasonably necessary for business operations, service delivery, legal compliance, security, or administration.
This may include sharing information with:
- employees, contractors, consultants, freelancers, and advisers
- hosting providers and infrastructure providers
- payment processors
- cloud storage providers
- analytics and communication providers
- customer relationship management systems
- software and automation providers
- artificial intelligence tool providers
- professional advisers, auditors, insurers, and legal counsel
- regulators, law enforcement agencies, courts, or public authorities where required by law or reasonably necessary to protect rights or safety
We take reasonable steps to ensure that third parties who process personal information on our behalf are subject to appropriate confidentiality, data protection, and security obligations.
10. Third-Party Services, Websites, and Integrations
In the course of providing our services, we may engage, integrate with, or rely upon trusted third-party providers, platforms, applications, infrastructure providers, and technology solutions.
These third parties may process, store, transmit, or otherwise handle personal information where necessary for hosting, communications, payments, analytics, support, service delivery, administration, automation, infrastructure, or related operational purposes.
We take reasonable steps to engage service providers that maintain appropriate security and confidentiality standards. However, we do not control and are not responsible for the independent privacy practices, content, operational decisions, or policies of third-party providers except to the extent required by applicable law.
Our website, communications, and services may also contain links to third-party websites, applications, or resources. This Privacy Policy applies only to personal information collected and processed by SMA and does not apply to third-party websites or services.
If you choose to access or use any third-party website or service, you should review its own privacy policy and terms before providing personal information.
11. International Data Transfers
As a business that may work with clients, contractors, service providers, and technology platforms across multiple jurisdictions, we may transfer, access, store, or process personal information outside your country of residence.
Where required by applicable law, we implement reasonable safeguards designed to protect personal information during international transfers. These safeguards may include contractual protections, recognised transfer mechanisms, confidentiality obligations, vendor due diligence, and appropriate security controls.
By using our website or services, you acknowledge that personal information may be transferred to and processed in countries whose data protection laws may differ from those of your country of residence.
12. Data Controller and Data Processor Roles
Depending on the nature of the service provided, SMA may act either as a data controller or a data processor.
We act as a data controller where we decide the purposes and means of processing personal information, including in relation to website visitors, prospective clients, applicants, subscribers, users of our platforms, and individuals who contact us directly.
We may act as a data processor where we process personal information solely on behalf of a client in connection with managed services such as digital marketing, website administration, customer management systems, analytics, advertising, lead generation, automation, or related activities.
Where we act as a data processor, we process personal information in accordance with the relevant client’s lawful instructions and any applicable contractual arrangements, unless otherwise required by law.
Clients remain responsible for ensuring that they have all necessary rights, permissions, notices, lawful bases, and consents required for the collection and disclosure of personal information submitted to us for service delivery purposes.
13. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, account administration, customer support, legal compliance, security, fraud prevention, dispute resolution, enforcement of contractual rights, and legitimate business operations.
Retention Period: Unless a longer period is required by law or justified following internal review, we generally retain personal information for a minimum of ninety (90) days and a maximum of twelve (12) months from the date of collection, the last meaningful interaction, the end of the relevant service, or the closure of the relevant account, project, or application, as applicable.
In appropriate cases, personal information may be retained beyond twelve (12) months where:
- retention is required by applicable law, regulation, court order, or lawful authority
- retention is reasonably necessary for the establishment, exercise, or defence of legal claims
- retention is necessary for fraud prevention, security investigation, audit, compliance, or risk management purposes
- retention is justified following internal review based on the nature of the data, the purpose of processing, the status of the relationship, or ongoing operational needs
Where appropriate and permitted by law, personal information may be anonymised, aggregated, archived, restricted, or securely deleted when it is no longer required.
Users remain responsible for maintaining independent copies of any files, documents, records, or content they upload, store, or provide to us unless we have expressly agreed otherwise in writing.
14. Data Security
We implement and maintain commercially reasonable technical, administrative, and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, misuse, loss, destruction, or other unlawful processing.
These safeguards may include:
- encryption in transit and, where appropriate, at rest
- authentication measures and password protection
- role-based access controls and permissions management
- secure cloud hosting and infrastructure services
- system monitoring, audit logging, and security event tracking
- internal policies, procedures, and access controls
- security reviews, updates, and risk management measures
Access to personal information is restricted to authorised personnel and authorised service providers who require access for legitimate business, operational, compliance, support, security, or service delivery purposes and who are subject to appropriate obligations.
However, no method of transmission over the internet or electronic storage system is completely secure. While we take reasonable steps to protect personal information, we do not guarantee absolute security.
15. Data Breach and Security Incident Management
We maintain procedures designed to identify, investigate, manage, and respond to actual or suspected security incidents involving personal information.
Where required by applicable law, we may notify affected individuals, clients, regulators, or relevant authorities of reportable personal data breaches within the time required by law.
Not all security incidents result in unauthorised access to personal information. We reserve the right to assess the nature, scope, severity, and reporting obligations associated with any incident before issuing notifications, subject to applicable law.
16. Account Access and User Responsibilities
Users are responsible for maintaining the confidentiality, security, and integrity of their account credentials, authentication methods, devices, and any other means used to access our services.
Users agree to:
- keep usernames, passwords, authentication credentials, and access information confidential
- take reasonable steps to prevent unauthorised access to their accounts, devices, and systems
- ensure that account information provided to us remains accurate, complete, and up to date
- notify us promptly of any actual or suspected unauthorised access, account compromise, or security incident
- cooperate with reasonable verification, investigation, or remedial measures taken in connection with security concerns
Users are responsible for activities conducted through their accounts to the extent resulting from their acts, omissions, or failure to maintain appropriate security measures.
We may suspend, restrict, disable, investigate, or terminate access to any account where we reasonably believe that suspicious activity, misuse, fraud, unauthorised access attempts, policy violations, or other security risks have occurred or are likely to occur.
17. Your Rights
Subject to applicable data protection laws, you may have rights in relation to your personal information, including the right to:
- request access to personal information we hold about you
- request correction of inaccurate or incomplete personal information
- request deletion of personal information in certain circumstances
- withdraw consent where processing is based on consent
- request restriction of processing where permitted by law
- object to certain processing activities, including direct marketing and some processing based on legitimate interests
- request transfer of personal information in a structured, commonly used, and machine-readable format where applicable
- request information about automated decision-making where applicable
- complain to a competent data protection authority or supervisory authority
The availability and scope of these rights may vary depending on your jurisdiction, the nature of the information, the legal basis for processing, and any applicable exemptions or limitations.
To protect privacy and security, we may require verification of identity before processing a request. We may also refuse, restrict, or defer requests where permitted by law.
If you are in the United Kingdom and believe that your personal information has been handled in a way that does not comply with applicable data protection law, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). Details of how to do so are available at www.ico.org.uk.
18. Monitoring, Audit Logs, and Operational Security
To maintain platform integrity, service reliability, security, compliance, fraud prevention, and operational management, we may monitor and maintain records relating to account access, login activity, device and browser information, file uploads, communications, permission changes, security incidents, platform interactions, and other relevant technical or operational activities associated with use of our services.
Such monitoring and record-keeping are carried out only for legitimate operational, technical, security, compliance, support, risk management, business administration, and legal purposes, and in accordance with applicable law.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.
20. Contact Us
If you have any questions, concerns, or requests about this Privacy Policy or our handling of personal information, please contact us at:
Email: hello@sellablemarketing.com