Skip to main content
ESTOPIA™engineering studio / scotland / remote

Privacy Policy

Effective date: 30 April 2026

Who We Are

Estopia Engineering is a software engineering consultancy registered in Scotland (company number SC874827). We operate the website estopia.net and provide web and application development services to businesses worldwide.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or engage with our services. Please read this policy carefully. If you disagree with the terms of this policy, please do not access the site.

You can reach us at any time at [email protected].

Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the website includes:

Personal Information

Personally identifiable information that you voluntarily provide to us when you fill out contact forms, lead generation forms, subscribe to our newsletter, or engage our services, such as:

  • Your name
  • Email address
  • Company name
  • Phone number (if provided)
  • Any other information you choose to provide

Partner Rewards and Referral Attribution Data

If you apply to join our Partner Rewards programme, we may collect information such as your partner type, reward preference, company details, and information about the kinds of businesses you usually introduce to us.

If you arrive on our website through a partner referral link, we may store the referral code, referring partner name, landing page path, and capture timestamp in first-party browser storage so we can attribute a later enquiry correctly. If you then submit a contact form, that referral attribution may be included with the enquiry we send to our backend systems.

Usage Data

We use PostHog (hosted in the EU at eu.posthog.com) and, where enabled for a given site deployment, Google Analytics 4 for website analytics. Analytics requests are only sent after you opt in via our cookie banner.

Data collected automatically includes:

  • Pages visited and time spent on each page
  • Clicks, scroll depth, and on-page interactions
  • Referrer (the website that directed you to us)
  • Browser type and version
  • Operating system
  • Device type and screen resolution

Session Recordings

We record browsing sessions using PostHog to improve user experience. Session recordings capture mouse movements, clicks, and page interactions. All form inputs are automatically masked in recordings — no passwords, email addresses, or personal data are visible in session replays.

We operate with person_profiles: "identified_only", meaning we only create individual user profiles when users voluntarily identify themselves (for example, by submitting a contact form). Anonymous visitors are not individually profiled.

Cookies

We use Osano Cookie Consent to manage cookie preferences. Visitors can choose whether optional analytics cookies may be set and can revisit that choice at any time from the footer of our website.

For full details on the cookies we use and your choices, please see our Cookie Policy.

How We Use Your Information

We use the information we collect about you for the following purposes:

  • Providing our services — to deliver the products and services you have requested, manage your account, and process transactions
  • Responding to inquiries — to respond to your comments, questions, and requests, and provide customer support
  • Partner rewards administration and referral attribution— to review partner applications, generate referral codes and links, deliver partner emails, attribute referred enquiries, and prevent misuse of the programme
  • Website analytics and UX improvement — to monitor and analyse usage trends and preferences via PostHog and, where enabled, Google Analytics 4 to improve the functionality and user experience of our website
  • Session recordings — to review browsing sessions for debugging and UX optimisation, with all personal form inputs automatically masked
  • Sending newsletters — to send you marketing communications, but only if you have explicitly opted in to receive them. You can unsubscribe at any time
  • Compliance and protection — to comply with legal obligations and to protect our rights, privacy, safety, or property

Legal Basis for Processing

We process your personal data under the following legal bases as defined by the UK General Data Protection Regulation (UK GDPR):

  • Legitimate interest — we process data to improve our services, understand how our website is used, communicate with prospective clients, and administer our partner rewards and referral attribution processes, where such processing does not override your rights
  • Consent — where you have given us explicit consent to process your data for a specific purpose, such as subscribing to our newsletter or accepting non-essential cookies. Consent for analytics cookies, session recordings, and any enabled Google Analytics measurement is managed via our cookie banner
  • Contractual necessity — where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract

How We Share Your Data

We do not sell your data. Period. We may share your data only with the following categories of service providers who assist us in operating our website and delivering our services:

  • PostHog — analytics and session recordings (EU-hosted at eu.posthog.com)
  • Resend — newsletter subscription management and operational email delivery, including partner referral link emails
  • Google Analytics 4— website measurement where enabled for a given site deployment and only after consent
  • Osano Cookie Consent — cookie consent management
  • Hosting infrastructure — servers and backend infrastructure for our website, API, and contact processing
  • Payment processors — for subscription billing

All third-party service providers are contractually obligated to protect your data and are only permitted to use it for the purposes we specify.

Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.

When we no longer have a legitimate business need to process your personal data, we will either delete or anonymise it. If deletion is not possible (for example, because your data has been stored in backup archives), we will securely store your data and isolate it from any further processing until deletion is possible.

Referral attribution stored in our first-party referral cookie expires after 30 days. A matching local storage entry may remain on your device until it is cleared, replaced, or you ask us to remove the related data from our systems.

You may request deletion of your data at any time by contacting us at [email protected].

Your Data Protection Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access — you have the right to request copies of your personal data
  • Right to rectification — you have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete
  • Right to erasure — you have the right to request that we erase your personal data, under certain conditions
  • Right to restrict processing — you have the right to request that we restrict the processing of your personal data, under certain conditions
  • Right to object to processing — you have the right to object to our processing of your personal data where we rely on legitimate interest as our legal basis
  • Right to data portability — you have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions
  • Right to withdraw consent — where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO at ico.org.uk.

Cookies

Our website uses cookies to enhance your browsing experience and to collect analytics data. Cookie consent is managed by Osano Cookie Consent, our cookie banner provider.

We use the following categories of cookies:

  • Strictly Necessary — essential for the website to function correctly, such as consent preferences and preserving referral attribution when you arrive via a partner link
  • Analytics— PostHog cookies and, where enabled, Google Analytics 4 cookies for understanding how visitors interact with our site
  • Functional — we do not currently use separate optional preference-based functional cookies on the marketing site

For comprehensive information about the cookies we use, their purposes, and durations, please refer to our Cookie Policy.

You can manage your cookie preferences at any time via our centre.

International Transfers

PostHog analytics data is hosted in the EU (Frankfurt, Germany). However, some of the providers we use, such as Resend and, where enabled, Google Analytics, may process personal data outside the UK or European Economic Area, including in the United States.

Where international transfers take place, we use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or comparable lawful transfer mechanisms required by applicable data protection law.

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • HTTPS encryption across our entire website
  • Access controls to limit data access to authorised personnel
  • Regular security reviews of our systems and processes
  • Consent-gated analytics loading so optional tracking stays off until you opt in

While no method of transmission over the internet is 100% secure, we strive to use commercially acceptable means to protect your personal data.

Children's Privacy

Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.

If you believe we have inadvertently collected data from a child under 16, please contact us immediately at [email protected].

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Effective date" at the top of this page.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of our website after any changes to this policy constitutes your acceptance of those changes.

Contact Us

Questions about this Privacy Policy? Get in touch.

Estopia Engineering — Scottish company SC874827