Privacy & Cookie Policy

Effective Date: 9th October 2026
Last Updated: 9th October 2026

At Differentiated Ltd, we respect your privacy and are committed to protecting your personal data. This Privacy & Cookie Policy explains how we collect, use, store, and share your personal data when you visit our website, interact with our content, or engage with our business services.

This policy is prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and Google’s EU User Consent Policy.

1. Who We Are & Contact Details

Differentiated Ltd is the Data Controller responsible for personal data collected through this website and in connection with our commercial activities:

  • Full Legal Name: Differentiated Ltd (Company Registration No. 11905079)
  • Registered Office: 30 St John’s Road, Mortimer Common, Reading, RG7 3TR
  • Privacy & Data Protection Contact: operations@differentiated.co.uk
2. Personal Data We Collect

We may collect, use, store, and transfer different kinds of personal data depending on your interaction with us:

  • Website Visitors: IP addresses, browser type and version, time zone setting, operating system, device information, approximate location, pages viewed, referring URLs, interaction data, and cookie identifiers.
  • Enquirers & Prospective Clients: Name, job title, company name, business email address, phone number, contents of your enquiry, and correspondence records.
  • Clients & Vendors: Name, business contact details, contract information, billing/invoicing details, project records, and transaction history.
  • Marketing Contacts: Business email address, job role, communications preferences, and engagement metrics (such as email opens and link clicks).

Information Origin & Sourcing

We collect personal data from:

  1. Direct interactions: When you fill out forms on our site, contact us, or engage our services.
  2. Automated technologies: As you interact with our website, we collect usage data via cookies and similar technologies (subject to your consent).
  3. Publicly available B2B sources: Professional platforms (such as LinkedIn), corporate websites, and public business directories for B2B networking.
  4. Third-party business information providers: We may obtain business contact information from specialist B2B data providers, such as Lusha, to identify relevant professional contacts and support our business development and marketing activities. This may include names, job titles, company information, business email addresses and business telephone numbers.
3. Purposes & Lawful Bases for Processing Data

Under the UK GDPR, we must have a valid lawful basis to process your personal data. The table below details how we use your data and our corresponding lawful bases:

Purpose / Activity Data Categories Involved Lawful Basis for Processing (UK GDPR)
Managing marketing & CRM records (HubSpot) Name, business email, company, contact history, marketing preferences Legitimate Interests (B2B marketing to professional contacts) or Consent
Responding to form enquiries & requests Name, email, phone, company, message contents Legitimate Interests (responding to commercial enquiries) or Pre-contractual steps
Delivering agency & consulting services Contact details, contract data, billing details Performance of a Contract
Managing business accounting & tax records Financial transactions, invoice details, client contact info Legal Obligation (HMRC compliance)
Running website analytics (GA4 & HubSpot) IP address, device IDs, page views, cookie IDs Consent (managed via our Cookie Consent Platform under PECR)
Displaying embedded media (Vimeo) Interaction data, player preferences, technical storage Consent (for non-essential player analytics/cookies)
Ensuring site security & threat prevention IP address, technical system logs Legitimate Interests (protecting site infrastructure)
4. Google Analytics 4 (GA4)

We use Google Analytics 4 (“GA4”), provided by Google LLC, to measure how visitors navigate and interact with our website.

  • Data Collected: GA4 collects technical online identifiers, including device information, browser settings, interactions, and pseudonymised IP details.
  • Consent Requirement: GA4 non-essential cookies and analytics tracking will only execute if you explicitly provide consent via our cookie banner.
  • Transparency Link: For complete information on how Google processes personal data when consent is granted, please review Google’s Business Data Responsibility Site.
5. Google Tag Manager (GTM)

We use Google Tag Manager (“GTM”) to manage and deploy website tracking scripts and functional tools. GTM itself functions purely as a tag management system; it does not set tracking cookies or directly collect personal identifiers on its own. GTM is configured to enforce your consent choices, ensuring that third-party scripts (such as GA4) execute only when permitted.

6. Google Consent Mode V2

We have implemented Advanced Google Consent Mode V2 across our site to communicate your privacy choices directly to Google tags.

  • When Consent is Granted: Google tags initialise normally, setting cookies to measure site interactions and performance.
  • When Consent is Denied: No tracking cookies are set. Google tags receive “cookieless pings” that contain aggregate, non-identifying technical signals used strictly for conversion modeling.
7. HubSpot CRM & Marketing Integration

We use HubSpot (HubSpot, Inc.) to power our website contact forms, CRM database, and marketing communications.

  • Forms & Contacts: When you submit an enquiry form, your details are stored within our secure HubSpot database to allow us to manage our relationship with you.
  • Tracking & Analytics: HubSpot utilises cookies to recognise returning visitors, measure site engagements, and assist our business outreach. Non-essential HubSpot cookies are strictly governed by our cookie consent mechanism and will not fire without your consent.
8. Vimeo Video Embeds

We embed video content provided by Vimeo, Inc. on select pages of our website. When you view pages containing embedded Vimeo videos, Vimeo may utilise cookies, local storage items, and video player analytics to deliver the stream and evaluate performance. Non-essential Vimeo tracking technologies are integrated with our consent platform and will remain blocked until appropriate consent is granted.

9. Cookie Audit & Storage Declarations

In accordance with PECR and UK GDPR, below is a complete list of cookies and storage items used on our website:

Provider Item Name Category Purpose Duration
Kilo CMP kilo_consent Strictly Necessary Stores your privacy consent choices (Local Storage). Persistent (stored until deleted by the user or cleared via browser settings)
Google Analytics _ga Analytics Primary GA4 cookie used to distinguish unique visitors. 13 months
Google Analytics _ga_* Analytics Used by GA4 to persist session state across pages. 13 months
HubSpot _hstc Analytics Main tracking cookie for visitors; stores domain, user ID, timestamp. 13 Months
HubSpot hubspotutk Analytics Tracks visitor identity associated with form submissions. 13 Months
HubSpot hssc Analytics Identifies if session numbers should be incremented. 30 Minutes
HubSpot hssrc Analytics Session cookie set to determine browser restarts. Session
Vimeo vuid Analytics / Functional Unique identifier used by Vimeo embedded players for analytics. 2 Years
Vimeo _cf_bm Strictly Necessary Cloudflare security and bot protection for Vimeo embeds. 30 Minutes
10. Third-Party Service Providers (Recipients)

We share personal data with trusted third-party service providers who process data strictly on our behalf under formal Data Processing Agreements (DPAs):

  • Google LLC: Website analytics infrastructure (GA4, GTM).
  • HubSpot, Inc.: CRM, contact forms, and email communications management.
  • Vimeo, Inc.: Embedded video player delivery.
  • Foleon B.V.: Digital publishing platform and content delivery infrastructure for interactive agency publications.
  • Website Hosting & Infrastructure Providers: Secure cloud hosting and database management.
  • Accounting & Financial Software Providers: Invoicing, accounting, payment and financial administration.
  • Business Operations & Time-Management Providers: Project management, time recording, resource management and related business administration.
  • Professional Advisors: Accountants, legal counsel and auditors where required or appropriate.
  • Other Service Providers: Where necessary, we may use specialist technology and professional service providers to support the operation of our business.
11. Links to External Websites

Our website may contain links to external websites, plugins, or applications (e.g., social media profiles). Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy notice of every website you visit.

12. International Data Transfers

Some of our technology providers (including Google, HubSpot, and Vimeo) are headquartered outside the UK and EEA, primarily in the United States. Whenever personal data is transferred internationally, we ensure appropriate safeguards are applied:

  • Transfers to organisations certified under the UK Extension to the EU-U.S. Data Privacy Framework (DPF).
  • Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement/Addendum (IDTA).
13. Data Retention Policy

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements:

Data Category Retention Schedule
Website Enquiries (Form Submissions) Retained for 2 years from last contact unless a client contract is executed.
Client & Contractual Records Retained for 7 years following contract termination (HMRC tax compliance).
B2B Marketing Contacts Retained until you opt out or after 24 months of total inactivity.
Analytics Data (GA4) User-level analytics data retained for 14 months from session activity.
Consent Log Records Retained for 12 months to satisfy regulatory compliance proof.
14. Data Security Safeguards

We have implemented appropriate technical and organisational security measures to protect your personal data from accidental loss, unauthorised access, alteration, or disclosure. Measures include:

  • Secure Socket Layer (SSL/TLS) encryption for all website traffic.
  • Restricted, role-based access controls for corporate databases and CRM tools.
  • Multi-factor authentication (MFA) across business systems.
  • Routine security monitoring and vendor due diligence reviews.
15. Individual Rights Under UK GDPR

Under data protection law, you have specific rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data in certain circumstances.
  • Right to Restrict or Object: Object to or restrict our processing of your data (including direct marketing).
  • Right to Data Portability: Request transfer of your data to another organization.
  • Right to Withdraw Consent: Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, please email operations@differentiated.co.uk. We respond to all valid requests within one calendar month.

16. B2B Communications & Direct Marketing

We may contact business and professional contacts for direct marketing purposes where we have a lawful basis to do so. These contacts may include existing clients, prospective clients, and professional contacts whose business contact information we have obtained directly from them, from publicly available sources, or from third-party business information providers.

We may use business contact information, such as your name, job title, organisation, business email address and business telephone number, to provide information about our services and other business-to-business communications that we reasonably believe may be relevant to your professional role or organisation.

Where we rely on legitimate interests for direct marketing, we will consider the nature of the relationship, the relevance of the communication and your reasonable expectations, and will respect your right to object to direct marketing.

  • Opt-Out Mechanism: Every commercial email includes a simple, automated “Unsubscribe” link in the footer.
  • Right to Object: You can object to our use of your personal data for direct marketing at any time.
  • Immediate Removal: You can request removal from our marketing lists at any time by emailing operations@differentiated.co.uk. We will stop sending direct marketing communications to you following your request, subject to any limited processing required to maintain a record of your marketing preference.
17. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects concerning individuals.

18. Regulatory Complaints & Policy Updates

Right to Lodge a Complaint

If you have concerns regarding our processing of your personal data, please contact us first so we can resolve the issue. You also have the right to lodge a complaint with the UK supervisory authority:

  • Information Commissioner’s Office (ICO)
  • Website: www.ico.org.uk
  • Helpline: 0303 123 1113

Policy Updates

We reserve the right to update this policy to reflect operational or regulatory changes. Updated versions will be published on this page with a revised “Last Updated” date. Where material changes occur, we will re-prompt for consent via our cookie banner.