Privacy Notice
Last updated: August 2026
1. Who We Are and Data Controller
Web Technology Codes (“we”, “us”, or “our”) provides bespoke software engineering, e-commerce development, SaaS product engineering, AI solutions, and cloud architecture services to organisations across the United Kingdom and internationally.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), Web Technology Codes acts as the Data Controller in respect of personal data collected through this website (https://www.webtechnologycodes.com) and direct communications.
If you have any questions about this Privacy Notice or how we handle your personal data, you can reach our privacy team at:
- Email: hello@webtechnologycodes.com
- UK Office: 23 Longmoors, Bracknell, RG42 1SH, United Kingdom
- Engineering & Delivery Centre: Gurugram, Haryana 122003, India
2. What Personal Data We Collect
We collect and process personal data that you voluntarily provide to us, as well as technical data collected automatically during your visit:
- Contact and Identification Data: Full name, business email address, company name, website URL, country, and phone number when you submit an enquiry, book a consultation, or communicate with us.
- Project and Technical Requirements: Information regarding your commercial goals, technology stack, software architecture, budget estimates, and expected timelines that you share in project briefs.
- Communications Data: Records of correspondence, emails, notes from discovery meetings, and messages submitted via WhatsApp or web forms.
- Technical & Usage Data: IP address, browser type and version, time zone setting, operating system, referral source, pages viewed, and page interaction metrics collected via strictly necessary and consented analytics cookies.
3. Lawful Bases for Processing
Under the UK GDPR, we only process your personal data where we have a valid lawful basis:
- Legitimate Interests: To respond to your project enquiries, evaluate commercial fit, arrange discovery consultations, provide technical proposals, protect against spam and security threats, and manage business-to-business relationships.
- Contractual Necessity: To take preparatory steps at your request prior to entering into a master services agreement, non-disclosure agreement (NDA), or statement of work, and to perform our obligations under an active contract.
- Consent: For non-essential analytics and performance cookies where you have explicitly opted in via our cookie consent banner. You can withdraw your consent at any time.
- Legal Obligation: Where necessary to comply with applicable statutory, accounting, tax, and regulatory requirements in the United Kingdom.
4. How We Use Your Data
We use your information exclusively for legitimate business purposes:
- To review your requirements and provide tailored technical guidance and commercial proposals.
- To execute non-disclosure agreements (NDAs) and protect confidential technical and business information.
- To manage delivery schedules, agile sprints, and project governance for client engagements.
- To monitor website security, prevent malicious activities, and maintain system integrity.
- To analyse aggregated website usage trends to improve user experience (subject to your cookie preferences).
5. Data Sharing and Third-Party Processors
We do not sell, rent, or trade personal data to third parties. We share data only with trusted service providers who process data on our behalf under strict confidentiality and data processing agreements:
- Hosting & Infrastructure Providers: AWS (Amazon Web Services) Lightsail for secure cloud server hosting and website delivery.
- Transactional Email Services: SendPorter for delivering enquiry notifications and transactional correspondence.
- Analytics Providers: Google Analytics (when consented) to collect anonymised aggregated traffic statistics.
- Legal & Professional Advisors: Accountants, legal counsel, and insurers where necessary for professional advice or regulatory compliance.
6. International Data Transfers
Web Technology Codes operates a hybrid delivery model with client consultation in the UK and an engineering delivery centre in Gurugram, India. Where personal data is transferred or accessed outside the UK or European Economic Area (EEA), we ensure appropriate safeguards are implemented in accordance with UK GDPR Chapter V, including:
- Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA).
- Robust organisational and technical measures including encrypted transmission (TLS/HTTPS), role-based access control, and endpoint security.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- General Enquiries: If an enquiry does not lead to a commercial engagement, contact records and project descriptions are securely deleted within 12 months.
- Client Contracts & Invoices: Retained for 6 years following completion of the engagement to comply with statutory UK tax and accounting laws (HMRC requirements).
- Analytics Data: Retained according to standard retention settings (up to 14 months) in an aggregated, non-personally identifiable format.
8. Data Security
We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or accidental destruction. These measures include TLS 1.3 encryption for data in transit, strict access controls, secure firewalled infrastructure, and regular security reviews.
9. Your Statutory Rights Under UK GDPR
As a data subject, you hold statutory rights regarding your personal information:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): You can request the deletion of your personal data where there is no overriding lawful reason for its continued processing.
- Right to Restrict Processing: You can request that we suspend processing your data in certain circumstances.
- Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format.
- Right to Object: You can object to our processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please email us at hello@webtechnologycodes.com. We respond to all verified requests within one calendar month, free of charge.
10. Regulatory Authority
If you have concerns about our data protection practices, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk | Helpline: 0303 123 1113