Privacy policy
Last updated: 3 October 2026
This policy explains how WE-DEV LTD (“WE-DEV”, “we”, “us”) collects and uses personal data when you visit we-dev.uk, contact us, buy a package or book hours, or work with us as a client. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
Who we are
WE-DEV LTD is the controller of the personal data described in this policy.
- Registered in England and Wales, company number 15878974
- Address: 17 Orient Close, St Albans, Hertfordshire AL1 1AJ, United Kingdom
- Email: info@we-dev.uk
- Phone: +44 (0)1727 309243
We are a small company and have not appointed a Data Protection Officer, because the law does not require us to. Questions about this policy or your data go to our founder, Danilo Fiorillo, at info@we-dev.uk.
When we build or maintain a website or app for a client and handle personal data on that client’s behalf (for example, the enquiries or orders their customers submit), the client is the controller and we act as their processor under a written agreement. This policy does not cover that processing; please read the client’s own privacy notice.
The personal data we collect
Information you give us
- Enquiries: your name, email address, phone number, company name and the details of your message when you use our contact form, email or call us.
- Bookings and orders: when you book hours or buy a package, your name, email address, phone number, billing address, whether you are buying as an individual or a business, company name and VAT number (if applicable), the service and hours chosen and any project details you provide.
- Client projects: contact details of the people we work with, meeting notes, project correspondence, and the access details you share so we can work on your website or systems.
- Account details: if we create a login for you on our site, your username, email address and password (stored in hashed form).
Information collected automatically
- Technical and security data: IP address, browser and device type, pages requested and the date and time of each request. Our security and network services (Cloudflare and Wordfence) process this to keep the site available and protect it from attacks.
- Analytics data: only if you accept analytics cookies, Google Analytics 4 collects information about how you use the site, such as pages viewed, approximate location (country or city), device type and how you arrived. See our cookie policy.
Payment data
Card payments are handled by Stripe. Your card details are entered into Stripe’s secure fields and go directly to Stripe. We never see or store your full card number. We receive a payment reference, the amount, the payment status and the last four digits and brand of your card.
We do not knowingly collect special category data (such as health information), and we ask you not to send it to us. Our services are aimed at businesses and adults; we do not knowingly collect data from children under 13.
How we use your data and our lawful bases
| Purpose | Data | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Replying to your enquiry and preparing a quote | Enquiry details | Legitimate interests (responding to people who contact us); or steps at your request before entering a contract |
| Taking bookings and payments, delivering the work, invoicing | Booking, order, payment and project data | Contract |
| Keeping accounting and tax records | Order, invoice and payment records | Legal obligation |
| Keeping the website secure and preventing fraud | Technical and security data, payment data | Legitimate interests (protecting our site, our clients and our business) |
| Measuring how the website is used | Analytics data | Consent |
| Sending occasional news about our services to clients and enquirers | Name, email address | Legitimate interests under the PECR “soft opt-in” for existing customers, with an opt-out in every email; otherwise consent |
| Handling complaints, disputes and legal claims | Relevant records | Legitimate interests (establishing and defending legal claims) |
Where we rely on legitimate interests, we have balanced our interests against yours. You can ask us for details of that assessment. Where we rely on consent, you can withdraw it at any time.
We do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.
Who we share data with
We use carefully chosen service providers (“processors”) who process personal data only on our instructions and under contracts that require them to keep it secure:
| Provider | What they do | Where data may be processed |
|---|---|---|
| Our web hosting provider | Hosts the website, its database and backups | United Kingdom or European Economic Area |
| Stripe | Processes card payments and helps prevent fraud | UK, EEA and United States |
| Mailjet (via WP Mail SMTP) | Sends emails from the website, such as booking confirmations and enquiry notifications | European Union |
| Cloudflare | Content delivery, DNS and protection against attacks and bots | Global network, including the United States |
| Wordfence (Defiant Inc.) | Website firewall and security scanning | United States |
| Google (Analytics 4 via Site Kit) | Website analytics, only with your consent | United States and other countries |
Stripe also acts as a separate controller for some purposes, such as fraud prevention and meeting its own legal obligations; see Stripe’s privacy policy. We may also share data with our accountant and professional advisers, with HM Revenue and Customs and other authorities where the law requires it, and with a buyer or successor if our business is ever sold or restructured.
International transfers
Some providers process data outside the UK. When they do, we rely on the safeguards UK law allows: UK adequacy regulations (for example, for the EU and EEA), the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or the International Data Transfer Addendum to the EU standard contractual clauses. You can ask us for more information about the safeguard used for a particular provider.
How long we keep data
- Enquiries that do not lead to work: up to 24 months after our last contact, then deleted.
- Client, booking, order and invoice records: six years after the end of the financial year in which the work ended, as required for accounting and tax purposes.
- Project files and access details: credentials you share are deleted or rotated when the work ends; project files are kept for as long as you remain a client and then for up to six years so we can support you and deal with any claims.
- Analytics data: Google Analytics retains event-level data for 14 months.
- Security logs: kept for a short period, normally no longer than 90 days, unless needed to investigate an incident.
- Marketing: until you unsubscribe, after which we keep your email address on a suppression list so we do not contact you again.
How we protect your data
The site is served over HTTPS and protected by Cloudflare and a web application firewall. Admin accounts use strong passwords and two-factor authentication, access is limited to people who need it, and backups are encrypted. No system is completely secure, but if a breach occurs that is likely to put your rights at risk, we will notify the Information Commissioner’s Office (ICO) and, where required, you.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you (subject access);
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data;
- ask us to restrict how we use your data;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- receive data you gave us in a portable format, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, where we rely on consent.
To use any of these rights, email info@we-dev.uk or write to us at the address above. We may need to confirm your identity. We will reply within one month, which can be extended by up to two further months for complex requests; we will tell you if that happens. There is normally no charge.
Complaints
If you are unhappy with how we have handled your data, please contact us first at info@we-dev.uk so we can try to put it right. We will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection: ico.org.uk, telephone 0303 123 1113, or Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Cookies
We use strictly necessary cookies to run the site, take payments and keep it secure, and we use analytics cookies only if you agree. Full details, and how to change your choice, are in our cookie policy.
Links to other websites
Our site links to other websites, including our clients’ sites. We are not responsible for their privacy practices, so please read their policies.
Changes to this policy
We may update this policy when our services, providers or the law change. The date at the top shows when it was last updated. If we make significant changes that affect how we use data you have already given us, we will tell you directly where we can.
See also our terms of business and refund policy.