Privacy Policy
Public version: 2.2
Effective date: 6 Sep 2026
Next review: 6 Sep 2027
Owner: Chief Executive / Privacy Lead
1. About this notice
This notice explains how SpotDev Services Ltd uses personal data when operating our website, marketing our services, responding to enquiries, managing business relationships and recruiting people.
SpotDev Services Ltd is the controller of the personal data described here. We are registered in England and Wales under company number 14296175. Our registered office is Office 11, 3 Edgar Buildings, Bath BA1 2FJ. Contact our Privacy Lead at hello@spotdev.co.uk, or write to our registered office.
When we process personal data on a client's instructions to deliver services, the client's privacy information applies to that processing. Our obligations as processor or sub-processor are set out in the applicable agreement and Data Processing Agreement. We separately act as controller for our own relationship, billing, security and business administration records.
2. Information we collect and its sources
We may collect:
- Contact and business details, including name, business email address, telephone number, job title, employer and enquiry information.
- Correspondence, meeting notes and recordings or transcripts of calls and meetings.
- Website and marketing information, including pages viewed, referral source, approximate location derived from IP address, browser/device details and email engagement.
- Contract, invoicing, payment and service-administration records.
- Recruitment information, including applications, CVs and interview notes.
We obtain information directly from you, from your device when you use our website, from people in your organisation and from public or professional sources used for business research, including company websites, Companies House and professional networking platforms such as LinkedIn.
We do not seek special-category personal data. Please do not provide it unless we have agreed a necessary, lawful purpose and suitable handling arrangements. Unexpected sensitive information is assessed and deleted or restricted where it is not required.
You can browse without submitting an enquiry. If you do not provide contact or other information necessary for a requested service, application or legal obligation, we may be unable to respond, provide that service or progress your application. Marketing consent is not a condition of buying our services.
3. Purposes and lawful bases
| Purpose | Lawful basis |
| Responding to enquiries and preparing proposals | Steps requested before a contract where you are the prospective contracting party; otherwise our legitimate interests in responding to business enquiries |
| Delivering services and administering relationships | Performance of a contract with you; otherwise our legitimate interests in managing a contract with your organisation |
| Business marketing and relevant outreach | Legitimate interests in promoting our services; consent where required for the communication |
| Non-essential website analytics and advertising technologies | Consent |
| Recording and transcribing calls or meetings | Legitimate interests in keeping accurate records and improving service |
| Security, fraud prevention and protecting legal rights | Legitimate interests in protecting our business, clients and information; legal obligation where applicable |
| Accounting, tax and statutory records | Legal obligation |
| Recruitment | Steps requested before a contract and legitimate interests in assessing suitability |
Where we rely on legitimate interests, we assess the purpose, necessity and effect on your rights. You can ask for information about the assessment relevant to your data.
You can object to direct marketing at any time. We will stop using your personal data for that purpose. Use the unsubscribe link in a message or email our Privacy Lead.
4. Cookies and similar technologies
We use necessary cookies to operate the website. Non-essential analytics and advertising technologies require consent through our cookie controls. You can change or withdraw your choice using the site's cookie settings.
These technologies may include HubSpot website/marketing analytics and Microsoft Clarity behavioural analytics. The cookie controls should identify the relevant technologies and purposes. Rejecting non-essential cookies does not prevent you from contacting us or purchasing our services.
5. Calls, meetings and AI assistance
We record incoming calls and record or transcribe online meetings for accuracy, training and a record of discussions. We tell participants when recording is taking place. You can ask not to be recorded or request deletion, subject to an applicable legal or evidential reason for retention.
We use approved AI tools for activities such as drafting, summarising and research, with access and data limited to the authorised purpose and human review of outputs. We do not use personal data to train or fine-tune shared or general-purpose models. We do not make decisions producing legal or similarly significant effects about you solely through automated processing. Any material change to that position would require appropriate assessment and updated privacy information before use.
6. Recipients
We use providers for CRM and marketing, website services, email and document storage, project delivery, telephony, meeting recording and transcription, finance and payments, integration and automation, data quality, application services and AI-assisted processing.
Providers receive only information appropriate to their role. Where they act as our processors, their processing is governed by instructions and contractual safeguards. Some recipients, such as professional advisers, financial institutions and regulators, may act as independent controllers for their own responsibilities.
We may disclose information where required by law, to protect legal rights, or in connection with a business sale or reorganisation subject to appropriate safeguards. We do not sell personal data. Contact our Privacy Lead for information about recipients relevant to your data. Client-specific processor arrangements are governed separately by the applicable DPA and service records.
7. International processing
Our people and providers may access or process information outside the United Kingdom. Our working arrangements include the United Kingdom, South Africa and the European Economic Area, including Romania and Italy. Some service providers process information in the United States or other locations identified for their service.
The applicable protection depends on the recipient, location and data flow. We use applicable adequacy arrangements or, where required, appropriate contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, with the required assessment and supplementary measures. Reliance on a provider's certification is limited to the entity, service and data covered by it.
There is no universal hosting location for every engagement. Client-procured systems and service-specific processing arrangements are recorded in the relevant agreement and service documentation. Ask our Privacy Lead for the applicable locations and a copy or explanation of the relevant safeguards.
8. Retention and security
We retain information for its purpose and applicable legal, contractual or evidential requirements, then delete or anonymise it. Our criteria include:
| Record | Retention criteria |
| Enquiries and proposals | Whether the enquiry remains active, there is a realistic business follow-up need, or a dispute requires preservation |
| Client and supplier relationship records | The engagement and the period needed for legal obligations, contractual matters or potential claims |
| Accounting and tax records | Applicable statutory requirements |
| Marketing records | Continued relevance, engagement and permission or other lawful basis; objections end marketing use |
| Calls and transcripts | The continuing need for an accurate enquiry/engagement record, with unnecessary copies removed and legal holds respected |
| Recruitment records | The recruitment process and the period justified for related queries or claims; any longer talent-pool use needs a separately explained basis |
| Objection and suppression records | The minimum information needed to honour an objection or unsubscribe for as long as that protection is needed |
| Security records | The period justified by security, incident, contractual and legal requirements, with restricted access |
Protected backups may expire through their normal lifecycle. Information subject to a legal hold is retained securely until the hold ends. You can ask for the criteria or period relevant to a particular record.
We use proportionate organisational and technical measures, including access control, managed-device protection, encryption and supplier governance. No system can guarantee that a security incident will never occur.
9. Your rights and complaints
Depending on the processing and applicable law, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it without affecting earlier lawful processing.
Contact hello@spotdev.co.uk. We may need proportionate information to verify your identity. We normally respond to rights requests within one month. Where a permitted extension is necessary, we explain it within the initial period. We explain any lawful restriction or refusal and your options to challenge it.
You may complain to us without using a particular form. We acknowledge complaints within 30 days and investigate and communicate the outcome without undue delay. You may also complain to the Information Commissioner's Office, whether or not you complain to us first.
10. Children, other websites and changes
Our website and services are directed at businesses, not children. If you believe we have received a child's personal data unexpectedly, contact our Privacy Lead so we can assess and address it.
Other websites have their own privacy notices. We review this notice annually and after material processing changes, update its version and effective date, and communicate significant changes directly where appropriate.