This Privacy Policy explains how we collect, use and protect personal data when you use this website, including the contact form, embedded YouTube videos and embedded maps.
1. Data Controller
The controller of your personal data is:
Paweł Szymaniewicz
trading as Paulbau
2 Glenallan Drive
EH16 5QX Edinburgh
United Kingdom
Phone: +44 7553693734
Email: hello@paulbau.co.uk
2. What data we collect
Depending on how you use the website, we may collect:
name,
email address,
phone number (if provided),
message content,
IP address,
date and time of submission,
technical data such as browser type, device information and basic usage data.
3. How we collect data
When you submit the contact form (Contact Form 7).
When you contact us directly by email.
When you browse the website (technical data and cookies).
When you view embedded content (YouTube videos and embedded maps).
4. Why we use your data
We use personal data for the following purposes:
to respond to enquiries sent via the contact form or email,
to communicate with potential and existing customers,
to provide services or prepare an offer,
to protect the website from spam and abuse,
to keep the website working properly and securely.
5. Legal basis
We process personal data under UK GDPR on the following legal bases:
Consent – where required, for example for non-essential cookies and embedded third-party content (such as YouTube videos and embedded maps).
Legitimate interests – for handling enquiries, maintaining website security and preventing spam/abuse.
Contract – when processing is necessary to take steps at your request before entering into a contract, or to deliver a service.
Legal obligation – where we must comply with a legal requirement.
6. Contact Form 7 and messages
When you submit the contact form, your data is sent to us so we can reply. Depending on settings, form submissions may also be stored in the website database and/or in email systems.
We do not use contact form data for unsolicited marketing.
7. Google reCAPTCHA (spam protection)
This website uses Google reCAPTCHA to protect forms and prevent spam. reCAPTCHA may collect information about your device and browsing activity on this website (including IP address, mouse movements, time spent on the page and browser settings) to determine whether you are a human or a bot.
This data is processed by Google in accordance with Google’s own privacy policies. Use of reCAPTCHA is based on our legitimate interest in securing the website and preventing abuse, and where required, on your consent (depending on how cookies/consent are configured on the website).
8. Embedded YouTube videos
Some pages may include embedded YouTube videos. When you play or interact with embedded YouTube content, YouTube/Google may set cookies and collect data about your interaction with the video. This may include your IP address and information about your device and browser.
We recommend accepting or rejecting embedded media cookies according to your preference. If you do not want this data to be shared with YouTube/Google, do not play the embedded videos.
9. Embedded maps
Some pages may include embedded maps (for example, Google Maps). When you view an embedded map, the map provider may collect data such as your IP address and may set cookies to provide and secure the service.
Where required, we rely on your consent for loading embedded map content. If you do not want this data to be shared, do not load the embedded map.
10. Cookies
This website uses cookies and similar technologies:
Essential cookies – required for the website to function properly.
Functional / embedded media cookies – used when loading third-party content such as YouTube videos or maps.
You can control cookies through your browser settings. If the website uses a cookie consent banner, you can also manage preferences there.
11. Who we share data with
We may share personal data only when necessary with:
our hosting provider (to run and secure the website),
service providers involved in email delivery and website maintenance,
Google (reCAPTCHA, and embedded services such as YouTube and maps when used).
We do not sell your personal data.
12. International data transfers
Some service providers (for example Google and hosting/email providers) may process data outside the UK. Where this happens, transfers are protected using appropriate safeguards required by UK data protection law.
13. How long we keep your data
We keep personal data only as long as needed:
to respond to your enquiry and continue communication,
to fulfil contractual and legal obligations,
until you request deletion, where applicable.
After that, we delete or anonymise the data.
14. Your rights
Under UK GDPR, you have the right to:
access your personal data,
request correction of inaccurate data,
request deletion of your data,
restrict processing,
object to processing,
request data portability,
withdraw consent at any time (where we rely on consent).
We use appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access or disclosure.
16. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be published on this website.
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.