Privacy Policy
Last updated: 19 August 2026
WEGOX GLOBAL LIMITED ("WEGOX", "we", "us" or "our") is a company registered in England and Wales under company number 16580618, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. This policy explains how we collect, use, share and protect personal data in connection with our website, our client engagements and our business communications, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data controller
WEGOX is the data controller for the personal data described in this policy. If you have any question about this policy or how we handle your data, you can contact our data controller directly at info@wegoxglobal.com or by post at the registered office address above.
2. What personal data we collect
We collect personal data in the following ways:
- Enquiry and contact form data. When you submit an enquiry through our website (for example, "Start a Project" or "Book Consultation"), we collect your full name, work email address, company name, practice area of interest, budget range and the project description you provide.
- Prospective collaborator data. When you submit an Expression of Interest through our Careers page, we collect your full name, email address, primary discipline, portfolio or GitHub URL, and the summary of experience you provide.
- Correspondence. If you email, call or otherwise contact us directly, we keep a record of that correspondence and any personal data it contains.
- Client and engagement data. If you become a client, we collect the additional personal data reasonably necessary to deliver, invoice and support that engagement (for example, billing contact details).
- Essential session cookies and basic analytics. Subject to your consent choices for anything beyond strictly essential cookies, we may collect technical and usage data via cookies (device/browser information, pages visited, approximate location from IP address). See our Cookie Policy for full detail on what we use and how to control it.
We do not knowingly collect special category data (such as health or biometric data) through our website.
3. Lawful basis for processing
| Purpose | Lawful basis |
|---|---|
| Responding to an enquiry submitted through our contact form | Legitimate interests (responding to a request you have initiated) |
| Entering into and performing a client engagement | Performance of a contract, or steps taken at your request prior to entering a contract |
| Non-essential cookies (analytics, performance) | Consent, which you may withdraw at any time |
| Complying with tax, accounting and other legal obligations | Legal obligation |
| Detecting and preventing fraud or misuse of our website | Legitimate interests |
4. How we use your data
- To respond to enquiries and route them to the correct team;
- To scope, deliver, invoice and support client engagements;
- To maintain business records required for accounting and tax purposes;
- To operate, secure and improve our website (only with consent for non-essential cookies); and
- To comply with our legal and regulatory obligations.
We do not sell personal data, and we do not use enquiry or client data for unrelated marketing without a separate, specific consent.
5. Who we share data with: our sub-processors
We share personal data only where necessary, with the following named service providers, each of whom processes data on our behalf under a written data processing agreement and only for the purpose stated:
| Sub-processor | Purpose |
|---|---|
| Vercel | Website hosting and edge computing |
| Resend | Transactional email delivery (enquiry alerts and auto-receipts) |
| Supabase | Secure cloud storage (PostgreSQL database) |
| Stripe | Payment infrastructure |
| Cloudflare | Edge security and network protection |
We also share personal data with professional advisers (accountants, legal counsel) where necessary for our own compliance. We do not share personal data with third parties for their own independent marketing purposes.
6. International data transfers
Where a service provider processes personal data outside the UK, we ensure an appropriate safeguard is in place before the transfer takes place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a UK adequacy regulation.
7. Data retention
We keep personal data only for as long as necessary for the purpose it was collected:
- Enquiries that do not become a client engagement: up to 24 months from the date of your enquiry, then deleted or anonymised.
- Client engagement records: for the duration of the engagement plus 6 years, to meet standard UK accounting, tax and contractual limitation periods.
- Cookie consent records: up to 12 months, after which we will ask you to confirm your preferences again.
8. Your rights
Under UK GDPR, you have the right to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data, where there is no overriding reason for us to keep it;
- Request restriction of, or object to, certain processing;
- Request a portable copy of data you provided to us; and
- Withdraw consent at any time, where processing is based on consent, without affecting processing carried out before you withdrew it.
9. Data Subject Access Requests (DSAR)
To exercise any of the rights above, or to submit a Data Subject Access Request, email info@wegoxglobal.com with the subject line "Data Subject Access Request". We may need to verify your identity before processing your request. We will respond within one calendar month of receiving a valid request, as required by UK GDPR, and will explain if we need to extend that period for a complex request.
10. Security, storage and encryption
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction:
- Encryption at rest: personal data held in our database is encrypted at rest using AES-256.
- Encryption in transit: all connections to and within our systems use TLS 1.3.
- Data residency: data is hosted in UK/EU sovereign regions, including the Vercel Edge Network, AWS eu-west-2 (London), and Supabase PostgreSQL.
- Access to internal systems is controlled and limited to personnel who need it to perform their role.
See section 5 above for the named sub-processors that host or process data on our behalf.
11. Children
Our website and services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page shows when it was last revised.
13. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at info@wegoxglobal.com so we can try to resolve it. You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.
14. Contact
WEGOX GLOBAL LIMITED
Company number 16580618
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
info@wegoxglobal.com
