PRIVACY POLICY
Last updated: 12.02.2026
1. Introduction

This Privacy Policy explains how GYFAMELY Ltd UK, operating GYG.Agency (“we”, “us”, “our”), collects, uses, processes and protects personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

This policy applies to personal data collected through GYG Agency and related communications.

2. Data Controller
GY Global Ltd UK
Registered in England & Wales
Email: legal@gyglobal.net 
Phone: +442045771323

We are the data controller responsible for your personal data.

3. Personal Data We Collect
We may collect and process the following categories of personal data:
a) Identity Data
Name, job title, company name.
b) Contact Data
Email address, business telephone number.
c) Technical Data
IP address, browser type, device data, usage information.
d) Communication Data
Information submitted via contact forms, inquiries, or consultations.
We do not intentionally collect special category data.

4. Lawful Basis for Processing
We process personal data under the following lawful bases:
  • Consent (Article 6(1)(a))
  • Contractual necessity (Article 6(1)(b))
  • Legitimate interests (Article 6(1)(f))
  • Legal obligation (Article 6(1)(c))
Our legitimate interests include operating, improving, securing and marketing our services in a B2B context.

5. How We Use Personal Data
We may use personal data to:
  • Respond to enquiries
  • Deliver professional services
  • Conduct business development
  • Improve website functionality
  • Monitor security and prevent misuse
  • Comply with legal obligations
We do not sell personal data.

6. Data Sharing
  • We may share personal data with:
  • Professional advisers
  • IT and hosting providers
  • CRM and analytics providers
  • Regulatory authorities if required
All processors are subject to appropriate contractual safeguards.

7. International Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
  • UK International Data Transfer Agreements (IDTA)
  • Adequacy decisions
  • Standard Contractual Clauses
8. Data Retention
We retain personal data only as long as necessary for:
  • The purpose for which it was collected
  • Legal compliance
  • Legitimate business purposes
  • Retention periods vary depending on context and regulatory requirements.
9. Data Security
We implement appropriate technical and organisational measures, including:
  • Access controls
  • Encryption where appropriate
  • Secure hosting environments
  • Limited internal access
10. Your Rights
Under UK GDPR, you have the right to:
  • Access your personal data
  • Rectify inaccurate data
  • Erase personal data
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent
Requests may be submitted to: legal@gyglobal.net
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

11. Updates
We may update this Privacy Policy periodically. Updates will be published on this page.