Privacy Policy

Junction Privacy Policy

Draft status

Master policy for Junction Solutions, Junction Hosting, Zen Cart Solutions and the Junction client portal

Draft for publication — 4 August 2026

Important publication check: Before publishing, confirm the final legal operator name, registered/business address, data-protection contact address, analytics/cookie tools and payment/email providers against the live systems.

1. Who we are

This Privacy Policy explains how personal data is collected and used across the Junction family of websites and services. The Junction family includes Junction Solutions, Junction Hosting, Zen Cart Solutions and the Junction client portal.

The data controller is Stephen Price, entrepreneur individuel, operating under the trading name Junction Solutions, SIREN 108 309 725. The business address is 61 rue de Lyon, 75012 Paris, France. For privacy questions or data-subject requests, contact legal@junction.solutions.

This policy applies to the following online properties and related services:

junction.solutions and its service and contact pages

junctionsolutions.host and Junction Hosting pages, order links and hosting information

zencart.solutions and Zen Cart Solutions pages

client.junction.solutions and the Blesta client portal

Client orders, billing, support tickets, knowledge-base access and managed hosting administration connected with those properties

2. Personal data we collect

Depending on how you interact with us, we may collect:

identity and contact details, such as your name, business name, email address, telephone number and postal address;

account and authentication details, including usernames, password-reset information and security records;

order, service and billing information, including products ordered, service status, invoices, payment status and correspondence;

support information, including tickets, attachments, technical details and the history of communications;

technical information, including IP address, browser and device information, log data, referral information and basic security events;

information you provide through contact forms, emails, consultations, project enquiries or client onboarding;

cookie and similar technology information, as described in our Cookie Policy.

We do not intentionally request special-category personal data through the websites. Please avoid sending sensitive personal information in contact forms or support tickets unless it is necessary and we have specifically asked for it.

3. How we use personal data

We use personal data for the following purposes:

to respond to enquiries and provide quotations or requested information;

to create and manage client accounts;

to process orders, provision services and administer hosting accounts;

to issue invoices, record payments and manage renewals, cancellations and refunds;

to provide technical support, investigate faults and maintain support history;

to operate, secure and improve the websites, portal, systems and services;

to send essential service messages, including account, order, billing, security and support communications;

to send marketing communications where permitted and where you have consented or another lawful basis applies;

to comply with legal, regulatory, tax, accounting and fraud-prevention obligations;

to establish, exercise or defend legal claims.

4. Lawful bases for processing

We rely on one or more of the following lawful bases under the UK GDPR and EU GDPR, as applicable:

Contract: where processing is necessary to provide an account, product or service you have requested, or to take steps before entering into a contract;

Legal obligation: where processing is necessary to meet accounting, tax, legal, regulatory or security obligations;

Legitimate interests: where processing is necessary to operate, secure and improve the business, respond to enquiries, manage support and protect systems, provided those interests are not overridden by your rights;

Consent: where we ask you to consent to optional marketing, non-essential cookies or another clearly specified purpose. You may withdraw consent at any time.

5. Orders, payments and billing

When you place an order or maintain a client account, we process the information needed to fulfil the order, create or maintain services, issue invoices and manage payments. Payment card details are handled by the relevant payment provider rather than stored by us in full. The providers used for a particular transaction will be identified at checkout or in the applicable service documentation.

Billing and accounting records are retained for the periods required by applicable tax and accounting rules, even where an account or service is later closed.

6. Client portal and hosting services

The Junction client portal is powered by Blesta and may process account, service, order, invoice, payment and support information. Junction Hosting may also process domain, hosting, technical, usage and security information needed to administer hosting accounts, backups, migrations, mailboxes, databases and support requests.

Where we provide development, ecommerce, integration or Zen Cart services, information may also be processed as part of project delivery, maintenance, troubleshooting and client communications. The exact data processed depends on the service and instructions provided by the client.

7. Sharing personal data

We may share personal data with trusted providers where necessary to operate the Junction family and deliver services. These may include:

hosting, infrastructure, backup, security and domain-service providers;

Blesta and related billing, account and support infrastructure;

payment providers and banking or payment-account providers;

email, telephone and communications providers;

analytics, cookie-consent and website-security providers, where enabled;

professional advisers, insurers, auditors and authorities where disclosure is lawful or required;

a purchaser, successor or professional adviser involved in a business transfer, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data. We require processors to handle data only for authorised purposes and to provide appropriate security and confidentiality safeguards.

8. International transfers

Some providers may process information outside the United Kingdom or European Economic Area. Where this occurs, we will use an appropriate legal transfer mechanism and safeguards, such as an adequacy decision, approved contractual clauses or another mechanism recognised by applicable data-protection law.

9. Retention

We keep personal data only for as long as it is needed for the purpose for which it was collected, to provide the service, to resolve disputes, to enforce agreements or to meet legal, tax, accounting and security obligations. Retention periods vary by category. When data is no longer required, it will be securely deleted, anonymised or placed beyond operational use.

10. Security

We use reasonable technical and organisational measures appropriate to the nature of the information and the risks involved. These may include access controls, authentication, backups, logging, software updates, encrypted connections and restricted administrative access. No internet service can be guaranteed completely secure, so you should use a strong unique password and notify us promptly of suspected unauthorised access.

11. Cookies and similar technologies

The public Junction websites currently do not use analytics, advertising or marketing cookies. The client portal and Blesta order routes use a strictly necessary session cookie named blesta_sid to maintain the client session and support secure navigation. It is HttpOnly, Secure and short-lived. Our Cookie Policy explains the cookies and similar technologies used, their purposes and how to manage preferences. If optional analytics, functionality or marketing technologies are introduced, this policy and the Cookie Policy will be updated and consent will be requested where required.

12. Marketing

We may send information about Junction services where permitted by law. You can unsubscribe from marketing communications at any time by using the unsubscribe option in the message or contacting enquiries@junction.solutions. Essential account, billing, security and service communications are not marketing and may still be sent when necessary.

13. Your rights

Subject to legal conditions and exemptions, you may have the right to:

access a copy of your personal data;

correct inaccurate or incomplete data;

request erasure of data;

request restriction of processing;

object to processing based on legitimate interests or to direct marketing;

receive certain data in a portable format;

withdraw consent where processing relies on consent;

lodge a complaint with the relevant supervisory authority.

To exercise a right, contact legal@junction.solutions. We may need to verify your identity before responding. We normally respond within one month, although the period may be extended where legally permitted for complex or multiple requests.

14. Children

Our services are intended for businesses and adults. We do not knowingly collect personal data from children through the websites. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.

15. Third-party websites and services

Our websites may link to third-party websites, payment pages, social-media services or client systems. Their privacy practices are governed by their own notices. We are not responsible for the content or privacy practices of third-party websites.

16. Changes to this policy

We may update this policy when our services, providers or legal obligations change. The latest version will be published on the relevant Junction website with its effective date. Where a change materially affects how we use personal data, we will provide additional notice where required.

17. Contact and complaints

For privacy questions, requests or concerns, contact:

Junction Solutions
Email: legal@junction.solutions
Telephone: +44 (0)33 01 33 94 96
Address: 61 rue de Lyon, 75012 Paris, France

If you are not satisfied with our response, you may contact the data-protection supervisory authority in the country where you live, work or believe an infringement occurred. For this French business, this is generally the Commission nationale de l’informatique et des libertés (CNIL).

Document control

Policy version: 1.0
Effective date: [insert publication date]
Last reviewed: 4 August 2026