Legal

Privacy Notice

How Yeti Digital Ltd collects, uses, stores and shares personal information in connection with yetiinc.com.

Version: 1.0
Effective from: 4 August 2026
Last updated: 4 August 2026

Key points

Yeti Digital Ltd is the controller responsible for personal information covered by this Privacy Notice.

We mainly process personal information when someone:

  • visits our website;
  • contacts us about a project, opportunity or our services;
  • communicates with us in connection with a prospective or existing business relationship;
  • accepts our Website Terms of Use through an express acceptance mechanism;
  • reports a security concern;
  • makes a complaint; or
  • exercises a data-protection right.

We use Vercel to host and deliver the website and Plausible Analytics for privacy-focused website measurement. We do not sell personal information.

For privacy requests or complaints, contact Email our legal team.

1. About this Privacy Notice

1.1 Scope

This Privacy Notice explains how Yeti Digital Ltd may collect, use, store, disclose and otherwise process personal information when you:

a. visit our website;

b. contact us about a project, opportunity or our services;

c. communicate with us by email, telephone, video call or another method;

d. expressly accept our Website Terms of Use where an acceptance mechanism is provided;

e. report a vulnerability or security concern;

f. make a complaint or exercise a data-protection right; or

g. otherwise interact with us in connection with the website or a prospective business relationship.

1.2 Website covered

The website covered by this Privacy Notice includes:

a. yetiinc.com;

b. www.yetiinc.com;

c. any subdomain of yetiinc.com; and

d. any replacement domain on which this Privacy Notice is published.

1.3 Principal purpose

This Privacy Notice principally concerns the website, prospective-business enquiries and related communications.

1.4 Other processing

Separate privacy information may apply where Yeti:

a. provides services under a client agreement;

b. processes personal information solely on a client's documented instructions;

c. recruits or employs staff;

d. engages contractors or suppliers; or

e. operates another product, platform or service.

Where Yeti processes personal information solely as a processor for a client, the relevant client is normally responsible for deciding how and why that information is used and its privacy notice will normally apply.

1.5 Legal effect

This Privacy Notice is intended to provide information about our processing of personal information. It does not create contractual rights beyond those provided by applicable law.

Nothing in this Privacy Notice limits any right or protection that cannot lawfully be limited.

2. Who we are

2.1 Controller

Yeti Digital Ltd is the controller responsible for the personal information described in this Privacy Notice.

Our details are:

Yeti Digital Ltd
Company number: 10773498
Registered in: England and Wales

Registered office:

5 Ribblesdale Place
Preston
England
PR1 8BZ

General enquiries: Email us
Privacy requests and complaints: Email our legal team
Security reports: Email our security team

2.2 Definitions

In this Privacy Notice:

a. Yeti, we, us and our mean Yeti Digital Ltd; and

b. personal information and personal data mean information relating to an identified or identifiable individual.

3. Personal information we may collect

3.1 General

The information we collect depends on how you interact with us and which website functions are available at the relevant time.

3.2 Information you provide

When you contact or communicate with us, we may collect:

a. your name;

b. your business email address;

c. a personal email address where you choose to use one;

d. your telephone number;

e. your job title, occupation or role;

f. the name of your business or organisation;

g. your website address;

h. information about a proposed project, opportunity or requirement;

i. indicative budget or timing information;

j. the content of your correspondence;

k. documents or attachments you provide;

l. written notes relating to calls or meetings;

m. your communication preferences; and

n. other information you choose to provide.

3.3 Calls, meetings and transcription

Where a call or meeting is recorded using audio, video or transcription technology, additional notice will be provided at or before recording where required.

3.4 Information you should not send

Unless we have specifically requested it and appropriate arrangements are in place, please do not send us:

a. passwords or authentication credentials;

b. private encryption keys;

c. payment-card information;

d. confidential source code;

e. production-system access details;

f. special-category personal information;

g. criminal-offence information;

h. information subject to another person's confidentiality rights; or

i. information that you are not authorised to disclose.

If this type of information is sent to us without being requested, we may restrict access to it, return it, securely delete it, or retain only what is reasonably necessary to deal with the communication, protect legal rights or comply with law.

3.5 Technical and website information

When you access the website, we and our hosting, infrastructure or technical providers may process limited technical information, including:

a. your IP address;

b. the date and time of a request;

c. the page, resource or file requested;

d. the referring page or website;

e. browser type and version;

f. device type;

g. operating system;

h. approximate geographic information derived from an IP address;

i. HTTP request and response information;

j. diagnostic and error information;

k. security information; and

l. information used to identify unusual, malicious or automated traffic.

Some technical information may be processed through hosting, network, security and diagnostic logs even where the website does not place cookies on your device.

3.6 Analytics information

Where website analytics are enabled, we may collect or receive information about website use, including:

a. page views;

b. approximate visitor numbers;

c. pages visited;

d. referring websites;

e. general geographic region;

f. browser type;

g. operating system;

h. device type;

i. screen size;

j. outbound-link activity;

k. file downloads; and

l. interactions with selected website elements.

We do not intend to use website analytics to collect the contents of private communications, passwords, authentication credentials, form-field contents or special-category personal information.

3.7 Website Terms acceptance records

Where the website expressly asks you to accept our Website Terms of Use, we may record:

a. the date and time of acceptance;

b. the version and effective date of the Website Terms accepted;

c. the page, form or function through which acceptance occurred;

d. the method of acceptance;

e. confirmation that the relevant acceptance control was selected;

f. a related submission, request or audit reference;

g. the version of this Privacy Notice made available at that time; and

h. limited technical information reasonably required to demonstrate the authenticity or integrity of the record.

We do not create an individual acceptance record merely because someone browses the website. An individual acceptance record will only be created where an express acceptance mechanism is provided, such as an unticked checkbox associated with a form or another deliberate action.

3.8 Rights, complaints and security information

Where you exercise a legal right, make a data-protection complaint or report a security concern, we may collect:

a. your identity and contact details;

b. evidence of identity or authority;

c. details of your request, complaint or report;

d. correspondence and supporting documents;

e. technical information or evidence;

f. investigation notes;

g. actions considered or taken;

h. professional advice received; and

i. the outcome of the matter.

3.9 Information received from other sources

We may receive limited personal information from:

a. a colleague or representative of your organisation;

b. a company within our corporate group;

c. a client, supplier or professional adviser;

d. a referral source or business contact;

e. a publicly available business source;

f. a professional-networking service;

g. a security researcher; or

h. a person authorised to act on your behalf.

Where required by law, we will provide appropriate privacy information concerning personal information obtained from another source.

4. How we use personal information

4.1 Purposes

We may use personal information to:

a. operate, maintain, secure and deliver the website;

b. provide requested website content and functionality;

c. understand, assess and respond to enquiries;

d. assess whether an opportunity or proposed project is suitable for Yeti;

e. arrange calls, meetings or demonstrations;

f. prepare proposals, estimates or commercial discussions;

g. communicate with prospective, current and former clients or business contacts;

h. manage prospective and existing business relationships;

i. follow up on previous enquiries or discussions;

j. keep an appropriate history of our dealings and communications;

k. record and demonstrate acceptance of our Website Terms where express acceptance is requested;

l. maintain contractual, commercial, operational, accounting and legal records;

m. understand website usage and performance;

n. improve website content, services and user experience;

o. identify and investigate errors, misuse, fraud and security threats;

p. investigate vulnerability or security reports;

q. prevent unwanted, duplicate, abusive or fraudulent communications;

r. maintain suppression or do-not-contact records;

s. establish, exercise or defend legal rights;

t. respond to data-protection requests and complaints;

u. comply with legal, regulatory, accounting, tax and corporate requirements;

v. manage an investment, business sale, financing, restructuring or transfer;

w. protect Yeti, companies within our corporate group, clients, suppliers and website visitors;

x. send relevant business communications where permitted by law; and

y. carry out other purposes that are reasonably compatible with the purposes described above.

4.2 No sale of personal information

We do not sell personal information or trade it as a commodity.

4.3 Enquiry sharing

We do not ordinarily disclose the substantive contents of a first-contact enquiry to an unrelated commercial partner unless:

a. you authorise the disclosure;

b. the proposed disclosure is apparent from your request and we provide appropriate information before it occurs;

c. the information has been anonymised or aggregated so that it no longer identifies you; or

d. disclosure is required or permitted by law.

4.4 Direct marketing and business communications

We may contact you about:

a. an enquiry you have made;

b. a current, prospective or previous business relationship;

c. matters reasonably connected with your organisation;

d. relevant Yeti services; or

e. another matter where contact is permitted by law.

Where a communication constitutes direct marketing, we will handle it in accordance with applicable data-protection and electronic-marketing law.

For business-to-business electronic marketing, the rules may differ depending on whether the recipient is a corporate subscriber or an individual subscriber, such as a sole trader or certain partnerships. Where consent or the soft opt-in is required, we will rely on it only where the relevant conditions are met.

You may object to direct marketing at any time. Each electronic marketing message will include, or be accompanied by, a practical way to opt out where required.

5. Our lawful bases

5.1 General

We must have a lawful basis for processing personal information. The basis used depends on the information, circumstances and purpose.

5.2 Lawful-basis summary

Processing purposeLawful basis normally relied on
Operating, securing and maintaining the websiteLegitimate interests
Responding to business enquiries and discussing prospective workLegitimate interests and, where applicable, steps at your request before entering a contract
Preparing proposals, estimates or termsLegitimate interests and, where applicable, steps before entering a contract
Administering a contract with an individualContract
Managing business contacts where the contract is with an organisationLegitimate interests
Recording express acceptance of Website TermsLegitimate interests
Website measurement and improvementLegitimate interests, unless consent or another basis is required
Fraud prevention, security and vulnerability handlingLegitimate interests and, where applicable, legal obligation
Accounting, tax, corporate and legal complianceLegal obligation and legitimate interests
Establishing, exercising or defending legal claimsLegitimate interests and, where applicable, legal obligation
Direct marketingLegitimate interests or consent, together with compliance with electronic-marketing rules
Processing based on a specific permission you give usConsent

5.3 Legitimate interests

Relevant legitimate interests may include:

a. operating, maintaining and improving our website;

b. responding to enquiries;

c. discussing prospective work;

d. developing and managing business relationships;

e. following up on business communications;

f. maintaining an appropriate relationship history;

g. recording express acceptance of Website Terms;

h. keeping contractual, evidential and operational records;

i. preventing duplicate or unwanted communications;

j. protecting systems, information and intellectual property;

k. detecting fraud, misuse and security incidents;

l. handling security reports;

m. understanding website performance;

n. managing and developing the business;

o. resolving complaints and disputes;

p. establishing, exercising and defending legal rights; and

q. sending relevant business-to-business communications where permitted by law.

Where appropriate, we consider the purpose and necessity of the processing, the nature of the information, what an individual may reasonably expect, possible effects on the individual and available safeguards.

5.4 Steps before entering into a contract

We may process information where necessary to take steps at your request before entering into a contract, including where you ask us to:

a. assess a proposed project;

b. provide information about services;

c. arrange a consultation;

d. prepare a proposal or estimate;

e. carry out preliminary discussions; or

f. discuss possible contractual terms.

5.5 Contract

Where you contract with us as an individual, we may process information where necessary to perform or administer that contract.

Where the contract is with your employer, company or another organisation, we will generally rely on legitimate interests or another appropriate lawful basis when processing your business contact information.

5.6 Legal obligations

We may process personal information where necessary to comply with legal obligations concerning matters such as tax, accounting, corporate administration, data protection, court or tribunal proceedings, law-enforcement requests and legally required records.

5.7 Consent

We may rely on consent where this is appropriate or legally required.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent processing under another lawful basis where one applies.

6. Website hosting and analytics

6.1 Vercel

The website is hosted and delivered using Vercel. Vercel may process website requests and technical information needed to provide, secure, monitor and deliver the website, including IP addresses, request information, approximate location derived from IP address, diagnostics and system information.

Further information about Vercel's processing is available in Vercel's Privacy Notice.

6.2 Plausible Analytics

We use Plausible Analytics to understand general website usage and improve the website.

Plausible is configured as a privacy-focused analytics service. It does not use analytics cookies or persistent cross-site identifiers and does not store raw visitor IP addresses. It produces aggregate website statistics rather than individual visitor profiles.

Further information is available in Plausible's Data Policy.

6.3 Analytics events

We may configure generic events, such as a button click, page interaction, outbound link or download, provided those events are not deliberately configured to include identifying information, enquiry contents, form-field values or acceptance identifiers.

6.4 Lawful basis

Our lawful basis for privacy-focused website measurement is normally our legitimate interest in understanding, maintaining and improving the website, unless applicable law requires consent or another basis.

7. Cookies and similar technologies

7.1 Current analytics position

Plausible Analytics does not use analytics cookies.

7.2 Other technologies

The website may use cookies, browser storage, scripts, tags or similar technologies where necessary or appropriate to:

a. deliver pages or requested functionality;

b. maintain security;

c. manage traffic;

d. remember a choice requested by a visitor;

e. prevent misuse;

f. measure website use and performance; or

g. provide another website function.

7.3 Consent and controls

Where consent or another user control is required by law, the relevant technology will be handled through an appropriate consent or preference mechanism.

Further information about technologies in use, their purposes and available controls is provided in our Cookie and Analytics Notice.

8. Who we may share information with

8.1 General

We may share personal information only where reasonably necessary and where an appropriate lawful basis applies.

8.2 Hosting, infrastructure and analytics

We may share or permit processing by:

a. Vercel, which hosts and delivers the website;

b. Plausible Analytics, which provides privacy-focused website measurement; and

c. other hosting, networking, security, diagnostic or technical providers needed to operate and protect the website.

8.3 Communication and operational providers

We may use providers of:

a. business email;

b. calendars and video meetings;

c. cloud storage;

d. document management;

e. project management;

f. customer or business relationship management;

g. security and monitoring;

h. backups;

i. professional communications; and

j. general business administration.

8.4 Companies within our corporate group

We may share information with Heyworth & Co Group Ltd or another company within our corporate group where reasonably necessary to:

a. administer the group;

b. respond to an enquiry relating to a group product or service;

c. provide operational or administrative support;

d. manage intellectual property;

e. protect legal rights;

f. manage financial or corporate affairs; or

g. complete an investment, restructuring or business transaction.

A company within our corporate group may act as a separate controller where it determines its own purposes and methods of processing.

8.5 Professional advisers, consultants and insurers

We may share information with solicitors, barristers, accountants, auditors, insurers, brokers, tax advisers, regulatory advisers, technical consultants and other professional advisers.

8.6 Authorities and legal recipients

We may disclose information to courts, tribunals, regulators, law-enforcement bodies, tax authorities, public authorities, insolvency practitioners and other persons where disclosure is required or permitted by law.

8.7 Business transactions

We may share information with prospective or actual purchasers, investors, funders, lenders, transaction advisers, counterparties or successors in connection with an investment, sale, acquisition, merger, restructuring, financing, insolvency process or transfer of assets or business operations.

The extent of any disclosure will depend on the circumstances and the purpose of the proposed transaction. We will seek to limit disclosure to what is reasonably necessary and use confidentiality or other safeguards where appropriate.

9. International transfers

9.1 General

Some service providers or their subprocessors may process personal information outside the United Kingdom.

For example, Vercel operates internationally and may process website technical information in the United States or other jurisdictions.

9.2 Safeguards

Where rules concerning restricted international transfers apply, we will use or rely on an appropriate legal mechanism. Depending on the provider and circumstances, this may include:

a. UK adequacy regulations;

b. the UK Extension to the EU-US Data Privacy Framework where the recipient participates;

c. the UK International Data Transfer Agreement;

d. the UK Addendum to approved standard contractual clauses;

e. approved standard contractual clauses;

f. another recognised transfer framework; or

g. another mechanism permitted by applicable law.

We may carry out transfer assessments, review provider terms or obtain additional contractual or organisational safeguards where required.

You may contact us for further information about safeguards applying to a particular category of transfer.

10. How long we retain personal information

10.1 General approach

We keep personal information only for as long as it is reasonably required for the relevant purpose, subject to legal, accounting, security and claims-related requirements.

10.2 Normal retention periods

Information categoryNormal retention approach
Unsuccessful or inactive prospective-business enquiriesNormally up to 3 years after the last meaningful contact
Enquiry information relevant to a contract, dispute or potential legal claimUp to 6 years after the relevant relationship, event or matter ends, or longer where law requires
Website Terms acceptance recordsNormally 6 years after the associated enquiry or relationship ends
Client, supplier, invoice, payment, tax and accounting recordsNormally 6 years after the relevant financial year or relationship, subject to applicable requirements
Business contact and relationship recordsWhile the relationship remains active and normally up to 3 years afterwards, unless a longer period is justified
Direct-marketing recordsWhile marketing remains relevant and lawful; minimal suppression information may be kept for as long as needed to respect an objection
Technical, hosting, diagnostic and security logsNormally up to 12 months, unless required for an incident, investigation, dispute or legal claim
Data-protection rights and complaint recordsNormally 6 years after the matter closes
Security and vulnerability reportsNormally up to 6 years after closure where needed for accountability, repeated-issue analysis or legal rights
Plausible aggregate analyticsFor the period configured in our analytics account, currently up to 3 years
Anonymised or aggregated informationMay be kept for longer where it no longer identifies an individual

10.3 Exceptions

We may retain information for longer where reasonably necessary because:

a. a complaint, dispute, investigation or legal claim exists or is reasonably anticipated;

b. a legal hold applies;

c. law, regulation, insurance or a binding contractual obligation requires it;

d. the information is relevant to fraud, misuse, security or the protection of systems and legal rights; or

e. deletion is temporarily impracticable because information is held in a secure backup or archive.

10.4 Deletion, anonymisation and backups

When identifiable information is no longer reasonably required, it may be deleted, anonymised, aggregated, securely archived with restricted access or allowed to expire through ordinary system, archive or backup cycles.

Backup information is not ordinarily restored except for business continuity, disaster recovery, security or technical necessity. Where restored, applicable deletion and restriction decisions will be reapplied where reasonably practicable.

10.5 Erasure requests

You may ask us to erase personal information. The right to erasure is not absolute. We may retain information where a lawful basis or other lawful reason remains, including legal obligations, tax and accounting requirements, the rights of another person, or the establishment, exercise or defence of legal claims.

11. Security

11.1 Measures

We use organisational and technical measures intended to protect personal information against unauthorised access, accidental loss, misuse, alteration, inappropriate disclosure and destruction.

The measures used depend on the nature of the information, systems involved, likelihood and severity of the risk, available technology and proportionality.

Measures may include:

a. access restrictions;

b. authentication;

c. encryption in transit;

d. supplier controls;

e. software updates;

f. security logging;

g. backups;

h. confidentiality obligations;

i. vulnerability management; and

j. incident-response arrangements.

11.2 No absolute guarantee

No internet service, system or electronic communication can be guaranteed to be completely secure.

You are responsible for choosing an appropriate method when sending sensitive or confidential information to us.

11.3 Security reports

Security concerns should be sent to Email our security team. Please do not include unnecessary personal information, credentials or live exploit data in an initial report.

12. Automated decision-making

We do not currently use personal information collected through the website to make decisions producing legal or similarly significant effects through solely automated processing.

We do not use website analytics to create individual profiles for significant decision-making.

If this materially changes, appropriate privacy information and safeguards will be provided where required by law.

13. Your data-protection rights

13.1 Rights

Depending on the circumstances, processing and lawful basis used, you may have the right to:

a. ask whether we process your personal information;

b. obtain a copy of personal information we hold about you;

c. correct inaccurate or incomplete information;

d. ask us to erase personal information;

e. ask us to restrict processing;

f. object to processing;

g. receive certain information in a portable format;

h. withdraw consent where processing is based on consent; and

i. complain about how personal information has been handled.

These rights are subject to legal conditions, limitations and exemptions.

13.2 Identity and scope

We may request information reasonably required to:

a. verify your identity;

b. confirm your authority to act for another person;

c. identify the information concerned; or

d. clarify the scope of a request.

We will not request more information than is reasonably necessary.

13.3 Fees

We do not ordinarily charge a fee. A reasonable fee may be charged, or a request may be refused, where permitted by law, including where a request is manifestly unfounded or excessive.

13.4 Response times

We respond to rights requests within the periods required by applicable data-protection law.

The usual period is one month after receiving the request and any information reasonably required to confirm identity or authority.

Where permitted by law, the period may be extended by up to two further months where a request is complex or a person has made a number of requests. Where an extension applies, we will provide information about it within the initial statutory period.

13.5 Right to object

You have the right to object where we process personal information on the basis of legitimate interests.

This right is subject to the applicable legal test. Processing may continue where there are compelling legitimate grounds that override your interests, rights and freedoms, or where processing is required to establish, exercise or defend legal claims.

You may object to direct marketing at any time.

Where a valid direct-marketing objection is received, we may retain limited information on a suppression list to ensure that the objection continues to be respected.

13.6 How to exercise a right

Email Email our legal team using the subject line Data Protection Request.

You may also write to the postal address in section 18.

14. Data-protection complaints

14.1 How to complain

You may make a data-protection complaint by:

a. emailing Email our legal team using the subject line Data Protection Complaint; or

b. writing to the postal address in section 18.

A complaint may be made through another channel. We will not refuse to consider a complaint solely because it was not submitted using the suggested route.

14.2 Helpful information

It is helpful, but not mandatory, to provide:

a. your name and contact details;

b. a description of the concern;

c. relevant dates or communications;

d. the outcome you are seeking; and

e. supporting information.

14.3 Our process

We will:

a. acknowledge receipt within 30 days;

b. take appropriate steps to investigate without undue delay;

c. keep you appropriately informed where required; and

d. communicate the outcome without undue delay.

We may request further information or evidence of identity or authority where reasonably necessary.

14.4 Information Commissioner's Office

You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection and information rights.

Information about making a complaint is available on the ICO website.

You are not required to complete Yeti's complaints process before contacting the ICO, although raising the matter with us first may allow it to be resolved more quickly.

15. Children

The website is principally intended for businesses and professional users and is not directed at children.

We do not intentionally seek to collect personal information from children through the website.

If we become aware that personal information concerning a child has been provided in circumstances where it should not have been, we may investigate and take appropriate action.

16. Third-party websites

The website may contain links to websites, products, platforms or services operated by other organisations.

Those organisations are responsible for their own privacy practices where they determine how and why personal information is processed.

This Privacy Notice does not govern personal information collected independently by another organisation. You should review the relevant third party's privacy information where appropriate.

17. Changes to this Privacy Notice

We may update this Privacy Notice where:

a. the website changes;

b. a service or technology is introduced or removed;

c. a supplier changes;

d. our processing activities change;

e. the law or regulatory guidance changes;

f. our business or group structure changes; or

g. clarification is considered appropriate.

The current version will be identified by its version number, effective date and last-updated date.

Changes apply from the effective date stated in the updated notice.

Where required by law, additional privacy information will be provided before personal information is used for a materially different purpose.

18. Contact us

Questions, requests and complaints concerning this Privacy Notice or our use of personal information may be sent to:

Privacy requests and complaints: Email our legal team
General enquiries: Email us
Security reports: Email our security team

Suggested subject lines:

  • Data Protection
  • Data Protection Request
  • Data Protection Complaint
  • Security Report

Post:

Yeti Digital Ltd
5 Ribblesdale Place
Preston
England
PR1 8BZ

Postal correspondence may be marked for the attention of the directors.