Privacy Policy

Public version: 2.2
Effective date: 6 Sep 2026
Next review: 6 Sep 2027
Owner: Chief Executive / Privacy Lead

1. About this notice

This notice explains how SpotDev Services Ltd uses personal data when operating our website, marketing our services, responding to enquiries, managing business relationships and recruiting people.

SpotDev Services Ltd is the controller of the personal data described here. We are registered in England and Wales under company number 14296175. Our registered office is Office 11, 3 Edgar Buildings, Bath BA1 2FJ. Contact our Privacy Lead at hello@spotdev.co.uk, or write to our registered office.

When we process personal data on a client's instructions to deliver services, the client's privacy information applies to that processing. Our obligations as processor or sub-processor are set out in the applicable agreement and Data Processing Agreement. We separately act as controller for our own relationship, billing, security and business administration records.

2. Information we collect and its sources

We may collect:

  • Contact and business details, including name, business email address, telephone number, job title, employer and enquiry information.
  • Correspondence, meeting notes and recordings or transcripts of calls and meetings.
  • Website and marketing information, including pages viewed, referral source, approximate location derived from IP address, browser/device details and email engagement.
  • Contract, invoicing, payment and service-administration records.
  • Recruitment information, including applications, CVs and interview notes.

We obtain information directly from you, from your device when you use our website, from people in your organisation and from public or professional sources used for business research, including company websites, Companies House and professional networking platforms such as LinkedIn.

We do not seek special-category personal data. Please do not provide it unless we have agreed a necessary, lawful purpose and suitable handling arrangements. Unexpected sensitive information is assessed and deleted or restricted where it is not required.

You can browse without submitting an enquiry. If you do not provide contact or other information necessary for a requested service, application or legal obligation, we may be unable to respond, provide that service or progress your application. Marketing consent is not a condition of buying our services.

3. Purposes and lawful bases

PurposeLawful basis
Responding to enquiries and preparing proposalsSteps requested before a contract where you are the prospective contracting party; otherwise our legitimate interests in responding to business enquiries
Delivering services and administering relationshipsPerformance of a contract with you; otherwise our legitimate interests in managing a contract with your organisation
Business marketing and relevant outreachLegitimate interests in promoting our services; consent where required for the communication
Non-essential website analytics and advertising technologiesConsent
Recording and transcribing calls or meetingsLegitimate interests in keeping accurate records and improving service
Security, fraud prevention and protecting legal rightsLegitimate interests in protecting our business, clients and information; legal obligation where applicable
Accounting, tax and statutory recordsLegal obligation
RecruitmentSteps requested before a contract and legitimate interests in assessing suitability

Where we rely on legitimate interests, we assess the purpose, necessity and effect on your rights. You can ask for information about the assessment relevant to your data.

You can object to direct marketing at any time. We will stop using your personal data for that purpose. Use the unsubscribe link in a message or email our Privacy Lead.

4. Cookies and similar technologies

We use necessary cookies to operate the website. Non-essential analytics and advertising technologies require consent through our cookie controls. You can change or withdraw your choice using the site's cookie settings.

These technologies may include HubSpot website/marketing analytics and Microsoft Clarity behavioural analytics. The cookie controls should identify the relevant technologies and purposes. Rejecting non-essential cookies does not prevent you from contacting us or purchasing our services.

5. Calls, meetings and AI assistance

We record incoming calls and record or transcribe online meetings for accuracy, training and a record of discussions. We tell participants when recording is taking place. You can ask not to be recorded or request deletion, subject to an applicable legal or evidential reason for retention.

We use approved AI tools for activities such as drafting, summarising and research, with access and data limited to the authorised purpose and human review of outputs. We do not use personal data to train or fine-tune shared or general-purpose models. We do not make decisions producing legal or similarly significant effects about you solely through automated processing. Any material change to that position would require appropriate assessment and updated privacy information before use.

6. Recipients

We use providers for CRM and marketing, website services, email and document storage, project delivery, telephony, meeting recording and transcription, finance and payments, integration and automation, data quality, application services and AI-assisted processing.

Providers receive only information appropriate to their role. Where they act as our processors, their processing is governed by instructions and contractual safeguards. Some recipients, such as professional advisers, financial institutions and regulators, may act as independent controllers for their own responsibilities.

We may disclose information where required by law, to protect legal rights, or in connection with a business sale or reorganisation subject to appropriate safeguards. We do not sell personal data. Contact our Privacy Lead for information about recipients relevant to your data. Client-specific processor arrangements are governed separately by the applicable DPA and service records.

7. International processing

Our people and providers may access or process information outside the United Kingdom. Our working arrangements include the United Kingdom, South Africa and the European Economic Area, including Romania and Italy. Some service providers process information in the United States or other locations identified for their service.

The applicable protection depends on the recipient, location and data flow. We use applicable adequacy arrangements or, where required, appropriate contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, with the required assessment and supplementary measures. Reliance on a provider's certification is limited to the entity, service and data covered by it.

There is no universal hosting location for every engagement. Client-procured systems and service-specific processing arrangements are recorded in the relevant agreement and service documentation. Ask our Privacy Lead for the applicable locations and a copy or explanation of the relevant safeguards.

8. Retention and security

We retain information for its purpose and applicable legal, contractual or evidential requirements, then delete or anonymise it. Our criteria include:

RecordRetention criteria
Enquiries and proposalsWhether the enquiry remains active, there is a realistic business follow-up need, or a dispute requires preservation
Client and supplier relationship recordsThe engagement and the period needed for legal obligations, contractual matters or potential claims
Accounting and tax recordsApplicable statutory requirements
Marketing recordsContinued relevance, engagement and permission or other lawful basis; objections end marketing use
Calls and transcriptsThe continuing need for an accurate enquiry/engagement record, with unnecessary copies removed and legal holds respected
Recruitment recordsThe recruitment process and the period justified for related queries or claims; any longer talent-pool use needs a separately explained basis
Objection and suppression recordsThe minimum information needed to honour an objection or unsubscribe for as long as that protection is needed
Security recordsThe period justified by security, incident, contractual and legal requirements, with restricted access

Protected backups may expire through their normal lifecycle. Information subject to a legal hold is retained securely until the hold ends. You can ask for the criteria or period relevant to a particular record.

We use proportionate organisational and technical measures, including access control, managed-device protection, encryption and supplier governance. No system can guarantee that a security incident will never occur.

9. Your rights and complaints

Depending on the processing and applicable law, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it without affecting earlier lawful processing.

Contact hello@spotdev.co.uk. We may need proportionate information to verify your identity. We normally respond to rights requests within one month. Where a permitted extension is necessary, we explain it within the initial period. We explain any lawful restriction or refusal and your options to challenge it.

You may complain to us without using a particular form. We acknowledge complaints within 30 days and investigate and communicate the outcome without undue delay. You may also complain to the Information Commissioner's Office, whether or not you complain to us first.

10. Children, other websites and changes

Our website and services are directed at businesses, not children. If you believe we have received a child's personal data unexpectedly, contact our Privacy Lead so we can assess and address it.

Other websites have their own privacy notices. We review this notice annually and after material processing changes, update its version and effective date, and communicate significant changes directly where appropriate.