Last updated: 2026-09-27
Who we are
Second Media Agency Ltd (“Second Media”) is an independent digital agency trading from Spaces Charing Cross, 300 Bath Street, Tay House, Glasgow G2 4JR, United Kingdom. This notice explains which personal data we process when you use this website, why, and for how long.
You can send any question about your data to info@secondmedia.co.uk.
The AI assistant
This website includes an AI assistant. It is clearly labelled as such and answers only from Second Media information that we have approved.
Conversation content is passed to a third-party AI provider in order to answer your question. That data is not used for model training. Chat history is kept only to respond to the relevant enquiry and is deleted automatically.
The assistant will never give you a price, contract or commitment on our behalf. Important matters are handed to a human specialist.
Data we collect
We process only what is needed to respond to your enquiry:
- Name, company, email, phone and project details you provide in the contact form
- Budget and timing preferences, used only to assess the enquiry
- Technically necessary data: IP address (hashed), browser type, language preference
- Chat content — stored only if you turn the conversation into a written enquiry
We do not store your raw IP address. A non-reversible hash is calculated for rate limiting and spam protection.
Legal basis
We process your data to respond to your enquiry and take steps towards a contract (UK GDPR, Art. 6(1)(b)). Marketing messages are sent only with your explicit consent (Art. 6(1)(a)). Technical security processing relies on our legitimate interests (Art. 6(1)(f)).
Retention
We keep written enquiries for a reasonable period after the business relationship ends. Chat history is deleted automatically after 30 days by default. The period is configurable through the AI_SESSION_TTL setting.
Your rights
You have the right to access, correct, delete, restrict, port your data and object. Email info@secondmedia.co.uk and we will respond within 30 days.
Security
All traffic runs over HTTPS. Forms are protected with CSRF tokens and a honeypot, and submissions are rate limited. API keys stay on the server and are never sent to the browser.