LEGAL

Privacy policy

What we collect, why we collect it, who else touches it and how to make us delete it. Written against what this site actually does.

Last updated 6 August 2026

Who is responsible for your data

The data controller is LEGAL ENTITY, trading as Digipto, registered in England and Wales with company number COMPANY NUMBER, registered office REGISTERED ADDRESS. Our registration with the Information Commissioner’s Office is ICO REGISTRATION NUMBER.

For anything about your personal data, write to privacy@digipto.io.

What we collect

When you send an enquiry: your name, email address, telephone number, the direction of the conversion you are asking about, the approximate amount, and anything you write in the message box. We also record that you ticked the consent box.

When you use the chat: the messages you send, the page you started from, the page that referred you, your browser’s user-agent string, and the country your request appears to come from. If you give contact details in the conversation, we take them from it and hold them the same way as an enquiry.

How you found us: campaign parameters in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the Google and Meta click identifiers gclid and fbclid, the referring website, and the page you landed on. This is how we tell which advertising is worth paying for.

If we go on to work together: the identity and source-of-funds records described in our identity checks page, and our correspondence with you.

We do not store your IP address against an enquiry, and we do not buy personal data about you from anyone else.

The score attached to your enquiry

Every enquiry is given a number and a label — hot, warm or cold — so that the team knows which to answer first. It is worked out from the amount you indicated, whether you gave a phone number, whether your email is a work address, whether you asked to speak to a person, and where you came from.

No decision about you is made by that score alone. It sets the order of a queue; a person reads every enquiry and decides what happens next. You can ask us what your enquiry scored and why — each point carries a written reason, so we can tell you exactly.

Why we are allowed to hold it

  • Consent — for contacting you about the enquiry you sent, and for any advertising or analytics cookies you accept. You can withdraw it at any time.
  • Legitimate interests — for running and securing the site, preventing spam and abuse, and understanding which advertising works. We have weighed this against your interests and use the minimum that answers the question.
  • Legal obligation — for anti-money-laundering identity and record-keeping duties, which apply once we act for you and override a request to delete.
  • Performance of a contract — for carrying out a conversion you have instructed.

Who else touches it

We do not sell your data and we do not pass it to anyone for their own marketing. These suppliers process it on our instructions in order to run the service:

  • Vercel — hosts the site and serves every page.
  • Supabase — the database holding enquiries and chat, and the connection that delivers chat messages as they are sent.
  • Anthropic — the assistant that answers first in the chat. Your messages are sent to its API to produce a reply. Do not put identity documents, account numbers or passwords into the chat.
  • Resend — sends our emails, including the reply to your enquiry.
  • Meta and Google — only if you accept advertising cookies. Decline and no tag from either is ever loaded.

Some of these process data outside the UK. Where they do, transfers rely on the UK’s international data transfer agreement or equivalent safeguards. CONFIRM TRANSFER MECHANISM PER SUPPLIER

How long we keep it

  • Enquiries that go nowhere — kept for RETENTION PERIOD, then deleted. Ask us sooner and we will delete them sooner.
  • Chat conversations — kept for RETENTION PERIOD.
  • Records where we acted for you — kept for at least five years after the end of the business relationship, because anti-money-laundering law requires it. This one we cannot delete on request.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you
  • correct anything that is wrong
  • delete it, where no legal duty requires us to keep it
  • stop or limit what we do with it
  • hand it over in a portable format
  • stop relying on legitimate interests, where you object

Write to privacy@digipto.io. We will respond within one month. There is no charge.

If you are not satisfied with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.

How it is protected

The site is served over HTTPS. Chat sessions are keyed by a random token in a cookie your browser will not let a script read. Staff sign in to the console with their own account and password. Access to enquiries is limited to the people who answer them.

No system is perfect. If a breach affects your rights we will tell you and the ICO within the time the law requires.

Children

This service is not for anyone under 18 and we do not knowingly collect data about children. If you believe a child has sent us their details, tell us and we will delete them.

Changes to this policy

If we change what we collect or who processes it, we update this page and the date at the top. Material changes affecting a live enquiry will be told to you directly rather than left here to find.