Skip to content

Morgan Reach Marketing — Privacy Policy 

Who we are

Morgan Reach Marketing (“we”, “us”, “our”) is a UK-based digital marketing agency providing strategy, performance marketing, SEO, branding, web development and AI/analytics services. Our main office is: 

Morgan Reach House 

136 Hagley Road 

Edgbaston, Birmingham B16 9NX 

General enquiries: 0121 236 0777 

Email: marketing@morganreach.com. (morganreachmarketing.com) 

This privacy policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over your data. It’s based on standard industry practice and shaped with reference to typical marketing-agency privacy notices. (Echo Poster) 

Data Controller

The data controller for personal data collected through this website and our services is Morgan Reach Marketing (contact details above). If you have questions about how we handle personal data, please contact marketing@morganreach.com. (morganreachmarketing.com) 

What personal data we collect 

We collect different types of personal data depending on how you interact with us: 

  • Contact and identity data: name, company, job title, email, telephone, postal address. 
  • Transactional and contractual data: quotes, invoices, purchase and payment details (where applicable). 
  • Communications data: emails, messages, notes from calls/meetings, CVs (if you apply for roles). 
  • Technical and website data: IP address (anonymised where possible), device/browser data, pages visited, cookies and similar technologies. 
  • Marketing preferences: whether you want to receive newsletters or promotional messages. 
  • Third-party data: information you give us about other people (e.g. a contact at your client or supplier) and data we process for clients as their processor. 

We only collect the minimum personal data necessary for the purpose described below. 

How we use your data (purposes and lawful bases) 

We process personal data on one or more of these lawful bases: 

  • Contract — to deliver services you’ve contracted us for (e.g. campaigns, reporting, site builds). 
  • Consent — where you’ve actively opted in (for example to receive marketing emails or non-essential cookies). 
  • Legitimate interests — to operate and improve our business, provide client support, prevent fraud, and send service-related messages where those interests are not overridden by your rights and freedoms. Examples: analysing website traffic to improve usability; contacting prospects about our services. 
  • Legal obligation — to comply with laws (for example accounting, tax and retention rules). 

We will not use your personal data for purposes incompatible with the original purpose for which it was collected without notifying you. 

Cookies and similar technologies 

We use cookies and similar technologies to operate the website, improve your experience and for analytics and marketing. Some cookies are strictly necessary (to keep forms working); others require consent (analytics, advertising). You can manage or withdraw cookie consent via your browser or the cookie controls on our site. For details of your rights and the legal background to cookies see ICO guidance. (ICO) 

Analytics, embeds and third-party services 

We may use third-party services (for example analytics providers, font services, map providers and video embeds) to provide features and measure site performance. These third parties may set their own cookies and collect data; their use of your personal data is governed by their own privacy policies. Where necessary we will obtain consent for non-essential tracking. 

(If you want a specific list of providers we use — e.g. Google Analytics, YouTube, Google Fonts — tell me and I’ll add an explicit vendor list and data-processing notes for each.) (Echo Poster) 

Newsletters and marketing 

We only send marketing emails if you’ve opted in or where we have another lawful basis (for example a contractual relationship or legitimate interest and you have not objected). All marketing emails include an unsubscribe link and we use a double opt-in where applicable. 

Sharing data with third parties 

We may share personal data with: 

  • Service providers who process data on our behalf (hosting, analytics, CRM, email platforms). 
  • Professional advisers and suppliers where necessary to deliver services. 
  • Legal or regulatory authorities, if required by law. 
  • Potential buyers/investors in the event of a sale of our business (with appropriate safeguards). 

All processors are selected for their security practices and only process data under our instructions. 

International transfers 

Some third-party services may transfer personal data outside the UK/EEA. We will only transfer personal data where there are appropriate safeguards (e.g. adequacy decisions, standard contractual clauses) or where you have given explicit consent. If you would like details of the safeguards for any transfer, contact marketing@morganreach.com. 

Data retention 

We keep personal data only for as long as necessary for the purposes set out above, or as required by law. Typical retention periods: 

  • Enquiries and contact forms: retained while relevant + up to 2 years. 
  • Client records and financial records: retained to meet contractual and statutory obligations (commonly up to 6 years). 
  • Marketing lists: retained until you opt out. 

If you require precise retention windows for a particular category of data, we’ll provide that on request. 

Your rights 

Under the UK GDPR you have rights including (depending on the circumstances) the right to: 

  • Access the personal data we hold about you. 
  • Request correction of inaccurate data. 
  • Request erasure (right to be forgotten) in certain situations. 
  • Request restriction of processing. 
  • Object to processing (including for direct marketing). 
  • Request portability of data you provided to us. 
  • Withdraw consent where processing is based on consent. 

To exercise any right, contact marketing@morganreach.com. We will respond within required statutory timescales. For more on these rights see ICO guidance. (ICO) 

Security 

We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access or disclosure. No internet system is 100% secure, but we regularly review and improve security practices (encryption in transit, access controls, staff training). 

Changes to this policy 

We may update this policy from time to time. We’ll post the updated date at the top of the policy page and, where appropriate, notify you by email.

How to complain 

If you have a concern about our handling of personal data, please contact marketing@morganreach.com so we can try to resolve it. If you remain unhappy you can complain to the UK Information Commissioner’s Office (ICO). Guidance on making complaints and how the ICO handles them is available on the ICO website. (ICO) 

Contact 

Data protection enquiries and requests: marketing@morganreach.com or write to Morgan Reach Marketing, Morgan Reach House, 136 Hagley Road, Edgbaston, Birmingham B16 9NX. (morganreachmarketing.com)