Legal

Privacy Policy

What this website collects, why we are allowed to, who else handles it and how long we keep it — described against what the code on this site actually does rather than a template.

Last updated: 16 September 2026

In one paragraph

This site has two forms and no tracking of the kind most privacy notices are written to excuse. If you fill in a form we receive what you typed, we email it to ourselves so we can reply, and we keep a copy in a server log as a safety net in case the email fails. There is a small arithmetic sum on each form to stop automated submissions; it runs entirely on our own server and no third-party service sees you solve it. No analytics or advertising script is loaded on any page of this site at present. We do not sell anything to anybody and we do not buy lists.

Who is responsible for your information

MakeMyApp UK operates this website and is the controller of the personal data described here, for the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018. You can reach us by email at info@makemyapp.uk or by telephone on +44 7446 973371. Any privacy question, including a request to exercise one of the rights listed further down, should go to that email address.

Separately from this website, when we build software for a client we normally act as a processor on that client’s behalf rather than as a controller. That relationship is governed by the data processing agreement in the engagement rather than by this notice, and this notice does not describe how any client system handles its own users’ data.

The two forms on this site, field by field

There is no account system, no comment facility and no newsletter. The only way personal data reaches us through this website is by submitting one of these two forms.

The enquiry form on the contact page

It asks for the following, and nothing else is captured from the page:

  • Name and email address — both required, because without them we cannot reply.
  • Phone or WhatsApp number — optional.
  • Company — optional.
  • What needs building — a choice from a fixed list such as an MVP, a mobile app, a web application or maintenance of an existing app.
  • Platforms — free text describing which platforms you need.
  • Where you are now — a choice from a fixed list, from “just an idea” through to a live application needing work.
  • Budget range — a choice from a fixed list of sterling bands, stated excluding VAT.
  • Timeline — free text.
  • A checkbox requesting a mutual NDA before you share details.
  • About the project — a free-text message, required. Whatever you choose to put in this box is the part of the form most likely to contain information you would rather keep narrow, so please keep it general until an NDA is in place.

The estimate capture on the cost calculator

The calculator itself runs in your browser and sends nothing anywhere while you use it. If you choose to have the result emailed to you, the form submits your name, your email address, the indicative range the calculator displayed and a summary of the options you selected, so that our reply can refer to what you actually chose. Selecting options and reading the figure on screen involves no submission at all.

What is attached to a submission automatically

Both handlers add the date and time the form was submitted. Beyond that, our web host keeps ordinary server access logs, which typically record the requesting IP address, the page requested, the time and the browser user-agent string, as any web server does. We do not use those logs for marketing or profiling; they exist for security and for diagnosing faults.

What happens once you press send

Two things, and only two.

  • The submission is emailed to us. A plain-text message containing the fields listed above is sent to an internal address monitored by the person who will reply to you, with your email address set as the reply-to so that answering you is a single click.
  • The submission is written to a server-side log as a delivery safety net. Email delivery can fail quietly. Rather than lose an enquiry that somebody took the trouble to write, the handler records the same fields in the server error log at the moment of submission, so a message that never arrived can still be found and answered. It is a recovery mechanism, not a database or a marketing list, and nothing reads it automatically.

The spam check, and why no third party sees it

Each form carries a short arithmetic question — two single-digit numbers to add together. It is deliberately not a commercial captcha product. There is no Google reCAPTCHA, no hCaptcha, no Cloudflare Turnstile and no behavioural scoring, so no third party is watching how you fill in the form and no cookie or fingerprint is set for the purpose.

It works like this: when the page is rendered the server generates two numbers and an expiry time, and sends them back to you inside a signed token in a hidden field. When you submit, the server checks the signature, checks the token has not expired and checks your answer. Because the token carries its own data and its own signature, nothing about you needs to be stored between loading the page and submitting it. There is also a hidden field that a human never sees and never fills in; anything submitted with that field completed is treated as automated and discarded. Neither mechanism records anything about you.

Why we are allowed to process it

UK GDPR requires a lawful basis for each processing activity. Ours are:

  • Steps taken at your request before entering a contract, Article 6(1)(b). You have asked for a scope, an estimate or a call. Replying to that request and preparing a proposal is the processing.
  • Legitimate interests, Article 6(1)(f). Keeping a recoverable copy of an enquiry so it is not lost to a failed email; protecting our own systems and forms from automated abuse; and keeping a record of what was quoted and agreed. In each case we have considered the effect on you and concluded it is minimal and expected: you contacted us, and you would reasonably expect us to be able to find and answer your message.
  • Legal obligation, Article 6(1)(c). Where correspondence forms part of records we are required to retain, for example the paperwork behind an invoice.

We do not rely on consent for anything on this site, because there is nothing here that would need it — no marketing list to opt into and no non-essential cookies to accept. We do not ask for and have no need for special category data, and you should not put health, biometric or similar information into the message box. We make no automated decisions that produce legal or similarly significant effects about anyone.

Who else handles it

  • Our web hosting provider, which runs the server this site sits on and holds the access logs and the recovery log described above.
  • A transactional email relay, which carries the notification message from this site to our inbox and acts as our processor for that delivery. It handles the message in transit and in its own sending records; it is not given a marketing list, because there is not one.
  • Our email provider, which stores the resulting message in the mailbox where it is read and answered.

Each of these is a processor acting on our instructions under a written agreement. We do not share enquiry contents with anyone else, we do not sell or rent personal data, and we do not pass your details to other suppliers looking for work.

International transfers

Some of the people who read and act on enquiries, and some of the infrastructure involved in delivering email, are outside the United Kingdom. In particular, our delivery team works in India, so an enquiry you send may be read there. That is a restricted transfer under UK GDPR and it needs a safeguard.

Where a transfer is to a country the UK has found to provide an adequate level of protection, we rely on those adequacy regulations. Where it is not, we rely on the International Data Transfer Agreement issued by the Information Commissioner, or the UK Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment and practical measures such as encryption in transit and access limited to the individuals who actually need it. If you would like to know which mechanism applies to a specific processor, ask and we will tell you.

This is a separate question from where a client project stores its data. On client builds we can and routinely do pin databases, backups and logs to UK or EU regions — that is an architecture decision taken at the start of an engagement, and it is covered by the data processing agreement for that project rather than by this notice.

How long we keep things

  • Enquiries that do not become projects: kept while we are in conversation and for up to 24 months after the last contact, so that we recognise you if you come back. After that they are deleted.
  • Enquiries that do become projects: kept for the life of the engagement and then with the project records, because they are the origin of what was agreed.
  • Records connected to invoicing: kept for six years from the end of the relevant accounting period, which is the retention ordinarily required of UK businesses for tax records.
  • The server-side recovery log and the host’s access logs: kept only as long as the host’s log rotation holds them, which is typically a matter of days to a few weeks. They are not used as a records system and are not backed up as one.

If you would rather we did not wait for those periods to expire, ask us to erase your enquiry and we will, subject to anything we are required to keep for tax or legal reasons.

Cookies

Reading this site and submitting a form sets no cookie. This theme stores nothing in your browser for visitors, the spam check is stateless by design, and there is no consent banner because there is nothing to consent to. WordPress itself sets cookies only for people who log in to the administration area, which means us rather than you.

Measurement and analytics

Analytics is not currently enabled on this website. No Google Analytics tag, no advertising pixel, no heatmap recorder and no third-party measurement script is loaded on any page. We would rather say that plainly than publish a policy describing tracking that does not exist.

If we switch analytics on later, this section will be rewritten to describe exactly what it collects, the date at the top of this page will change, and the tag will only appear because a specific configuration constant has been set — it is not sitting dormant in the page waiting to be triggered.

Keeping it secure

The site is served over HTTPS, form submissions are validated on the server rather than trusting anything the browser sends, and the forms carry a cross-site request forgery token as well as the spam check. Access to the mailbox that receives enquiries is limited to the people who answer them and protected by multi-factor authentication. No arrangement is perfect, and if a breach ever occurred that presented a risk to people’s rights and freedoms we would report it to the Information Commissioner’s Office within 72 hours and tell the individuals affected where the law requires it.

Your rights

Under UK GDPR and the Data Protection Act 2018 you have the following rights in relation to the personal data we hold about you:

  • Access. To be told whether we hold data about you and to receive a copy of it, together with an explanation of what we do with it. This is what is usually called a subject access request.
  • Rectification. To have inaccurate data corrected and incomplete data completed.
  • Erasure. To have data deleted where we no longer need it for the purpose we collected it, or where you have successfully objected to the processing.
  • Restriction. To have processing paused — for example while a dispute about accuracy is resolved — so that we hold the data but do nothing else with it.
  • Portability. To receive the data you gave us in a structured, commonly used, machine-readable form, or to have it sent directly to another controller where that is technically feasible.
  • Objection. To object to processing carried out on the basis of our legitimate interests, including any form of direct marketing. An objection to direct marketing is absolute and we would stop immediately.
  • Withdrawal of consent. Where we ever rely on consent for something, to withdraw it as easily as it was given, without affecting anything done before you withdrew it.
  • Automated decision-making. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions.

Email info@makemyapp.uk to exercise any of these. We respond within one month, which the law allows us to extend by a further two months for complex requests — if that happened we would tell you inside the first month and explain why. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity first, which usually means replying from the address the enquiry came from.

Complaining about how we have handled your data

If you are unhappy with how we have dealt with your personal data, please tell us first — most problems are a misunderstanding and are quicker to fix directly. You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office, at any time and without going to us first. The ICO can be reached at ico.org.uk, by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or on its helpline. Complaining to the ICO does not affect any other legal remedy available to you.

Children

This site sells business services and is not directed at children. We do not knowingly collect personal data from anyone under 18 through it. If you believe a child has submitted a form here, tell us and we will delete the submission.

Links away from this site

Some pages link to third parties — WhatsApp, app store listings, documentation and similar. Following one of those links takes you into that organisation’s privacy arrangements, not ours, and we have no control over what they collect. This notice covers only makemyapp.uk.

Changes to this notice

When this notice changes the date at the top changes with it. If a change is significant — a new processor, a new purpose, analytics being switched on — it will be described here rather than folded silently into the wording.

What this document is not

This is a plain-English description of how this website handles personal data. It is not legal advice, and it is not a template for your own privacy notice. If you are building something that processes personal data, the right sequence is a proper data protection assessment for your own circumstances, with a solicitor or data protection adviser where the processing is significant. We are happy to explain what a system we build for you actually does with data — that is a factual question and we will answer it precisely.

Getting in touch

Any question about this notice, or any request relating to your data, goes to info@makemyapp.uk or +44 7446 973371.