This policy explains what personal data DataVolve collects when you use datavolve.co or contact us, why we collect it, who we share it with and what rights you have. It is written for visitors and prospective clients in the United Kingdom and elsewhere.

1. Who we are

DataVolve is a trading name. For the purposes of UK data protection law, DataVolve is the controller of the personal data described here. You can contact us about anything in this policy at sales@datavolve.co.

2. What we collect

SourceData
Contact formName, e-mail address, phone number, the service you are interested in, budget range and your project description
E-mail and WhatsAppYour name, contact details and whatever you choose to tell us in your message
Discovery call bookingName, e-mail address, chosen time and any notes you add when booking
Website analyticsPages visited, referring site, approximate location, device and browser information, collected through cookies (see section 6)
Hosting logsIP address and request details, kept by our hosting provider for security and operation

We do not ask for special category data (such as health information) through the website. Please do not send confidential client or case information in an initial enquiry.

3. Why we use it and our lawful basis

  • To reply to your enquiry and prepare a proposal. Lawful basis: taking steps at your request before entering into a contract, and our legitimate interest in responding to business enquiries.
  • To deliver and manage a project if you become a client. Lawful basis: performance of a contract.
  • To understand how the website is used and improve it. Lawful basis: our legitimate interests (see section 6 on cookies).
  • To keep the website secure and meet legal obligations. Lawful basis: legitimate interests and legal obligation.

We do not sell your personal data, and we do not use it for automated decisions that have legal or similarly significant effects on you.

4. Who we share it with

We use a small number of service providers who process data on our behalf:

  • Web3Forms: delivers contact form submissions to our inbox
  • Our e-mail provider: stores the enquiries and e-mails we receive
  • WhatsApp (Meta): if you choose to message us on WhatsApp
  • Calendly: discovery call scheduling
  • Google Analytics: website usage statistics
  • GitHub Pages: website hosting

We may also share data where the law requires it, or with professional advisers under a duty of confidentiality.

5. International transfers

Some of these providers, and members of our team, are located outside the UK, including in the United States and Pakistan. Where personal data is transferred outside the UK, we rely on a UK adequacy decision where one exists, or on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Contact us for more information about the safeguards used.

6. Cookies and analytics

The website uses Google Analytics, which sets cookies (such as _ga) to distinguish visitors and measure how pages are used. You can block or delete these cookies in your browser settings, or install Google’s Analytics opt-out browser add-on. The website does not use advertising cookies.

7. How long we keep it

  • Enquiries that do not become projects: up to 24 months, then deleted.
  • Client and project records: for the length of the engagement and up to 6 years after it ends, for legal and accounting purposes.
  • Analytics data: according to the retention setting in Google Analytics, a maximum of 14 months.

8. Your rights

Under UK GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. To exercise any of these rights, e-mail sales@datavolve.co. We will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

9. Security

We take appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS) across the website and restricted access to enquiry inboxes.

10. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed.