← Back to the front page

Privacy policy

Last updated 1 August 2026 · Version 4.0

This policy explains what personal data Highbeam SEO ("we") collects through saaslinkbuildingagency.com, why we collect it, how long we keep it, and what rights you have over it. It is written to satisfy the UK GDPR, the EU GDPR (Regulation 2016/679) and, where applicable, the California Consumer Privacy Act.

1. Who is responsible

Highbeam SEO is the data controller for information collected through this site. We are a SaaS link building agency.

To reach the person responsible for data protection, use the enquiry form and start your message with "Privacy request". It is routed away from the commercial team.

2. What we collect

CategoryContentsSource
Enquiry dataName, work email, company and domain, target page and keyword, funding stage, budget band, free-text messageYou, via the form
Anti-abuse dataIP address and browser user-agent recorded by the form processor at the moment of submissionAutomatic, submission only
CorrespondenceEmails, authority maps, proposals and notes exchanged afterwardsYou and us

Nothing else is collected. This site runs no analytics, sets no advertising or session cookies, embeds no third-party pixels and performs no device fingerprinting. That is why there is no cookie banner — there is nothing to consent to. The only outbound requests the page makes are for its own stylesheet and script, a web-font stylesheet, and the form endpoint at the moment you press send.

We also record limited technical information about every visit — pages, clicks, country, a truncated network address and whether the request came from a person or a crawler. Section 10 sets out exactly what, why, and for how long.

3. Why we use it, and on what basis

We do not profile you, do not make automated decisions about you, and do not build a marketing list from form submissions. Submitting the form subscribes you to nothing. If we do not end up working together, you will not hear from us again unless you write again.

4. Who processes it for us

Each is bound by a data-processing agreement and may not use your data for its own purposes. We never sell, rent, licence or trade personal data, and we never pass your details to other agencies, publishers, link vendors or lead brokers.

5. International transfers

Some processors operate infrastructure outside the European Economic Area, principally in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

6. How long we keep it

Enquiries that do not become engagements24 months from last contact, then deleted
Enquiries we decline12 months, so the context survives if you write again
Client recordsTerm of engagement plus 7 years where tax law requires
Anti-abuse logs30 days

7. Your rights

Wherever you live, we honour all of the following: access to what we hold, rectification of anything inaccurate, erasure, restriction of processing, portability in a machine-readable format, objection to processing based on legitimate interest, and withdrawal of consent at any time without affecting processing already carried out.

Send any of these through the contact form. We respond within 30 days, usually far sooner, and never charge a fee. If you are unhappy with the outcome, you may complain to your national supervisory authority.

8. Security

The site is served over HTTPS and submissions are encrypted in transit. Internally, access to enquiry data is limited to the two founders and the researcher assigned to your account. Company devices are encrypted at rest and shared tools require two-factor authentication. If a breach ever creates a risk to your rights, we will notify you and the relevant authority within 72 hours of becoming aware of it.

9. Children

This is a business-to-business service. We do not knowingly collect data from anyone under 16. If you believe a minor has submitted information here, tell us and we will delete it.

10. Cookies and measurement

No cookies. This site sets no cookies at all — none for advertising, none for sessions, and none belonging to anyone but us. That is why you have not been asked to dismiss a banner.

One first-party identifier. Your browser stores a random string in this site's own local storage so we can tell a returning reader from a new one. It is not a cookie, it is not readable by any other website, it is never sold, shared or matched against anything, and clearing your browser data removes it. It carries no name, email or account.

What our own measurement records. We run no Google Analytics and no third-party trackers. Our own servers log, for each request:

Why. To see which pages and campaigns work, to keep the site available, and to separate genuine readers from the crawlers and scrapers that make up a large share of traffic. Legal basis: our legitimate interest in operating and improving the site (Article 6(1)(f) GDPR). We have limited what we collect specifically so that this basis holds — no cross-site tracking, no profiles, no advertising use, no data brokers.

How long. Raw request and interaction logs are deleted automatically after 180 days. Enquiries you send us are kept for as long as section 6 describes.

Opting out. If your browser sends a Global Privacy Control signal we record no interaction data at all. You can also block this site's scripts, or write to us using the contact details in section 1 and we will delete what relates to you.

11. Changes

Material changes are reflected in the version and date at the top of this page. Where a change affects data you have already given us, we contact you directly before it takes effect.

← Back to the front page