Legal
Privacy Notice
How Yeti Digital Ltd collects, uses, stores and shares personal information in connection with yetiinc.com.
Version: 1.0
Effective from: 4 August 2026
Last updated: 4 August 2026
Key points
Yeti Digital Ltd is the controller responsible for personal information covered by this Privacy Notice.
We mainly process personal information when someone:
- visits our website;
- contacts us about a project, opportunity or our services;
- communicates with us in connection with a prospective or existing business relationship;
- accepts our Website Terms of Use through an express acceptance mechanism;
- reports a security concern;
- makes a complaint; or
- exercises a data-protection right.
We use Vercel to host and deliver the website and Plausible Analytics for privacy-focused website measurement. We do not sell personal information.
For privacy requests or complaints, contact Email our legal team.
1. About this Privacy Notice
1.1 Scope
This Privacy Notice explains how Yeti Digital Ltd may collect, use, store, disclose and otherwise process personal information when you:
a. visit our website;
b. contact us about a project, opportunity or our services;
c. communicate with us by email, telephone, video call or another method;
d. expressly accept our Website Terms of Use where an acceptance mechanism is provided;
e. report a vulnerability or security concern;
f. make a complaint or exercise a data-protection right; or
g. otherwise interact with us in connection with the website or a prospective business relationship.
1.2 Website covered
The website covered by this Privacy Notice includes:
a. yetiinc.com;
b. www.yetiinc.com;
c. any subdomain of yetiinc.com; and
d. any replacement domain on which this Privacy Notice is published.
1.3 Principal purpose
This Privacy Notice principally concerns the website, prospective-business enquiries and related communications.
1.4 Other processing
Separate privacy information may apply where Yeti:
a. provides services under a client agreement;
b. processes personal information solely on a client's documented instructions;
c. recruits or employs staff;
d. engages contractors or suppliers; or
e. operates another product, platform or service.
Where Yeti processes personal information solely as a processor for a client, the relevant client is normally responsible for deciding how and why that information is used and its privacy notice will normally apply.
1.5 Legal effect
This Privacy Notice is intended to provide information about our processing of personal information. It does not create contractual rights beyond those provided by applicable law.
Nothing in this Privacy Notice limits any right or protection that cannot lawfully be limited.
2. Who we are
2.1 Controller
Yeti Digital Ltd is the controller responsible for the personal information described in this Privacy Notice.
Our details are:
Yeti Digital Ltd
Company number: 10773498
Registered in: England and Wales
Registered office:
5 Ribblesdale Place
Preston
England
PR1 8BZ
General enquiries: Email us
Privacy requests and complaints: Email our legal team
Security reports: Email our security team
2.2 Definitions
In this Privacy Notice:
a. Yeti, we, us and our mean Yeti Digital Ltd; and
b. personal information and personal data mean information relating to an identified or identifiable individual.
3. Personal information we may collect
3.1 General
The information we collect depends on how you interact with us and which website functions are available at the relevant time.
3.2 Information you provide
When you contact or communicate with us, we may collect:
a. your name;
b. your business email address;
c. a personal email address where you choose to use one;
d. your telephone number;
e. your job title, occupation or role;
f. the name of your business or organisation;
g. your website address;
h. information about a proposed project, opportunity or requirement;
i. indicative budget or timing information;
j. the content of your correspondence;
k. documents or attachments you provide;
l. written notes relating to calls or meetings;
m. your communication preferences; and
n. other information you choose to provide.
3.3 Calls, meetings and transcription
Where a call or meeting is recorded using audio, video or transcription technology, additional notice will be provided at or before recording where required.
3.4 Information you should not send
Unless we have specifically requested it and appropriate arrangements are in place, please do not send us:
a. passwords or authentication credentials;
b. private encryption keys;
c. payment-card information;
d. confidential source code;
e. production-system access details;
f. special-category personal information;
g. criminal-offence information;
h. information subject to another person's confidentiality rights; or
i. information that you are not authorised to disclose.
If this type of information is sent to us without being requested, we may restrict access to it, return it, securely delete it, or retain only what is reasonably necessary to deal with the communication, protect legal rights or comply with law.
3.5 Technical and website information
When you access the website, we and our hosting, infrastructure or technical providers may process limited technical information, including:
a. your IP address;
b. the date and time of a request;
c. the page, resource or file requested;
d. the referring page or website;
e. browser type and version;
f. device type;
g. operating system;
h. approximate geographic information derived from an IP address;
i. HTTP request and response information;
j. diagnostic and error information;
k. security information; and
l. information used to identify unusual, malicious or automated traffic.
Some technical information may be processed through hosting, network, security and diagnostic logs even where the website does not place cookies on your device.
3.6 Analytics information
Where website analytics are enabled, we may collect or receive information about website use, including:
a. page views;
b. approximate visitor numbers;
c. pages visited;
d. referring websites;
e. general geographic region;
f. browser type;
g. operating system;
h. device type;
i. screen size;
j. outbound-link activity;
k. file downloads; and
l. interactions with selected website elements.
We do not intend to use website analytics to collect the contents of private communications, passwords, authentication credentials, form-field contents or special-category personal information.
3.7 Website Terms acceptance records
Where the website expressly asks you to accept our Website Terms of Use, we may record:
a. the date and time of acceptance;
b. the version and effective date of the Website Terms accepted;
c. the page, form or function through which acceptance occurred;
d. the method of acceptance;
e. confirmation that the relevant acceptance control was selected;
f. a related submission, request or audit reference;
g. the version of this Privacy Notice made available at that time; and
h. limited technical information reasonably required to demonstrate the authenticity or integrity of the record.
We do not create an individual acceptance record merely because someone browses the website. An individual acceptance record will only be created where an express acceptance mechanism is provided, such as an unticked checkbox associated with a form or another deliberate action.
3.8 Rights, complaints and security information
Where you exercise a legal right, make a data-protection complaint or report a security concern, we may collect:
a. your identity and contact details;
b. evidence of identity or authority;
c. details of your request, complaint or report;
d. correspondence and supporting documents;
e. technical information or evidence;
f. investigation notes;
g. actions considered or taken;
h. professional advice received; and
i. the outcome of the matter.
3.9 Information received from other sources
We may receive limited personal information from:
a. a colleague or representative of your organisation;
b. a company within our corporate group;
c. a client, supplier or professional adviser;
d. a referral source or business contact;
e. a publicly available business source;
f. a professional-networking service;
g. a security researcher; or
h. a person authorised to act on your behalf.
Where required by law, we will provide appropriate privacy information concerning personal information obtained from another source.
4. How we use personal information
4.1 Purposes
We may use personal information to:
a. operate, maintain, secure and deliver the website;
b. provide requested website content and functionality;
c. understand, assess and respond to enquiries;
d. assess whether an opportunity or proposed project is suitable for Yeti;
e. arrange calls, meetings or demonstrations;
f. prepare proposals, estimates or commercial discussions;
g. communicate with prospective, current and former clients or business contacts;
h. manage prospective and existing business relationships;
i. follow up on previous enquiries or discussions;
j. keep an appropriate history of our dealings and communications;
k. record and demonstrate acceptance of our Website Terms where express acceptance is requested;
l. maintain contractual, commercial, operational, accounting and legal records;
m. understand website usage and performance;
n. improve website content, services and user experience;
o. identify and investigate errors, misuse, fraud and security threats;
p. investigate vulnerability or security reports;
q. prevent unwanted, duplicate, abusive or fraudulent communications;
r. maintain suppression or do-not-contact records;
s. establish, exercise or defend legal rights;
t. respond to data-protection requests and complaints;
u. comply with legal, regulatory, accounting, tax and corporate requirements;
v. manage an investment, business sale, financing, restructuring or transfer;
w. protect Yeti, companies within our corporate group, clients, suppliers and website visitors;
x. send relevant business communications where permitted by law; and
y. carry out other purposes that are reasonably compatible with the purposes described above.
4.2 No sale of personal information
We do not sell personal information or trade it as a commodity.
4.3 Enquiry sharing
We do not ordinarily disclose the substantive contents of a first-contact enquiry to an unrelated commercial partner unless:
a. you authorise the disclosure;
b. the proposed disclosure is apparent from your request and we provide appropriate information before it occurs;
c. the information has been anonymised or aggregated so that it no longer identifies you; or
d. disclosure is required or permitted by law.
4.4 Direct marketing and business communications
We may contact you about:
a. an enquiry you have made;
b. a current, prospective or previous business relationship;
c. matters reasonably connected with your organisation;
d. relevant Yeti services; or
e. another matter where contact is permitted by law.
Where a communication constitutes direct marketing, we will handle it in accordance with applicable data-protection and electronic-marketing law.
For business-to-business electronic marketing, the rules may differ depending on whether the recipient is a corporate subscriber or an individual subscriber, such as a sole trader or certain partnerships. Where consent or the soft opt-in is required, we will rely on it only where the relevant conditions are met.
You may object to direct marketing at any time. Each electronic marketing message will include, or be accompanied by, a practical way to opt out where required.
5. Our lawful bases
5.1 General
We must have a lawful basis for processing personal information. The basis used depends on the information, circumstances and purpose.
5.2 Lawful-basis summary
| Processing purpose | Lawful basis normally relied on |
|---|---|
| Operating, securing and maintaining the website | Legitimate interests |
| Responding to business enquiries and discussing prospective work | Legitimate interests and, where applicable, steps at your request before entering a contract |
| Preparing proposals, estimates or terms | Legitimate interests and, where applicable, steps before entering a contract |
| Administering a contract with an individual | Contract |
| Managing business contacts where the contract is with an organisation | Legitimate interests |
| Recording express acceptance of Website Terms | Legitimate interests |
| Website measurement and improvement | Legitimate interests, unless consent or another basis is required |
| Fraud prevention, security and vulnerability handling | Legitimate interests and, where applicable, legal obligation |
| Accounting, tax, corporate and legal compliance | Legal obligation and legitimate interests |
| Establishing, exercising or defending legal claims | Legitimate interests and, where applicable, legal obligation |
| Direct marketing | Legitimate interests or consent, together with compliance with electronic-marketing rules |
| Processing based on a specific permission you give us | Consent |
5.3 Legitimate interests
Relevant legitimate interests may include:
a. operating, maintaining and improving our website;
b. responding to enquiries;
c. discussing prospective work;
d. developing and managing business relationships;
e. following up on business communications;
f. maintaining an appropriate relationship history;
g. recording express acceptance of Website Terms;
h. keeping contractual, evidential and operational records;
i. preventing duplicate or unwanted communications;
j. protecting systems, information and intellectual property;
k. detecting fraud, misuse and security incidents;
l. handling security reports;
m. understanding website performance;
n. managing and developing the business;
o. resolving complaints and disputes;
p. establishing, exercising and defending legal rights; and
q. sending relevant business-to-business communications where permitted by law.
Where appropriate, we consider the purpose and necessity of the processing, the nature of the information, what an individual may reasonably expect, possible effects on the individual and available safeguards.
5.4 Steps before entering into a contract
We may process information where necessary to take steps at your request before entering into a contract, including where you ask us to:
a. assess a proposed project;
b. provide information about services;
c. arrange a consultation;
d. prepare a proposal or estimate;
e. carry out preliminary discussions; or
f. discuss possible contractual terms.
5.5 Contract
Where you contract with us as an individual, we may process information where necessary to perform or administer that contract.
Where the contract is with your employer, company or another organisation, we will generally rely on legitimate interests or another appropriate lawful basis when processing your business contact information.
5.6 Legal obligations
We may process personal information where necessary to comply with legal obligations concerning matters such as tax, accounting, corporate administration, data protection, court or tribunal proceedings, law-enforcement requests and legally required records.
5.7 Consent
We may rely on consent where this is appropriate or legally required.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent processing under another lawful basis where one applies.
6. Website hosting and analytics
6.1 Vercel
The website is hosted and delivered using Vercel. Vercel may process website requests and technical information needed to provide, secure, monitor and deliver the website, including IP addresses, request information, approximate location derived from IP address, diagnostics and system information.
Further information about Vercel's processing is available in Vercel's Privacy Notice.
6.2 Plausible Analytics
We use Plausible Analytics to understand general website usage and improve the website.
Plausible is configured as a privacy-focused analytics service. It does not use analytics cookies or persistent cross-site identifiers and does not store raw visitor IP addresses. It produces aggregate website statistics rather than individual visitor profiles.
Further information is available in Plausible's Data Policy.
6.3 Analytics events
We may configure generic events, such as a button click, page interaction, outbound link or download, provided those events are not deliberately configured to include identifying information, enquiry contents, form-field values or acceptance identifiers.
6.4 Lawful basis
Our lawful basis for privacy-focused website measurement is normally our legitimate interest in understanding, maintaining and improving the website, unless applicable law requires consent or another basis.
7. Cookies and similar technologies
7.1 Current analytics position
Plausible Analytics does not use analytics cookies.
7.2 Other technologies
The website may use cookies, browser storage, scripts, tags or similar technologies where necessary or appropriate to:
a. deliver pages or requested functionality;
b. maintain security;
c. manage traffic;
d. remember a choice requested by a visitor;
e. prevent misuse;
f. measure website use and performance; or
g. provide another website function.
7.3 Consent and controls
Where consent or another user control is required by law, the relevant technology will be handled through an appropriate consent or preference mechanism.
Further information about technologies in use, their purposes and available controls is provided in our Cookie and Analytics Notice.
8. Who we may share information with
8.1 General
We may share personal information only where reasonably necessary and where an appropriate lawful basis applies.
8.2 Hosting, infrastructure and analytics
We may share or permit processing by:
a. Vercel, which hosts and delivers the website;
b. Plausible Analytics, which provides privacy-focused website measurement; and
c. other hosting, networking, security, diagnostic or technical providers needed to operate and protect the website.
8.3 Communication and operational providers
We may use providers of:
a. business email;
b. calendars and video meetings;
c. cloud storage;
d. document management;
e. project management;
f. customer or business relationship management;
g. security and monitoring;
h. backups;
i. professional communications; and
j. general business administration.
8.4 Companies within our corporate group
We may share information with Heyworth & Co Group Ltd or another company within our corporate group where reasonably necessary to:
a. administer the group;
b. respond to an enquiry relating to a group product or service;
c. provide operational or administrative support;
d. manage intellectual property;
e. protect legal rights;
f. manage financial or corporate affairs; or
g. complete an investment, restructuring or business transaction.
A company within our corporate group may act as a separate controller where it determines its own purposes and methods of processing.
8.5 Professional advisers, consultants and insurers
We may share information with solicitors, barristers, accountants, auditors, insurers, brokers, tax advisers, regulatory advisers, technical consultants and other professional advisers.
8.6 Authorities and legal recipients
We may disclose information to courts, tribunals, regulators, law-enforcement bodies, tax authorities, public authorities, insolvency practitioners and other persons where disclosure is required or permitted by law.
8.7 Business transactions
We may share information with prospective or actual purchasers, investors, funders, lenders, transaction advisers, counterparties or successors in connection with an investment, sale, acquisition, merger, restructuring, financing, insolvency process or transfer of assets or business operations.
The extent of any disclosure will depend on the circumstances and the purpose of the proposed transaction. We will seek to limit disclosure to what is reasonably necessary and use confidentiality or other safeguards where appropriate.
9. International transfers
9.1 General
Some service providers or their subprocessors may process personal information outside the United Kingdom.
For example, Vercel operates internationally and may process website technical information in the United States or other jurisdictions.
9.2 Safeguards
Where rules concerning restricted international transfers apply, we will use or rely on an appropriate legal mechanism. Depending on the provider and circumstances, this may include:
a. UK adequacy regulations;
b. the UK Extension to the EU-US Data Privacy Framework where the recipient participates;
c. the UK International Data Transfer Agreement;
d. the UK Addendum to approved standard contractual clauses;
e. approved standard contractual clauses;
f. another recognised transfer framework; or
g. another mechanism permitted by applicable law.
We may carry out transfer assessments, review provider terms or obtain additional contractual or organisational safeguards where required.
You may contact us for further information about safeguards applying to a particular category of transfer.
10. How long we retain personal information
10.1 General approach
We keep personal information only for as long as it is reasonably required for the relevant purpose, subject to legal, accounting, security and claims-related requirements.
10.2 Normal retention periods
| Information category | Normal retention approach |
|---|---|
| Unsuccessful or inactive prospective-business enquiries | Normally up to 3 years after the last meaningful contact |
| Enquiry information relevant to a contract, dispute or potential legal claim | Up to 6 years after the relevant relationship, event or matter ends, or longer where law requires |
| Website Terms acceptance records | Normally 6 years after the associated enquiry or relationship ends |
| Client, supplier, invoice, payment, tax and accounting records | Normally 6 years after the relevant financial year or relationship, subject to applicable requirements |
| Business contact and relationship records | While the relationship remains active and normally up to 3 years afterwards, unless a longer period is justified |
| Direct-marketing records | While marketing remains relevant and lawful; minimal suppression information may be kept for as long as needed to respect an objection |
| Technical, hosting, diagnostic and security logs | Normally up to 12 months, unless required for an incident, investigation, dispute or legal claim |
| Data-protection rights and complaint records | Normally 6 years after the matter closes |
| Security and vulnerability reports | Normally up to 6 years after closure where needed for accountability, repeated-issue analysis or legal rights |
| Plausible aggregate analytics | For the period configured in our analytics account, currently up to 3 years |
| Anonymised or aggregated information | May be kept for longer where it no longer identifies an individual |
10.3 Exceptions
We may retain information for longer where reasonably necessary because:
a. a complaint, dispute, investigation or legal claim exists or is reasonably anticipated;
b. a legal hold applies;
c. law, regulation, insurance or a binding contractual obligation requires it;
d. the information is relevant to fraud, misuse, security or the protection of systems and legal rights; or
e. deletion is temporarily impracticable because information is held in a secure backup or archive.
10.4 Deletion, anonymisation and backups
When identifiable information is no longer reasonably required, it may be deleted, anonymised, aggregated, securely archived with restricted access or allowed to expire through ordinary system, archive or backup cycles.
Backup information is not ordinarily restored except for business continuity, disaster recovery, security or technical necessity. Where restored, applicable deletion and restriction decisions will be reapplied where reasonably practicable.
10.5 Erasure requests
You may ask us to erase personal information. The right to erasure is not absolute. We may retain information where a lawful basis or other lawful reason remains, including legal obligations, tax and accounting requirements, the rights of another person, or the establishment, exercise or defence of legal claims.
11. Security
11.1 Measures
We use organisational and technical measures intended to protect personal information against unauthorised access, accidental loss, misuse, alteration, inappropriate disclosure and destruction.
The measures used depend on the nature of the information, systems involved, likelihood and severity of the risk, available technology and proportionality.
Measures may include:
a. access restrictions;
b. authentication;
c. encryption in transit;
d. supplier controls;
e. software updates;
f. security logging;
g. backups;
h. confidentiality obligations;
i. vulnerability management; and
j. incident-response arrangements.
11.2 No absolute guarantee
No internet service, system or electronic communication can be guaranteed to be completely secure.
You are responsible for choosing an appropriate method when sending sensitive or confidential information to us.
11.3 Security reports
Security concerns should be sent to Email our security team. Please do not include unnecessary personal information, credentials or live exploit data in an initial report.
12. Automated decision-making
We do not currently use personal information collected through the website to make decisions producing legal or similarly significant effects through solely automated processing.
We do not use website analytics to create individual profiles for significant decision-making.
If this materially changes, appropriate privacy information and safeguards will be provided where required by law.
13. Your data-protection rights
13.1 Rights
Depending on the circumstances, processing and lawful basis used, you may have the right to:
a. ask whether we process your personal information;
b. obtain a copy of personal information we hold about you;
c. correct inaccurate or incomplete information;
d. ask us to erase personal information;
e. ask us to restrict processing;
f. object to processing;
g. receive certain information in a portable format;
h. withdraw consent where processing is based on consent; and
i. complain about how personal information has been handled.
These rights are subject to legal conditions, limitations and exemptions.
13.2 Identity and scope
We may request information reasonably required to:
a. verify your identity;
b. confirm your authority to act for another person;
c. identify the information concerned; or
d. clarify the scope of a request.
We will not request more information than is reasonably necessary.
13.3 Fees
We do not ordinarily charge a fee. A reasonable fee may be charged, or a request may be refused, where permitted by law, including where a request is manifestly unfounded or excessive.
13.4 Response times
We respond to rights requests within the periods required by applicable data-protection law.
The usual period is one month after receiving the request and any information reasonably required to confirm identity or authority.
Where permitted by law, the period may be extended by up to two further months where a request is complex or a person has made a number of requests. Where an extension applies, we will provide information about it within the initial statutory period.
13.5 Right to object
You have the right to object where we process personal information on the basis of legitimate interests.
This right is subject to the applicable legal test. Processing may continue where there are compelling legitimate grounds that override your interests, rights and freedoms, or where processing is required to establish, exercise or defend legal claims.
You may object to direct marketing at any time.
Where a valid direct-marketing objection is received, we may retain limited information on a suppression list to ensure that the objection continues to be respected.
13.6 How to exercise a right
Email Email our legal team using the subject line Data Protection Request.
You may also write to the postal address in section 18.
14. Data-protection complaints
14.1 How to complain
You may make a data-protection complaint by:
a. emailing Email our legal team using the subject line Data Protection Complaint; or
b. writing to the postal address in section 18.
A complaint may be made through another channel. We will not refuse to consider a complaint solely because it was not submitted using the suggested route.
14.2 Helpful information
It is helpful, but not mandatory, to provide:
a. your name and contact details;
b. a description of the concern;
c. relevant dates or communications;
d. the outcome you are seeking; and
e. supporting information.
14.3 Our process
We will:
a. acknowledge receipt within 30 days;
b. take appropriate steps to investigate without undue delay;
c. keep you appropriately informed where required; and
d. communicate the outcome without undue delay.
We may request further information or evidence of identity or authority where reasonably necessary.
14.4 Information Commissioner's Office
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection and information rights.
Information about making a complaint is available on the ICO website.
You are not required to complete Yeti's complaints process before contacting the ICO, although raising the matter with us first may allow it to be resolved more quickly.
15. Children
The website is principally intended for businesses and professional users and is not directed at children.
We do not intentionally seek to collect personal information from children through the website.
If we become aware that personal information concerning a child has been provided in circumstances where it should not have been, we may investigate and take appropriate action.
16. Third-party websites
The website may contain links to websites, products, platforms or services operated by other organisations.
Those organisations are responsible for their own privacy practices where they determine how and why personal information is processed.
This Privacy Notice does not govern personal information collected independently by another organisation. You should review the relevant third party's privacy information where appropriate.
17. Changes to this Privacy Notice
We may update this Privacy Notice where:
a. the website changes;
b. a service or technology is introduced or removed;
c. a supplier changes;
d. our processing activities change;
e. the law or regulatory guidance changes;
f. our business or group structure changes; or
g. clarification is considered appropriate.
The current version will be identified by its version number, effective date and last-updated date.
Changes apply from the effective date stated in the updated notice.
Where required by law, additional privacy information will be provided before personal information is used for a materially different purpose.
18. Contact us
Questions, requests and complaints concerning this Privacy Notice or our use of personal information may be sent to:
Privacy requests and complaints: Email our legal team
General enquiries: Email us
Security reports: Email our security team
Suggested subject lines:
- Data Protection
- Data Protection Request
- Data Protection Complaint
- Security Report
Post:
Yeti Digital Ltd
5 Ribblesdale Place
Preston
England
PR1 8BZ
Postal correspondence may be marked for the attention of the directors.