LEGAL
Privacy Policy
Last updated 10th September 2026
Who we are
This website is operated by Imhotep Consulting ("Imhotep," "we," "us"). Matthew is the data controller responsible for your personal data in connection with this website. You can contact us at matthewgaston@outlook.com.
What information we collect
When you contact us. If you use the contact form, email us, or otherwise get in touch, we collect your name, email address, and any other information you choose to include in your message.
When you browse our website. We use Framer's built-in website analytics, which is anonymised and does not use cookies, track you across sites, or collect any information that identifies you personally.
We do not collect any special category data (such as health, financial, or biometric information) through this website, and we ask that you do not include such information in any message you send us.
How we use your information
We use the personal data we collect to:
Respond to your enquiries and correspond with you about potential or ongoing work
Comply with our legal obligations
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
Our legal basis for processing
Under UK GDPR, we rely on the following legal bases:
Legitimate interests — to respond to enquiries and operate our website effectively
Contract — where processing is necessary to perform a contract with you, for example, if you become a client
This website uses Framer's built-in analytics to understand how it's used. This tool is fully anonymised, does not use cookies, and cannot be used to identify you. As a result, no cookie banner or consent is required for this website.
How long we keep your information
We keep enquiry and correspondence data for up to 24 months from your last contact with us, unless a longer period is required to meet a legal or accounting obligation, for example, if you become a client.
Sharing your information
We may share your data with trusted third-party service providers who help us operate this website or run our business — for example, website hosting and the contact form (Framer), email providers, or accounting software — but only to the extent necessary for them to provide their services, and always under appropriate confidentiality and data protection terms.
We will not share your personal data with any other third party without your consent, unless required to do so by law.
Your rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you
Request correction of inaccurate data
Request deletion of your data
Object to or restrict certain processing
Request a copy of your data in a portable format
To exercise any of these rights, contact us at matthewgaston@outlook.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.
Data security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with an updated "last updated" date.
Contact us
If you have any questions about this policy or how we handle your data, please contact us at matthewgaston@outlook.com.