This policy explains how Vesica Agency ("we", "us", "our") collects and uses your personal data when you use this website or enquire about our services. We are the data controller for the purposes of UK data protection law (UK GDPR and the Data Protection Act 2018).
Vesica Agency is a web design and social media management business based in Leeds, West Yorkshire. If you have any questions about this policy or your data, contact us at hello@vesica.agency.
When you submit our contact form, we collect the information you give us, which may include:
If you accept analytics cookies via our cookie banner, we also use Google Analytics to understand how visitors use this site — see the Cookies section below for details. Standard server logs (such as IP address and browser type) may be recorded by our hosting provider for security and operational purposes.
We use the information you provide to:
Our lawful bases for processing are your consent (when you contact us), the performance of a contract (once you become a client), and our legitimate interests in running and securing our business.
We use a single essential local storage entry to remember your cookie-banner choice so we don't ask again. This is strictly necessary and doesn't require consent under UK PECR.
If you click Accept on our cookie banner, we also load Google Analytics (GA4), which sets cookies (such as _ga) to measure page views, approximate location, and device/browser type. These cookies only load after you've given consent, and are not set at all if you click Reject. You can withdraw consent at any time by clearing your browser's local storage and cookies for this site, which will show the banner again on your next visit.
This site has an AI assistant in the corner of the page. It only processes anything if you open it and type a message — it isn't listening or collecting anything otherwise.
When you send it a message, we process:
Please don't type anything into the assistant that you wouldn't put in an email. It's there to answer questions about our services — it isn't a secure channel, and it isn't the place for financial, health or other sensitive information.
Where your conversation is processed. To generate its replies, your message is sent to an AI provider outside the UK. Our assistant uses DeepSeek first, and falls back to Groq when DeepSeek is unavailable, so your message may be processed by either. In both cases we remain the controller of your message and are responsible to you for it under UK GDPR.
DeepSeek is the AI platform operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., registered in China, so your message is processed outside the UK. This is a restricted transfer under UK GDPR. We are telling you about it plainly rather than burying it: DeepSeek’s Open Platform Terms of Service do not name a transfer safeguard such as the International Data Transfer Agreement, so we cannot point to one, and DeepSeek’s published privacy policy states that data an end user sends through a developer’s application is not covered by it. That means we cannot promise you a specific contractual protection over that leg of the journey, and we are not going to claim one we do not have. What we can point to is that DeepSeek has appointed an EU and UK representative, Prighter, who you may contact directly about your data at rep_deepseek@prighter.com, and that you can complain to the ICO as set out below or ask us to delete a conversation at any time. If you would rather your message was not processed in China, please email hello@vesica.agency instead of using the assistant — we are happy to answer the same questions by email.
Groq is the AI inference service operated by Groq, Inc., based in the United States, which is also a restricted transfer. It is used only as a fallback when DeepSeek is unavailable. Under Groq’s terms we remain the controller of that data and are responsible for telling you how it is handled. Groq states that it does not use messages sent through its API to train AI models, and does not retain them once your reply has been generated, other than short-lived logs kept only to investigate abuse or faults. Groq’s EU/UK representative can be contacted at groq@gdpr-rep.com.
Replies are generated by AI. The assistant's answers are produced automatically and may be wrong, incomplete or out of date. Treat them as a starting point, not as advice — please confirm anything that matters with us directly. It is not a substitute for professional advice of any kind.
What we keep, and for how long. We store a transcript of assistant conversations for 12 months so we can see what customers commonly ask and improve the assistant's answers, then delete it. Transcripts are held on our own systems, which are access-controlled and protected by two-factor authentication. We do not store your IP address alongside these transcripts. Short extracts may also appear temporarily in our hosting provider's function logs.
Our lawful basis for this is our legitimate interests in answering enquiries promptly and improving the assistant. If you'd like a conversation deleted, email hello@vesica.agency with the rough date and time and we'll remove it.
We only share your data with service providers that help us run the website and respond to you, including:
We never sell your personal data.
AI assistant conversations are kept for 12 months, then deleted. We keep enquiry data for as long as needed to respond and for a reasonable period afterwards. Client data is retained for the duration of our engagement and for as long as required to meet legal, accounting, and tax obligations, then securely deleted.
Under UK GDPR you have the right to access, correct, delete, or restrict the processing of your personal data, to object to processing, and to data portability. To exercise any of these, email hello@vesica.agency.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk if you believe we've handled your data improperly.
We may update this policy from time to time. The "last updated" date above shows when it was last revised.