00%
UK GDPR & PECR Compliance

Privacy & Cookie Policy

We are dedicated to safeguarding your privacy and ensuring your personal data is handled securely in accordance with UK GDPR and PECR.

Effective Date July 23, 2026
Region Scope United Kingdom (UK GDPR & PECR)
Data Controller Digifier
DPO Email hello@digifier.co.uk

1. Introduction

Welcome to Digifier ("we", "us", "our"). We value the privacy of our visitors and clients. This Privacy & Cookie Policy explains how we collect, store, share, and protect personal data collected from individuals visiting our website and interacting with our services, in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

2. Who We Are (Data Controller)

For the purpose of UK GDPR and PECR, the Data Controller is:
Digifier
298, Romford Road, Forest Gate, London E7 9HD
Email: hello@digifier.co.uk
Phone: +44-07867244213

3. Information We Collect & Why

We only collect and process personal data when we have a valid legal basis under UK GDPR to do so. The data we collect includes:

  • Contact Enquiries: Your name, email address, phone number, and service interest when submitted through our Contact Form. Legal Basis: Steps before entering a contract, or Legitimate Interest (to respond to your enquiries).
  • Newsletter Signups: Your email address when subscribing to receive newsletters, updates, and design tips. Legal Basis: Consent.
  • Analytical Cookies: Usage metrics, traffic patterns, and page flow parameters. Legal Basis: Consent (opt-in).
  • Strictly Necessary Cookies: Security parameters (such as CSRF protection tokens), session persistence flags, and layout preferences. Legal Basis: Legitimate Interest (strictly necessary to deliver the requested digital services).

4. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you hold the following rights regarding your personal data:

  • Right to Access: You can request copy of the personal data we hold about you.
  • Right to Rectification: You can request corrections to incorrect or incomplete information.
  • Right to Erasure (To Be Forgotten): You can request deletion of your personal data under certain conditions.
  • Right to Restrict Processing: You can restrict the processing of your data.
  • Right to Object: You can object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact our Data Protection Team at hello@digifier.co.uk. We will respond within one calendar month.

Users have the right to lodge a complaint with the **Information Commissioner's Office (ICO)**, the UK's independent data protection authority, if they believe their data protection rights have been infringed. For more information or to lodge a complaint, please visit the ICO Website (ico.org.uk).

5. Cookie Policy

Our website utilizes cookies to deliver secure user interfaces, remember consent settings, and evaluate performance. You can review the categories of cookies we use below and modify your preferences at any time.

6. Data Retention

We retain personal data only for specific, limited durations aligned with the purpose of collection and statutory legal demands:

  • Contact Enquiries: Retained for 12 months from the date of resolution to coordinate subsequent customer relations.
  • Customer Records: Retained for 6 years after contract termination in compliance with UK tax, legal, and accounting regulations.
  • Newsletter Subscriptions: Retained until the withdrawal of consent (unsubscribing). Upon unsubscribing, the contact email is immediately blocked from campaigns.

7. Third-Party Processors & Sub-processors

We share data with trusted third-party providers who act as data processors to deliver secure operations. These sub-processors are bound by data processing agreements to keep your data confidential:

8. International Data Transfers

Personal data may be transferred to and processed by our third-party processors outside the United Kingdom (specifically the United States). When transferring data internationally, we ensure appropriate safeguards are implemented in compliance with UK GDPR. These safeguards include the execution of standard contractual clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum (IDTA), guaranteeing a level of privacy equivalent to UK law.

9. Data Security

We employ HTTPS encryption for all traffic to protect data transit. Your data is stored on secure, encrypted servers. Client-side cookies set by JavaScript use the Secure flag (when run on HTTPS) and are configured with SameSite=Lax to prevent cross-site leakage. Crucial session parameters are locked via HttpOnly headers configured server-side.

10. Updates to This Policy

We may modify this policy periodically to reflect operational, legal, or regulatory changes. The date of the last update is indicated at the top of this document. Continued use of our site indicates acceptance of the updated policy terms.