Privacy Policy
Version 1.1 · Last updated: 9 August 2026
Pellmark is a trading name of RELION DIGITAL LIMITED, a company registered in England and Wales, company number 14972293, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
The short version
We collect what you give us (enquiries, applications, account details) plus minimal technical data needed to run a secure website. Our site analytics are cookie-free and do not build profiles of you. We do not sell personal data and do not share it for advertising. We are a UK company; where our providers process data in the US, recognised transfer safeguards are in place. You have the usual UK GDPR rights, and you can always reach us at support@pellmark.com.
Who we are
Pellmark is a trading name of RELION DIGITAL LIMITED (company number 14972293, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ). For the personal data described in this policy, we are the controller. We are registered with the Information Commissioner’s Office.
Contact for anything in this policy: support@pellmark.com.
What this policy covers, and one important boundary
This policy covers personal data we process for our own purposes: when you visit pellmark.com, enquire, apply, enter our monthly selection, become a client or partner, or otherwise deal with us.
It does not cover the websites we build and host for our clients. On those websites, the business named on the site decides what data is collected and why; we process that data on their behalf under our Data Processing Addendum, and the privacy notice on that website is the one that applies to its visitors. If you have a question about data on a Pellmark-hosted client website, contact the business named on it, or write to support@pellmark.com and we will pass your query to them without undue delay.
What we collect, why, and on what legal basis
Visitors to pellmark.com
Our analytics are privacy-first and cookie-free: we see aggregate information (pages visited, referral source, approximate location at country or city level, device type) without cookies and without building individual profiles. Our infrastructure also processes IP addresses transiently in server and security logs to deliver the site and protect it from attack. Legal basis: legitimate interests (running and securing our website). (One narrow exception to “transiently”: if a form submission fails to send, a short record of it is written to those logs so the enquiry is not lost. See Enquiries and applications below.)
Enquiries and applications
When you enquire, request a consultation or apply for a build, we collect your name, business name, contact details and the content of your message, and we use them to respond, ask qualifying questions and prepare your quote or order. Legal basis: taking steps at your request before entering a contract; legitimate interests for follow-up on open enquiries.
Submissions from the forms on this website reach us as email, delivered by Resend (see the sub-processor list). If that delivery fails, we write a record of the submission to our server logs so your enquiry is not lost: your name and contact details (and business name where relevant), but not free-text application answers or an uploaded CV. Those log records are held for no more than 7 days and are used only to follow up the enquiry. Legal basis: legitimate interests (making sure an enquiry we were sent actually reaches us).
Independent Sales Partner applications
When you apply to become an Independent Sales Partner, we may collect your name and contact details, country and time zone, professional profile, CV or résumé if you provide one, your application answers, and the partner route you select. If you are shortlisted, we may also collect a Loom/video or equivalent response and interview or assessment notes.
We use this information to assess your suitability for an Independent Sales Partner relationship, communicate with you, conduct the selection process, and decide whether to offer you an Independent Sales Partner Agreement. Legal bases: taking steps at your request before entering a contract; legitimate interests in assessing and administering applications.
Applying does not add you to a marketing list. We use the application information only for the selection process and the administration of any resulting partner relationship.
Clients and partners
When you become a client, agency partner or Independent Sales Partner we process account and contact details, order and service records, billing and payment records, and our correspondence with you, to deliver the service or administer the partnership, run our billing, and keep the records the law requires us to keep. Legal bases: performing our contract with you; legal obligation (accounting and tax records); legitimate interests (service quality and records of what was agreed).
The monthly free-website selection
If you enter the monthly selection, we process your email address, business details and application answers to run the selection. Legal basis: consent, which you can withdraw at any time; withdrawal requests are actioned within 24 hours. Entry conditions for the selection (including that winners are publicly named and featured) are published on the entry page and in our website terms.
Suppliers and other contacts
Business contact details of suppliers and professional contacts, processed to manage our relationship with you. Legal basis: legitimate interests or contract.
Who we share personal data with
We use a small set of service providers to run Pellmark: hosting and security infrastructure, payment processing, transactional email delivery for our website forms, email and productivity tools, CRM and support tooling, and AI production tooling used to build websites. The current providers, their roles and locations are published and kept up to date at pellmark.com/privacy/sub-processors.
- We share data with providers only so they can perform their service for us, under contracts that protect it.
- We share data with our professional advisers (accountants, insurers, lawyers) where needed.
- We disclose data where the law, a court or a regulator requires it.
- If our business is sold or reorganised, data transfers to the successor under this policy.
We do not sell personal data, and we do not share it with anyone for advertising.
International transfers
We are a UK company and operate from the UK. Some of our providers process data in the United States or on global networks. Where they do, the transfer is covered by a recognised safeguard under UK data protection law: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework for certified US providers), or the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. The safeguard for each provider is shown in the sub-processor list.
How long we keep personal data
- Enquiries that do not become clients: kept for 12 months from our last exchange, then deleted.
- Unsuccessful Independent Sales Partner applications, including any later-stage video and assessment notes: kept for 12 months from the decision or our last exchange, whichever is later, then deleted.
- Server-log records of a failed form delivery: kept for no more than 7 days, then deleted with the logs.
- Client and partner records, including successful Independent Sales Partner applications: kept for the length of the relationship, then for 7 years after it ends, because tax and accounting law requires it.
- Selection entries: kept until you withdraw your entry; withdrawals are actioned within 24 hours.
- Hosted website archives after cancellation: kept for 90 days for reactivation and handover, then deleted (this is a service commitment in our client agreement).
- Security incident records: kept for at least 7 years.
Your rights
Under UK GDPR you have the right to access your personal data, correct it, have it erased, restrict or object to our processing of it, receive a copy in a portable format, and withdraw consent where consent is the basis. Email support@pellmark.com and we will respond within one month. We may need to verify your identity first.
If you are unhappy with how we have handled your data, we would appreciate the chance to put it right first, but you also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
How we protect personal data
All connections to our website and systems are encrypted in transit. Access to personal data is limited to authorised people on a least-privilege basis with multi-factor authentication where supported. We run automated backups, continuous monitoring and a monthly security log review, and we have a defined incident process: if a breach puts people at risk, we notify the ICO within 72 hours and affected people without undue delay, as the law requires.
Children
Pellmark provides services to businesses. Our website and services are not directed at children and we do not knowingly collect children’s data.
Cookies
pellmark.com does not set cookies by default, which is why there is no cookie banner. The detail, including the narrow security exception, is in our cookie policy at pellmark.com/cookies.
Changes to this policy
We update this policy when the facts change: new providers, new features, or changes in the law. The current version and its date are always shown at the top of this page, and material changes affecting clients or partners are notified by email.