Legal · Document 02 of 02
Privacy Policy
What we collect, why we are allowed to, who else sees it, and how to get it back or have it deleted. This policy covers every WebDeviAnt Studios product.
The short version. A guide, not the policy. Where the two differ, the clauses below win.
We collect the minimum we need to run an account, take a payment and keep the service up. We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content to train models. Our products are separate services and we do not join your data up between them. Our sites use no analytics or advertising cookies at all. Where a product is end-to-end encrypted, we cannot read what passes through it even if we wanted to. You can ask for a copy of your data, or its deletion, at any time.
01 Who is responsible for your data
Antony Bentinck, trading as WebDeviAnt Studios, a sole trader established in England with a trading address in Godalming, Surrey, United Kingdom, is the data controller for the personal data described in clause 4 — except where clause 3 says we are acting as a processor instead.
For anything about this policy, or to exercise a right under clause 12, email [email protected]. Our postal address is available on request.
We are not required to appoint a Data Protection Officer, and have not. Data protection questions are handled by the owner of the business, personally.
02 What this policy covers
This policy covers webdeviant.io and every WebDeviAnt Studios product, currently WireHQ, NitroSearch and Drop2p. Where a product processes data in a way this policy does not describe, that product publishes its own notice and it takes precedence for that product.
One policy does not mean one pool of data. The products are separate services that do not interoperate. We do not combine what we hold about you in one product with what we hold about you in another, we do not build a profile across them, and holding an account in one tells the others nothing. The reason a single policy covers all of them is that WebDeviAnt Studios is the controller for each — the same company, not the same system.
It does not cover third-party services you choose to connect to ours — your identity provider, your store platform, your payment provider — each of which has its own policy.
It sits alongside our Master Terms & Conditions, which govern the contract itself.
03 Controller or processor
The distinction matters, because it decides who you should ask about what.
If you contact us about data we hold as a processor, we will tell you promptly and point you at the controller, rather than acting on it ourselves.
04 What we collect
What end-to-end encryption means here. Where a product encrypts content end to end, we hold ciphertext and nothing else. We cannot read it, produce it in response to a request, or restore it if you lose the key — not as a policy choice, but because the design does not allow it.
05 Why we use it, and our lawful basis
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms. You can object at any time — see clause 12 — and we will stop unless we have compelling grounds not to.
We do not make decisions about you by automated means alone that produce legal or similarly significant effects. Automated rate limiting and abuse blocking may temporarily restrict a request; a human will review it if you ask.
06 What we never do
These are commitments, not aspirations. If any of them ever changes, it will be announced under clause 15 before it happens, not discovered afterwards.
- We do not sell personal data. Not to advertisers, not to data brokers, not to anyone.
- We do not use your content to train machine-learning models.
- We do not run advertising or analytics trackers, or share data with an ad network.
- We do not build profiles of you across sites, and we do not participate in cross-site tracking schemes.
- We do not join up your data between our own products. Each is a separate service with a separate account; being a customer of one does not make you a record in another.
- We do not require a third-party account to use our products.
07 Cookies and similar technologies
This website sets no cookies at all. It runs no analytics, loads no fonts or scripts from a third party, and has nothing to consent to — which is why you were not shown a banner.
In the products, we use only what is strictly necessary: a session or authentication cookie or token to keep you signed in, and where relevant a security token to protect a form from cross-site abuse. These are exempt from the consent requirement in the Privacy and Electronic Communications Regulations because the service you asked for cannot work without them.
Local storage. A product may store settings in your browser — a theme preference, an in-progress transfer — on your own device. Clearing your browser data removes it.
If we ever introduce a non-essential cookie, we will ask for your consent first and give you a way to withdraw it.
08 Who else sees your data
We keep the list of third parties deliberately short. Each is bound by a contract that permits it to act only on our instructions, and none of them may use your data for their own purposes.
We may also disclose personal data where we are legally required to, where it is necessary to establish or defend a legal claim, or to protect the rights and safety of our customers or the public. We will tell you about a request unless we are prohibited from doing so.
If the business is ever sold or transferred, personal data may transfer with it. Any buyer would be bound by this policy until you were told otherwise.
A current, itemised list of sub-processors is available on request from [email protected], and business customers can ask to be notified of changes.
09 Where your data is held
We host in the United Kingdom and the European Economic Area, and design our products to keep data there. Each product’s documentation states its data residency; where a product advertises EU hosting, that is where its indexes and operational data live.
Where a supplier processes data outside the UK or EEA — a payment provider is the usual case — we rely on an approved safeguard: an adequacy decision, or the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with any additional measures the transfer requires. You can ask us which applies to a given supplier.
10 How long we keep it
We keep personal data only for as long as we need it, then delete it.
11 How we protect it
- Encryption in transit everywhere, and encryption of secrets and credentials at rest.
- Passwords stored only as salted hashes — we cannot read yours, and would never ask for it.
- Multi-factor authentication available to you, and required for our own administrative access.
- Least-privilege access: only the people who need it, only for as long as they need it.
- Tenant isolation, logging and regular patching of the systems we run.
- Backups where a product needs them, and none where a product is designed to hold nothing.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you directly without undue delay where the risk to you is high.
If you think you have found a vulnerability, please tell us at [email protected] before disclosing it publicly. Clause 18 of the Master Terms sets out how we respond.
12 Your rights
Under the UK GDPR you have the right to:
- Be informed — which is what this document is for.
- Access a copy of the personal data we hold about you.
- Rectification of anything inaccurate or incomplete.
- Erasure of your data, where we have no overriding reason to keep it — a legal retention obligation being the usual one.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Data portability — a machine-readable copy of data you gave us that we process by consent or under a contract.
- Object to processing based on legitimate interests, and to direct marketing at any time and without exception.
- Withdraw consent at any time where consent is the basis we rely on, without affecting anything done beforehand.
Email [email protected]. We will respond within one month, and will tell you if we need longer because a request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity first — not to obstruct you, but because handing someone else’s data to the wrong person is itself a breach.
If your request concerns data we hold as a processor for a business customer, see clause 3: we will forward it and tell you who to ask.
13 Marketing
We will only send marketing email if you asked for it, or if you are an existing customer and it is about something closely related to what you already have. Every marketing email carries an unsubscribe link that works immediately and permanently.
Service messages under clause 5 are not marketing and continue while you hold an account. We do not sell or rent our mailing list.
14 Children
Our products are business and productivity tools and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
15 Changes to this policy
The current version always lives at webdeviant.io/studios/privacy/, with its version number and effective date at the top.
If we make a change that materially affects how we handle your personal data, we will email account holders at least 30 days before it takes effect. Minor corrections and clarifications take effect when published.
16 Contact us, or complain
Email [email protected]. A person reads it, and we would much rather fix something than have it escalated.
If we cannot resolve it, you have the right to complain to the UK supervisory authority:
If you are in the EEA, you may instead complain to the supervisory authority where you live or work.