Skip to content
§ Legal

GDPR

If we build something that holds your customers' data, you stay responsible for it and we work to your instructions. This page explains how that works in practice.

Last updated 6 August 2026

This page is about data belonging to your customers, handled by systems we build for you. For data we hold about you directly, read the Privacy Policy.

Controller and processor, in plain terms

UK GDPR splits responsibility in two. The controller decides why personal data is collected and what happens to it. The processor acts on the controller’s instructions.

  • When we build a shop, an app or an AI agent for you, your business is the controller. It is your customer list, and the decisions about it are yours.
  • We are the processor. We handle that data only to build, run and support what you have asked us to build.
  • We never use your customers' data for our own purposes. Not to market to them, not to train models, not to build anything for another client.

Data processing agreement

UK GDPR requires a written contract between controller and processor. We will sign a data processing agreement covering the subject matter, duration, nature and purpose of the processing, the categories of data involved, and our obligations under Article 28. Ask and we will send it before work starts rather than after.

Subprocessors

Delivering the work means relying on infrastructure providers. These are the ones that may process personal data on your behalf, and each is bound by terms at least as protective as ours.

SubprocessorRoleLocation
NetlifyHosting for this websiteUnited States, under UK and EU transfer safeguards
CloudflareContent delivery, DNS and protection against attacksGlobal network, under UK and EU transfer safeguards
GoogleBusiness email and, where a client asks for it, AnalyticsUnited States, under UK and EU transfer safeguards
StripeCard payments on shops we build, where that appliesUnited States and Ireland, under UK and EU transfer safeguards
AnthropicThe Claude models behind AI features we buildUnited States, under UK and EU transfer safeguards

Which of these actually apply depends on what we build for you. A brochure site touches far fewer than a shop with accounts and payments. We will tell you which are in play for your project, and we will tell you before adding a new one.

AI and your data

Where a project uses AI, we build on Claude, from Anthropic. Two points matter for compliance, and we would rather state them plainly than leave you to check.

  • Data you or your customers put into an AI feature we build is not used to train the underlying model.
  • We design these features to send the model only what it needs to answer, rather than piping your whole database through it.
  • Anything the model is uncertain about is escalated to a person rather than guessed at, which matters when a wrong answer would affect someone's rights.

Security

Article 32 requires measures appropriate to the risk. In practice that means:

  • Encryption in transit as standard, and at rest where the platform supports it.
  • Access limited to the people who need it, removed when a project ends.
  • Separate credentials per environment, with secrets kept out of source control.
  • Dependencies monitored for known vulnerabilities and patched rather than left.
  • Backups for systems we run, tested rather than assumed.

When one of your customers exercises their rights

Requests for access, correction or deletion come to you as controller, not to us. Where the data sits in something we built, we will help you find it, export it or delete it within your response deadline. If a request reaches us directly, we will forward it to you rather than answer it ourselves.

If something goes wrong

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and with what we know at that point, so you can meet your own 72-hour deadline to the ICO. We will not sit on it while we work out how it reads.

When the work ends

At handover, everything transfers to you: the code, the hosting, the database, the accounts. Once the transfer is confirmed and no legal obligation requires us to keep a copy, we delete what remains on our side. You own it, so you should hold it.

Our details

  • Trading as WebCurry
  • Studio: Design Studio, 52 Walsworth Road, Hitchin, Hertfordshire SG4 9SX
  • Data protection contact: [email protected]