Privacy Policy
We are pleased that you are visiting our website at www.wifisetup.co.uk. Data protection and data security when using our website are very important to us. We would therefore like to inform you which of your personal data we collect when you visit our website and for what purposes it is used.
This notice also covers personal data used in providing our services, managing customer and supplier relationships, and giving invited users access to private business applications such as WiFiSetup Finance. The Finance-specific details appear under Data We Collect, item j.
Who is Responsible?
The person responsible in the sense of the UK’s Data Protection Act (“DPA”) and the EU’s General Data Protection Regulation (“GDPR”) is Andrew James, a sole trader trading as WiFiSetup, of Manod Rd, Blaenau Ffestiniog, LL41 4DE (“we”, “us”, “our”). Please direct any questions you may have to info@wifisetup.co.uk or write to us at the above address.
Principles of Data Processing
- Personal Data Personal data is any information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, e-mail address, IP address or user behaviour.
- Processing The processing of personal data (e.g. collection, retrieval, use, storage or transmission) always requires a legal basis.
- Legal basis In accordance with the DPA and the GDPR, we have to have at least one of the following legal bases to process your Personal Data: i) you have given your consent, ii) the data is necessary for the fulfilment of a contract / pre-contractual measures, iii) the data is necessary for the fulfilment of a legal obligation, or iv) the data is necessary to protect our legitimate interests, provided that your interests are not overridden.
- Retention Processed personal data will be deleted as soon as the purpose of the processing has been achieved and there are no longer any legally required retention obligations.
Data We Collect
- Provision and Use of the Website
When you call up and use our website, we collect the personal data that your browser automatically transmits to our server. This is technically necessary for us to display our website and to ensure its stability and security. In this sense, we collect the following data: i) IP address of the requesting computer, ii) Date and time of access, iii)name and URL of the file accessed, iv) website from which the access was made (referrer URL), v) browser used and, if applicable, the operating system of your computer as well as the name of your access provider. The legal basis is our legitimate interest. - Hosting
The hosting services used by us for the purpose of operating our website is Verpex hosting LTD. In doing so Verpex, processes inventory data, contact data, content data, usage data, meta data and communication data of customers, interested parties and visitors of our website and services, on the basis of our legitimate interests. - Content Management System
We use the Content Management System (CMS) of WordPress by Automattic Inc, to publish and maintain the created and edited content and texts on our website. This means that all content and texts submitted to our website is transferred to WordPress. The legal basis is our legitimate interest. - reCAPTCHA
We also use Google`s reCAPTCHA from Google to check whether data input is made by a human being or by an automated program. For this purpose, reCAPTCHA analyses the behaviour of the website visitor on the basis of various characteristics. This analysis begins automatically as soon as the website visitor enters the website. The legal basis for using reCAPTCHA is our legitimate interest. - Cookies
We use so-called cookies on our website. Cookies are pieces of information that are transmitted from our web server or third-party web servers to your web browser and stored there for later retrieval. Cookies may be small files or other types of information storage. There are different types of cookies: i) Essential Cookies. Essential cookies are cookies to provide a correct and user-friendly website; and ii) Non-essential Cookies. Non-essential Cookies are any cookies that do not fall within the definition of essential cookies, such as cookies used to analyse your behaviour on a website (“analytical” cookies) or cookies used to display advertisements to you (“advertising” cookies). - Cookie Consent
Our website uses a cookie consent management tool to obtain your consent to the storage of cookies and to document this consent. When you enter our website, the following Personal Data is transferred to us via Hu-manity: i) Your consent(s) or revocation of your consent(s); ii) Your IP address; iii) Information about your browser; iv) Information about your device; v) Time of your visit to our website. The basis for processing is our legitimate interest. - Contacting Us
We offer you the opportunity to contact us using various methods. We collect the data you submit such as your name, email address, telephone number and your message in order to process your enquiry and respond to you. The legal basis is both your consent and contract. - When Using our Services
We process the Personal Data involved in your use of our services in order to be able to provide our contractual services. This includes in particular our support, correspondence with you, invoicing, fulfilment of our contractual, accounting and tax obligations. Accordingly, the data is processed on the basis of fulfilling our contractual obligations and our legal obligations. - Administration, Financial Accounting, Office Organisation, Contact Management
We process data in the context of administrative tasks as well as organisation of our business, and compliance with legal obligations, such as archiving. In this regard, we process the same data that we process in the course of providing our contractual services. The processing bases are our legal obligations and our legitimate interest. - WiFiSetup Finance — Private Business Administration
WiFiSetup Finance is our private application for managing WiFiSetup’s own finances. Access is limited to the owner and named people invited to assist the business. We are responsible for this processing for our own business purposes; we do not operate Finance on Intuit’s behalf.
Information and sources. When the owner connects business accounts, Finance obtains information from Monzo Business and QuickBooks. This includes account and pot balances, transactions and payment references, customer and supplier contact details, invoices, bills, payments, credits, accounting categories and attachment details. Authorised users may upload invoices and receipts and add bookkeeping notes and proposed categories. Customer and supplier information may therefore come from these business records rather than directly from the individual.
Purposes and legal bases. We use this information to check purchases, maintain accounting evidence, understand available funds and identify outstanding invoices. Accounting records required by law are processed to meet our legal obligations. Necessary business administration and access security are based on our legitimate interests in managing the business and protecting its records, taking account of individuals’ rights and expectations.
Invited users and advisers. We keep invited users’ names, email addresses, assigned roles, protected password records, invitation and recovery records, sign-in times and recorded actions. The owner or invited user supplies these details. An email address and password are needed to use an invited account. The owner may allow named accountants, bookkeepers or other advisers to inspect records or amend local reviews within their assigned role, solely for authorised WiFiSetup work. Our business email delivery provider sends invitations, password-reset links and related security messages, processing recipients’ email addresses, message content and delivery information for this purpose.
Providers and location. Finance uses connected banking and accounting services and a business email delivery provider. Our Finance server and operator-managed backups are in the UK. These external services have their own processing arrangements and may process information outside the UK, including in the United States. Their published safeguards include UK adequacy arrangements, the UK Extension to the EU–US Data Privacy Framework for participating organisations, or approved contractual safeguards, including the UK Addendum to EU Standard Contractual Clauses, as applicable to the service and destination. For details of the providers involved with your information or a copy of the relevant transfer safeguards, contact info@wifisetup.co.uk. Providers remain responsible for their own processing under their applicable terms and notices.
Security and cookies. Finance uses HTTPS, named accounts and restricted access. Passwords are hashed and integration secrets are encrypted; this does not mean that every stored financial record or backup is encrypted. Its essential sign-in cookie expires after 12 hours. Finance uses no advertising or analytics cookies. These are the controls currently implemented for Finance; no independent security certification or formal ongoing review programme is claimed.
Retention and disconnection. Business records are retained while necessary for their accounting purpose, statutory obligations or unresolved queries and claims. User-access and activity records are retained as needed for administration and security. The owner administers retention and deletion requests; Finance currently has no automatic retention-deletion schedule. Earlier copies can remain in backups until those backups are retired. Disconnecting a provider stops further imports through that connection but does not erase imported records. Provider consent can also be revoked in the provider’s account settings.
Your rights and use of automation. The rights and contact arrangements elsewhere in this policy apply to Finance, including restriction of processing where the law provides that right. Some records must be retained to meet legal obligations. Finance does not sell records or use them for advertising or model training. Its current deployed features do not send accounting records to a generative AI service or make solely automated decisions with legal or similarly significant effects. Purchase suggestions remain subject to human review.
Data Security
However, we would like to point out that, due to the structure of the Internet, it is possible that the rules of data protection and the above-mentioned security measures are not observed by other persons or institutions that are not in our area of responsibility. We have no technical influence on this. It is the user’s responsibility to protect the data he or she provides against misuse by encrypting it or in any other way.
International Transfers
How We May Share Your Personal Data
We may also disclose your Personal Data for any purpose with your consent or for law enforcement, fraud prevention or other legal actions as required by law or regulation, or if we reasonably believe that we must protect us, our customers or other business interests. Except as described above of which you will be informed in advance, we will not disclose your Personal Data.
What We Do Not Do
- We do not request Personal Data from minors and children;
- We do not use Automated decision-making including profiling; and
- We do not sell your Personal Data.
Privacy Rights
Under the DPA and the GDPR, you can exercise the following rights:
- Right to information
- Right to rectification
- Right to deletion
- Right to restriction of processing
- Right to data portability
- Right of objection
- Right to withdraw consent
- Right to complain to a supervisory authority
- Right not to be subject to a decision based solely on automated processing.
Updating your information and withdrawing your consent If you believe that the information we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing or want to withdraw any consents you have given us, please contact us.
Access Request
Complaint to a Supervisory Authority
Validity and Questions
This Privacy Policy was last updated on Wednesday, 9 September 2026, and is the current and valid version. However, from time to time changes or a revision to this policy may be necessary.
If you have any questions or comments about this Policy or wish to exercise your rights under applicable laws, please contact us using info@wifisetup.co.uk or write to us at the above address.