Privacy Policy
Last updated: February 2026
Introduction
Willstead ("we", "us", "our") operates willstead.co.uk and app.willstead.co.uk. This privacy policy explains how we collect, use, store, and protect your personal data when you use our websites and services.
We are committed to protecting your privacy and ensuring your data is handled responsibly and transparently.
What we collect
We collect the following types of data:
- Name and email address — collected when you use our email capture form to receive tool results or updates.
- Estate planning data — information you enter into our tools and document creation questionnaires (such as asset values, beneficiary details, and personal circumstances).
- Payment information — processed securely by Stripe. We never store your card details on our servers.
- Usage data — collected via Plausible Analytics, a privacy-focused analytics platform that does not use cookies or collect personal data.
How we use your data
We use the data we collect for the following purposes:
- To provide our estate planning tools and generate legally structured documents.
- To send you results you have requested via email.
- To improve our services using aggregated, anonymised data only.
- To comply with legal obligations.
Legal basis (GDPR)
We process your data under the following legal bases:
- Consent — when you provide your email address to receive results or communications.
- Contract performance — when we generate documents you have purchased.
- Legitimate interests — for service improvement using anonymised, aggregated data.
Data sharing
We do not sell your data. We share data only with the following third parties, strictly as required to deliver our services:
- Stripe — for secure payment processing.
- Plausible Analytics — privacy-focused analytics that does not collect personal data.
- Email delivery service — used solely for sending results emails you have requested.
Data retention
We retain your data for only as long as necessary:
- Tool calculations — not stored. All calculations are processed client-side only.
- Email capture data — retained until you unsubscribe.
- Document data — retained for 12 months after creation, then permanently deleted.
- Payment records — retained as required by law (6 years).
Your rights
Under GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data.
- Portability — request your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Complaint — lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
We use Plausible Analytics for website analytics, which does not use cookies and does not collect personal data. As a result, no cookie consent banner is required on our website.
Security
We take the security of your data seriously and implement appropriate measures to protect it:
- HTTPS encryption on all pages and data transfers.
- Data encrypted at rest.
- Regular security reviews and updates.
Contact
If you have any questions about this privacy policy or wish to exercise your data rights, please contact us at: