Professional web development environment

Privacy Statement

Defining the professional standards and operational agreements for our partnership in digital excellence.

(0) Introduction and Definitions

MG WebDev Ltd. ("we", "us", "our") respects your privacy and is committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

This Privacy Statement explains how we collect, use, disclose, transfer, and store your personal data when you visit or interact with our website (www.mgwebdev.eu and subdomains), use our services (including our management/resource portal), submit inquiries, or enter into contracts with us.

Note on scope: This statement applies to personal data we process as data controller for our own websites and services. For client websites we host or manage, we act as data processor on behalf of the client (data controller). Clients are responsible for their own privacy statements and compliance. We process form submissions on hosted client sites solely to notify the client (via email) and for security/logging purposes.

(1) Personal data we collect

We collect the following categories of personal data:

1.1 Contact and identification data. Full legal name, email address, phone number, postal address, and full address (when provided via forms, quotes, contracts, or consultations).

1.2 Account and service data. Information for creating/managing user accounts in our portal (e.g., login credentials, usage logs, etc.)

1.3 Payment data. Payment information (processed securely via third-party PayPal; we do not store full card details ourselves).

1.4 Technical and usage data. IP address, browser type, device info, pages visited, interaction data (via Google Analytics, Microsoft Clarity), server logs (for security and service improvement)

1.5 Other data. Any data you voluntarily provide in messages, support tickets, or feedback.

We do not routinely collect sensitive/special category data (e.g., health data). Date of birth or similar is not collected unless exceptionally relevant (e.g., contract-specifics).

(2) How we collect your data

  • Directly from you (forms, emails, contracts, portal login).
  • Automatically (server logs, analytics tools).
  • Via third parties (e.g., PayPal for payments).

(4) Sharing your data

We share data only as necessary:

  • Service providers: Google (Analytics), Microsoft (Clarity), Cloudflare (security), AWS/Netlify/Vercel (hosting/beta-testing), PayPal (payments), Axeptio (consent management)
  • Professional advisors (e.g., accountants, lawyers) under confidentiality.
  • Authorities of required by law.

These providers act as processors under GDPR-compliant agreements (where applicable).

(5) International Transfers

Some recipients are in the US or other non-EEA countries. We rely on:

  • The EU-US Data Privacy Framework (DPF) adequacy decisions for certified providers (e.g., Google, AWS, PayPal, Microsoft participate).
  • Standard Contractual Clauses (SCCs) or other safeguards where DPF does not apply.

A list of DPF participants is available at dataprivacyframework.gov.

(6) Retention periods

We retain personal data only as long as necessary:

  • Inquiry/support data: up to 1 year (or longer if ongoing).
  • Account/portal data: During active use + up to 2 years after inactivity (or per contract)
  • Analytics/technical logs: Typically 14-26 months (tool defaults, e.g., Google Analytics).
  • Longer retention only for legal obligations, disputes, or security.

Afterwards, data is deleted or anonymized.

(7) Cookies and Tracking Technologies

We use cookies and similar technologies (essential for functionality, analytics via Google/Microsoft, etc.). Our consent management is handled by Axeptio (banner on our site). You can manage pererences there.

For details, see our Cookie Policy (linked via Axeptio banner or located at www.mgwebdev.eu/cookie-statement)

(8) Your rights under GDPR

You have the right to:

  • Access, rectify, or erase your data.
  • Restrict or object to processing (including legitimate interests-based).
  • Data portability.
  • Withdrawal consent (where applicable) - this does not affect prior processing.
  • Lodge a complaint with the Belgian Data Protection Authority (www.gegevensbeschermingsautoriteit.be) or your local DPA.

To exercise rights, email [email protected]. We respond within one month (extendable if complex). Verification may be required.

(9) Security

We implement appropriate technical and organizational measures (e.g., encryption, access controls, regular updates) to protect your data. However, no system is 100% secure.

(10) Children's Privacy

Our services are not directed at children under the age of 18. We do not knowingly collect data from minors. If we become aware such data has been collected, we will delete it as soon as possible.

(11) Changes to this statement

We may update this statement. Changes will be posted here with the updated date, displayed at the top of this page. Significant changes may be notified via email or site notice.

(12) Contact

For questions: [email protected]

By using our site/services, you acknowledge this statement.

Support and Contact Information

The Core of Accountability

For legal inquiries, technical support, or questions regarding these terms of service, our team is available to assist you across multiple channels.