Privacy policy

In plain English: what we collect and what we do with it.

Last updated 8 October 2026.

Who we are

W2 Create is part of The W2 Collective. The W2 Collective (trading as W2 Create, W2 Systems and W2 Taps) is the controller of the personal data collected through this site and through the enquiries you send us.

  • Email: enquiries@thew2collective.co.uk
  • WhatsApp and phone: +44 7367 422209
  • Based in Santa Cruz, Madeira, Portugal, working with clients in Portugal and the United Kingdom.

For anything about data protection, email us with "data protection" in the subject line. We answer formal requests within one month.

What we collect when you get in touch

The form asks for your name, business name, phone or WhatsApp number, what you need and, if you want, your current website or social page, email and a message. We use this only to reply to you and to prepare your free preview. To build the preview we may use information that is already public about your business, such as your current website, photos and reviews.

The lawful basis is legitimate interest: answering an enquiry you started. Form submissions are handled by Netlify, our hosting provider, and reach us by email. We keep enquiries for two years from your last contact, then delete them. We do not add you to a mailing list.

WhatsApp and email

WhatsApp messages stay in WhatsApp and are subject to Meta's privacy terms. Email stays in our mailbox. We keep business correspondence while we work together and, where it relates to a contract, for six years afterwards.

Cookies and analytics

This site sets no tracking cookies and runs no analytics or advertising scripts. Fonts load from Google Fonts, so your browser's request to Google includes your IP address, as any web request does. There is no cookie banner because there is nothing to consent to. If that changes, this page changes first.

Our clients' data

When we build a website, dashboard or automation for a business, that business remains the controller of its customers' data. We act as a processor, only on its instructions.

  • Wherever possible, everything runs on accounts in the client's own name.
  • We use access tokens rather than passwords wherever the provider allows it, and the client can revoke access at any time.
  • Sub-processors depend on the build and may include Netlify, Supabase, Google, Microsoft, Meta (WhatsApp), Resend and Anthropic. Each client is told which ones apply before anything goes live.
  • We never use client data to train or improve anything of our own.

Your rights

Under the EU GDPR and UK GDPR you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, and receive it in a portable format. Just email us; we will not charge you. If you are unhappy, you can complain to the Information Commissioner's Office in the UK (ico.org.uk) or the Comissão Nacional de Proteção de Dados in Portugal (cnpd.pt).

International transfers

Some providers are based outside the UK and EU. Where data leaves the UK or EEA, it goes under the safeguards those providers maintain, usually standard contractual clauses and, for US providers, the relevant adequacy framework.

Changes

If we change anything material, the date at the top changes and existing clients are told directly.