Privacy Policy

Last updated: 27 August 2026

Who we are

Lewis McKee Consulting Ltd (“we”, “us”, “our”) is a limited company registered in England & Wales, company number 15072661, registered office 20 Wenlock Road, London, N1 7GU. We are the data controller for the personal data described in this policy.

We are registered with the UK Information Commissioner’s Office (ICO), registration number ZB720078. For any privacy question or to exercise your rights, contact us at hello@lewismckeeconsulting.com.

The data we collect

  • Contact and account details — your name, business name, email address and phone number.
  • Billing details — your billing contact and address. Card payments are handled by our payment processor (Stripe); we do not store full card numbers.
  • Service data — information needed to deliver your services, such as device, Microsoft 365 and support-ticket data for the systems we manage on your behalf.
  • Usage data — basic technical logs (e.g. sign-in activity) needed to run and secure the portal.
  • Website visit data — when you browse our public website we record the page visited, the referring site, your approximate country, and your device and browser type. This is aggregated and anonymous: we do not store your IP address, and the identifier used to count visitors is rebuilt from scratch every day, so you cannot be recognised from one day to the next.

How we use it

  • To provide, manage and support the services you have signed up for.
  • To take payment and manage your account and invoices.
  • To monitor, secure and maintain the systems we manage for you.
  • To meet our legal, accounting and regulatory obligations.
  • To communicate with you about your service.

Our legal bases

We rely on: performance of our contract with you (to deliver and bill for services); our legitimate interests (to run, secure and improve our business and to keep your systems safe); legal obligation (e.g. tax and accounting records); and your consent where it applies, which you can withdraw at any time.

Payments

Card payments are processed by Stripe. Your card details are collected and stored by Stripe under their own security and privacy standards (Stripe is PCI-DSS certified); we receive confirmation of payment and a secure reference, not your full card number. Stripe’s handling of your data is governed by their privacy policy at stripe.com/privacy.

Who we share it with

We do not sell your data. We share it only with the service providers needed to deliver our services — for example our payment processor (Stripe), Microsoft, our software hosting and database providers, licensing distributors, and — where you have consented to it — our website analytics provider (Hotjar) — each acting under contract and only for the purposes above. We may also disclose data where required by law.

How long we keep it

We keep your data for as long as you are a client and for as long afterwards as we need to meet legal, tax and accounting obligations, after which it is securely deleted or anonymised.

Anonymous website visit records are kept for 13 months and then deleted automatically.

Your rights

Under UK data protection law you have the right to access, correct, delete or restrict the use of your personal data, to object to certain processing, and to data portability. To exercise any of these, email hello@lewismckeeconsulting.com. You also have the right to complain to the ICO (ico.org.uk), though we’d appreciate the chance to put things right first.

Security

We take appropriate technical and organisational measures to protect your data, including access controls, encryption in transit, and reputable, security-conscious service providers. No system is ever completely secure, but we work to keep the risk low and to respond quickly if something goes wrong.

Cookies and website analytics

The client portal uses only essential cookies, needed to keep you signed in and secure. We do not use advertising cookies anywhere, and we do not track you across other websites.

Our public website counts page visits using our own software, running on our own systems. It sets no cookies and stores no identifier on your device. To count visitors without identifying anyone, we combine your IP address, your browser’s user-agent string and a secret value into a one-way hash and keep only the result — never the IP address itself. That secret changes every day, so the same visitor produces a completely different value tomorrow. We consider this anonymous rather than personal data, and it needs no consent.

Separately, and only if you agree to it, we use Hotjar to see how people read our pages — which sections get attention and where a page loses someone. Hotjar does set cookies and does record how you move through the page, so it runs only after you have accepted it on the banner shown on your first visit. Declining changes nothing about how the site works. To change your mind later, clear this site’s stored data in your browser and the banner will ask again; you can also opt out of Hotjar across all sites at hotjar.com/legal/compliance/opt-out. Hotjar acts as our processor and its own privacy policy is at hotjar.com/legal/policies/privacy.

Hotjar is never used on the client portal. Nothing you do once signed in — tickets, invoices, devices or documents — is recorded or shared with any analytics provider.

Changes to this policy

We may update this policy from time to time. The “last updated” date above shows when it last changed. Material changes affecting you will be communicated directly.