Last updated: 28 October 2025
We're Smalldesk Ltd (trading as Handle), and we take your privacy seriously. We're the controller of your personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Got questions? Drop us a line at privacy@handle.help
This policy covers personal data processed when you visit our websites (including handle.help), join our waitlist, interact with our marketing, contact us, or use our services and related communications.
We do not require special category data for our services. Please do not submit it.
We process personal data for the purposes and legal bases below:
| Purpose | Examples | Legal basis |
|---|---|---|
| Waitlist and product updates | Store waitlist entries, send launch emails, manage early access | Consent (UK GDPR Art. 6(1)(a)) |
| Service communications | Administrative and security notices, operational updates | Contract (6(1)(b)) or Legitimate interests (6(1)(f)) |
| Direct marketing to business contacts | News, product updates, event invites | Consent (6(1)(a)) or Legitimate interests (6(1)(f)); compliance with PECR applies |
| Analytics and site performance | Measure traffic, improve UX, debug incidents | Legitimate interests (6(1)(f)) |
| Security and fraud prevention | Detect abuse, protect accounts and systems | Legitimate interests (6(1)(f)) |
| Legal compliance | Respond to lawful requests, enforce terms | Legal obligation (6(1)(c)) |
Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, we balance those interests against your rights.
We use trusted processors to host, send, or store data on our behalf. These processors act only on our instructions and are bound by contracts:
All processors are carefully selected and bound by data processing agreements. We recommend reviewing their respective privacy policies to understand how they handle data.
We may update this list as our stack evolves. Material changes will be reflected in this policy.
Some processors (e.g., Mailgun, AWS, Apollo.io, Google) may process data outside the UK and EEA. Where transfers occur, we use the ICO-approved International Data Transfer Addendum to the Standard Contractual Clauses (SCCs) or rely on an adequacy decision, as applicable.
We keep personal data only as long as needed for the purposes above or to comply with legal obligations. Waitlist and prospect contact details may be retained to manage ongoing communications about Handle. If you object or withdraw consent, we will suppress your details from further marketing.
You can:
To exercise rights, email privacy@handle.help. We may request verification. We aim to respond within one month.
You may complain to the UK Information Commissioner's Office (ICO): ico.org.uk.
You can unsubscribe using links in our emails or by contacting us.
If you unsubscribe, we keep a minimal suppression record to honour your choice.
We apply technical and organisational measures, including access controls, encryption in transit and at rest (where supported by the platform), least-privilege access, logging, and regular reviews of third-party security posture. No method of transmission or storage is 100% secure.
We may update this policy. The latest version is available at https://handle.help/legal/privacy. Material changes will be signposted on the site or by email where appropriate.
Questions or requests: privacy@handle.help