SpotCheck® is a product of SpotDev Services Ltd(“SpotDev”, “we”, “us”), a company registered in England and Wales, company number 14296175, VAT number GB-425818778, registered office Office 11, 3 Edgar Buildings, George Street, Bath BA1 2FJ.
SpotDev as controller. We decide why and how to process your SpotCheck account, security and service-usage data, transactional communications, support requests, and any separately consented marketing data.
SpotDev as processor or sub-processor. For audit data that you submit on behalf of an organisation, that organisation remains the controller (or a processor for another controller) and SpotDev processes the data only on its documented instruction. A website audit uses the confirmation submitted with that request. A HubSpot audit records a separate, versioned acknowledgement for the selected portal. The candidate acknowledgement remains inactive pending final policy-owner approval and exact-version configuration.In each case, starting the audit constitutes the instruction and agreement to the limited hosted processing, AI processing and report retention described on this page and in the terms.
What we collect
We collect the minimum data needed to run an audit and show you the results:
Account details. Your email address, name, and (if you provide them) company name, job role, and company size, collected when you sign in or complete onboarding.
Audit metadata. The website URL or HubSpot portal you asked us to audit, when the audit ran, and its status.
HubSpot snapshot data. Read-only configuration data returned by the HubSpot API scopes you approve during connection (for example user counts, property setup, workflow configuration). The audit uses read and search operations only; no customer-portal update or deletion step is part of an audit. Raw responses remain in memory for scoring. Only derived, time-limited evidence is persisted, and each row expires 24 hours after persistence. The graded report and its findings are retained separately and have no automatic expiry. Customer-portal traffic is restricted to allow-listed GET requests and documented read/search requests; SpotCheck has no customer-portal write operation.
Website crawl data. For website audits, publicly accessible pages we fetch from the domain you submit (including HTML, rendered page data, screenshots, and page performance data), used only to generate your report. Each raw crawl evidence row expires 24 hours after it is persisted. The current visual-review feature privacy-minimises screenshots with a fail-closed OCR and image-redaction boundary before any optional model review; screenshots that cannot be safely minimised are withheld rather than sent. Where a visual review does run, its screenshot is held as a separate stored object rather than inside the report itself, reachable only through the same sign-in and report permissions as the report, and deleted when the report is deleted. It is held by our hosting provider, named below. A historical report produced by an earlier report contract may still hold the selected compressed screenshot and evidence record inside the report.
Usage data. Standard technical logs (IP address, browser type, pages viewed) needed to operate and secure the service.
Why we process it (lawful basis)
Where SpotDev acts as controller, we rely on:
Performance of a contract: running the audit you asked for and showing you the report.
Legitimate interests: keeping the service secure, improving audit accuracy, and following up on audits where you have asked us to help fix findings.
Consent: any marketing communication, which you can withdraw at any time. Marketing consent is always opt-in, never a default.
Where SpotDev acts as processor or sub-processor, the relevant organisation decides the lawful basis and is responsible for the required notices, permissions and authority. We process that audit data only to carry out the instructed audit, secure the service, retain the instructed report artefacts, and meet applicable legal obligations.
Who we share it with
We use a small number of processors and sub-processors to run SpotCheck. Each receives only the data needed for its function. For client audit data, starting the audit is the documented instruction and explicit agreement for these limited exceptions to SpotDev's normal practice of working inside client systems:
Railway hosts our application, database and object-storage infrastructure, including the stored visual-review screenshots described above.
OpenAI provides optional, non-scored advice from minimised derived evidence and a bounded website model-mention experiment. HubSpot model input is limited to privacy-safe evidence records derived from deterministic results and aggregates, never raw CRM records or raw snapshots. Website final-review input is a bounded, identity-minimised packet of derived measurements and check outcomes; the model-mention questions omit crawled copy, target identity, contact details and precise location. CRO screenshots are sent only after fail-closed privacy redaction produces a derived image; unsafe screenshots are withheld. OpenAI Responses requests explicitly set store to false, so SpotCheck does not use Responses application-state storage. OpenAI's separate default abuse-monitoring logs may retain customer content for up to 30 days unless the organisation is approved and configured for a different data-control regime. OpenAI prompt caching is a separate provider control and may retain cache state for up to 24 hours on supported models. OpenAI states that API data is not used to train its models unless the organisation opts in. SpotDev does not claim Zero Data Retention unless the OpenAI organisation entitlement is verified. SpotDev's effective OpenAI retention, monitoring, residency and opt-in settings require owner-approved account readback; until then SpotCheck assumes the provider defaults described here. Deterministic scoring remains complete without AI.
Google (Chrome UX Report and PageSpeed Insights) supplies public field Core Web Vitals and separate Lighthouse lab diagnostics for website audits.
HubSpot is both the source of portal audit data (with your permission) and, separately, SpotDev’s own CRM, where we record account-level audit metadata, scores and requested follow-up. Raw CRM records and raw audit snapshots are not copied into SpotDev’s CRM.
We do not sell your data, and we do not share it with anyone for their own marketing purposes.
How long we keep it
Derived HubSpot evidence and raw website crawl evidence expire 24 hours after each row is persisted. A report is a separate, longer-lived record with no automatic expiry. It includes the graded findings and may include validated model samples, evidence and provenance needed to explain optional non-scored advice. Where a visual review ran, its screenshot is kept as a separate stored object for as long as the report itself, and is deleted when the report is deleted; a report produced under an earlier contract may instead hold that screenshot inside the report. We keep these report artefacts so you can review and track the audit over time. Reports persist until deletion is completed following an authorised request or legal requirement, subject to any longer legal hold needed for accounting, security, or dispute resolution.
This retention is part of the documented instruction given when an authorised user starts the audit. You can withdraw future access by disconnecting the portal and can request deletion using the contact details below. Operational log and backup periods remain pending owner approval and supplier-configuration readback in the proposed processing schedule; they do not inherit the evidence-row timer.
Cookies
SpotCheck uses strictly necessary authentication and security cookies, including session, sign-in state and cross-site request forgery protection cookies. We do not use advertising or third-party tracking cookies on this site.
Your rights
Under UK GDPR, you have the right to:
access the personal data we hold about you;
ask us to correct inaccurate data;
ask us to delete your data or restrict how we use it;
object to processing based on legitimate interests;
receive a copy of your data in a portable format;
withdraw marketing consent at any time; and
complain to the Information Commissioner’s Office (ico.org.uk) if you think we have got this wrong.