1. About this policy
This Privacy Policy explains how EEZEE DIGITAL LTD ("eezee", "we", "us")
collects and uses personal data when you use the eezee platform (the "Service") at
build-eezee.com and connected sites. It is written to meet our obligations under the UK
GDPR and the Data Protection Act 2018.
Please also read our Terms of Service.
2. Two different roles — please read
eezee handles personal data in two distinct roles, and this matters for your rights:
As a controller — for personal data about the businesses that sign up to eezee (the account owner and their staff) and about visitors to our own eezee website. We decide how and why this data is used.
As a processor — for personal data about the customers of the businesses that use eezee (for example someone who makes a booking or places an order on a Merchant's site). Here, the Merchant is the controller and eezee only processes that data on the Merchant's instructions to provide the Service. If you are a customer of a business that uses eezee and want to exercise your rights, please contact that business first (see clause 11).
3. Who we are and how to contact us
Controller: EEZEE DIGITAL LTD, a company registered in England and Wales (company number 17450282), registered office Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, trading as "eezee".
ICO registration number: [ICO REG NO — register at ico.org.uk before processing].
Contact for privacy matters: support@build-eezee.com.
[If a Data Protection Officer is appointed, add their details; a DPO may not be legally required — confirm with solicitor.]
4. The personal data we collect
4.1 Merchant account data (we are controller)
- Identity and contact: the account owner's name and email address; business name; the names of staff/providers you add.
- Authentication: a securely hashed password and session information. We never store your password in plain text.
- Business content you provide: your description of your business and any content you enter or generate (some of which may contain personal data if you choose to include it).
- Billing: records of AI Credit purchases (amount, date, Stripe reference). Card details are handled by Stripe — we do not receive or store full card numbers.
- Connected payment account: your Stripe Connect account identifier and whether payments are enabled (we do not receive your Stripe login or banking credentials).
- Usage and technical data: log data, and an append‑only audit trail of key account actions (kept deliberately light on personal data — e.g. amounts, counts and product names, not customer names or emails).
4.2 Website‑visitor data (we are controller)
When you visit our own eezee marketing site, we collect limited technical data (such as IP
address and basic request logs) and essential cookies needed to run the site. [Add analytics detail here only if/when analytics are introduced.]
4.3 Customer data processed for Merchants (we are processor)
When a Merchant operates a site on eezee, we process, on the Merchant's behalf, the personal data their customers submit, which may include:
- Bookings: customer name and email address, and the service, provider and appointment time; reminder timestamps.
- Orders: customer name, email address, delivery address, order notes, and order contents and totals. We process this data only to provide the booking, shop, payment and email features to the Merchant. We do not use Customer Data for our own purposes.
5. Why we use personal data, and our lawful bases
| Purpose | Data | Lawful basis (UK GDPR) |
|---|---|---|
| Create and administer your eezee account | Merchant account data | Contract (Art. 6(1)(b)) |
| Provide the website builder and AI features | Business content you provide | Contract |
| Process AI Credit purchases and keep billing records | Billing data | Contract; Legal obligation (tax) |
| Send transactional emails (e.g. booking confirmations, reminders, password resets) | Name, email | Contract; Legitimate interests |
| Keep the audit trail and secure the Service | Usage/technical data | Legitimate interests; Legal obligation |
| Comply with law and handle legal claims | As needed | Legal obligation; Legitimate interests |
| Process Customer Data through the Service | Customer Data | We act as processor; the Merchant sets the lawful basis |
Where we rely on legitimate interests, we have balanced those interests against your rights. You can ask us about this balancing at any time.
6. AI processing
To generate and edit sites, the information you enter into the AI features (your business
description and edit instructions) is sent to our AI provider, Anthropic, which processes
it to return generated content. [Confirm current position with Anthropic's commercial terms: inputs/outputs of the commercial API are not used to train their models. State this only if it remains accurate at publication.] Do not enter personal data into the AI features unless you
need to, and do not enter special‑category data.
7. Sharing your data and our sub‑processors
We do not sell personal data. We share it with service providers ("sub‑processors") who help us run the Service, under contracts that require them to protect it:
| Sub‑processor | Purpose | Location [confirm] |
|---|---|---|
| Railway | Application hosting, compute and database storage | [US/EU region — confirm] |
| Cloudflare | DNS, CDN and network security | Global edge |
| Stripe | Payment processing (Credit packs and Merchant payouts) | US/EU/UK |
| Anthropic | AI generation and edit features | US [confirm] |
| MailerSend | Sending transactional email | [EU/US — confirm] |
| Turso | Hosted per‑tenant database (used at scale) | [confirm region] |
We may also disclose data where required by law, to enforce our Terms, or to protect our rights, users or the public. If our business is sold or reorganised, data may transfer to the successor, subject to this policy.
[Maintain this table as the definitive sub‑processor list and update it when providers change — EEZ‑65/70.]
8. International transfers
Some sub‑processors are outside the UK (for example in the US). Where personal data is transferred outside the UK, we rely on an appropriate safeguard under UK data‑protection law, such as UK adequacy regulations or the International Data Transfer Agreement / the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures needed. You can ask us for more information about the safeguards in place.
9. How long we keep data
We keep personal data only as long as necessary for the purposes above:
| What | How long | Why |
|---|---|---|
| Merchant account data | Life of the account, then 90 days | So a Merchant who lapses can return or export |
| Site content, orders and bookings (Customer Data) | Life of the account, then 90 days | Same — and see below on the Merchant's choice |
| Billing and tax records | 6 years | Required by law |
| Audit trail | 12 months | Our accountability record for security and Trust & Safety |
| Onboarding drafts not converted to a Site | Until they expire, then deleted automatically | Nothing to keep |
Customer Data (where we are processor). At the end of the Service the Merchant chooses: we delete their data, or they export it and we then delete it. Either way it is available to download from the back office for 90 days and deleted after that. A Merchant can ask us to delete sooner at any time. This is the choice UK GDPR Article 28(3)(g) gives the Merchant as controller, and it is theirs to make, not ours.
10. How we protect data
We use technical and organisational measures appropriate to the risk, including encryption of passwords, restricted access, isolation of each Merchant's data in its own database, and processing payments through Stripe so that card data does not reach our systems. No system is perfectly secure, and we cannot guarantee absolute security.
11. Your rights
Under UK data‑protection law you have rights to: access your data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and to withdraw consent where we rely on it. You can also object to direct marketing at any time.
- If we are the controller (Merchant account data, eezee website visitors), contact us at support@build-eezee.com and we will respond within the statutory time limit (normally one month).
- If you are a customer of a business using eezee, we act as processor. Please contact that business to exercise your rights; we will assist them as required.
12. Cookies
We use a small number of essential cookies to run the Service — for example to keep you
signed in to the back office. Payment and security features from Stripe and Cloudflare may set
their own cookies. [If any non‑essential/analytics cookies are added, add a cookie banner and consent mechanism and list them here.]
13. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from children through our own site.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "last updated" date and, for material changes affecting Merchants, take reasonable steps to notify you.
15. Complaints
If you have a concern about how we handle your data, please contact us first. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.