Information this notice covers
This notice covers Adev's website, requested resources and scoping calls, corporate outreach, contracting, billing and Adev's own business operations. When Adev processes personal information solely on a client's documented instructions, the client is normally the controller and its notice also applies.
Website requests
Resource and scoping forms collect your full name, work email, company, selected problem categories, request type, source page and a server timestamp. Firebase and Google Cloud validate the request and write it to an access-restricted Google Workspace lead register. Adev uses this information to provide the requested resource or scheduling path and to follow up about that request. Adev does not add form submitters to a general marketing list.
The normal lawful bases are steps requested before a possible contract and Adev's legitimate interests in responding to relevant business enquiries, operating the site securely and maintaining business records.
Corporate outreach
Adev may research limited professional contact information from company websites and other public business sources to contact relevant people in corporate roles. A first message identifies Adev, explains the contact's relevance and source, links to this notice and provides a simple objection or unsubscribe method.
Saleshandy processes contact, delivery, open, click, reply, bounce and opt-out events for this purpose. Access is restricted to authorised Adev personnel. Adev does not target consumers, personal addresses or sole traders by default. A permanent minimal suppression record is kept so an opted-out address is not sourced and contacted again.
Scheduling, media and browser providers
Google appointment scheduling loads only after you choose to open the scheduler. Information you enter then goes directly to Google Workspace. YouTube privacy-enhanced embeds load only after you choose to play a video. Google Fonts, jsDelivr and cdnjs/Cloudflare receive ordinary technical request information when they deliver fonts, icons or scripts. reCAPTCHA Enterprise processes technical and interaction signals solely to protect public forms.
Optional analytics, marketing tags and session replay are not active.
Client services
Depending on an engagement, Adev may process business contacts, CRM and communications records, technical configurations, industrial operations information, commercial information, workforce assignment records and approved integration credentials. The exact controller/processor roles, providers, regions, retention and international access are documented for each engagement.
Special-category information, criminal-offence data, payment-card data, biometrics and other particularly regulated information are restricted by default and require explicit necessity, assessment, contract coverage and approval. Credentials and tokens are segregated as secrets and are not placed in project documents or repositories.
AI-assisted work
Adev may combine deterministic rules and confidence-scored AI to prepare drafts or recommendations. Named people approve material outputs. AI does not independently approve commercial commitments, worker decisions, safety outcomes or industrial-control actions. ChatGPT Plus is restricted to public, generic, effectively anonymised or sanitised development inputs; identifiable client data and credentials are prohibited.
Providers and recipients
Recurring providers include Google Workspace and Gemini, Firebase and Google Cloud, reCAPTCHA Enterprise, GitHub, Saleshandy, Airwallex, Stripe, Zoho Vault, restricted OpenAI use, Google Fonts, jsDelivr, cdnjs/Cloudflare, YouTube and Google Calendar. The current purpose and status of each is published in the trust-centre provider table. Engagement-specific providers require assessment and prior written client consent before subprocessor use.
Payments and signatures
Adev uses Airwallex for invoicing and may offer Stripe-hosted payment links. Card and bank details are entered into the payment provider's service, not an Adev application. Authorised Google Workspace eSignature may be used for approved documents, with the authoritative signed copy retained in restricted Workspace storage.
International access
Adev Group Ltd is the accountable UK contracting entity and specialist delivery personnel may work from India. Client-selected systems, transformation keys and identity mappings remain in UK, EEA or client-owned environments. Routine engineering uses synthetic, effectively anonymous or tokenised data wherever practicable. Necessary limited personal-data access is documented in the engagement processing schedule and protected through named access, contractual terms, applicable transfer safeguards and assessments. High-risk data or materially expanded access requires separate approval.
Routine consulting calls may involve controlled window-only screen sharing under the engagement schedule. Recording, transcription, meeting AI assistants, screenshots and downloads are disabled by default. If credentials, sensitive workforce information, precise location or other high-risk information appears, sharing stops until the additional access is assessed and approved.
Retention
- Inactive website leads and inactive outreach prospects: normally 12 months.
- Permanent suppression register: minimum work email or identifier and opt-out date.
- Client working data: normally deleted within 60 days after engagement end; encrypted managed-service backups expire within the following 30-day cycle.
- Temporary encrypted-device downloads: no later than seven days after active use.
- Filtered operational and security logs: normally 90 days.
- Commercial, tax, contract, dispute and signature records: the applicable legal or contractual schedule, with seven years as the default commercial audit period where Adev is responsible.
Your rights and complaints
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is used. Email privacy@adevgroup.co.uk. Adev responds for information it controls. For client-controlled information, Adev routes the request to the client and assists only on documented instructions.
You may complain to the UK Information Commissioner's Office and, where applicable, an EU supervisory authority. Adev currently treats CCPA controls as voluntary alignment unless an applicability assessment determines that the statute applies.