Define Digital Limited

Privacy Policy

Effective date: 4 August 2026

1. Who we are

Define Digital Limited (“we”, “us”, “our”) builds bespoke business systems — data platforms, web apps and mobile apps. This policy explains how we handle personal data when you use this website or contact us through it.

We are registered in England and Wales (Company Number 10671700) and are the data controller for personal data collected through this website.

Define Digital Limited
Unit 6, The Mead Business Centre
Mead, Hertford SG13 7BJ
Email: hello@definedigital.uk


2. What we collect

When you use the contact form

Name, email address and your message (required); company name, telephone number, and whether you’re interested in a retainer (optional). We use this to respond to your enquiry — nothing else. No newsletter, no data sold.

Automatically

Our hosting provider collects standard technical logs — IP address, browser type, pages requested — for security and to keep the site running. We also use Cloudflare Web Analytics to count page views and to see which pages are read and where visitors arrived from. It sets no cookies, stores nothing on your device, and does not fingerprint you or follow you between sites or sessions. We run no advertising trackers.

Theme preference

If you switch between light and dark mode, your choice is stored in your browser’s local storage. It never leaves your device and identifies nothing about you.


3. How we use it and why we’re allowed to

PurposeLegal basis
Responding to your enquiry and providing quotationsLegitimate interests / steps prior to a contract
Delivering services if you become a clientPerformance of a contract
Keeping the website secure and preventing spamLegitimate interests
Complying with legal obligationsLegal obligation

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms.


4. Where your data goes

When you submit the contact form, your enquiry is:

  • received by our workflow system and stored in our database, hosted by Supabase in London, United Kingdom;
  • sent to us as an email notification so we can reply.

The website itself is served by Vercel, whose global edge network may process technical request data (such as your IP address) outside the UK. Vercel participates in recognised international transfer frameworks, and transfers are covered by appropriate safeguards including the UK Addendum to the EU Standard Contractual Clauses.

Our analytics beacon is served by Cloudflare, which acts as our processor for site measurement. As with any request over the internet, that request carries your IP address in transit; Cloudflare does not use it to identify you or to build a profile, and no identifier is stored on your device.

We may also share personal data with professional advisers (accountants, lawyers) where necessary, and with regulators such as HMRC or the ICO where required by law.

We require all service providers to protect your data and process it only on our instructions. We do not sell personal data to anyone.


5. How long we keep it

  • Enquiries that don’t proceed: 2 years, then deleted
  • Client records and project files: 7 years after the end of the business relationship (legal and accounting requirements)
  • Server logs: retained by our hosting provider for a short rolling period

After the applicable period, data is securely deleted or anonymised.


6. Security

Data in transit is encrypted (TLS). Access to our systems is restricted and protected by access controls, and our database provider maintains its own certified security programme. No internet transmission is completely secure, but we take reasonable and proportionate measures to protect your data.


7. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict, and object to our processing of your personal data, and to data portability. To exercise any of these rights, email hello@definedigital.uk — we respond within one month.

If you believe we’ve mishandled your data, you can complain to the Information Commissioner’s Office:

Information Commissioner’s Office
ico.org.uk · 0303 123 1113


8. Cookies

This website does not use cookies. Your theme preference is stored in local storage on your own device, which is not transmitted to us or anyone else.

Our analytics is deliberately cookieless: it stores nothing on your device and uses no fingerprinting, so there is nothing here that requires your consent under the Privacy and Electronic Communications Regulations. That is why you are not shown a cookie banner. If that ever changes, we will update this policy and ask for consent first.


9. Third-party links

Where this site links elsewhere, those sites have their own privacy practices. We’re not responsible for them.


10. Changes to this policy

Updates are posted on this page with a revised effective date. Material changes will be flagged more prominently.


If you’re a client and need a Data Processing Agreement covering systems we build or host for you, contact us — that relationship is covered by a separate agreement, not this policy.