Legal

Privacy Policy

Last updated: 15 May 2026 · Version 1.0

The short version: we only collect the data we actually need to deliver the service or follow up on your enquiry. We don't sell data. We don't share it with third parties beyond the tools we run on (listed below). You can ask us to delete your data at any time and we will, within 30 days. Detailed version follows.

1. Who we are

First60 ("we", "us", "our") is the trading name of [Your registered company name] Ltd, a private limited company registered in England & Wales under company number [Company No.], with registered office at [Registered office address].

For the purposes of UK GDPR, we are the data controller of any personal data we collect about you directly. For data we process on behalf of our clients (for example, lead data flowing through systems we install), we act as a data processor under a Data Processing Agreement with that client.

We are registered with the UK Information Commissioner's Office (ICO) under registration number [ICO Reg No.].

2. What data we collect

2.1 When you visit first60.co.uk

2.2 When we contact you proactively (B2B outreach)

2.3 When you become a client

3. Why we collect it (lawful basis)

DataWhyLawful basis
Website enquiry formAnswer your enquiryConsent
Audit call bookingRun the call you bookedPerformance of contract / consent
B2B cold outreach to corporate rolesTell you about our serviceLegitimate interest
Billing & service dataDeliver the service you paid forPerformance of contract
Anonymous analyticsImprove the siteLegitimate interest

4. Who we share data with (sub-processors)

To deliver the service we use the following third-party tools. Each one is contractually bound by UK GDPR-compliant Data Processing Agreements:

ProviderWhat they processWhere
GoHighLevel (HighLevel Inc.)CRM, automations, SMS, email, schedulingUSA — with UK GDPR Standard Contractual Clauses
Twilio Inc.SMS & voice routingUSA — SCCs in place
Vapi AIAI voice agent processingUSA — SCCs in place
Stripe Inc.Card paymentsUSA / UK — PCI-DSS compliant
GoCardless LtdUK Direct DebitUnited Kingdom
Cloudflare Inc.Website hosting & DNSGlobal edge — UK SCCs in place
Google LLC (Workspace)Business emailUSA / EU — SCCs in place

We do not sell your data to anyone, ever. We never share data with advertising networks.

5. How long we keep it

6. Your rights

Under UK GDPR you have the right to:

To exercise any right, email us at privacy@first60.co.uk and we'll respond within 30 days.

7. Cookies

This site uses only essential cookies for functionality. We don't currently set advertising or tracking cookies. If we add analytics in future (e.g. Google Analytics, Plausible), this policy will be updated and any non-essential cookies will require your consent via a banner.

8. Security

We use industry-standard security including:

9. International transfers

Some of our sub-processors are based in the USA or process data globally. Where data leaves the UK, we rely on:

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified at least 14 days before they take effect, either via the email we have on file for you or via a notice on this page. The "Last updated" date at the top reflects the most recent revision.

11. Contact

Questions about this policy or how we handle your data:

Template notice: This document is a fit-for-purpose template for a UK B2B service business. Before going live, replace the bracketed placeholders and have a qualified UK solicitor review it for your specific operation. The cost is typically £200–£500 and worth it.