Skip to main content

Privacy Policy

Last updated 5 August 2026

1. Controller identity

Gdev is the trading name of George Angheluta, a sole trader established in England.

For information processed for Gdev's own business purposes, the controller is:

  • Controller: George Angheluta, trading as Gdev
  • Address: Gravesend DA12 2AW
  • Email: hello@gdev.agency

2. Scope

This notice explains how Gdev handles personal information concerning Website visitors, prospective clients, clients, former clients, client representatives, suppliers, professional contacts, meeting participants, complainants and people whose genuine testimonial or project information is published.

When Gdev processes personal information solely on a client's documented instructions, Gdev may act as a processor and the client may act as controller. That processing should be covered by the Client Service Agreement and its Data Processing Schedule.

3. Information collected

Depending on the interaction, Gdev may process:

Identity and contact information

Name, business name, job title, email, telephone number, business address, professional profile and communication preferences.

Enquiry and project information

Business information, website details, goals, requested services, budget, timelines, technical requirements, feedback, approvals and support information.

Contract and billing records

Proposals, signed agreements, statements of work, invoices, payment status, transaction references and accounting records. Gdev does not intend to store complete payment-card details.

Communications

Emails, form submissions, meeting notes, support correspondence, decisions, approvals and complaint records. Calls and meetings are not recorded unless disclosed in advance and lawfully justified.

Website and security information

IP address, approximate location derived from IP, browser/device type, requested pages, referral source, date/time, diagnostic information, security events, anti-bot results and server logs.

Appointment information

Name, email, selected date/time, time zone, meeting topic, calendar details and information entered in a booking form.

Platform access information

Work email, username, repository identifier, permission level, account identifier, domain-management access and records of access being granted or removed.

Marketing preferences

Consent, objections, unsubscribe requests and suppression records if marketing is introduced. A normal enquiry does not automatically subscribe the sender to marketing.

4. Sensitive information

Do not send special-category, criminal-record, identification, financial credential or other highly sensitive information through the general contact form.

If sensitive information is received unexpectedly, Gdev will assess whether it should be securely deleted, returned, restricted or retained for a lawful reason.

5. Sources

Information may be obtained directly from you, your employer or business, Website forms, email, telephone, meetings, contracts, invoices, client-owned platforms, referrals, public business websites, professional directories and relevant service providers.

6. Purposes and lawful bases

Enquiries and proposals

Used to respond, understand requirements, arrange meetings, prepare quotations and decide whether to accept work.

Lawful bases: steps requested before a contract and legitimate interests in responding to business enquiries.

Delivering services

Used to manage projects, communicate, design, develop, configure, obtain approvals, launch, support and hand over work.

Lawful bases: contract, pre-contract steps and legitimate interests in dealing with representatives of business clients.

Used to invoice, record payments, maintain tax/accounting records, recover debts and protect legal rights.

Lawful bases: contract, legal obligation and legitimate interests.

Website operation and security

Used to deliver the Website, prevent abuse, protect forms, diagnose errors, investigate incidents and enforce terms.

Lawful bases: legitimate interests, legal obligation and legal claims where applicable.

Analytics and improvement

Used to understand performance and general usage. Where storage/access technologies require consent, they are not activated before valid consent. Where a statutory exception applies, Gdev will provide the required information and objection mechanism.

Lawful bases: legitimate interests and, where required, consent.

Meetings

Used to arrange appointments, issue invitations, prevent conflicts and follow up.

Lawful bases: pre-contract steps, contract and legitimate interests.

Portfolio and testimonials

Used to demonstrate genuine work and feedback.

Lawful bases: consent where appropriate, contractual permission and legitimate interests balanced against the person's rights.

Direct marketing

Gdev does not currently operate a general newsletter. Any future marketing will comply with applicable data-protection and electronic-marketing rules. You may object to direct marketing at any time.

Used to investigate complaints, obtain advice, protect legal rights and comply with lawful requests.

Lawful bases: legal obligation, legitimate interests and legal claims.

7. Recipients

Information may be shared where necessary with:

  • Cloudflare for DNS, hosting, content delivery, security, Turnstile, functions and limited analytics;
  • Resend for transactional email and contact-form delivery;
  • Google for Workspace email, Drive, Calendar, Meet and collaboration;
  • GitHub for repositories and technical project records;
  • banks, payment, invoicing and accounting providers;
  • professional advisers, insurers and security specialists;
  • courts, regulators, HMRC and authorities where lawful; and
  • a successor in a genuine business transfer, subject to appropriate safeguards.

Gdev does not sell personal information.

The precise supplier list should be maintained in an internal vendor/subprocessor register and reflected in this notice when materially relevant.

8. Processor arrangements

Where a provider processes information on Gdev's behalf, Gdev will take proportionate steps to review its privacy/security information, use available processing terms, restrict access, configure security controls, review subprocessors and remove access when no longer required.

Where Gdev processes end-user information on a client's instructions, the Client Service Agreement's Data Processing Schedule should apply.

9. International transfers

Some providers operate internationally. Where Gdev initiates a restricted transfer, it will use an available lawful mechanism where required, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the International Data Transfer Agreement, the UK Addendum or another permitted safeguard.

Further details about a relevant safeguard may be requested from hello@gdev.agency.

10. Retention

Unless a longer period is required by law, an insurer, a dispute or another legitimate requirement, Gdev normally applies these periods:

  • enquiries not resulting in work: up to 18 months after the last substantive communication;
  • unsuccessful proposals: up to 18 months after expiry/rejection or last substantive communication;
  • contracts, approvals and core project records: up to 6 years after the client relationship ends;
  • invoices and tax/accounting records: the legally required period, normally at least 5 years after the relevant 31 January submission deadline for self-employed records and longer where required;
  • support records: duration of support plus up to 6 years where needed for legal purposes;
  • routine security/diagnostic logs: normally 30 to 90 days, longer if required for an incident;
  • access permissions: removed when no longer required;
  • credentials: deleted or rotated at handover/termination where appropriate;
  • marketing preferences: until withdrawn or no longer needed, with minimal suppression information retained to respect opt-outs;
  • complaints/legal claims: as long as reasonably necessary to investigate and protect rights; and
  • backups: until overwritten in the ordinary backup cycle, normally within 90 days unless a different technical period applies.

Retention must be reviewed against actual systems and tax obligations.

11. Security

Proportionate measures may include HTTPS, multi-factor authentication, password management, restricted permissions, encrypted provider connections, environment-secret storage, restricted API keys, software updates, device security, backups, anti-spam controls, logging, supplier review, access removal, credential rotation and incident procedures.

No online service is completely secure. Gdev does not promise absolute security but will assess risk and use proportionate controls.

12. Personal-data breaches

Gdev maintains a process to identify, assess and record personal-data breaches. Where required, Gdev will notify the ICO and affected individuals within the legally required timeframes. Where Gdev acts as processor, it will notify the client according to the applicable processing agreement.

13. Rights

Depending on the circumstances, you may have rights to be informed, access information, correct it, erase it, restrict processing, object, request portability, withdraw consent and challenge certain solely automated decisions.

Rights are not absolute and exemptions may apply.

Requests should be sent to hello@gdev.agency. Gdev may need to verify identity and clarify scope. A fee is not normally charged unless legally permitted.

14. Direct-marketing objection

You have an absolute right to object to direct marketing. Send the objection to hello@gdev.agency.

15. Data-protection complaints

You may complain about Gdev's handling of personal information by emailing hello@gdev.agency with the subject Data protection complaint where possible.

Include your name, contact details, issue, relevant dates and requested outcome.

Gdev will:

  • provide a clear way to complain;
  • acknowledge receipt within 30 days;
  • investigate without undue delay;
  • make appropriate enquiries;
  • keep you informed as appropriate; and
  • communicate the outcome without undue delay.

Gdev may request proportionate proof of identity or authority where needed.

You may also complain to the Information Commissioner's Office. Gdev would appreciate the opportunity to investigate first, but you are not required to do so.

Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF Telephone: 0303 123 1113

16. Children

The Website and services are directed at adults and business users. Gdev does not knowingly collect information directly from children through the Website.

17. Changes and contact

This notice may be updated when processing, suppliers, law or guidance changes.

Questions should be sent to:

  • George Angheluta, trading as Gdev
  • Address: Gravesend DA12 2AW
  • Email: hello@gdev.agency