Privacy Policy
Last updated: 16 July 2026
This policy explains how personal data is handled when you browse the website, request a quote, become a client or use the support chat.
1. Controller and contact details
DIGIFY IT LTD is the data controller for the processing described here. It is registered in England and Wales under company number 16944733, with registered office at Suite 1, 2 Britannia Street, Leicester, England, LE1 3LE.
Privacy requests can be sent to info@digifyit.co.uk. Please do not send identity documents unless we ask for information reasonably needed to verify a request.
2. Data we collect
Enquiry and client data may include your name, organisation, email address, request category, subject, message, project requirements, quote and contract records, approvals, invoices and related correspondence.
Support data may include the same contact details, a ticket reference, a secure recovery code, status, timestamps, messages, optional attachments and delivery records from email or Discord. Please avoid including passwords, payment-card details, government identifiers, health information or other unnecessary sensitive data.
Technical data may include IP address, request time, requested path, browser or device information, security events and server logs reasonably needed to deliver and protect the service. The website does not currently use advertising or audience-measurement cookies.
3. Purposes and legal bases
We process data to answer enquiries, prepare quotes, form and perform contracts, deliver and support projects, secure the service, prevent abuse, keep business records, establish or defend legal claims and comply with law.
Depending on the context, the legal bases are steps requested before a contract and performance of a contract, legitimate interests in operating a secure and effective business, and compliance with a legal obligation. Where a separate optional activity legally requires consent, we will ask for it and it may be withdrawn at any time without affecting earlier lawful processing.
Our legitimate interests include responding to genuine business enquiries, maintaining support history, improving service quality, preventing fraud and protecting systems. We balance these interests against the rights and reasonable expectations of the people concerned.
4. Support chat and browser storage
The chat creates a ticket so a conversation can continue on the website and by email. A recovery code is required to reopen private messages. The code is stored server-side in protected form and remains only in page memory in the browser session; it is not saved in local storage.
The browser may retain the ticket reference, email address and local expiry under the strictly functional key described in our Cookie and Local Storage Policy. Selecting the forget option removes that local entry but does not immediately erase the support record from our systems.
5. Recipients and service providers
Access is limited to people and providers who need it for the purposes above. These may include Hostinger for hosting, our email provider for correspondence, Discord for internal support coordination, security scanning tools, professional advisers and public authorities where disclosure is legally required.
Messages and attachments may be relayed to email and a private Discord support area. Attachments are validated and may be malware-scanned before onward transmission. Providers process data under their own security and retention controls as well as the contractual safeguards available to us.
6. Automation and AI assistance
Where optional AI assistance is enabled, selected support content may be sent to the configured AI provider to prepare an internal draft. Direct identifiers and other sensitive values are redacted where the system can identify them, and the draft must be reviewed by a person before any client reply.
No decision with legal or similarly significant effect is made solely by automated means. AI output is not sent directly to a client without human action.
7. International transfers
Some providers may process data outside the United Kingdom or European Economic Area. Where required, we rely on an adequacy regulation or decision, approved contractual clauses such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses, and proportionate technical and organisational measures.
8. Retention
Website ticket conversations remain available to the visitor for 90 days after the last exchange or resolution. The support database, messages and attachments may be retained for up to 3 years after the last contact, then deleted through the application's retention process unless a legal claim or obligation requires longer.
Copies relayed to email or Discord follow the retention controls applied to those business accounts and may not be removed by the application's database purge. Quote records with no resulting project are normally reviewed after 12 months. Contract, invoice and accounting records may be retained for up to 6 years, or longer where law or an active dispute requires it. Security logs are kept only as long as reasonably necessary for operations and investigation.
9. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, data portability, or object to processing based on legitimate interests. You may withdraw consent where processing is based on consent. These rights can be limited where data must be retained by law, for another person's rights, or for legal claims.
We normally respond within one month after receiving a valid request. We may ask for proportionate information to confirm identity and may extend the period where the law permits for a complex request.
10. Complaints
Please contact us first at info@digifyit.co.uk. You may also complain to the UK Information Commissioner's Office at ico.org.uk. If EU data-protection law applies, you may contact the supervisory authority in your habitual residence, workplace or place of the alleged infringement.
11. Security and children
We use access controls, private attachment storage, signed download links, input validation, rate limits, malware-scanning controls and encrypted transport where available. No internet service is completely risk-free, so please send only information necessary for the request.
The website and services are intended for organisations and adults. We do not knowingly seek personal data from children. A parent or guardian who believes a child has submitted data should contact us.
12. Changes
We may update this policy when services, providers or legal requirements change. Material changes will be highlighted where appropriate, and the current version is identified by the date above.