This website is operated by FeatherON LTD (registered in England and Wales, company number 17011469). This policy explains what information is collected when you use it and how it is used.

What we collect

  • Booking information. Consultancy bookings are processed by Cal.com and payments by Stripe. Their handling of your data (name, email, payment details, scheduling information) is governed by their respective privacy policies. We only receive the details needed to prepare for and deliver the engagement.
  • Shop orders. Card payments are processed by Stripe (email, billing address, payment instrument - we never see your card details). Purchase emails with your download link are delivered by Resend. The purchased files themselves are hosted on Vercel Blob storage behind signed links; the links carry no personal data beyond an order reference.
  • Client portal and electronic signatures. If we share a document with you through the portal, we hold your email address, the document itself, and a record of every access. Where you first sign in we record your acceptance of the conditions of access, with the date, time, your network (IP) address, your browser identification and a hash of the exact wording you accepted. Where you sign a document we also record the name you type as your signature and the same details again. That evidence is the signature: without it an electronic signature cannot be attributed to anyone. See the section below for how long it is kept.
  • Technical data. Like any website, the hosting platform (Vercel) processes standard request logs (IP address, user agent, timestamps) for security and delivery purposes.
  • Engagement correspondence. If you email us, we keep the correspondence for as long as needed to handle your enquiry and any resulting engagement.

The client portal in detail

Documents are held in private encrypted storage and are readable only by the email addresses they were sent to. Access is by a one-time code emailed to that address; there is no password. Codes are stored only as a hash, expire after 15 minutes and work once. Sessions end after 8 hours.

  • Why we hold it. To perform, or take steps toward, a contract with you, and because we have a legitimate interest in keeping a reliable record of what was agreed and by whom.
  • How long. Signed documents and their audit trail are kept for 7 years from the date of signature, which covers the limitation period for contract claims in England and Wales. Records of your acceptance of the conditions of access are kept for the same period, because they form part of the evidence for any document you signed. Unsigned documents are removed once they are no longer needed.
  • Who else sees it. Nobody. Storage and hosting are Vercel, and portal email is delivered by Resend. There is no third-party electronic signature provider involved, so your documents are not processed by DocuSign or any equivalent service.
  • Your rights, and one limit on them. You can ask for a copy of everything we hold about you at any time, and the full audit trail for your own documents is visible to you in the portal. We cannot delete the evidence attached to a signature while it is still needed to establish an agreement you entered into, because deleting it would remove your protection as much as ours. Everything else can be deleted on request.

Subprocessors

These are the third parties that process personal data on our behalf. The list is short by design: we keep the number of processors low and we do not use a subprocessor for anything we can do ourselves.

  • Vercel Inc. Website and client portal hosting, encrypted document storage (Vercel Blob), request logs and performance analytics. Purpose: running this site and the portal.
  • Resend. Transactional email delivery, including portal one-time codes, signature confirmations and shop download links. Purpose: sending email we would otherwise send by hand.
  • Stripe Payments Europe Ltd. Card payments for advisory bookings and shop orders. Stripe is the controller for card data and we never see card details. Purpose: taking payment.
  • Cal.com. Booking and scheduling for advisory sessions, workshops and intro calls, including the NDA confirmation recorded at booking. Purpose: scheduling.

There is no third-party electronic signature provider, no customer relationship management system, no marketing automation platform and no advertising or analytics vendor beyond Vercel's own.

Subprocessors on client engagements

Engagement work is different, and it is worth stating plainly because clients ask. On build and advisory engagements we do not host client systems or client data ourselves. Cloud, database, storage, artificial intelligence, SMS, email, payment, error tracking and app store accounts are opened in the client's own name, on the client's own billing, from day one. Those providers are therefore the client's own processors under the client's own contracts, not our subprocessors, and the client can see, change or remove any of them without us.

Where an engagement requires us to process personal data, the statement of work carries the data processing terms required by Article 28 of the UK GDPR, and it identifies the providers involved. We appoint no subprocessor of our own on an engagement without the client's prior written approval, and no subcontractor or agent of ours is given access to client systems, client confidential information or personal data without that approval, which overrides the Permitted Receivers wording in our mutual NDA.

Where an engagement uses artificial intelligence services, we procure them on enterprise terms that prohibit training on client data, provide for zero or short retention, and process within the United Kingdom or the European Economic Area. We will provide a copy of those terms to a client on request.

International transfers

Vercel, Resend and Cal.com are established outside the United Kingdom and may process data in the United States. Stripe processes in the European Economic Area and, for some functions, the United States. Each of those transfers relies on the transfer mechanisms in that provider's own data processing terms, including the UK International Data Transfer Addendum where it applies. On engagements, client data is hosted in the United Kingdom and is not transferred outside it without the client's prior written approval.

Personal data breaches

If we become aware of a personal data breach affecting personal data we process for a client, we notify that client without undue delay and in any event within 24 hours, with the information they need to meet their own obligations to the Information Commissioner and to the people affected.

What we don't do

  • We do not sell personal data.
  • We do not run third-party advertising or ad-tracking pixels.
  • We do not use client content from engagements in case studies or marketing without explicit written permission.

Confidentiality

Advisory engagements are confidential. An NDA is available on request before any discussion of your systems, incidents or roadmap.

Your rights

Under UK GDPR you may request access to, correction of, or deletion of your personal data by emailing hello@featheron.com.

Contact

Questions about this policy: hello@featheron.com.