top of page
Abstract Flame

Privacy Policy

MEDIA4YOU

Privacy and Cookie Policy

How Media4You collects, uses, shares and protects personal data across its website, shop and services.

Last updated: 20 July 2026

Applies to: www.media4you.co.uk and Media4You orders and services

 

Media4You respects your privacy. This Policy explains what personal data we handle, why we use it, the lawful bases we rely on, how long we keep it and the rights available to you under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).

1. Who is responsible for your data

Benjamin Horwood, trading as Media4You, is the data controller for the personal data described in this Policy unless we tell you that another organisation is the controller.

Website: https://www.media4you.co.uk

Privacy email: info@media4youiow.co.uk

Telephone: 07395 322561 (email is preferred)

Postal address: Pan Cottage, Pan Lane, Niton, Ventnor, Isle of Wight, PO38 2BU, United Kingdom

For some client projects we act as a processor rather than a controller. For example, a business client may decide why personal data is placed in a website, booking system, NAS, communications system or supplied footage while we handle it only to deliver the contracted work. In that situation, the client’s privacy notice applies to its use of the data and a separate data-processing agreement may apply between the client and Media4You.

2. Scope of this Policy

This Policy covers visitors to our website, account and forum users, prospective and existing customers, shop purchasers and recipients, gift-card users, event participants and people captured in photography or drone imagery where Media4You is the controller, suppliers, contractors, job applicants and people who contact us.

A third-party website, platform, embedded service or customer-controlled service may have its own privacy notice. Please read that notice where you interact directly with it.

3. Personal data we may collect

Information you give us

Identity and contact details, such as name, business name, postal and delivery address, email address, telephone number and account username.

Enquiry, quotation and contract information, including project requirements, site details, communications, approvals, survey responses and support requests.

Order and transaction information, including products, services, delivery status, gift-card details, invoices, refunds and payment status. We do not normally receive your full payment-card number from the payment processor.

Customer content and credentials supplied for a project, including text, images, video, audio, logos, databases, access permissions and files.

Account, forum, review and community content, including profile information, comments and material you choose to publish.

Job-application and contractor information, including CV, employment history, qualifications, references and right-to-work information where relevant.

Safety, access or accommodation information, which may include health information where genuinely needed to provide a service safely or make a reasonable adjustment.

Information collected automatically

Device and usage information, such as IP address, device type, browser, operating system, approximate location derived from IP, referring page, pages viewed, timestamps, diagnostic logs and cookie identifiers.

Account and security events, including sign-in attempts, fraud indicators, consent records and preferences.

Photography, video, audio and drone data

Our work may capture identifiable people, voices, vehicle registrations, property, location, timestamps and contextual information. For commissioned work, the client may be the controller and Media4You may be its processor. Where Media4You decides the purpose—for example, our own portfolio, operational records or direct promotion—we will identify and document an appropriate lawful basis and respect applicable objections, permissions and safeguards.

We do not use facial recognition or create biometric identification profiles unless this is expressly agreed, lawful and covered by additional information before processing.

Information received from others

We may receive data from a customer or event organiser, a person buying a gift, payment and fraud-prevention providers, Wix, Printful, delivery companies, social-media or advertising platforms, referees, public registers, professional advisers and people who refer you to us. We will provide privacy information directly where the law requires and it is not disproportionate or impossible.

4. How and why we use personal data

The lawful basis depends on the purpose and context. We do not rely on consent where another basis is more appropriate, and you may withdraw consent at any time without affecting earlier lawful processing.

Purpose

Data

Lawful basis

How we use it

Enquiries and quotes

Contact details, messages and project requirements

Steps requested before a contract; legitimate interests in responding and planning work

Answer enquiries, assess feasibility, prepare quotes and follow up

Orders and services

Identity, contact, order, delivery, project, access and communication data

Contract; legal obligation; legitimate interests in delivery and support

Take payment, provide goods/services, fulfil, deliver, support and manage changes

Accounts and community

Profile, sign-in, preferences, posts and moderation records

Contract; legitimate interests in operating a safe community

Create accounts, provide features, moderate content and secure access

Photography and drone work

Images, video, audio, location and project metadata

Contract; legitimate interests; consent where appropriate; legal obligation

Create deliverables, maintain safety and operational records, and use approved portfolio material

Marketing

Name, contact details, interests, purchase/enquiry history and consent choices

Consent where PECR requires it; otherwise carefully assessed legitimate interests

Send relevant news and offers, measure campaigns and maintain suppression lists

Website and security

Device, cookie, log and fraud data

Consent for non-essential cookies; legitimate interests and legal obligation for necessary security

Run, analyse and protect the website, prevent misuse and diagnose faults

Business administration

Invoices, contracts, correspondence, complaints and supplier data

Legal obligation; contract; legitimate interests

Accounting, tax, insurance, debt recovery, disputes, audit and business management

Recruitment

Application, interview, reference and eligibility data

Steps before a contract; legitimate interests; legal obligation; consent or employment-law bases where needed

Assess applicants, arrange interviews and keep appropriate recruitment records

 

Where we rely on legitimate interests, those interests include running and improving a small business, responding to customers, protecting systems, recovering payment, documenting work, promoting completed public work and preventing fraud. We assess necessity and balance our interests against your rights and reasonable expectations.

Where we process special-category data, such as health information needed for accessibility or safety, we also identify an additional UK GDPR condition—for example explicit consent, vital interests or an employment/social-protection condition where applicable. We do not seek such data unless it is necessary.

5. If you do not provide requested information

Some data is necessary to quote, form or perform a contract, deliver an order, comply with law or keep a site safe. If you do not provide it, we may be unable to proceed or may need to modify or cancel the affected work. Optional fields and marketing choices will be identified where practicable.

6. Who we share personal data with

We share only what is reasonably necessary. Recipients may include:

Wix.com and relevant Wix group companies, which provide our website, hosting, accounts, forms, online shop and related platform tools.

Printful and its fulfilment partners, which receive order, recipient, product and delivery information needed to manufacture, package and dispatch print-on-demand goods.

Payment processors and fraud-prevention providers displayed at checkout. They process payment details under their own privacy information; Media4You normally receives confirmation and transaction data rather than complete card details.

Couriers, postal operators, hosting, domain, email, cloud-storage, backup, communications, customer-support, analytics and security providers.

Website, booking, channel-management, advertising, mapping, social-media, video, 3D-model and embedded-content platforms chosen for a project or used on our website.

Employees, vetted freelancers, subcontractors and specialist trades who need the information to perform the work and are subject to appropriate confidentiality and data-protection obligations.

Accountants, insurers, banks, legal advisers, debt-recovery providers, auditors and other professional advisers.

Police, regulators, courts, the Civil Aviation Authority, tax authorities or other public bodies where disclosure is legally required or reasonably necessary to protect rights, safety or prevent crime.

A purchaser, investor or successor involved in a genuine business sale or reorganisation, subject to appropriate confidentiality and lawful processing.

We do not sell personal data. We do not permit a service provider to use personal data for its own unrelated marketing merely because it processes data for us.

7. International transfers

Some providers, including global website, fulfilment, cloud, payment and platform companies, may process personal data outside the United Kingdom. Where UK transfer restrictions apply, we use a lawful mechanism appropriate to the destination and recipient, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard or exception. We also consider practical security and supplementary measures where required.

You may contact us for more information about the relevant safeguard, subject to legitimate confidentiality and security restrictions.

8. How long we keep personal data

We keep data only as long as reasonably needed for the purpose collected, legal and insurance requirements, dispute limitation periods, security and backup cycles. Our normal guide is:

Record

Normal retention approach

Enquiries that do not become orders

Up to 24 months after the last meaningful contact, unless you ask us to delete sooner or a dispute requires longer

Contracts, invoices, tax and core transaction records

Normally 6 years after the end of the relevant relationship or financial year, and longer only where law, insurance or a live claim requires

Customer account and forum profile

While active and normally up to 12 months after closure; transaction, moderation or legal records may be kept longer

Project working files, footage and technical data

For the agreed project period; where no period is agreed, working copies are normally reviewed for deletion within 12 months after final delivery, subject to backups, support and legal needs

Website security and diagnostic logs

Normally up to 12 months, unless an incident or legal requirement justifies longer

Marketing records

Until you opt out or consent is withdrawn; active records are reviewed periodically, normally at least every 24 months; suppression records are retained to respect opt-outs

Unsuccessful job applications

Normally up to 6 months after the recruitment process, unless a longer talent-pool period is agreed or a claim requires longer

Complaints, incidents and claims

Normally 6 years after closure, or longer where a legal, aviation, insurance or regulatory requirement applies

 

Deletion from live systems may be followed by later expiry from encrypted or rolling backups. Data may be anonymised so that it no longer identifies anyone; anonymised information may be kept for statistics, service improvement and business records.

9. Cookies and similar technologies

Our website uses cookies, pixels, local storage and similar technologies. Essential technologies support security, network management, checkout, account sign-in, load balancing and your privacy choices. They may be used without consent where the law permits because the requested service cannot function without them.

Analytics, personalisation, advertising and other non-essential technologies are used only after the required consent. You can accept, reject or adjust them through the cookie banner or settings control. Withdrawing consent does not affect earlier lawful processing, but it stops future non-essential storage or access once the setting takes effect.

The cookie settings panel provides the current cookie categories, providers and durations because these can change when Wix apps, embeds or site features are updated. Browser controls can also block or delete cookies, but doing so may affect functionality. Third-party embeds may set their own cookies only in accordance with your choices and their notices.

10. Direct marketing

We may send electronic marketing where you have consented or where the PECR “soft opt-in” lawfully applies to similar Media4You goods or services offered to an existing customer. Every electronic marketing message will provide a simple opt-out. You can object at any time by using that link or emailing info@media4youiow.co.uk.

We may use limited business-contact data for relevant business-to-business marketing where lawful and within reasonable expectations. UK GDPR still applies where an individual is identifiable, and the right to object to direct marketing is absolute. We keep a minimal suppression record so we do not contact you again by mistake.

11. Security

We use proportionate technical and organisational measures, which may include access controls, multi-factor authentication where available, encryption in transit, device and account security, least-privilege access, secure backups, supplier assessment, confidentiality duties and incident procedures. No internet transmission or storage system can be guaranteed completely secure, but we regularly consider the risks appropriate to the data and service.

If a personal-data breach is likely to create a risk to people, we will assess and report it to the Information Commissioner’s Office where required. If a breach is likely to result in a high risk, we will also notify affected people without undue delay where the law requires.

12. Your data-protection rights

Depending on the circumstances, you may have the right to:

be informed about how your personal data is used;

request access to your personal data and a copy of it;

ask us to correct inaccurate or incomplete data;

ask for deletion where there is no lawful reason to continue processing;

ask us to restrict processing in specified circumstances;

receive data you provided in a structured, commonly used, machine-readable format and have it transmitted where the portability right applies;

object to processing based on legitimate interests, and object at any time to direct marketing;

withdraw consent at any time where processing relies on consent; and

not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to lawful exceptions.

We do not currently make solely automated decisions with legal or similarly significant effects about Media4You customers. Payment, platform or fraud providers may operate their own automated checks under their notices.

To exercise a right, email info@media4youiow.co.uk. We may request information reasonably needed to verify identity and protect data. We normally respond within one month, although the law permits an extension for complex or numerous requests. Rights are not absolute; if an exemption applies, we will explain our decision where permitted.

13. Children and vulnerable people

Our website shop and direct contracting services are intended for adults. A person under 18 should involve a parent, guardian or responsible organisation when purchasing or commissioning work. We do not knowingly invite a child under 13 to create an account or consent to online data processing without appropriate parental authorisation.

Photography, video or drone work may include children or vulnerable people at schools, sports days, events or commissioned sites. We will agree responsibilities with the organising client, apply suitable notices and permissions where required, minimise unnecessary capture, use heightened safeguards and respond appropriately to safeguarding or privacy concerns.

14. Links, embedded content and social media

Our website may include maps, videos, social posts, reviews, 3D viewers, booking tools or other embedded services. Using an embed may disclose technical information to its provider and, with consent where required, allow cookies. Your interaction with a social-media account or third-party platform is also governed by that provider’s privacy notice.

15. Complaints

Please contact us first at info@media4youiow.co.uk so we can investigate. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority:

Website: https://ico.org.uk/make-a-complaint/

Telephone: 0303 123 1113

Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you live outside the UK, you may also be entitled to contact the relevant local data-protection authority.

16. Changes to this Policy

We may update this Policy when our services, providers or legal duties change. The current version and last-updated date will be published on our website. If a change materially affects how we use existing personal data, we will provide an additional notice where required and seek fresh consent where consent is necessary.

bottom of page