Privacy Policy
Last updated: 16 July 2026 Effective date: 1 July 2025
50 Site Challenge respects the privacy of people who visit our website, contact us, request a private concept or proposal, or work with us. This Privacy Policy explains what personal data we collect, why we use it, when we share it, how long we retain it, and the choices and rights available to you.
This notice applies to 50sitechallenge.com, related 50 Site Challenge web properties, and communications connected with our services (together, the Services).
1. Who is responsible for your data
The controller responsible for personal data processed under this Privacy Policy is:
InvictoSoft Ltd Trading as: 50 Site Challenge Registered address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ Company number: 15360928 Email: hello@50sitechallenge.com
In this notice, “50 Site Challenge,” “we,” “us,” and “our” mean the controller identified above.
If you are located in the European Economic Area (EEA), United Kingdom, Switzerland, or another jurisdiction requiring a local representative and we are required to appoint one, the relevant representative’s contact details will be published here before we offer Services in that jurisdiction.
2. The data we collect
We collect only data that is reasonably necessary for the purposes described in this notice. The categories depend on how you interact with us.
Information you provide
You may provide us with:
- Contact details, such as your name, business name, role, email address, telephone number, postal address, and social-media profile details.
- Business and project information, such as your website, services, customers, objectives, brand assets, project requirements, budget range, timeline, feedback, and communications with us.
- Files and materials you choose to provide, such as logos, photographs, copy, design files, product information, drawings, PDFs, video, and other project materials.
- Billing and transaction information necessary to prepare proposals, invoices, contracts, and payment records. Payment-card information is processed by the applicable payment provider and is not intentionally stored by us unless expressly stated at the point of collection.
- Any other information you voluntarily send to us.
Please do not send sensitive personal data unless we specifically request it and have explained why it is needed. Sensitive personal data can include health information, government-issued identifiers, financial-account credentials, biometric data, precise location data, religious or political information, and information about children.
Information collected when you use the website
When you visit the Services, our hosting, security, and analytics systems may process limited technical and usage information, including:
- IP address, device and browser type, operating system, language, time zone, approximate location inferred from IP address, and network or diagnostic information;
- pages viewed, referring page, page-load and interaction events, date and time of access, and aggregated or event-level usage information;
- security and fraud-prevention information, including logs needed to protect the Services and investigate technical issues.
We do not intentionally use website analytics to identify you by name, build advertising audiences, serve behavioural advertising, or make decisions producing legal or similarly significant effects about you.
Information from other sources
We may receive professional or business contact information from publicly available sources, referrals, business directories, social-media profiles, event organisers, service providers, or a colleague who refers you to us. We use this information only for relevant business communications, relationship management, or to evaluate a possible project.
3. How we use personal data
We use personal data only where a lawful basis applies and for the following purposes:
| Purpose | Typical data used | Lawful basis where GDPR/UK GDPR applies |
|---|---|---|
| Responding to an inquiry, arranging a call or meeting, preparing a concept, proposal, scope, or quote | Contact, business, and project information | Taking steps at your request before entering a contract; legitimate interests in responding to relevant business inquiries |
| Delivering services, administering a project, providing support, and managing client relationships | Contact, project, account, communication, and billing information | Performance of a contract; legitimate interests in operating and improving our services |
| Processing payments, accounting, tax, and record keeping | Billing, transaction, and contract information | Performance of a contract; compliance with legal obligations; legitimate interests in managing our business |
| Operating, securing, troubleshooting, and improving the Services | Technical, security, and usage information | Legitimate interests in maintaining secure, reliable, and effective Services |
| Measuring aggregate website use and improving content and performance | Limited analytics and usage information | Consent where required by applicable law; otherwise legitimate interests in understanding and improving the Services |
| Sending relevant business communications or updates | Professional contact and communication information | Consent where required; otherwise legitimate interests in communicating with existing clients and relevant business contacts, subject to applicable law and opt-out rights |
| Protecting rights, resolving disputes, enforcing agreements, and meeting legal requirements | Relevant records and communications | Legitimate interests; compliance with legal obligations; establishment, exercise, or defence of legal claims |
Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations. You may object to processing based on legitimate interests as described in Section 10.
We do not sell personal data. We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Analytics, cookies, and similar technologies
We use cookies and similar technologies in two distinct ways: strictly necessary technologies that make the Services work, and consent-aware analytics provided by PostHog.
Strictly necessary cookies
These are always active because the Services cannot function safely without them:
- Authentication cookies that keep you signed in to the client portal and protect your account session.
- A consent-record cookie that stores your cookie choice (the choice made, region, and timestamp) so we do not ask you repeatedly and can evidence your decision.
- Anti-abuse verification (Cloudflare Turnstile) on public forms, which processes limited technical signals (such as device and network characteristics) to distinguish people from automated abuse. Turnstile is not used for advertising or tracking across other sites. For Cloudflare’s practices, see the Cloudflare Privacy Policy and the Turnstile Privacy Addendum.
Analytics, error tracking, and session replay (PostHog)
We use PostHog for website analytics, error tracking, and limited session replay. How it behaves depends on where you are and what you choose:
- Where consent is required (for example the EEA, United Kingdom, and Switzerland), we show a cookie banner before any analytics identifier is stored on your device. If you accept, PostHog stores a device identifier in cookies or local storage so we can understand usage across visits, and limited session replay may be enabled. If you decline, nothing is stored on your device for analytics; we instead measure aggregate usage through PostHog’s cookieless, privacy-preserving server-side method.
- Where consent is not required by applicable law, analytics run by default and the banner is not shown. You can still opt out at any time using the Cookie settings control on this page.
- Error tracking. We use PostHog to capture technical error information (such as the error message, stack trace, page URL, browser, and related technical context) when something breaks, so we can diagnose and fix problems. Error events are used only for reliability and product improvement.
- Session replay. Where analytics are accepted, we may record a limited sample of browsing sessions (mouse movement, scrolling, clicks, and page structure) to understand usability problems. All typed input is masked by default, and replays are used only for product improvement.
You can change or withdraw your choice at any time using the Cookie settings control on this page. Withdrawing consent stops cookie-based analytics from that point onward.
We do not intentionally deploy advertising cookies, cross-site advertising trackers, remarketing pixels, or social-media tracking pixels on the public website.
Cookieless or aggregate measurement does not mean that no personal data is processed. Technical data, server logs, and analytics event data can still be personal data under applicable law. We therefore describe this processing in this Privacy Policy and apply an appropriate lawful basis: consent where required, and otherwise our legitimate interests in understanding and improving the Services.
You can also use browser settings, privacy extensions, or device controls to limit certain technologies. These controls may affect some website functionality.
5. When we share data
We may share personal data with carefully selected recipients only as necessary for the purposes above:
- Service providers that support our Services, such as hosting, domain, email, analytics, communications, document, project-management, security, payment, accounting, and customer-support providers.
- Professional advisers such as lawyers, accountants, auditors, insurers, and consultants where necessary.
- Business partners or subcontractors involved in a project, only where necessary and subject to appropriate contractual or confidentiality obligations.
- Authorities and other parties where we reasonably believe disclosure is required by law, regulation, legal process, or to protect rights, safety, security, property, or the integrity of the Services.
- A successor or prospective transaction party in connection with a merger, reorganisation, financing, acquisition, sale of assets, or similar corporate transaction, subject to appropriate safeguards.
We require service providers to process personal data only for authorised purposes and to apply appropriate security and confidentiality measures.
Our principal service providers at the time of the last update are:
| Provider | Purpose | Primary processing location |
|---|---|---|
| Vercel Inc. | Website hosting and content delivery | United States (global edge network) |
| PostHog Inc. | Website analytics, error tracking, and limited session replay | European Union (EU Cloud) |
| Neon Inc. | Database hosting (accounts, inquiries, and project records) | United States (configured cloud region) |
| Resend (Plus Five Five, Inc.) | Transactional and notification email delivery | United States |
| Cloudflare, Inc. | File storage (profile images) and anti-abuse verification (Turnstile) | United States (global network) |
| Google LLC | Optional “Continue with Google” sign-in | United States |
We update this list when we add or replace a provider that processes personal data on our behalf.
6. International transfers
We and our service providers may process personal data in countries other than the country where you live, including countries that may have different data-protection laws.
Where data-protection law requires a transfer mechanism for international transfers, we use an applicable mechanism, such as an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. You may request information about relevant safeguards by contacting us at hello@50sitechallenge.com.
7. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, maintain records, meet legal or accounting obligations, resolve disputes, and enforce agreements.
Our general retention approach is:
- Inquiry and prospective-client records: normally up to 24 months after the last meaningful interaction, unless a longer period is necessary for an ongoing opportunity, legal claim, or applicable law.
- Client project and contract records: for the project term and normally up to 7 years after completion or the end of the business relationship, subject to applicable legal, tax, accounting, and limitation requirements.
- Billing and tax records: for the period required by applicable law.
- Security and server logs: for a limited period appropriate to security, diagnostics, and legal requirements.
- Analytics data: up to 30 days and no longer than reasonably necessary for the stated analytics purpose.
We may retain data longer where necessary to establish, exercise, or defend legal claims, comply with legal obligations, or prevent fraud and abuse. When data is no longer required, we delete it, anonymise it, or securely isolate it where deletion is not immediately feasible.
8. Security
We use reasonable technical, organisational, and contractual measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, least-privilege practices, encryption where appropriate, secure service providers, account-security measures, backups, and internal confidentiality obligations.
No online service or transmission method can be guaranteed completely secure. Please do not send passwords, payment-card details, government-issued identifiers, or other highly sensitive information through ordinary website forms or email unless we have provided a secure, specific method for doing so.
9. Your privacy rights
Depending on where you live and subject to applicable exceptions, you may have the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent where processing is based on consent;
- request portability of data you provided to us, where applicable;
- opt out of certain targeted advertising, sale, sharing, or profiling activities where applicable; and
- lodge a complaint with a relevant data-protection authority.
To make a request, email hello@50sitechallenge.com with the subject line Privacy Request. We may request information reasonably necessary to verify your identity and protect your data. We will not discriminate against you for exercising applicable privacy rights.
Direct-marketing choices
You may opt out of marketing communications at any time by using the unsubscribe method provided in the message or by emailing hello@50sitechallenge.com. We may still send non-promotional communications, such as responses to inquiries, service notices, invoices, contractual communications, or important updates about an existing relationship.
Additional rights for EEA, UK, and Swiss individuals
If the GDPR, UK GDPR, or Swiss data-protection law applies, you may also complain to the supervisory authority in your country of habitual residence, workplace, or the place of the alleged infringement. You can object at any time to processing based on legitimate interests where your particular situation gives rise to grounds for objection. You have an unconditional right to object to direct marketing.
10. United States privacy disclosures
This section applies to residents of US states with applicable comprehensive privacy laws, to the extent those laws apply to us.
In the preceding 12 months, we may have collected the categories described in Section 2: identifiers and contact information; professional or employment-related information; commercial and transaction information; internet, device, and usage information; approximate location inferred from IP address; and communications or project materials you provide.
We collect these categories from you, your device or browser, our service providers, public sources, referrals, and business contacts. We use and disclose them for the purposes and recipient categories described in Sections 3 and 5.
We do not sell personal information or share personal information for cross-context behavioural advertising as those terms are defined by applicable US privacy laws. We do not knowingly sell or share personal information of consumers under 16 years of age. We do not use or disclose sensitive personal information for purposes that require a right to limit under applicable US privacy laws.
To exercise applicable privacy rights, including rights to know, access, correct, delete, or appeal a decision regarding a privacy request, contact hello@50sitechallenge.com. If we deny a request, you may appeal by replying to our decision and stating that you wish to appeal.
11. Children
The Services are intended for business and professional audiences and are not directed to children. We do not knowingly collect personal data from children under 16, or a higher age where required by applicable law. If you believe a child has provided personal data to us, contact hello@50sitechallenge.com and we will take appropriate steps to address the request.
12. Third-party links and client materials
The Services may link to third-party websites, platforms, or services. Their privacy practices are governed by their own notices, not this Privacy Policy. We are not responsible for third-party privacy practices.
Where we build, host, administer, or support a client website or digital product, that client may be the independent controller of personal data collected through that client’s service. The client’s own Privacy Policy and agreements govern that processing unless we expressly state otherwise in writing.
13. Changes to this notice
We may update this Privacy Policy when our practices, Services, technologies, or legal obligations change. We will publish the updated version on this page and revise the “Last updated” date. If a change is material, we will provide additional notice where required by applicable law.
14. Contact us
For questions, requests, or concerns about this Privacy Policy or our privacy practices, contact:
InvictoSoft Ltd Trading as: 50 Site Challenge Email: hello@50sitechallenge.com Postal address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ