Privacy Policy
WP Minds (BTLtimes.com LTD) | Effective Date: 2 July 2026 | Version 2.0
This policy replaces all previous versions, including the policy dated 18 August 2018.
Your Privacy Matters
We are committed to protecting your personal data and being transparent about how we use it. This policy explains what data we collect, why we collect it, how long we keep it, and your rights over it. Please read it carefully. If you have any questions, contact us at support[at]wpminds.com.
1. Who We Are
This Privacy Policy is published by BTLtimes.com LTD, trading as WP Minds.
| Legal name | BTLtimes.com LTD |
| Trading name | WP Minds |
| Company number | 07204533 (registered in England and Wales) |
| Registered address | C/O J.R. Accounts Ltd, 34-37 Liverpool Street, London, EC2M 7PP, United Kingdom |
| support[at]wpminds.com | |
| Website | wpminds.com |
| ICO Registration | ZA256014 |
We are the data controller for personal data collected through wpminds.com and our associated services.
We also operate a team based in Lahore, Pakistan, who may have access to certain client data in the course of service delivery. This is governed by our international transfer safeguards (see Section 10).
2. Who This Policy Applies To
This policy applies to:
This policy does not apply to websites operated by third parties, even if linked from wpminds.com.
3. Personal Data We Collect
3.1 Data You Provide Directly
3.2 Data Collected Automatically
3.3 Data From Third Parties
We do not collect any special category data (health, religion, ethnicity, biometric, criminal records) and do not knowingly process personal data of children under 13.
4. How We Use Your Personal Data
The table below summarises how we use personal data, our lawful basis under UK GDPR, how long we retain it, and who we share it with.
| Activity / Data Collected | Lawful Basis | Retention Period | Third-Party Recipients |
| Responding to enquiries and providing service quotes | Legitimate interests (Art. 6(1)(f)) — necessary to run our business | 6 months from last contact if no engagement; 6 years from end of contract if engaged | None |
| Delivering website design, development, SEO, and hosting services | Contract performance (Art. 6(1)(b)) | 6 years from contract end (Companies Act) | Hosting providers, project management tools, Pakistan team (see Section 10) |
| Processing payments and issuing invoices | Contract performance (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)) | 7 years (HMRC record-keeping) | Stripe (payment processing), accountants |
| Sending transactional emails (order confirmations, support responses) | Contract performance (Art. 6(1)(b)) | 12 months from transaction | Google Workspace (email infrastructure) |
| Sending marketing emails, newsletter, podcast updates | Consent (Art. 6(1)(a)) | Until you unsubscribe | Email marketing platform (see processors list) |
| Improving our website and user experience via analytics | Consent (Art. 6(1)(a)) — via cookie consent | Aggregated data: 26 months (GA4 default). No individual profiles retained. | Google Analytics (anonymised) |
| Displaying relevant advertising on other websites | Consent (Art. 6(1)(a)) — via cookie consent | Data held by ad network per their policy | Google Ads, Meta Ads (if consent given) |
| Security monitoring, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) | Up to 90 days for server logs; longer if security incident is under investigation | Hosting provider, CAPTCHAs |
| Complying with legal obligations (tax, regulatory) | Legal obligation (Art. 6(1)(c)) | As required by applicable law (typically 7 years) | HMRC, professional advisers, courts |
5. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for every processing activity. We rely on the following:
- Contract (Art. 6(1)(b)): When you engage us for services, we must process your data to perform the contract. This includes delivering work, sending invoices, and communicating about your project.
- Legitimate Interests (Art. 6(1)(f)): We process some data where we have a legitimate business interest that is not overridden by your rights, for example responding to enquiries and maintaining site security. We have conducted a Legitimate Interests Assessment (LIA) for these activities.
- Consent (Art. 6(1)(a)): For marketing emails, analytics cookies, and advertising cookies, we rely on your explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal Obligation (Art. 6(1)(c)): We process certain data because we are required to by law, including financial records for HMRC and responding to lawful requests from public authorities.
| We do not make automated decisions (including profiling) that have a significant legal or similarly significant effect on you. |
6. Who We Share Your Data With
We do not sell your personal data. We share it only in the following circumstances.
6.1 Service Providers (Data Processors)
We use trusted third-party processors to help us deliver services. They process your data only on our instructions and under binding contractual obligations:
| Processor | Location | Purpose |
| Google Workspace | USA / EEA | Email, document storage, calendar |
| Stripe | USA | Payment processing (card data never stored by us) |
| WP Engine / Hosting Provider | USA / UK | Website hosting and server infrastructure |
| CookieYes | Ireland / UK | Cookie consent management |
| Google Analytics | USA | Website analytics (anonymised, consent-gated) |
| Basecamp / Project Management | USA | Project tracking and client communication |
| WP Minds Lahore Team | Pakistan | Service delivery support (see Section 10) |
6.2 Legal Disclosure
We may disclose personal data where required by law, court order, or where necessary to protect our rights, the rights of others, or to investigate fraud or a security breach.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of our business, client data may be transferred to the acquiring entity. We will notify affected individuals in advance where practicable.
7. How Long We Keep Your Data
| Type of Data | Retention Period |
| Active client project files | Duration of project + 6 years |
| Invoices and financial records | 7 years (HMRC requirement) |
| Enquiries that did not become clients | 6 months from last contact |
| Marketing email lists | Until you unsubscribe or withdraw consent |
| Website analytics data (GA4) | 26 months (Google’s default retention) |
| Server access logs | 90 days (security monitoring) |
| Cookie consent records | 12 months |
| Support and chat communications | 12 months from last interaction |
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data. We will respond to all requests within 30 calendar days (extendable to 60 days for complex requests, with notice).
- Right of access (Art. 15): You can request a copy of the personal data we hold about you (a Subject Access Request).
- Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17): You can ask us to delete your personal data where we no longer have a lawful basis to keep it. Note: we may be required to retain some data by law (e.g. financial records).
- Right to restriction (Art. 18): You can ask us to temporarily stop processing your data in certain circumstances.
- Right to data portability (Art. 20): Where processing is based on consent or a contract, you can ask us to provide your data in a structured, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests at any time. We will stop unless we can demonstrate a compelling legitimate reason that overrides your interests.
- Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at support[at]wpminds.com. We may need to verify your identity before processing your request.
9. How We Protect Your Data
We take data security seriously and have implemented appropriate technical and organisational measures, including:
- HTTPS/TLS encryption on all pages of wpminds.com
- Encrypted storage of passwords (bcrypt hashing; we never store plaintext passwords)
- Restricted access to client data: only team members who need access to deliver your project have it
- Payment data processed exclusively via Stripe (PCI-DSS compliant); we do not store card numbers
- Regular software updates and security patches to our WordPress installation and plugins
- Backups stored securely and separately from the live site
- Data Processing Agreements in place with all third-party processors
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify affected individuals without undue delay.
10. International Data Transfers
10.1 Transfers to the United States
We use a number of service providers based in the United States, including Google (Google Workspace, Google Analytics, Google Ads), Stripe, and Basecamp. We rely on Standard Contractual Clauses (SCCs) incorporated into the terms of service of these providers. Google’s data transfer safeguards are available at business.safety.google/gdpr/. Stripe’s Data Processing Agreement is available at stripe.com/legal/dpa.
10.2 Transfers to Pakistan
Our service delivery team is located in Lahore, Pakistan. Pakistan does not have a UK adequacy decision.
| International Data Transfer Agreement (IDTA) in Place Transfers of personal data to our Pakistan team are governed by a UK International Data Transfer Agreement (IDTA), which has been signed and is in effect. This provides the appropriate safeguards required under UK GDPR for transfers of personal data to countries without an adequacy decision. The categories of data accessible to the Pakistan team are limited to what is strictly necessary for service delivery: client name, website access credentials, project assets, and communication history relating to active contracts. Sensitive data such as payment details is not accessible to the Pakistan team. |
10.3 EEA and EU Residents
The UK has EU adequacy decisions in place, meaning data transferred from the EEA to the UK benefits from equivalent legal protections. EU residents additionally have rights under the EU GDPR and may contact their local supervisory authority.
11. Marketing Communications
We may send you marketing emails about our services, blog content, podcast episodes, and promotions if you have given us your consent to do so.
- You can unsubscribe from marketing emails at any time by clicking the ‘Unsubscribe’ link in any email we send.
- You can also update your preferences by contacting us at support[at]wpminds.com.
- Withdrawing consent for marketing does not affect our ability to send you transactional emails (such as invoices or support responses) that are necessary for your service.
12. Cookies
We use cookies and similar technologies on wpminds.com. Our Cookie Policy explains what cookies we use, why, and how to manage them.
13. California Residents — CCPA / CPRA
If you are a resident of California, USA, additional rights apply to you under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
13.1 Categories of Personal Information Collected
In the past 12 months, we have collected: identifiers (name, email, IP address); commercial information (services purchased, transaction history); internet or network activity (browsing behaviour on our site); and professional information (business name, job title where provided).
13.2 Your California Rights
- Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: You can request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Opt-Out of Sale / Sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising without consent.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your California rights, contact us at support[at]wpminds.com. We will respond within 45 calendar days.
14. Canadian Residents: CASL
If you are located in Canada, the Canadian Anti-Spam Legislation (CASL) applies to commercial electronic messages we send to you.
- We will only send marketing emails to Canadian recipients with express consent, or where implied consent applies under CASL (e.g. an existing business relationship within the last 24 months).
- Every commercial email we send includes a clear, functional unsubscribe mechanism.
- Unsubscribe requests will be honoured within 10 business days as required by CASL.
For privacy enquiries, contact us at support[at]wpminds.com.
15. Children’s Privacy
Our services are directed at businesses and adults. We do not knowingly collect personal data from children under the age of 13 (or 16 in the EEA). If you believe we have inadvertently collected data from a child, please contact us at support[at]wpminds.com and we will delete it promptly.
16. Links to Third-Party Websites
Our website may contain links to third-party websites, social media platforms, or partner sites. This Privacy Policy does not apply to those sites. We do not control, and are not responsible for, the privacy practices of third-party websites.
17. Changes to This Privacy Policy
We review this Privacy Policy at least annually and whenever our data processing activities change. The current version and Effective Date are shown at the top of this document.
Where changes are material, we will notify you by email (if you are a client or subscriber) and by posting a prominent notice on the website.
18. Contact Us and How to Complain
18.1 Data Controller Contact
Email: support[at]wpminds.com
Post: BTLtimes.com LTD t/a WP Minds, C/O J.R. Accounts Ltd, 34-37 Liverpool Street, London, EC2M 7PP
Please mark your correspondence: FAO Data Protection.
We aim to respond to all data protection enquiries within 14 days and to all formal Subject Access Requests within 30 calendar days.
18.2 Complaints to the ICO
If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Phone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
If you are in the EU, you also have the right to contact your local data protection authority.
