Last updated: 27 July 2026
1. Who we are
Bluebulb Technologies ("we", "us") is the data controller for personal data collected through this website. You can contact us at sales@bluebulbtech.co.uk or by post at 1 Canada Square, 37th Floor, Canary Wharf, London, England, E14 5AA.
Where we process data on behalf of a client as part of a delivery engagement, we act as a data processor under that client's instructions and the terms of our contract.
2. What we collect
- Enquiry and booking details — name, email address, company, phone number, preferred call time and the message you send us.
- Usage data — pages viewed, services clicked and form submissions, collected only where you have accepted analytics cookies.
- Technical data — IP address and browser information processed by our hosting provider to deliver and secure the site.
We do not ask for special category data through this website and ask that you do not include it in enquiry messages.
3. Why we use it and our lawful basis
- To respond to enquiries and schedule discovery calls — legitimate interests, or steps taken at your request before entering a contract.
- To deliver contracted services — performance of a contract.
- To measure how the site performs — consent, given through the cookie banner.
- To meet legal and accounting obligations — legal obligation.
4. Cookies
We set strictly necessary cookies and local storage needed to run the site and remember your consent choice. Analytics and marketing cookies are only used with your permission. Full detail is in our Cookie Policy.
5. Sharing your data
We share personal data only with service providers who help us operate — website hosting, email, analytics and scheduling tools — and with professional advisers or authorities where the law requires it. We never sell personal data. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
6. How long we keep it
- Website enquiries and booking requests: up to 24 months from last contact.
- Client records and contracts: 6 years after the engagement ends.
- Analytics data: up to 14 months in aggregated form.
7. Security
We apply access control, encryption in transit, least-privilege administration and supplier due diligence appropriate to the data we hold. No system is perfectly secure, so we also maintain an incident process and will notify you and the ICO where a breach is reportable.
8. Your rights
Under UK GDPR you can request access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time. See our GDPR page for how to make a request.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
9. Changes to this notice
We update this notice when our practices change. The date at the top always reflects the current version.
