Privacy Policy

I am a registered sole trader operating as Esther Selhi I offer book coaching and fiction editing to clients. My client/customer base is worldwide. This policy describes how I protect and make use of the information you give me. If you are asked to provide information, it will only be used in ways stated in this policy. This privacy policy was last updated on 28.10.24.

Why do I collect data from you?
I gather and use certain information about you in order to:

respond to your requests for information (e.g. my availability or a quote for editorial services)
allow you to register for a special offer
allow me to contact you while an editing project is ongoing
enable certain functions on this website
better understand how visitors use this website

What information do I collect from you?
I collect the following minimal information:
name
contact postal address
email address
information pertinent to your enquiry (e.g. word count, nature of project, whether you’re an author or an editor)

How do I use this data?
The data I collect is used as follows:
For my internal accounting processes (e.g. so I can invoice you) and so that I am compliant with my tax authority (HMRC) should it request an audit.
To contact you in response to your enquiry, order, quote, special offer or booking.
To give you access to content you have purchased that resides on my website.
To record your agreement to the terms and conditions of my editorial services.
I will never use this data for marketing or promotion purposes without getting your permission in writing first (for example, to publish your testimonial for me on my website), or unless you have signed up to be notified about a specific offer.

How do I use cookies?
A cookie is a small file placed on your computer’s hard drive. It enables my website to identify your computer as you view different pages on my website.

The only way in which I use cookies is for web analytics, specifically [web analytics provider].

Cookies do not provide me with access to your computer or any information about you other than that which you elect to share with me.

You can use your web browser’s cookie settings to determine how my website uses cookies. If you do not want my website to store cookies on your computer or device, you can amend your settings. Please note that this may affect how my website functions, and some pages may become unavailable to you.

To learn more about cookies, visit All About Cookies.
To read [web analytics provider’s] privacy statement, and how you can request that I remove your information from my analytics data, see [web analytics provider’s] data privacy policies and approach [add link] and its data processing terms [add link].

How do I collect your personal data?
I collect and store minimal information via the following forms:
Contact form (via WordPress)
Booking-confirmation form (via Dubsado)
Course/book order form (via Dubsado)
Newsletter signup (via MailerLite)
Email (via Gmail or WordPress)

I will never lease, distribute or sell your information to third parties unless you give me written permission to do so, or I am required to do so by law.

You can ask me to remove your data from [your host] or [your provider] at any time. Please note that if your information is being held to enable access to content that you’ve purchased from me (e.g. courses/books), the removal of your data will remove your access.

How do I store your personal data?
The minimal information I collect is stored on the following data servers:
WordPress. This is my website and blog host. It is password-protected and has SSL-certification (https) to provide an additional layer of security. You can access WordPress’ privacy policy here https://automattic.com/privacy/.
Dropbox. This is my cloud-based file management system accessed via my password-protected computer. My Dropbox account is protected by a two-step password-authentication process. You can access its privacy policy here https://www.dropbox.com/en_GB/terms.
Stripe This is the password-protected online payment service I use for sales of my courses and books, and for editorial-services clients who elect not to be invoiced via direct bank transfer.
Dubsado. This is the accounting app I use to send invoices. Your name, email address and a project summary are stored. You can access its privacy policy here https://www.dubsado.com/legal/privacy-policy  its security policy here.
MailerLite. This is the software I use to communicate via Newletter. You can access its privacy policy here https://www.mailerlite.com/legal/privacy-policy 

DATA SERVERS IN THE UNITED STATES

WordPress, Dropbox, Dubsado, and MailerLite servers are based in the US but are registered with the EU–US Privacy Shield.

All Stripe or PayPal transactions are subject to their Privacy Policy’s Stripe https://stripe.com/gb/privacy Paypal https://www.paypal.com/uk/legalhub/privacy-full. Your data will used for accounting purposes only and will never be divulged to third parties.

How long do I keep your data for?
Because many of my customers and clients work with me more than once, I do not delete data unless specifically requested to do so.
HMRC, the UK tax authority requires me to keep records for six years.
Please ask if you want me to delete or amend your records. As long as I’m complying with HMRC’s legal requirements, I’ll action your request immediately.

With whom is your data shared?
No one, unless you request that I do so in writing, or HMRC elects to audit my business.

Contact me
If you have any questions or requests for modification or removal of your data, you are welcome to email me at speaktome@estherselhi.com.

If you need assistance with creating your own GDPR-compliant website privacy policy, the ICO https://ico.org.uk/ provides some excellent guidance.