Privacy Policy
Your privacy and data protection are our top priorities. This comprehensive policy outlines how we collect, use, protect, and manage your personal information in full compliance with UK GDPR and data protection laws.
Secure Storage
Encrypted data protection
GDPR Compliant
Full UK/EU compliance
Your Rights
Complete data control
Transparent
Clear data practices
Data Collection & Information We Gather
We collect information to provide better services, improve user experience, and fulfill our contractual obligations. All data collection is lawful, fair, and transparent under UK GDPR regulations.
Personal Information We Collect
Contact & Identity Information
- Full NameCommunication and project identificationLegal basis: Contract performance
- Email AddressProject communication and updatesLegal basis: Contract performance & legitimate interest
- Phone NumberDirect communication and supportLegal basis: Contract performance
- Business Name & RoleProfessional context and project planningLegal basis: Contract performance
- Postal AddressInvoicing and legal documentationLegal basis: Contract performance & legal obligation
Technical & Usage Data
Automatically Collected Information
- IP Address & LocationSecurity, analytics, and geo-targetingLegal basis: Legitimate interest
- Browser & Device InfoWebsite optimization and compatibilityLegal basis: Legitimate interest
- Page Views & NavigationUser experience improvementLegal basis: Legitimate interest
- Referral SourcesMarketing effectiveness analysisLegal basis: Legitimate interest
- Session DurationWebsite performance optimizationLegal basis: Legitimate interest
Project & Business Information Collection
During our business relationship, we collect project-specific information necessary for service delivery, invoicing, and ongoing client support.
Project Requirements
- Website goals and objectives
- Target audience information
- Branding guidelines and preferences
- Content and media files
- Functional requirements specification
- Timeline and budget constraints
- Third-party service requirements
- Domain and hosting preferences
Financial Information
- Billing address and details
- VAT number (if applicable)
- Payment method preferences
- Invoice delivery preferences
- Purchase order numbers
- Credit application details
- Payment history records
- Refund and dispute information
Communication Records
- Email conversations and attachments
- Meeting notes and call recordings
- Project feedback and revisions
- Support ticket history
- Video conference recordings
- File sharing activity logs
- Change request documentation
- Project completion sign-offs
How We Collect Your Information
We collect information through various touchpoints and methods, always with transparency and appropriate legal basis under GDPR regulations.
Direct Collection Methods
Contact Forms
Website contact forms, quote requests, and consultation bookings
Data collected: Name, email, phone, project details
Email Communication
Direct email exchanges during project discussions and support
Data collected: Email content, attachments, contact preferences
Phone & Video Calls
Consultation calls, project meetings, and support conversations
Data collected: Contact details, meeting notes, recordings (with consent)
Contract Signing
Project agreements and legal documentation
Data collected: Signature, business details, project specifications
Automatic Collection Methods
Website Analytics
Google Analytics tracking for website performance and user behavior
Data collected: Page views, session duration, bounce rate, referral sources
Cookies & Tracking
Essential and analytical cookies for website functionality
Data collected: User preferences, session data, performance metrics
Server Logs
Technical logs for security, performance, and error monitoring
Data collected: IP addresses, browser info, timestamps, error reports
Third-Party Tools
CRM systems, email marketing platforms, and project management tools
Data collected: Interaction history, engagement metrics, project progress
Data Minimization Principle
We follow the GDPR principle of data minimization, collecting only the information necessary for specific, legitimate purposes. We regularly review and purge unnecessary data.
Purpose Limitation
Data used only for stated purposes
Accuracy Maintenance
Regular data updates and corrections
Storage Limitation
Data kept only as long as necessary
Your Privacy Rights Under UK GDPR
Under the UK General Data Protection Regulation (GDPR), you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights promptly and transparently.
Right of Access
Request copies of your personal data
You can ask us to confirm if we process your data and request a copy of all personal information we hold about you.
Right to Rectification
Correct inaccurate personal data
You can ask us to correct any personal information you think is inaccurate or incomplete.
Right to Erasure
Request deletion of your data
You can ask us to delete your personal data in certain circumstances, such as when it's no longer necessary.
Right to Restrict Processing
Limit how we use your data
You can ask us to suspend processing of your personal data in specific circumstances.
Right to Data Portability
Receive your data in a usable format
You can ask us to transfer your data to another service provider in a structured, commonly used format.
Right to Object
Object to processing of your data
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights for Automated Decision-Making
Protection from automated decisions
You have rights regarding automated decision-making, including profiling that affects you legally.
Right to Withdraw Consent
Withdraw consent at any time
Where we process data based on consent, you can withdraw that consent at any time.
How to Exercise Your Privacy Rights
We've made it simple to exercise your privacy rights. Follow these steps to submit requests and receive prompt, professional responses.
Request Process
Submit Your Request
Email us at info@webdevwales.com with your data request
Include: Full name, email, and specific request type
Identity Verification
We verify your identity for security
Provide: Photo ID or answer security questions
Request Processing
We review and process your request
Timeline: Maximum 30 days for most requests
Response Delivery
We deliver the requested information or action
Format: Secure email or encrypted file transfer
Required Information for Requests
For All Requests
- β’ Your full name and email address
- β’ Clear description of your request
- β’ Preferred communication method
- β’ Any relevant dates or time periods
For Data Access Requests
- β’ Specific data categories you want to access
- β’ Time period for the data request
- β’ Preferred format for data delivery
For Deletion Requests
- β’ Specific data to be deleted
- β’ Reason for deletion request
- β’ Confirmation of account closure (if applicable)
Important: We may ask for additional information to verify your identity and ensure we're responding to legitimate requests.
Data Protection & Security Measures
We implement comprehensive security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction.
Encryption
SSL/TLS encryption for data transmission and storage
Secure Hosting
ISO 27001 certified data centers in the UK
Access Control
Role-based access and regular security audits
Our Security Commitments
Technical Safeguards
- β’ 256-bit SSL encryption for all data transfers
- β’ Regular security vulnerability assessments
- β’ Automated backup systems with encryption
- β’ Multi-factor authentication for admin access
- β’ Real-time monitoring and intrusion detection
Organizational Measures
- β’ Staff training on data protection principles
- β’ Regular review of data processing activities
- β’ Incident response and breach notification procedures
- β’ Data minimization and retention policies
- β’ Third-party security assessments
How We Use Your Personal Data
We process your personal data for specific, lawful purposes that are necessary for our business operations and service delivery. All processing activities comply with UK GDPR requirements.
Service Delivery
- Project planning and consultation
- Website development and design
- Technical support and maintenance
- Training and handover sessions
- Quality assurance and testing
- Performance monitoring and optimization
Business Operations
- Customer relationship management
- Marketing and communication
- Website analytics and improvement
- Security monitoring and fraud prevention
- Business development and growth
- Staff training and development
Legal Compliance
- Financial record keeping
- VAT and tax reporting
- Regulatory compliance monitoring
- Data breach notification
- Court order compliance
- Professional indemnity requirements
Data Retention & Deletion Policies
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and protect our legitimate interests.
Retention Periods by Data Type
Project Files & Communications
Period: 7 years after project completion
Reason: Legal obligation & potential disputes
Financial Records & Invoices
Period: 7 years from end of financial year
Reason: HMRC requirements & audit purposes
Marketing & Analytics Data
Period: 3 years from last interaction
Reason: Business development & compliance
Website Activity Logs
Period: 12 months from collection
Reason: Security monitoring & performance
Support & Maintenance Records
Period: 3 years after service ends
Reason: Quality assurance & warranty
Personal Identifiers
Period: Until erasure request or 7 years
Reason: Ongoing relationship management
Automatic Deletion Process
Regular Review Cycle
- β’ Quarterly data audit and review
- β’ Automated deletion of expired data
- β’ Manual review of edge cases
- β’ Documentation of deletion activities
Secure Deletion Methods
- β’ Multi-pass data overwriting
- β’ Cryptographic key destruction
- β’ Physical media destruction when needed
- β’ Verification of complete removal
Exceptions to Deletion
- β’ Legal hold for ongoing disputes
- β’ Regulatory investigation requirements
- β’ Active contract performance needs
- β’ Anonymized data for analytics
Third-Party Sharing & Data Protection Officer
We never sell your personal data. Limited sharing occurs only with trusted service providers under strict contractual obligations for data protection.
When We Share Data
- Hosting Providers: Secure data storage and website hosting services
- Payment Processors: Secure transaction processing and invoicing
- Analytics Services: Website performance and user experience insights
- Professional Services: Legal, accounting, and business consultancy
- Legal Authorities: When required by law or to protect rights
Data Protection Safeguards
- Data Processing Agreements: All third parties sign comprehensive DPAs
- UK/EU Based Providers: Priority given to UK and EU service providers
- Security Audits: Regular assessment of third-party security measures
- Minimal Data Sharing: Only necessary data shared for specific purposes
- Transfer Safeguards: Adequate protection for any international transfers
Contact Information
Data Protection Officer
Name: Jack Warner (WebDev Wales)
Email: info@webdevwales.com
Phone: +44 07916 214843
Response Time: Within 48 hours for urgent matters
Supervisory Authority
Authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Right: Lodge complaints about data processing