This Privacy Policy explains how EveryCode collects, uses, stores and protects personal data when you visit everycode.net, ask us for a quote, sign up for our newsletter, correspond with us or become a client. We have written it in plain English so that you can understand exactly what happens to your information, why it happens and what choices you have.
In short: we collect only what you choose to send us, we use it to answer you and deliver the work you hire us for, we never sell it, and our website uses no analytics, advertising cookies or third-party trackers. Below are the full details required by the EU and UK GDPR and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
1. Who we are
EveryCode (also written EveryCode.NET) is a remote-first web and WordPress development studio, established in 2011, with a Ukraine-based founder and project manager and a distributed team of senior developers.
For the personal data described in this policy, EveryCode is the data controller. This means we decide why and how your personal data is processed and we are responsible for it. As a remote-first business we do not operate a public office; the fastest way to reach us about any privacy matter is by e-mail at [email protected]. Please include the word "Privacy" in the subject line so that your message is prioritised.
When we handle personal data that belongs to our clients' own customers or users as part of a project, we usually act as a data processor on the client's behalf. That situation is explained separately in section 13.
2. Scope of this policy
This policy applies to:
- visitors to everycode.net and all of its pages, including our blog, pricing and portfolio pages;
- people who contact us through any form on the website, by e-mail or through other communication channels;
- subscribers to our newsletter;
- prospective clients who request a quote, and existing clients and their staff who work with us on a project or a Care Plan.
It does not cover third-party websites or the websites and applications we build for clients, which have their own privacy notices. Our use of browser storage is explained in more detail in our Cookie Policy, and the contractual rules for our services are set out in our Terms of Service.
3. Personal data we collect
You never need to give us personal data simply to read our website. Where a form field is mandatory, it is because we cannot answer your request without it.
3.1 Project planner form
Our project planner lets you describe a project and request a free quote. Depending on what you choose to fill in, it may collect your name, e-mail address, company or organisation name, website address, country or time zone, the type of project and services you need, your budget bracket (for example "up to $3,000" or "$10,000–$25,000"), your preferred timeline, a free-text description of the project and any other details you decide to share.
You may also upload files such as a project brief, specification, wireframes, design files or screenshots. Uploaded files are processed only to understand your project and prepare a quote. Please avoid including other people's personal data in them unless genuinely necessary.
3.2 Quick contact form
Our quick contact form collects your name, e-mail address, message and any optional details you add.
3.3 Feedback ("Rate Us") form
The feedback form lets clients and visitors rate our work and leave comments. It may collect your name, e-mail address, company name, your rating and your written feedback. We will only publish your feedback as a testimonial, or attach your name or company to it, if you have given us clear permission to do so.
3.4 Newsletter sign-up
If you subscribe to our newsletter, we collect your e-mail address and, if you provide it, your first name. Every newsletter includes a way to unsubscribe, and you can also unsubscribe at any time by e-mailing us.
3.5 Contact page
The form on our contact page collects your name, e-mail address, subject, message and any optional details you choose to share, such as your company or website.
3.6 E-mail and other correspondence
When you e-mail us, or we communicate through Slack, video calls or similar tools, we receive your name, contact details, messages and attachments. We never record calls without all participants' prior agreement.
3.7 Client project data
When you become a client, we process the information needed to run the project and the business relationship. This includes the names, job titles, e-mail addresses and other contact details of your team members; billing details such as your company name, billing address and tax or VAT number where relevant; quotes, invoices and payment records; project communications; and access credentials you give us to your hosting, website, repositories or other systems.
3.8 Server logs kept by our hosting provider
Like almost every website, everycode.net is served by a hosting provider whose servers automatically record technical information when a page is requested. These logs typically include your IP address, the date and time of the request, the page or file requested, the referring page, the HTTP status code and your browser's user-agent string. They are used only to keep the website running and secure, never to profile visitors.
3.9 Information stored in your browser
Our website keeps three small items in your browser's local or session storage (your cookie-banner choice, your first name for the thank-you page and an unfinished project-planner draft). They stay on your device and are not sent to us; see our Cookie Policy.
3.10 Payment information
Payments are handled by third-party payment processors, such as PayPal, card payment processors and bank transfer services including Wise. When you pay, you provide your payment details directly to the processor. We receive only a payment confirmation with limited details such as your name, amount, date and transaction reference. We never receive or store full card numbers.
3.11 What we do not collect
Our website is static and self-hosted: all fonts, scripts and styles are served from our own server. We do not use Google Fonts, external content delivery networks, analytics tools, advertising networks, social media pixels or any third-party tracking technology. We do not ask for, and we ask you not to send us, special categories of personal data such as information about health, religion, political opinions, ethnic origin or sexual orientation.
4. How we use your data and our legal bases
Under the GDPR and UK GDPR we must have a legal basis for each way we use personal data. The table below sets out our purposes and the legal basis we rely on for each.
| Purpose | Data used | Legal basis |
|---|---|---|
| Answering enquiries sent through the quick contact form, contact page or e-mail | Name, contact details, message content | Steps taken at your request before entering into a contract (Art. 6(1)(b)); otherwise our legitimate interest in responding to people who contact us (Art. 6(1)(f)) |
| Reviewing your project planner submission and uploaded files to prepare a quote | Planner answers, budget bracket, timeline, uploaded files | Steps taken at your request before entering into a contract (Art. 6(1)(b)) |
| Delivering projects, Care Plans and support, including managing access to your systems | Client contact details, project data, credentials, communications | Performance of a contract (Art. 6(1)(b)) |
| Invoicing, receiving payments and processing refunds | Billing details, invoices, payment records | Performance of a contract (Art. 6(1)(b)) and compliance with legal obligations (Art. 6(1)(c)) |
| Keeping accounting and tax records | Invoices, payment records, client identification details | Compliance with legal obligations (Art. 6(1)(c)) |
| Sending our newsletter | E-mail address, first name | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Collecting feedback and improving our services | Feedback form content, rating | Our legitimate interest in improving our work (Art. 6(1)(f)) |
| Publishing testimonials or showing a project in our portfolio | Name, company, feedback, project screenshots | Your consent (Art. 6(1)(a)) |
| Keeping the website secure and available | Server log data | Our legitimate interest in protecting our website and visitors (Art. 6(1)(f)) |
| Establishing, exercising or defending legal claims, and handling disputes or chargebacks | Relevant correspondence, contracts, payment records | Our legitimate interest in protecting our legal rights (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced them against your rights and expectations; you can ask us about this assessment and you have the right to object (see section 9).
5. How long we keep your data
We keep personal data only for as long as we need it for the purpose it was collected for, plus any period required by law. When a retention period ends, we delete the data or anonymise it so that it can no longer identify you.
| Type of data | Retention period |
|---|---|
| Enquiries and planner submissions that do not lead to a project | Up to 24 months after our last contact, so that we can pick up the conversation if you come back, unless you ask us to delete them sooner |
| Files uploaded through the project planner (no project started) | Up to 12 months after our last contact, then deleted |
| Project communications and project files for clients | For the duration of the engagement and up to 5 years afterwards, to support warranty requests, follow-up work and legal claims |
| Access credentials you give us | Only for as long as access is needed; we delete them from our records when the project or Care Plan ends and recommend that you change them |
| Invoices, payment and accounting records | For the period required by applicable tax and accounting laws |
| Newsletter subscription | Until you unsubscribe or withdraw consent; we then keep only a minimal record of your opt-out so that we do not contact you again |
| Feedback and testimonials | Feedback up to 3 years; published testimonials until you withdraw your consent |
| Server logs kept by our hosting provider | A short period set by the hosting provider's security practices, typically a few weeks, unless needed longer to investigate a specific security incident |
| Browser storage items | Stored on your device only; see our Cookie Policy for each item's lifetime |
6. Who we share your data with
We do not sell, rent or trade your personal data. We share it only with the categories of recipients below, and only to the extent needed:
- Hosting provider — stores and serves our website, runs the server-side script that sends form submissions to us by e-mail, and keeps server logs.
- E-mail provider — stores and delivers our e-mail, including form submissions, project correspondence and, where applicable, our newsletter.
- Payment processors — such as PayPal, card processors and Wise, which process payments and refunds under their own privacy policies and legal obligations.
- Project and collaboration tools — such as messaging (for example Slack), video conferencing, code repositories, file sharing and task management tools used to run projects with you.
- Our team — developers and specialists working on your project, bound by confidentiality and given access only to what they need.
- Professional advisers — such as accountants or lawyers, where necessary and under a duty of confidentiality.
- Authorities — where disclosure is legally required or necessary to establish, exercise or defend legal claims.
- A successor business — if EveryCode were reorganised or sold, under this policy or equivalent protection, with advance notice to you.
Where a service provider processes personal data on our behalf, we use providers that offer appropriate data protection commitments and, where required, we put a data processing agreement in place with them.
7. International transfers
EveryCode is based in Ukraine and our team is distributed across several countries. Some of our service providers may also store or process data in other countries. This means your personal data may be transferred outside the European Economic Area (EEA), the United Kingdom or your own country.
Where personal data from the EEA or UK is transferred to a country that has not been recognised as providing an adequate level of data protection, we protect it using appropriate safeguards. In most cases this means the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where UK data is involved, combined with additional technical and organisational measures where appropriate. Where a provider is located in a country with an adequacy decision, or is certified under a recognised framework, we may rely on that instead. You can request a copy of the relevant safeguards by e-mailing [email protected].
8. How we protect your data
As a studio that provides WordPress security services, we apply the same care to your data. Our measures include:
- serving our website exclusively over encrypted HTTPS connections;
- a static, self-hosted website with no third-party scripts;
- restricting access to personal data and client systems to the team members who need it for a specific task;
- using strong, unique passwords, password managers and two-factor authentication on accounts that hold client or business data, wherever the service supports it;
- sharing access credentials through secure channels and removing them when access is no longer needed;
- access-controlled repositories for client code, updated devices and confidentiality obligations for everyone who works with us.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs that is likely to put your rights and freedoms at risk, we will notify the relevant supervisory authority and, where required, you, in line with applicable law.
9. Your rights under the GDPR and UK GDPR
If you are in the EEA or the UK, or if the GDPR otherwise applies to our processing of your data, you have the following rights:
- Right of access — to ask whether we process your personal data and to receive a copy of it, together with information about how we use it.
- Right to rectification — to have inaccurate data corrected and incomplete data completed.
- Right to erasure — to ask us to delete your personal data, for example where it is no longer needed or you have withdrawn consent. Some data, such as invoices, must be kept for legal reasons.
- Right to restriction — to ask us to limit how we use your data, for example while we check its accuracy or consider an objection.
- Right to data portability — to receive data you provided in a machine-readable format, or have it sent to another organisation, where processing is based on consent or contract.
- Right to object — to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, and to object at any time to direct marketing, in which case we will stop.
- Right to withdraw consent — where we rely on consent, such as for the newsletter or a published testimonial, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- Right to lodge a complaint — with a data protection supervisory authority.
9.1 How to exercise your rights
To exercise any of these rights, e-mail us at [email protected]. You do not have to pay a fee. We will respond within one month, extendable by up to two further months for complex requests, in which case we will tell you why. We may ask you to confirm your identity first. If we cannot comply, for example because the law requires us to keep certain records, we will explain why.
9.2 Complaints to a supervisory authority
We would appreciate the chance to resolve any concern first, but you have the right to complain to a supervisory authority at any time. In the EEA, this is usually the data protection authority in the country where you live, work or where the alleged infringement took place. In the UK, it is the Information Commissioner's Office (ICO).
10. Privacy rights for California residents (CCPA/CPRA)
This section applies to residents of California and supplements the rest of this policy. To the extent the CCPA/CPRA applies to us, California residents have the following rights:
- Right to know the categories and specific pieces of personal information we have collected, the sources, the business purposes for collection and the categories of third parties with whom we disclose it.
- Right to delete personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to limit the use of sensitive personal information. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
- Right to non-discrimination for exercising any of these rights.
We do not sell or share personal information, as those terms are defined by the CCPA/CPRA, and we have not done so in the past 12 months. We do not use cross-context behavioural advertising. The categories we collect (identifiers, commercial and professional information, limited internet activity in server logs, and communications) are described in section 3; purposes, retention and recipients are in sections 4 to 6.
To make a request, e-mail [email protected]. We will verify your request by matching the information you give us with the information we hold, and we will respond within 45 days, which may be extended once by a further 45 days where necessary. You may use an authorised agent to make a request on your behalf; we may ask for proof of the agent's authority and verify your identity directly. Residents of other US states with comparable privacy laws may contact us in the same way and we will handle their requests in accordance with the applicable law.
11. Children's privacy
Our website and services are intended for businesses and adults. We do not knowingly collect personal data from anyone under 16; if you believe a child has sent us data, contact us and we will delete it promptly.
12. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Every quote, proposal and decision about working together is made by a person on our team.
13. Client data we process on your behalf
When we build, maintain or support a website or application for a client, we may have access to personal data that the client controls, such as the client's customers, orders, user accounts, form entries or mailing lists stored in a WordPress or WooCommerce database. In these cases, the client is the data controller and EveryCode acts as a data processor. This means that we:
- process that data only on the client's documented instructions and only to deliver the agreed services;
- apply appropriate security measures, and work on copies with personal data removed or anonymised wherever practical, for example in development and staging environments;
- do not use it for our own purposes, and never sell it or use it for marketing;
- keep it confidential and help the client meet its data subject request and breach-notification obligations;
- delete or return the data at the end of the engagement, as the client chooses, unless the law requires us to keep it.
A Data Processing Agreement (DPA) that reflects Article 28 of the GDPR, including Standard Contractual Clauses where needed, is available on request. Please ask at [email protected], ideally before the project starts. If you are a customer of one of our clients, please direct privacy requests to that client; if you contact us, we will forward your request.
14. Links to other websites
Our website may link to other websites, such as client projects or external resources. We are not responsible for their privacy practices, so please read their policies.
15. Changes to this policy
We may update this Privacy Policy when our practices or the law change; the date at the top shows the latest version. If we make significant changes, we will make that clear on this page and, where appropriate, notify clients and newsletter subscribers by e-mail.
16. Contact us
If you have any question about this Privacy Policy, want to exercise your rights or would like to request a Data Processing Agreement, please e-mail us at [email protected] or use our contact page.