Privacy Policy
Last updated: February 2026
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the choices you have. It applies to Nutkins UK Ltd trading as proheadshots.mom ("ProHeadshots", "we", "us") and this website.
The simple version
We only collect information we need to run our headshot photography service, respond to enquiries, and deliver your images. We do not sell your data. We use a small number of trusted providers for things like payments, email, and privacy-friendly website analytics. This page explains everything in plain English.
What information we collect
Information you give us
When you contact us, request a quote, or book a session, you may give us:
- Your name
- Your email address and phone number
- Company name and role (if relevant)
- Details about the type of images you need, dates, locations, and any practical requirements
- Billing details needed for invoicing
Payment details: If you pay by card, your card details go directly to our payment provider. We do not store your full card number.
Information collected automatically
When you visit our website, your browser communicates standard technical data with our hosting provider so the site can load. This includes your IP address and device type, which are processed by the hosting infrastructure and are not stored or used by us for tracking purposes.
How we use your information
We use your information to:
- Respond to enquiries and provide quotes
- Schedule sessions and confirm practical details
- Process payments and issue invoices/receipts
- Deliver your finished images and provide support if you have questions
- Run and improve the website
Who we share your information with
We share personal data only when needed to deliver the service, and only with trusted providers. We never sell your personal information.
Payments
- Stripe and Square – process card payments securely. We receive confirmation of payment, but we do not store your full card details.
Client management
- Light Blue – stores client booking details and job information so we can run sessions smoothly and keep records.
Website hosting and delivery
- Website hosting – our site is served via a hosting/CDN provider. Your browser will share normal technical data (like IP address and device info) so the site can load.
Cookies and analytics
This website does not use cookies and does not run any client-side analytics scripts. We do not track individual visitors or collect browsing data on this site.
We use Google Search Console to understand how the site performs in search results. This is a webmaster tool that processes anonymised search data on Google's servers. It does not involve cookies or any tracking on your device.
Legal basis for processing
Under the UK GDPR, we process personal data using one or more of the following lawful bases:
- Contract – to provide a service you have requested (for example, booking and delivering a session).
- Legitimate interests – to run our business, respond to enquiries, and improve our website in a privacy-friendly way.
- Legal obligation – to keep required records (for example, accounting and tax).
- Consent – where you have actively chosen to give it (for example, if you ask us to contact you in a specific way).
How long we keep your information
We keep personal data only as long as we need it for the purpose it was collected for, and to meet legal requirements. As a guide:
- Invoices and accounting records – typically kept for 6 years (and the current financial year), in line with UK record-keeping requirements.
- Enquiry and booking information – kept while we are discussing or delivering work, and for a reasonable period afterwards so we can support you and keep a clear record of what was agreed.
Your rights
You have rights over your personal data. These include:
- Access – ask what data we hold about you
- Correction – ask us to fix inaccurate information
- Deletion – ask us to delete your data in certain situations
- Restriction – ask us to limit how we use your data
- Objection – object to certain types of processing
- Portability – request a copy of your data in a commonly used format
To exercise any of these rights, email peter@proheadshots.mom.
How we protect your information
We take security seriously. We use reputable providers, keep access limited, and use secure systems for payments and storage. No website can promise perfect security, but we work hard to keep your information protected.
Children
This website and our services are not aimed at children. If you believe a child has provided personal data to us, please contact us and we will deal with it appropriately.
Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of the page.
Data controller and contact
Data controller: Nutkins UK Ltd (trading as proheadshots.mom).
If you have any questions about this policy or how we handle your data, email peter@proheadshots.mom.
Business details
- Company: Nutkins UK Ltd, trading as proheadshots.mom (Company No. 10781892).
- Registered address: 48 May Pole Knap, Somerton, Somerset, TA11 6HR.
- ICO registration: ZB975724.
Complaints
If you are unhappy with how we have handled your data, please contact us first so we can try to sort it out. You can also complain to the Information Commissioner's Office (ICO).