Privacy notice
Last updated 22 September 2026
What personal data we collect, why, and your rights over it. This notice applies wherever you’re based, and follows UK data protection law and, where it applies, the EU General Data Protection Regulation.
Who we are
Colophon is a trading name of The Thousand Rays Ltd (company number 16823245), 15 Heath Street, Bristol, England, BS5 6SN. We’re the controller of the personal data described here. Contact us about privacy at ray@thebristolcreative.co or on +44 7960 800999. We haven’t appointed a data protection officer; privacy questions come to us directly.
This website
This site doesn’t use cookies or analytics, and it loads nothing from other companies’ servers, so there is no cookie banner. Our host, Netlify, keeps standard server logs, including IP addresses, to deliver pages and keep the service secure. Netlify’s privacy policy covers those logs.
When you email or call us
We collect your name, your contact details and what you tell us, and use them to reply and, if you book, to arrange the work. Our legal basis is our legitimate interest in answering enquiries, or taking steps towards a contract at your request. We keep this for two years after our last contact.
When you become a client
We keep your contact and billing details, the agreed scope, our correspondence and our deliverables. Our legal bases are performing our contract with you and meeting our tax and accounting obligations. We keep these records for six years after the work ends, which covers the period HMRC requires and the time limit for most contract claims.
Material you send us to review
Your assets may include images, voices or names of people. For that material you are the controller and we act as your processor, under the data protection clause in our terms of business. We use it only to do the work, and delete or return it when the work ends unless the law requires us to keep it.
When we contact businesses
We may use business contact details published on company websites or professional profiles to tell people about our services. Our legal basis is our legitimate interest in telling businesses about relevant services. Every message explains how to opt out, and we stop as soon as you ask. We keep these details for two years or until you opt out, after which we keep only enough to make sure we don’t contact you again.
Payments
Card payments are handled by SumUp, which acts as a separate controller under its own privacy policy. We never see or store your full card number. Bank transfers are handled by our bank.
Who we share data with
Only the providers we need to run the business: our website host, our email and file-storage providers, SumUp, our bank and our accountant. We don’t sell personal data, and we don’t use it for advertising.
Transfers outside the UK and EU
Some providers, including Netlify, process data in the United States. Where data leaves the UK or the European Economic Area, we rely on the safeguards the law provides, such as adequacy regulations or standard contractual clauses approved by the UK and EU authorities.
Your rights
You can ask us to give you a copy of the data we hold about you, correct it, delete it, limit how we use it, or pass it to another provider. You can also object to how we use it, including for marketing. Email or call us to use any of these rights. We reply within one month, and there’s no charge unless a request is clearly unfounded or excessive.
If you’re unhappy with how we’ve handled your data, please tell us first. You can also complain to the Information Commissioner’s Office in the UK or, in the EU, to the data protection authority in your country.
Security and decisions
We protect personal data with appropriate technical and organisational measures, and we report breaches to you and the regulator where the law requires it. We don’t make decisions about people by automated means alone.
Changes
We update this notice when our practices change. The date at the top shows the latest version.