GDPR
If we build something that holds your customers' data, you stay responsible for it and we work to your instructions. This page explains how that works in practice.
Last updated 6 August 2026
Controller and processor, in plain terms
UK GDPR splits responsibility in two. The controller decides why personal data is collected and what happens to it. The processor acts on the controller’s instructions.
- When we build a shop, an app or an AI agent for you, your business is the controller. It is your customer list, and the decisions about it are yours.
- We are the processor. We handle that data only to build, run and support what you have asked us to build.
- We never use your customers' data for our own purposes. Not to market to them, not to train models, not to build anything for another client.
Data processing agreement
UK GDPR requires a written contract between controller and processor. We will sign a data processing agreement covering the subject matter, duration, nature and purpose of the processing, the categories of data involved, and our obligations under Article 28. Ask and we will send it before work starts rather than after.
Subprocessors
Delivering the work means relying on infrastructure providers. These are the ones that may process personal data on your behalf, and each is bound by terms at least as protective as ours.
| Subprocessor | Role | Location |
|---|---|---|
| Netlify | Hosting for this website | United States, under UK and EU transfer safeguards |
| Cloudflare | Content delivery, DNS and protection against attacks | Global network, under UK and EU transfer safeguards |
| Business email and, where a client asks for it, Analytics | United States, under UK and EU transfer safeguards | |
| Stripe | Card payments on shops we build, where that applies | United States and Ireland, under UK and EU transfer safeguards |
| Anthropic | The Claude models behind AI features we build | United States, under UK and EU transfer safeguards |
Which of these actually apply depends on what we build for you. A brochure site touches far fewer than a shop with accounts and payments. We will tell you which are in play for your project, and we will tell you before adding a new one.
AI and your data
Where a project uses AI, we build on Claude, from Anthropic. Two points matter for compliance, and we would rather state them plainly than leave you to check.
- Data you or your customers put into an AI feature we build is not used to train the underlying model.
- We design these features to send the model only what it needs to answer, rather than piping your whole database through it.
- Anything the model is uncertain about is escalated to a person rather than guessed at, which matters when a wrong answer would affect someone's rights.
Security
Article 32 requires measures appropriate to the risk. In practice that means:
- Encryption in transit as standard, and at rest where the platform supports it.
- Access limited to the people who need it, removed when a project ends.
- Separate credentials per environment, with secrets kept out of source control.
- Dependencies monitored for known vulnerabilities and patched rather than left.
- Backups for systems we run, tested rather than assumed.
When one of your customers exercises their rights
Requests for access, correction or deletion come to you as controller, not to us. Where the data sits in something we built, we will help you find it, export it or delete it within your response deadline. If a request reaches us directly, we will forward it to you rather than answer it ourselves.
If something goes wrong
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and with what we know at that point, so you can meet your own 72-hour deadline to the ICO. We will not sit on it while we work out how it reads.
When the work ends
At handover, everything transfers to you: the code, the hosting, the database, the accounts. Once the transfer is confirmed and no legal obligation requires us to keep a copy, we delete what remains on our side. You own it, so you should hold it.
Our details
- Trading as WebCurry
- Studio: Design Studio, 52 Walsworth Road, Hitchin, Hertfordshire SG4 9SX
- Data protection contact: [email protected]