How information is handled
Context without credentials
A development enquiry can explain an application and its difficulties without exposing access secrets. Wulverdev’s registered company is controller for the corporate correspondence and website described here. Its complete Scottish registration number is included in the company record below.
The information involved
Reading these pages requires delivery through Cloudflare, with technical details such as IP information, the resource requested and browser characteristics. Writing to the company introduces the details you choose to supply, typically a business identity, reply route and explanation. The page code adds no advertising or visitor-analytics service.
Purpose and lawful bases
Protecting the publication and handling relevant software enquiries are legitimate interests considered under Article 6(1)(f). Requested steps before an agreement may use Article 6(1)(b). A necessary legal record may use Article 6(1)(c). Each basis belongs to its actual purpose; an introductory message is not unrestricted permission for other uses.
When the work concerns a customer system
Wulverdev’s role as a processor, where applicable, must be established in the engagement with documented instructions. The scope should cover authorised access, service providers, security, and return or deletion at handover. Do not include production credentials or personal datasets in a general company enquiry.
Lifecycle and location
The retention period is determined by the continuing enquiry, project or defensible legal need. Once information no longer serves that reason, it should be deleted or made anonymous. Global delivery providers can create international transfers, which must use a relevant adequacy route or approved contractual safeguard when required.
Requests about your information
The registered office is the route to seek access, correction, restriction or deletion of data held in relation to your correspondence. You may object or request portability in the circumstances allowed by law. Include enough detail to identify the exchange, and expect only proportionate identity verification. The ordinary response deadline is one month.
If something goes wrong
A data breach requires an assessment of impact and containment. Notification to the ICO within the applicable 72-hour period and communication to individuals depend on the statutory conditions. An unresolved concern may also be referred directly to the ICO. This publication serves business enquiries and is not intended for children.