Our Privacy Policy

Last updated: June 2026

1. Introduction & Data Controller Identity

The Nexablack ("we," "our," or "us") is a full service marketing agency operating as a registered business based in Manchester, UK. For the purposes of UK GDPR and the Data Protection Act 2018, The Nexablack acts as the Data Controller for any personal data collected through our website, services, and communications. This means we are responsible for deciding how your personal data is processed and for what purposes.

If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection team at connect@thenexablack.com.

2. Information We Collect

We may collect the following types of information when you engage with our agency services:

  • Personal Data: Name, email address, phone number, billing information, and project details you provide via our contact form, quote request, or discovery calls.
  • Usage Data: Information about how you interact with our site, including pages visited, time spent, referring URLs, and interactions with our interactive tools like the ROI calculator and wireframe sandbox.
  • Cookies & Tracking: We use essential cookies for site functionality and analytics cookies to improve our website performance. If you arrive via our Meta (Facebook/Instagram) ad campaigns, we use the Meta Pixel for conversion tracking and retargeting purposes. You can opt out of targeted advertising via your Meta Ad Settings or by contacting us directly. We also use Google Analytics to understand how visitors use our service pages.
  • Communication Data: Records of emails, calls, and messages exchanged during project discussions, including service briefs and feedback on design concepts. If you communicate with us via WhatsApp Business, your messages and profile information will be stored securely as part of our client relationship management system.

3. How We Use Your Information

We use the collected data for the following purposes related to our marketing, design, and development services:

  • Respond to your inquiries, provide quotes, and deliver our brand identity, web development, SEO, and video editing services.
  • Improve our website, service offerings, and client experience based on usage patterns and feedback.
  • Send periodic marketing emails about our services, blog posts, and industry insights only with your explicit consent.
  • Comply with legal obligations, including GDPR requirements for data processing and storage.
  • Process payments and manage client accounts for ongoing retainer services like social media management and SEO.
  • Qualify and route inbound leads using automated workflows and AI-powered tools (see Section 4 for details on automated processing).

4. Automated Processing & AI Tools

As part of our commitment to delivering efficient, high-quality services, we may use automated tools and AI-powered platforms to assist with lead qualification, client communication, and workflow management. Specifically:

  • AI Lead Qualification: We may use AI models (such as OpenAI's API) to help categorise and prioritise inbound enquiries based on project scope and client requirements. This allows us to respond faster and route your enquiry to the right team member.
  • Workflow Automation: We use automation platforms (like n8n) to manage customer data across our systems, ensuring timely follow-ups, proposal generation, and project updates.
  • Data Privacy Assurance: Any data processed through third-party AI APIs is handled in accordance with strict data processing agreements. We do not use your personal data or project details to train public AI models. Your information is used solely for the purpose of delivering our services to you.

Where automated decision-making has a legal or similarly significant effect on you, we will obtain your explicit consent and provide you with the opportunity to request human intervention.

5. International Data Transfers

As a global agency serving clients across the UK and internationally, your personal data may be transferred to and processed in countries outside the UK and European Economic Area (EEA). Our administrative operations and team members may be located in various regions, and we use third-party service providers that may store or process data globally.

Where we transfer your personal data outside the UK, we ensure an equivalent degree of protection is afforded to it by implementing at least one of the following safeguards:

  • Transferring to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government or the European Commission.
  • Using specific contracts approved by the UK Information Commissioner's Office (ICO) or European Commission, known as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), which give personal data the same protection it has in the UK.

If you would like further information on the specific mechanisms used for international data transfers, please contact us.

6. Data Protection and Security

We implement industry-standard security measures to protect your personal data, including SSL encryption across all pages, secure servers with access controls, and regular security reviews. Our website uses HTTPS across all pages, and we limit access to personal data to employees and contractors who have a business need to know. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security of your data.

7. Third-Party Disclosure, Service Providers & External Links

We do not sell, trade, or transfer your personal information to third parties without your consent, except as required by law or to trusted partners who assist in operating our website and business. These partners include payment processors (e.g., Stripe), email service providers, analytics platforms (Google Analytics), advertising platforms (Meta, TikTok), project management tools, and AI service providers (OpenAI). All third-party providers are contractually obligated to keep your data secure and process it only for the purposes we specify.

Third-Party Links: Our website may contain links to external websites, including client portfolio examples, partner agencies, and social media profiles (Facebook, Instagram, LinkedIn, YouTube, TikTok, Pinterest). Please note that we are not responsible for the privacy practices or content of these third-party websites. We encourage you to review the privacy policies of any external sites you visit from our domain, as they are not covered by this Privacy Policy.

8. Your Rights Under UK GDPR

As a UK-based business serving clients across Manchester and the UK, we comply with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. You have the following rights regarding your personal data:

  • Right to be informed: You have the right to be informed about the collection and use of your personal data — this Privacy Policy fulfils that obligation.
  • Right of access: You can request access to the personal data we hold about you and understand how it is processed.
  • Right to rectification: You can request correction of inaccurate or incomplete data at any time by contacting us.
  • Right to erasure (right to be forgotten): You can request deletion of your data where there is no compelling reason for its continued processing.
  • Right to restrict processing: You can request that we restrict the processing of your data in certain circumstances, such as while a correction request is being verified.
  • Right to data portability: You can request a copy of your data in a structured, commonly used, and machine-readable format.
  • Right to object: You can object to the processing of your data for direct marketing purposes at any time, including profiling related to such marketing.
  • Rights related to automated decision-making: You have the right not to be subject to a decision based solely on automated processing where it produces legal effects concerning you.

To exercise any of these rights, please contact us at connect@thenexablack.com. We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. For client projects, we retain project files, communications, and related data for up to 6 years after project completion in accordance with UK tax laws and limitation periods. Marketing and enquiry data is retained until you unsubscribe, request deletion, or for a maximum of 2 years after our last contact, whichever is sooner.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal obligations, or the regulatory environment. When we make significant changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by email for clients with active projects or retainers. We encourage you to review this policy periodically to stay informed about how we are protecting your data.

11. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, have concerns about how we handle your information, or would like further information on our data processing safeguards, please contact us at connect@thenexablack.com or call +447784831982. Our registered address is BL9 7HG, Bury, Greater Manchester, UK. You also have the right to contact the Information Commissioner's Office (ICO) at any time regarding your data protection concerns.