white arrow

Privacy Notice

‘Lococo Creative Limited’ Organisation Privacy Notice

This Privacy Notice sets out the data processing activities and commitments of Lococo Creative Limited pursuant to the requirements of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

Our contact details

This Privacy Notice applies to our website hosted at www.locococreative.co.uk (the “Website”) and also applies to our data collection practices outside of the Website. More formally, we are Lococo Creative Limited, a limited liability company registered in England and Wales under company number 08041564 and our registered office is located at 12 Brookfield Drive, Wolvey, Hinckley, Leicestershire, England, LE10 3LT.

Our trading office address is Office 20a, The Hall, Priory Road, Wolston, Coventry, Warwickshire CV8 3FZ, telephone 024 7698 0700, email: hello@locococreative.co.uk.

This Privacy Notice covers the collection, processing and other use of personal data under the Data Protection Act 2018 (“DPA”) and the General Data Protection Regulation (“GDPR”).

For the purpose of the DPA and GDPR, we are the data controller, and any enquiry regarding the collection or processing of your data should be addressed to Joanne Coope at hello@locococreative.co.uk or at our registered office listed above.

By using the Website, you consent to your data being stored and processed in accordance with this Privacy Notice.

What is the purpose of this notice?

To describe how we collect and use personal data about you in accordance with the General Data Protection Regulation (GDPR).

What we need

Lococo Creative Limited will be what’s known as the “Controller” of the personal data you provide to us. We only collect basic personal data about you, which does not include any special categories of personal information about you (known as Special Category Data). This does include, where applicable, name, address, e-mail, telephone number, social media accounts and financial information (payment information).

Why we need it

We need to know your basic personal data in order to provide our graphic design and brand identity services, process your orders, conduct relationship management, and enhance the security of our network and information systems. The lawful bases we rely on for processing this information are Contractual Obligation, Legal Duty, and Legitimate Interest. We will not collect any personal data from you that we do not need to provide and oversee this service to you.

What we do with it

We only ever use your personal data with your consent, or where it is necessary:

  • to enter into, or perform, a contract with you
  • to comply with a legal duty
  • to protect your vital interests
  • for our own (or a third party’s) lawful interests, provided your rights don’t override these.


In any event, we’ll only use your information for the purpose or purposes it was collected for (or for closely related purposes).

We may process personal information for certain legitimate business purposes, which include some or all of the following:

  • where the processing enables us to enhance, modify, personalise or otherwise improve our services/communications for the benefit of our customers
  • to identify and prevent fraud
  • to enhance the security of our network and information systems
  • to better understand how people interact with our websites
  • to provide postal communications which we think will be of interest to you
  • to determine the effectiveness of promotional campaigns and advertising.


Whenever we process data for these purposes, we will ensure that we always keep your personal data rights in high regard and take account of these rights at all times. 

When we process your personal data for our legitimate interests, we will make sure that we consider and balance any potential impact on you (both positive and negative), and your rights under data protection laws. Our legitimate business interests do not automatically override your interests – we will not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You have the right to object to this processing if you wish, and if you wish to do so, please email hello@locococreative.co.uk. Please bear in mind that if you object, this may affect our ability to carry out the tasks above for your benefit.

Where we keep it and security

We are based in the UK and store our data within the EU. Some organisations which provide services to us may transfer personal data outside of the European Economic Area (EEA), which is generally the nature of data stored in “the Cloud”. We will only allow them to do so if your data is adequately protected.

  • Google Workspace (Email and File Storage): As this is a US-based provider, your personal data may be transferred to or accessible from the US. We only allow this under strict terms designed to uphold your privacy rights, such as relying on necessary legal mechanisms (like the UK Addendum to the EU Standard Contractual Clauses) to govern these transfers.
  • ClickUp (Project and Lead Management): As this is a US-based provider, your data may be transferred outside of the EEA/UK for processing. We ensure this transfer is governed by appropriate international data transfer mechanisms to guarantee the continued protection of your data.
  • Capsule CRM (Customer Relationship Management): This provider primarily stores data within the UK/EEA, significantly minimising the risk of unnecessary data transfer outside of the EEA.
  • FreeAgent (Finance and Accounting): As this is a UK-based provider, your data is securely stored within the UK, meaning your data does not leave the EEA/UK during its financial processing.

 

  • Encryption at Rest: All primary devices utilised to access or store client data benefit from full-disk encryption (e.g., BitLocker or FileVault).
  • Data in Transit: We rely on Transport Layer Security (TLS/SSL) encryption for all cloud services and file sharing.
  • DPA: We maintain a template Data Processing Agreement (DPA) to formally execute whenever a client requires us to act as a Data Processor.

How long we keep it (Retention Policy)

We will only use and store information for so long as it is required for the purposes it was collected for. How long information will be stored depends on the information in question and what it is being used for. For example, if you ask us not to send you marketing e-mails, we will stop storing your e-mails for marketing purposes (though we’ll keep a record of your preference not to be e-mailed).

We continually review what information we hold and delete what is no longer required. We never store payment card information. We will not retain your data for any longer than necessary. We enforce the following strict Complete Deletion policy based on the Storage Limitation Principle:

  • Clients & Suppliers (Invoiced Records): Data is held for seven years after the last invoice or interaction. This period covers our Legal Obligation to retain financial records for audit purposes.
  • Prospects & Network (Non-Invoiced Records): Data is held for three years (36 months) of dormancy. This period covers our Legitimate Interest in lead conversion and professional networking.

Action on Expiration

When a record reaches its retention limit, we execute a Complete Deletion procedure, permanently purging the entire record, including all associated communication history (email content in Gmail/Capsule), from all active systems to ensure no unnecessary personal data is processed. We run this full check on an Annual basis.

What we would also like to do with it

We would, however, like to use your name and e-mail address to inform you of our future offers and similar products. This information is not shared with third parties, and you can unsubscribe at any time via phone, e-mail or on our website.

What are your rights?

We want to ensure that you remain in control of your personal data. Part of this is making sure you understand your legal rights, which are as follows:

  • the right to confirmation as to whether we have your personal data and, if we do, to obtain a copy of the personal information we hold (this is known as a data subject access request)
  • the right to have your data erased (though this will not apply where it is necessary for us to continue to use the data for a lawful reason)
  • the right to have inaccurate data rectified
  • the right to object to your data being used for marketing or profiling; and
  • where technically feasible, you have the right to the personal data you have provided to us, which we process automatically based on your consent or the performance of a contract. This information will be provided in a common electronic format.

Please keep in mind that there are exceptions to the rights above and, though we will always try to respond to your satisfaction, there may be situations where we are unable to do so.

If you wish to raise a complaint on how we have handled your personal data, you can contact Joanne Coope, who will investigate the matter. 

If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law, you can complain to the Information Commissioner’s Office, the UK supervisory authority for data protection issues.

Version six: November 2025