Privacy Policy

WP Minds (BTLtimes.com LTD)  |  Effective Date: 2 July 2026  |  Version 2.0

This policy replaces all previous versions, including the policy dated 18 August 2018.

Your Privacy Matters

We are committed to protecting your personal data and being transparent about how we use it. This policy explains what data we collect, why we collect it, how long we keep it, and your rights over it. Please read it carefully. If you have any questions, contact us at support[at]wpminds.com.

1.  Who We Are

This Privacy Policy is published by BTLtimes.com LTD, trading as WP Minds.

Legal nameBTLtimes.com LTD
Trading nameWP Minds
Company number07204533 (registered in England and Wales)
Registered addressC/O J.R. Accounts Ltd, 34-37 Liverpool Street, London, EC2M 7PP, United Kingdom
Emailsupport[at]wpminds.com
Websitewpminds.com
ICO RegistrationZA256014

We are the data controller for personal data collected through wpminds.com and our associated services.

We also operate a team based in Lahore, Pakistan, who may have access to certain client data in the course of service delivery. This is governed by our international transfer safeguards (see Section 10).

2.  Who This Policy Applies To

This policy applies to:

  • Visitors to wpminds.com
  • Prospective clients who submit enquiries or book consultations
  • Clients who purchase WP Minds services (website design, development, SEO, hosting, maintenance, Local SEO, PPC)
  • Subscribers to our email newsletter or podcast updates
  • Job applicants and contractors

This policy does not apply to websites operated by third parties, even if linked from wpminds.com.

3.  Personal Data We Collect

3.1  Data You Provide Directly

  • Contact details: name, email address, telephone number, business name
  • Enquiry content: project descriptions, budget ranges, requirements you share with us
  • Account credentials: username and password (if you create an account on our site)
  • Payment details: billing name, address, and VAT number (card numbers are processed by Stripe and never stored by us)
  • Communications: content of emails, live chat messages, and form submissions
  • Marketing preferences: your opt-in or opt-out choices for newsletters

3.2  Data Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device type
  • Usage data: pages visited, time on site, links clicked, referring URL
  • Cookie data: as described in our Cookie Policy
  • Log files: server access logs retained for security and debugging purposes

3.3  Data From Third Parties

  • Google Analytics: aggregated and anonymised usage data from visitors who consent to analytics cookies
  • Google Search Console: search query data showing how users find our site via Google
  • Payment processors: Stripe provides transaction confirmation, not raw card data

We do not collect any special category data (health, religion, ethnicity, biometric, criminal records) and do not knowingly process personal data of children under 13.

4.  How We Use Your Personal Data

The table below summarises how we use personal data, our lawful basis under UK GDPR, how long we retain it, and who we share it with.

Activity / Data CollectedLawful BasisRetention PeriodThird-Party Recipients
Responding to enquiries and providing service quotesLegitimate interests (Art. 6(1)(f)) — necessary to run our business6 months from last contact if no engagement; 6 years from end of contract if engagedNone
Delivering website design, development, SEO, and hosting servicesContract performance (Art. 6(1)(b))6 years from contract end (Companies Act)Hosting providers, project management tools, Pakistan team (see Section 10)
Processing payments and issuing invoicesContract performance (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c))7 years (HMRC record-keeping)Stripe (payment processing), accountants
Sending transactional emails (order confirmations, support responses)Contract performance (Art. 6(1)(b))12 months from transactionGoogle Workspace (email infrastructure)
Sending marketing emails, newsletter, podcast updatesConsent (Art. 6(1)(a))Until you unsubscribeEmail marketing platform (see processors list)
Improving our website and user experience via analyticsConsent (Art. 6(1)(a)) — via cookie consentAggregated data: 26 months (GA4 default). No individual profiles retained.Google Analytics (anonymised)
Displaying relevant advertising on other websitesConsent (Art. 6(1)(a)) — via cookie consentData held by ad network per their policyGoogle Ads, Meta Ads (if consent given)
Security monitoring, fraud prevention, and abuse detectionLegitimate interests (Art. 6(1)(f))Up to 90 days for server logs; longer if security incident is under investigationHosting provider, CAPTCHAs
Complying with legal obligations (tax, regulatory)Legal obligation (Art. 6(1)(c))As required by applicable law (typically 7 years)HMRC, professional advisers, courts

5.  Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis for every processing activity. We rely on the following:

  • Contract (Art. 6(1)(b)): When you engage us for services, we must process your data to perform the contract. This includes delivering work, sending invoices, and communicating about your project.
  • Legitimate Interests (Art. 6(1)(f)): We process some data where we have a legitimate business interest that is not overridden by your rights, for example responding to enquiries and maintaining site security. We have conducted a Legitimate Interests Assessment (LIA) for these activities.
  • Consent (Art. 6(1)(a)): For marketing emails, analytics cookies, and advertising cookies, we rely on your explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal Obligation (Art. 6(1)(c)): We process certain data because we are required to by law, including financial records for HMRC and responding to lawful requests from public authorities.
    We do not make automated decisions (including profiling) that have a significant legal or similarly significant effect on you.

    6.  Who We Share Your Data With

    We do not sell your personal data. We share it only in the following circumstances.

    6.1  Service Providers (Data Processors)

    We use trusted third-party processors to help us deliver services. They process your data only on our instructions and under binding contractual obligations:

    ProcessorLocationPurpose
    Google WorkspaceUSA / EEAEmail, document storage, calendar
    StripeUSAPayment processing (card data never stored by us)
    WP Engine / Hosting ProviderUSA / UKWebsite hosting and server infrastructure
    CookieYesIreland / UKCookie consent management
    Google AnalyticsUSAWebsite analytics (anonymised, consent-gated)
    Basecamp / Project ManagementUSAProject tracking and client communication
    WP Minds Lahore TeamPakistanService delivery support (see Section 10)

    6.2  Legal Disclosure

    We may disclose personal data where required by law, court order, or where necessary to protect our rights, the rights of others, or to investigate fraud or a security breach.

    6.3  Business Transfers

    In the event of a merger, acquisition, or sale of our business, client data may be transferred to the acquiring entity. We will notify affected individuals in advance where practicable.

    7.  How Long We Keep Your Data

    Type of DataRetention Period
    Active client project filesDuration of project + 6 years
    Invoices and financial records7 years (HMRC requirement)
    Enquiries that did not become clients6 months from last contact
    Marketing email listsUntil you unsubscribe or withdraw consent
    Website analytics data (GA4)26 months (Google’s default retention)
    Server access logs90 days (security monitoring)
    Cookie consent records12 months
    Support and chat communications12 months from last interaction

    8.  Your Rights

    Under UK GDPR, you have the following rights regarding your personal data. We will respond to all requests within 30 calendar days (extendable to 60 days for complex requests, with notice).

    • Right of access (Art. 15): You can request a copy of the personal data we hold about you (a Subject Access Request).
    • Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
    • Right to erasure (Art. 17): You can ask us to delete your personal data where we no longer have a lawful basis to keep it. Note: we may be required to retain some data by law (e.g. financial records).
    • Right to restriction (Art. 18): You can ask us to temporarily stop processing your data in certain circumstances.
    • Right to data portability (Art. 20): Where processing is based on consent or a contract, you can ask us to provide your data in a structured, machine-readable format.
    • Right to object (Art. 21): You can object to processing based on legitimate interests at any time. We will stop unless we can demonstrate a compelling legitimate reason that overrides your interests.
    • Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

    To exercise any of these rights, please contact us at support[at]wpminds.com. We may need to verify your identity before processing your request.

    9.  How We Protect Your Data

    We take data security seriously and have implemented appropriate technical and organisational measures, including:

    • HTTPS/TLS encryption on all pages of wpminds.com
    • Encrypted storage of passwords (bcrypt hashing; we never store plaintext passwords)
    • Restricted access to client data: only team members who need access to deliver your project have it
    • Payment data processed exclusively via Stripe (PCI-DSS compliant); we do not store card numbers
    • Regular software updates and security patches to our WordPress installation and plugins
    • Backups stored securely and separately from the live site
    • Data Processing Agreements in place with all third-party processors

    In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify affected individuals without undue delay.

    10.  International Data Transfers

    10.1  Transfers to the United States

    We use a number of service providers based in the United States, including Google (Google Workspace, Google Analytics, Google Ads), Stripe, and Basecamp. We rely on Standard Contractual Clauses (SCCs) incorporated into the terms of service of these providers. Google’s data transfer safeguards are available at business.safety.google/gdpr/. Stripe’s Data Processing Agreement is available at stripe.com/legal/dpa.

    10.2  Transfers to Pakistan

    Our service delivery team is located in Lahore, Pakistan. Pakistan does not have a UK adequacy decision.

    International Data Transfer Agreement (IDTA) in Place
    Transfers of personal data to our Pakistan team are governed by a UK International Data Transfer Agreement (IDTA), which has been signed and is in effect. This provides the appropriate safeguards required under UK GDPR for transfers of personal data to countries without an adequacy decision. The categories of data accessible to the Pakistan team are limited to what is strictly necessary for service delivery: client name, website access credentials, project assets, and communication history relating to active contracts. Sensitive data such as payment details is not accessible to the Pakistan team.

    10.3  EEA and EU Residents

    The UK has EU adequacy decisions in place, meaning data transferred from the EEA to the UK benefits from equivalent legal protections. EU residents additionally have rights under the EU GDPR and may contact their local supervisory authority.

    11.  Marketing Communications

    We may send you marketing emails about our services, blog content, podcast episodes, and promotions if you have given us your consent to do so.

    • You can unsubscribe from marketing emails at any time by clicking the ‘Unsubscribe’ link in any email we send.
    • You can also update your preferences by contacting us at support[at]wpminds.com.
    • Withdrawing consent for marketing does not affect our ability to send you transactional emails (such as invoices or support responses) that are necessary for your service.

    12.  Cookies

    We use cookies and similar technologies on wpminds.com. Our Cookie Policy explains what cookies we use, why, and how to manage them.

    13.  California Residents — CCPA / CPRA

    If you are a resident of California, USA, additional rights apply to you under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

    13.1  Categories of Personal Information Collected

    In the past 12 months, we have collected: identifiers (name, email, IP address); commercial information (services purchased, transaction history); internet or network activity (browsing behaviour on our site); and professional information (business name, job title where provided).

    • Identifiers: name, email address, IP address, online identifier
    • Commercial information: services purchased, transaction history
    • Internet or network activity: browsing behaviour on our site, interactions with our content
    • Professional or employment-related information: business name, job title (where provided)

    13.2 Your California Rights

    • Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
    • Right to Delete: You can request deletion of personal information we have collected, subject to certain exceptions.
    • Right to Correct: You can request correction of inaccurate personal information.
    • Right to Opt-Out of Sale / Sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising without consent.
    • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

    To exercise your California rights, contact us at support[at]wpminds.com. We will respond within 45 calendar days.

    14. Canadian Residents: CASL

    If you are located in Canada, the Canadian Anti-Spam Legislation (CASL) applies to commercial electronic messages we send to you.

    • We will only send marketing emails to Canadian recipients with express consent, or where implied consent applies under CASL (e.g. an existing business relationship within the last 24 months).
    • Every commercial email we send includes a clear, functional unsubscribe mechanism.
    • Unsubscribe requests will be honoured within 10 business days as required by CASL.

    For privacy enquiries, contact us at support[at]wpminds.com.

    15. Children’s Privacy

    Our services are directed at businesses and adults. We do not knowingly collect personal data from children under the age of 13 (or 16 in the EEA). If you believe we have inadvertently collected data from a child, please contact us at support[at]wpminds.com and we will delete it promptly.

    16. Links to Third-Party Websites

    Our website may contain links to third-party websites, social media platforms, or partner sites. This Privacy Policy does not apply to those sites. We do not control, and are not responsible for, the privacy practices of third-party websites.

    17. Changes to This Privacy Policy

    We review this Privacy Policy at least annually and whenever our data processing activities change. The current version and Effective Date are shown at the top of this document.

    Where changes are material, we will notify you by email (if you are a client or subscriber) and by posting a prominent notice on the website.

    18. Contact Us and How to Complain

    18.1 Data Controller Contact

    Email: support[at]wpminds.com
    Post: BTLtimes.com LTD t/a WP Minds, C/O J.R. Accounts Ltd, 34-37 Liverpool Street, London, EC2M 7PP

    Please mark your correspondence: FAO Data Protection.

    We aim to respond to all data protection enquiries within 14 days and to all formal Subject Access Requests within 30 calendar days.

    18.2 Complaints to the ICO

    If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

    Website: ico.org.uk
    Phone: 0303 123 1113
    Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF

    If you are in the EU, you also have the right to contact your local data protection authority.