Privacy and cookies
What personal data we collect on digiaos.com and in our work with business contacts, why, who helps us process it, and how you stay in control.
The short version
- We collect what you send us (for example through the contact form or by email) and, only if you agree, data from analytics and advertising tools on this site.
- Analytics, advertising and session-recording tags stay switched off until you accept them in the cookie banner. Rejecting is as easy as accepting, and you can change your mind at any time.
- We never sell your personal data for money.
- We use trusted providers such as Google, Meta, Microsoft and Brevo. Whenever we pass your data to a provider in another country, we protect it with an approved safeguard (section 7).
- You can ask to see, correct, delete or move your data, or object to how we use it. Write to info@digiaos.com. We reply within one month.
1. Who we are
DigiAOS is operated by DigiAOS LLC, a limited liability company registered in Wyoming, USA, [registered address] (“DigiAOS”, “we”, “us”). We are the controller of the personal data described here. Because we offer our services to people in the EU and the UK, and, with your consent, measure how visitors use our site, the EU GDPR and the UK GDPR apply to how we handle their data.
Our representative in the EU (GDPR Article 27): [EU representative name, address, email]. Our representative in the UK (UK GDPR Article 27): [UK representative name, address, email]. You and data protection authorities can contact them instead of us about any data protection question.
Privacy contact: info@digiaos.com. We are not required to appoint a data protection officer. The person responsible for privacy at DigiAOS can be reached at the same address.
This policy covers our website, our contact form, our emails, and how we handle business contacts (prospects, clients and partners). When we process data on behalf of a client as part of our services, the client is the controller and our data processing agreement with them applies instead.
2. What we collect and why
For each purpose, this table shows what data we use, the legal basis under the EU and UK GDPR, and where to find how long we keep it.
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry | Email address, message, anything else you choose to send, and the date | Steps before a contract at your request (Art. 6(1)(b)), or our legitimate interest in replying to business enquiries (Art. 6(1)(f)) |
| Managing business relationships (CRM) | Name, company, role, work email and phone, notes of our conversations, deals and meetings | Legitimate interest in running and growing our business (Art. 6(1)(f)); contract (Art. 6(1)(b)) for clients |
| Delivering services, invoicing and accounting | Contact and billing details, contract and payment records | Contract (Art. 6(1)(b)); our legitimate interest in meeting the tax and accounting rules that apply to us (Art. 6(1)(f)) |
| Newsletter and marketing emails | Email address, name, company, sign-up record, whether emails are opened or links clicked | Your consent (Art. 6(1)(a)); for existing clients, our legitimate interest in marketing similar services (Art. 6(1)(f) and the ePrivacy “soft opt-in”), always with an easy opt-out |
| Website analytics | Pages viewed, clicks, device and browser type, approximate location (country or city), referring site, cookie IDs | Your consent (Art. 6(1)(a)) |
| Advertising and measuring ads | Cookie and advertising IDs, ad click IDs, pages visited, conversions such as sending the form, and hashed (scrambled) contact details if you consent | Your consent (Art. 6(1)(a)) |
| Session recordings and heatmaps | Clicks, scrolls, mouse movement, pages and device data. Text you type into form fields is masked | Your consent (Art. 6(1)(a)) |
| Security and spam prevention | IP address in server logs; a one-way hash of your IP address when you send the form | Legitimate interest in keeping the site and our mailbox secure (Art. 6(1)(f)) |
| Legal claims and compliance | Records needed to establish, exercise or defend legal claims, and proof of consent | Legitimate interest (Art. 6(1)(f)); for proof of consent, our obligation under the GDPR (Art. 6(1)(c) and Art. 7(1)) |
Where the data comes from
Mostly from you. We also receive business contact details from people who introduce you to us, from events, and from public professional sources such as company websites and business registers. If we add you to our CRM from such a source, we tell you within a reasonable period and at the latest one month after we obtain your details, or when we first contact you if that is sooner. You can object at any time.
Legitimate interests we rely on
Replying to enquiries, building and maintaining business relationships, marketing our services to businesses, and keeping our systems secure. We weigh these against your rights and never use them for cookies or tracking, which always need your consent.
Do you have to give us data?
No. But without an email address we can’t reply to you, and without contract and billing details we can’t work together.
4. Your cookie choices
- When you first visit, a banner asks for your choice. Accept all, Reject all and Choose are equally easy. Nothing is pre-selected.
- Until you accept, our analytics and advertising tags don’t fire and set no cookies (Google Consent Mode “basic” setup). Loading the page still fetches Google Tag Manager and the CookieYes banner from their servers. Like any web request, this passes your IP address and browser details to Google and CookieYes, but no tracking data is collected.
- You can change or withdraw your choice at any time through the cookie settings on this site. Withdrawing doesn’t affect processing that happened before.
- We store your choice for 12 months, then ask again. We also ask again if we add new tools or purposes.
- If your browser sends a Global Privacy Control (GPC) signal, we treat it, wherever you are in the US, as an opt-out of sale, sharing and targeted advertising. We don’t respond to “Do Not Track” signals, because there is no agreed standard for them.
- You can also block or delete cookies in your browser settings. The site works without them.
5. Emails and newsletters
We send newsletters and marketing emails with Brevo. If you sign up, we ask you to confirm your address (double opt-in) and keep a record of when and how you agreed. Every email has an unsubscribe link, and unsubscribing takes effect immediately and costs nothing.
Brevo tells us whether an email was opened and which links were clicked, so we can see what is useful and stop sending what isn’t. You can avoid this by unsubscribing or by blocking images in your email app.
To existing clients, we may send information about services similar to those you bought from us without prior consent, where the law allows it. We don’t track opens or clicks in these emails unless you have consented. You can object at any time, and we will stop. We keep your address on a suppression list so we don’t email you again by mistake.
7. International transfers
DigiAOS LLC is based in the United States. When you send us data directly, for example through the contact form or by email, it comes straight to us in the US. The GDPR does not count this as a transfer, but the EU and UK GDPR still apply to how we handle it.
When we pass personal data to providers in other countries, including providers in the US, we protect it with:
- Standard Contractual Clauses approved by the European Commission (Decision 2021/914), with the UK Addendum for UK data;
- adequacy decisions for countries the EU or UK recognise as giving equivalent protection, such as the United Kingdom (EU decision renewed until 2031) and Switzerland;
- the EU–US Data Privacy Framework (Decision 2023/1795) and its UK and Swiss extensions, where the provider is certified. The EU General Court upheld the Framework in September 2025 and an appeal is pending at the EU Court of Justice. If the Framework falls, the Standard Contractual Clauses continue to apply.
Our team may access data from different countries, for example while travelling. They do so through the same secured systems, under the same rules. You can ask us for a copy of the safeguards that apply.
8. How long we keep data
| Data | How long |
|---|---|
| Enquiries that don’t lead to work | 12 months after our last contact |
| Business contacts in our CRM | 3 years after our last interaction, unless you ask us to delete them sooner |
| Client records, contracts and invoices | For the length of the relationship, then as long as the tax and accounting laws that apply to us require, usually up to 7 years after the end of the tax year |
| Newsletter subscription | Until you unsubscribe. Proof of consent is kept 3 years after that |
| Unsubscribe and objection list | As long as needed to respect your choice (email address only) |
| Google Analytics 4 data | 14 months |
| Session recordings (Microsoft Clarity) | 30 days for recordings (a random sample and any we mark as favourites up to 9 months); heatmaps and click data 9 months |
| Advertising data held by Google, Meta and LinkedIn | According to their own policies; our ad audiences expire after at most 540 days |
| Spam-protection IP hash | 1 hour |
| Server logs | Up to 30 days, unless needed to investigate a security incident |
| Cookie consent record | 12 months |
9. Your rights
Wherever you live, you can ask us to:
- see the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- delete your data;
- restrict how we use it while a question is being resolved;
- move data you gave us to another provider in a common format;
- withdraw consent at any time, for example in the cookie settings or by unsubscribing.
Right to object. You can object at any time to processing based on our legitimate interests. You can object to direct marketing, including any profiling for it, without giving a reason, and we will stop.
Write to info@digiaos.com. We reply within one month (extendable by two months for complex requests, in which case we tell you why). We may need to confirm your identity first. Using your rights is free, unless a request is manifestly unfounded or excessive, and we won’t treat you differently for using them. Some rights have legal limits. For example, we keep invoices and accounting records for as long as tax law requires, even if you ask us to delete them.
10. Security
The site is served only over encrypted connections (HTTPS). Access to our systems is limited to people who need it and protected by strong passwords and two-factor authentication where available. Providers are bound by data processing agreements. If a breach puts your rights at risk, we notify the relevant data protection authorities without undue delay and, where feasible, within 72 hours of becoming aware of it, tell you without undue delay where the law requires it, and follow the US state breach-notification laws that apply.
11. Automated decisions and profiling
We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects. If you accept marketing cookies, advertising platforms may use your visits to show you our ads elsewhere (remarketing) or to measure their results. You can prevent this by rejecting marketing cookies.
12. United Kingdom
If you are in the UK, the UK GDPR and the Data Protection Act 2018 give you the same rights as described above. You can complain to us first at info@digiaos.com. We acknowledge complaints within 30 days and respond without undue delay. You can also complain to the UK regulator, the Information Commissioner’s Office (ICO). From 30 September 2026 it becomes the Information Commission and is still known as the ICO. Its address is Wycliffe House, Water Lane, Wilmslow SK9 5AF; phone 0303 123 1113; ico.org.uk/make-a-complaint. Transfers from the UK to certified US companies rely on the UK Extension to the Data Privacy Framework; other transfers use the UK Addendum or IDTA.
13. United States
Depending on your state of residence and whether a law’s thresholds apply to us, you may have rights under state privacy laws such as those of California, Colorado, Connecticut, Virginia, Texas and others. We honour the following requests from all US residents regardless of thresholds.
What we collect
In the last 12 months we have collected these categories: identifiers (name, email, IP address, cookie and advertising IDs); professional information (company, role); commercial information (services discussed or bought); internet activity (pages viewed and interactions on our site, email opens and clicks); and approximate location. We collect them from you, from your device, and from public business sources, for the purposes in section 2. We keep them for the periods in section 8. We don’t collect sensitive personal information.
“Sale”, “sharing” and targeted advertising
We don’t sell personal data for money. But if you accept marketing cookies, letting Google, Meta, Microsoft or LinkedIn collect data through our site for advertising may count as a “sale”, “sharing” or “targeted advertising” under some state laws. The categories involved are identifiers and internet activity. You can opt out at any time by choosing Reject all in the cookie settings, by turning on Global Privacy Control in your browser where your state recognises it, or by emailing us. We don’t knowingly sell or share the data of anyone under 18.
Your rights
You can ask to know what we collect and how we use it, to access, correct or delete it, and to opt out of sale, sharing and targeted advertising. Email info@digiaos.com. We confirm receipt within 10 business days and respond within 45 days (extendable once by 45 days). We verify requests by matching the details you give with our records. You can use an authorised agent with your signed permission. If we refuse a request, you can appeal by replying to our answer with “Appeal” in the subject line. We decide appeals within 45 days and tell you the outcome and reasons in writing. If you disagree, you can contact your state attorney general. We don’t discriminate against anyone for using these rights.
California
In the last 12 months, if you accepted marketing cookies, we may have “sold” or “shared” (as California law defines these terms) identifiers and internet activity to advertising providers: Google, Meta, Microsoft and LinkedIn. We disclosed the categories listed above to our service providers (section 6) for business purposes. We act on opt-out requests within 15 business days. We don’t respond to Do Not Track signals. Third parties listed in section 6 may collect data about your online activity over time and across websites if you accept marketing or analytics cookies.
14. Other countries
- EU and EEA: you can also complain to the data protection authority in the EU or EEA country where you live or work, or where the issue happened. You can find yours at edpb.europa.eu.
- Switzerland: the revised Federal Act on Data Protection gives you the rights above. Data may be transferred to the countries listed in sections 6 and 7 under the safeguards described there. You can contact the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
- Canada (including Quebec): tracking and advertising tools are off by default and run only if you turn them on in the cookie settings. Your data may be processed outside Canada, where different laws apply. The person responsible for protecting personal information is our privacy lead, reachable at info@digiaos.com. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information.
- Brazil: under the LGPD you have the rights above plus the right to information about who we share data with. As a small-scale processing agent we have not appointed a data protection officer (encarregado); contact us at info@digiaos.com. You can complain to the ANPD.
- Australia: you can complain to us first, and then to the Office of the Australian Information Commissioner (oaic.gov.au). Your data may be processed in the EU, the UK and the US.
- Everywhere else: we apply the protections in this policy to everyone, even where local law requires less.
15. Children
Our services are for businesses. This site is not directed at children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
16. Changes to this policy
We update this policy when our tools, purposes or the law change, and review it at least once a year. The date at the top shows the latest version. If a change significantly affects how we use your data, we will tell you on this site, and by email if you are a client or subscriber. If we add new cookie categories or tools that need consent, we ask for your consent again.
17. Contact and complaints
Questions or requests: info@digiaos.com, or write to DigiAOS LLC, [registered address], USA.
If you are unhappy with how we handle your data, please tell us first so we can fix it. You also have the right to complain to the data protection authority in the country where you live or work. In the EU and EEA you can find yours at edpb.europa.eu; in the UK it is the ICO (section 12).