Privacy Policy
Plain-English summary of how we handle your data.
Last updated: 17 April 2026
YUFAN & Co. Ltd ("we", "us") is a company registered in England & Wales. We are the data controller for personal data collected through this website and our client engagements. This policy explains what we collect, why, how long we keep it, and your rights under the UK GDPR.
1. Data we collect
From the contact form: your name, email, phone (if provided), company, role, team size, indicative budget, referral source, and the message you send us. From the AI chat widget: the questions you type, our responses, and an anonymous session cookie so we can keep a conversation coherent. We do not store IP addresses, device fingerprints, or any identifier that could link chat content to you personally. From website analytics: aggregated page views and referrer data. No third-party tracking cookies.
2. Why we use it
To respond to your enquiry and qualify whether we are the right fit for your business. To improve the quality of our AI assistant by reviewing anonymous conversation logs. To fulfil our contract with you if we proceed to an engagement.
3. Legal basis
Contact form: your consent (given when you tick the consent box and submit the form), and our legitimate interest in running our business. Chat widget: legitimate interest in providing and improving the service. No personal data is collected, so no consent is required. Client engagements: performance of a contract, plus legal obligations (tax, accounting, UK company law).
4. Who we share data with
We do not sell your data. We use a small number of trusted processors: • Vercel (hosting) — EU/US datacentres, GDPR-compliant • Supabase (stores anonymous chat logs only) — EU datacentres • Google Cloud (runs the AI model powering the chat widget) — EU/US datacentres • An email provider to deliver your enquiry to our team All processors have signed Data Processing Agreements with us.
5. How long we keep it
Contact form submissions: 24 months, then deleted unless you have become a client. Chat logs: 12 months, then deleted. Client records: 6 years after the engagement ends, as required by UK company law and HMRC.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or port your personal data. You can also object to processing and withdraw consent at any time. To exercise any of these rights, email hello@yufanandco.com. We will respond within 30 days. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies
This site uses one functional cookie: an anonymous session identifier for the chat widget so a conversation stays coherent across page loads. It contains no personal data and expires after 30 days. We do not use advertising, tracking, or analytics cookies.
8. Contact
Questions about this policy or your data: hello@yufanandco.com. Postal address available on request.