Define Digital Limited
Privacy Policy
Effective date: 4 August 2026
1. Who we are
Define Digital Limited (“we”, “us”, “our”) builds bespoke business systems — data platforms, web apps and mobile apps. This policy explains how we handle personal data when you use this website or contact us through it.
We are registered in England and Wales (Company Number 10671700) and are the data controller for personal data collected through this website.
Define Digital Limited
Unit 6, The Mead Business Centre
Mead, Hertford SG13 7BJ
Email: hello@definedigital.uk
2. What we collect
When you use the contact form
Name, email address and your message (required); company name, telephone number, and whether you’re interested in a retainer (optional). We use this to respond to your enquiry — nothing else. No newsletter, no data sold.
Automatically
Our hosting provider collects standard technical logs — IP address, browser type, pages requested — for security and to keep the site running. We also use Cloudflare Web Analytics to count page views and to see which pages are read and where visitors arrived from. It sets no cookies, stores nothing on your device, and does not fingerprint you or follow you between sites or sessions. We run no advertising trackers.
Theme preference
If you switch between light and dark mode, your choice is stored in your browser’s local storage. It never leaves your device and identifies nothing about you.
3. How we use it and why we’re allowed to
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry and providing quotations | Legitimate interests / steps prior to a contract |
| Delivering services if you become a client | Performance of a contract |
| Keeping the website secure and preventing spam | Legitimate interests |
| Complying with legal obligations | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms.
4. Where your data goes
When you submit the contact form, your enquiry is:
- received by our workflow system and stored in our database, hosted by Supabase in London, United Kingdom;
- sent to us as an email notification so we can reply.
The website itself is served by Vercel, whose global edge network may process technical request data (such as your IP address) outside the UK. Vercel participates in recognised international transfer frameworks, and transfers are covered by appropriate safeguards including the UK Addendum to the EU Standard Contractual Clauses.
Our analytics beacon is served by Cloudflare, which acts as our processor for site measurement. As with any request over the internet, that request carries your IP address in transit; Cloudflare does not use it to identify you or to build a profile, and no identifier is stored on your device.
We may also share personal data with professional advisers (accountants, lawyers) where necessary, and with regulators such as HMRC or the ICO where required by law.
We require all service providers to protect your data and process it only on our instructions. We do not sell personal data to anyone.
5. How long we keep it
- Enquiries that don’t proceed: 2 years, then deleted
- Client records and project files: 7 years after the end of the business relationship (legal and accounting requirements)
- Server logs: retained by our hosting provider for a short rolling period
After the applicable period, data is securely deleted or anonymised.
6. Security
Data in transit is encrypted (TLS). Access to our systems is restricted and protected by access controls, and our database provider maintains its own certified security programme. No internet transmission is completely secure, but we take reasonable and proportionate measures to protect your data.
7. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, and object to our processing of your personal data, and to data portability. To exercise any of these rights, email hello@definedigital.uk — we respond within one month.
If you believe we’ve mishandled your data, you can complain to the Information Commissioner’s Office:
Information Commissioner’s Office
ico.org.uk · 0303 123 1113
8. Cookies
This website does not use cookies. Your theme preference is stored in local storage on your own device, which is not transmitted to us or anyone else.
Our analytics is deliberately cookieless: it stores nothing on your device and uses no fingerprinting, so there is nothing here that requires your consent under the Privacy and Electronic Communications Regulations. That is why you are not shown a cookie banner. If that ever changes, we will update this policy and ask for consent first.
9. Third-party links
Where this site links elsewhere, those sites have their own privacy practices. We’re not responsible for them.
10. Changes to this policy
Updates are posted on this page with a revised effective date. Material changes will be flagged more prominently.
If you’re a client and need a Data Processing Agreement covering systems we build or host for you, contact us — that relationship is covered by a separate agreement, not this policy.

