Privacy Policy
This policy explains how A4T Studio uses personal information through its website, project work and limited business outreach, and the choices available to you.
Last updated: September 1, 2026
Who controls your data
ASK FOR TASK LTD is the controller for personal data collected through this website. The company is registered in England and Wales under company number 14697408 and operates A4T Studio and Pinglo.
Registered office: The Matilda House, St. Katharines Way, London, England, E1W 1LF. Privacy contact: admin@askfortask.co.uk.
Business outreach
We sometimes use limited public business information to decide whether one relevant, individual introduction may be useful to an organisation. This can include a person’s name, professional role, organisation, published work email address, the page where it was published, public business activity relevant to a possible project, and our record of messages, replies, delivery failures, corrections and objections.
Sources may include an organisation’s own website, an official event or project announcement, a public registry, or a recognised trade-association profile. The contact address and the project evidence may come from different public sources. We do not infer private email addresses, and we do not treat a published address as consent.
Our purpose is to identify a specific potential business conversation, make a limited approach when the person’s role and the contact route make that reasonable, answer requested information, and prevent duplicate or unwanted approaches. We rely on legitimate interests for this processing and consider relevance, necessity, the recipient’s reasonable expectations and the possible effect on them before sending. If the organisation’s status, the purpose of an address or the balance is uncertain, we do not use that contact.
Each first message identifies the public source of the contact details and links to this notice. We do not automatically chase an unanswered first message or an automated acknowledgement. You can object to direct marketing at any time by replying or emailing admin@askfortask.co.uk. We will stop marketing and keep only the minimum suppression record needed to avoid contacting you or another address at the same organisation by mistake.
Information we collect
Contact and project enquiries
The contact form may collect your name, email address, project topic, region, budget range, target date, consent choice, and message. If you use the guided project assistant, your selected service, project stage, region, budget, target date, written objective, name, and email are combined into a contact enquiry.
Reviews and publication permission
The review form collects your name, private email address, optional company or project, service, relationship to the work, review text, contact consent, and optional publication permission. A review is not published automatically. We may contact you to verify the work and confirm final wording and attribution before publication.
Professional profiles and CV uploads
The professional form collects your name, email, location or time zone, work categories, specialisms, preferred responsibility, availability, optional portfolio or LinkedIn URL, project interests, consent, and PDF CV. Structured application details are stored in Cloudflare D1. The PDF is checked for size, MIME type, extension, and file signature, then sent privately through Resend; it is not stored in the public website or D1 database.
Product support
Support requests for Pinglo or another A4T Studio service may include your contact details, the product involved, a description of the issue, and information needed to investigate it. Please do not send passwords, payment information, identity documents, or another person’s private information unless a secure route has been agreed.
Security and operational logs
Cloudflare may process technical request information such as an IP address, request time, requested path, browser or network information, and security events to deliver and protect the website. To limit repeated form submissions, the Worker converts the connecting IP address into a one-way hash and stores only that hash, the form route, a short time window, and a request count. A4T Studio application logs are designed not to include submitted names, email addresses, form messages, CV content, or full partner destinations.
Outbound partner-link requests
When a controlled partner or portfolio link is requested, our first-party counter stores only the approved partner slug, a controlled source-page label, the UTC date, and an aggregate request count. It does not create a visitor ID or store an IP address, name, email address, fingerprint, or browsing profile. Bots and link scanners may also be counted, so these figures are requests rather than guaranteed human visits.
Why we use information and our lawful bases
- Enquiries and project delivery: to respond, prepare a proposal, take steps requested before a contract, and perform an agreed contract.
- Professional profiles: to consider a voluntary submission for suitable current or future projects, based on your consent and our legitimate interest in building an appropriate delivery network. You can withdraw the submission at any time.
- Reviews: to receive and verify feedback under our legitimate interests. We rely on your consent before considering a named review for publication, and you can withdraw that permission.
- Product support, security, and service reliability: to answer support requests, prevent misuse, diagnose faults, and protect the company and users under our legitimate interests.
- Partner-link statistics: to understand which public work examples are useful, based on our legitimate interest in improving the website without identifying visitors.
- Relevant business outreach: to assess and make one limited business introduction, respond when invited, and prevent duplicate or unwanted approaches, based on our legitimate interests and subject to a recipient-by-recipient relevance and balancing check.
- Legal requirements: to keep or disclose information where the law requires it, or where necessary for legal claims and dispute handling.
Who receives information
Cloudflare provides website delivery, security, Worker execution, and the D1 database. Resend delivers form notifications and attached CVs to ASK FOR TASK LTD. A professional or delivery partner may receive the project information needed for their agreed role, but only after the route and confidentiality requirements are understood.
For business outreach, Microsoft 365 Business Basic (without Teams) and Outlook provide the company mailbox and message storage. Microsoft supplies these services under its applicable commercial product and data-protection terms. We use OpenAI’s ChatGPT Plus and Codex to assist with public-source research, drafting, classification and authorised scheduling, alongside access-controlled local company records. Nikita Piazenko oversees this work. AI assistance does not make a recipient’s reply, interest, qualification or buying decision for them.
ChatGPT Plus is an individual service rather than an OpenAI business workspace. OpenAI states that content may be used to improve its models depending on the account’s Data Controls. We therefore limit this workflow to relevant published business information and correspondence, and do not use it to obtain private contact details. Information about OpenAI’s controls is available in its Data Controls guidance.
We may also disclose information to professional advisers, courts, regulators, law enforcement, or another authority where legally required or necessary to establish, exercise, or defend legal rights. We do not sell form submissions, professional profiles, CVs or business-outreach records.
International transfers
Cloudflare, Resend, Microsoft and OpenAI operate internationally, so information may be processed outside the United Kingdom. Storage location can vary by service and account configuration; a UK email address does not mean that all processing stays in the UK. Where UK data-protection law requires a safeguard, the relevant provider describes contractual transfer safeguards, adequacy arrangements or another permitted mechanism in its terms and privacy information. You can ask us for the provider information relevant to your record. Project work involving an overseas professional or client is assessed according to the information and location involved.
How long information is kept
- Ordinary enquiries and guided project submissions: normally up to 24 months after submission or the latest contact. A record may be kept longer if a working relationship begins or it is needed for a contract, legal duty, complaint, or claim.
- Reviews: normally up to 24 months after submission or the latest contact, with approved publication records retained while the review remains in use.
- Professional profiles and CV information: normally up to 12 months after the latest contact unless a working relationship begins, deletion is requested sooner, or longer retention is legally required.
- Outbound partner-link aggregate counts: up to 24 months, after which older daily totals are deleted.
- Form rate-limit records: short-lived hashed network keys normally expire within 30 minutes and are removed by scheduled cleanup.
- Security and operational logs: for the period provided by the configured Cloudflare logging and security services, or longer where a specific incident must be investigated or a legal requirement applies.
- Uncontacted or rejected outreach research: reviewed within 30 days. We remove personal contact information when there is no continuing justified purpose.
- Unanswered first outreach messages: reviewed 90 days after the first message. We remove unnecessary personal research and working message copies unless a documented reason requires retention.
- Substantive business conversations: normally reviewed after 24 months without substantive activity. Contract, accounting, complaint and legal records may have separate retention requirements if a client relationship begins.
- Do-not-contact records: limited to the address or organisation identifier, date and reason needed to prevent another approach. Nikita Piazenko reviews their continued necessity annually while outreach continues.
Scheduled database cleanup removes expired website records. Business-outreach reviews are currently carried out manually and are not described as automatic deletion. We review company-held mailbox and local working copies; providers may retain limited backups, security records or deleted content for the periods in their own terms. Records connected to an active contract, approved review in use, legal duty, complaint, or claim can be placed on retention hold and are not removed by the ordinary schedule.
How information is protected
Public forms use encrypted transport, short-window submission limits, request-size limits, server-side validation, parameterised database statements, restricted file types, and no-store responses. Website security headers restrict framing, executable sources, and unnecessary permissions. Access is limited to people and providers who need the information for the stated purpose.
No internet service can promise absolute security. If you believe personal data or a service may be at risk, contact admin@askfortask.co.uk.
Your data-protection rights
Depending on the circumstances, you may ask for access to your personal data, correction, deletion, restriction, objection to processing, or a portable copy. Where processing relies on consent, you can withdraw that consent at any time without affecting earlier lawful processing.
Send a request to admin@askfortask.co.uk. We may need enough information to confirm your identity and locate the relevant record. If you remain concerned, you can complain to the UK Information Commissioner’s Office.
Automated decisions
A4T Studio does not use website forms or the business-outreach workflow to make solely automated decisions with legal or similarly significant effects. Enquiries, reviews, professional submissions and substantive business replies are considered by a person.
Cookies and analytics
The current website does not set advertising or cross-site tracking cookies and does not use Google Analytics, Meta Pixel, fingerprinting, or session replay. Read Cookies and Analytics for details about first-party aggregate partner-link measurement and future policy changes.