Privacy policy.
This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have. Compliant with GDPR (EU/UK), CCPA/CPRA (California), DPDP Act 2023 (India), LGPD (Brazil), Privacy Act 1988 (Australia), Privacy Act 2020 (NZ), PIPEDA (Canada), PDPA (Singapore), and PDPL variants (UAE, Saudi).
Data we collect
We collect three categories of personal data:
- Information you provide — name, email, company, phone, contact preferences, audit data, billing details. Only what's necessary for the engagement.
- Information from your use of our site — IP address, device, browser, pages viewed, referrer, time on page. Plausible (cookieless, GDPR-safe). Microsoft Clarity + GA4 only after consent (see Cookie Policy).
- Information from third parties — referrals, public profile information (LinkedIn, GitHub) if you grant access for partnership purposes.
How we use it
We use personal data to:
- Deliver the services you've contracted us for
- Send transactional emails about your engagement
- Send marketing emails (only if you've opted in — separately from transactional)
- Improve our site and service quality
- Comply with legal obligations
Lawful bases (GDPR / UK GDPR)
For EU and UK data subjects, we process under these lawful bases:
- Performance of contract — engagement delivery, billing, support.
- Legitimate interests — site analytics (cookieless), service improvement.
- Consent — non-essential cookies (Clarity, GA4), marketing emails.
- Legal obligation — tax records, anti-money-laundering checks.
Who we share with
We share personal data only with sub-processors listed at /legal/sub-processors/ — and only as required to deliver the service you've contracted. We do not sell personal data. CCPA "Do Not Sell or Share" preference is honoured globally via the cookie banner toggle.
How long we keep it
Engagement data: retained for 7 years after engagement ends (statutory retention requirements). Marketing data: retained until you unsubscribe + 30-day grace. Analytics data: 14-month rolling window (GA4 default), Clarity 30 days.
Your rights
Depending on your jurisdiction you have the right to access, correct, delete, port, restrict processing, or object to processing. California residents have additional CCPA/CPRA rights including "right to know," "right to delete," and "right to opt out of sale/share." Indian residents have DPDP rights including consent withdrawal and grievance redressal.
Email dpo@digitalmarketingagencyfor.com to exercise any of these. We respond inside the statutory window for your jurisdiction (30 days GDPR, 45 days CCPA, etc.).
International transfers
We operate from the US, UK, EU, India, and APAC. Personal data may be transferred between these jurisdictions. EU/UK transfers use Standard Contractual Clauses (SCCs) + UK Addendum where applicable. India transfers comply with DPDP Act 2023 cross-border provisions.
Children's data
Our services are B2B and not directed at children under 16. We do not knowingly collect children's data. If you believe we have, please email the DPO and we will delete it within 30 days.
Changes
Material changes are posted here with an updated effective date and announced via email to active engagement contacts.
Contact + DPO
Data Protection Officer: dpo@digitalmarketingagencyfor.com. We are also reachable at hello@digitalmarketingagencyfor.com for general questions.