Back to DigiAOS

Privacy and cookies

What personal data we collect on digiaos.com and in our work with business contacts, why, who helps us process it, and how you stay in control.

Effective and last updated: 27 September 2026 · Version 1.0

The short version

1. Who we are

DigiAOS is operated by DigiAOS LLC, a limited liability company registered in Wyoming, USA, [registered address] (“DigiAOS”, “we”, “us”). We are the controller of the personal data described here. Because we offer our services to people in the EU and the UK, and, with your consent, measure how visitors use our site, the EU GDPR and the UK GDPR apply to how we handle their data.

Our representative in the EU (GDPR Article 27): [EU representative name, address, email]. Our representative in the UK (UK GDPR Article 27): [UK representative name, address, email]. You and data protection authorities can contact them instead of us about any data protection question.

Privacy contact: info@digiaos.com. We are not required to appoint a data protection officer. The person responsible for privacy at DigiAOS can be reached at the same address.

This policy covers our website, our contact form, our emails, and how we handle business contacts (prospects, clients and partners). When we process data on behalf of a client as part of our services, the client is the controller and our data processing agreement with them applies instead.

2. What we collect and why

For each purpose, this table shows what data we use, the legal basis under the EU and UK GDPR, and where to find how long we keep it.

PurposeDataLegal basis
Answering your enquiryEmail address, message, anything else you choose to send, and the dateSteps before a contract at your request (Art. 6(1)(b)), or our legitimate interest in replying to business enquiries (Art. 6(1)(f))
Managing business relationships (CRM)Name, company, role, work email and phone, notes of our conversations, deals and meetingsLegitimate interest in running and growing our business (Art. 6(1)(f)); contract (Art. 6(1)(b)) for clients
Delivering services, invoicing and accountingContact and billing details, contract and payment recordsContract (Art. 6(1)(b)); our legitimate interest in meeting the tax and accounting rules that apply to us (Art. 6(1)(f))
Newsletter and marketing emailsEmail address, name, company, sign-up record, whether emails are opened or links clickedYour consent (Art. 6(1)(a)); for existing clients, our legitimate interest in marketing similar services (Art. 6(1)(f) and the ePrivacy “soft opt-in”), always with an easy opt-out
Website analyticsPages viewed, clicks, device and browser type, approximate location (country or city), referring site, cookie IDsYour consent (Art. 6(1)(a))
Advertising and measuring adsCookie and advertising IDs, ad click IDs, pages visited, conversions such as sending the form, and hashed (scrambled) contact details if you consentYour consent (Art. 6(1)(a))
Session recordings and heatmapsClicks, scrolls, mouse movement, pages and device data. Text you type into form fields is maskedYour consent (Art. 6(1)(a))
Security and spam preventionIP address in server logs; a one-way hash of your IP address when you send the formLegitimate interest in keeping the site and our mailbox secure (Art. 6(1)(f))
Legal claims and complianceRecords needed to establish, exercise or defend legal claims, and proof of consentLegitimate interest (Art. 6(1)(f)); for proof of consent, our obligation under the GDPR (Art. 6(1)(c) and Art. 7(1))

Where the data comes from

Mostly from you. We also receive business contact details from people who introduce you to us, from events, and from public professional sources such as company websites and business registers. If we add you to our CRM from such a source, we tell you within a reasonable period and at the latest one month after we obtain your details, or when we first contact you if that is sooner. You can object at any time.

Legitimate interests we rely on

Replying to enquiries, building and maintaining business relationships, marketing our services to businesses, and keeping our systems secure. We weigh these against your rights and never use them for cookies or tracking, which always need your consent.

Do you have to give us data?

No. But without an email address we can’t reply to you, and without contract and billing details we can’t work together.

3. Cookies and similar tools

Cookies are small files a website stores in your browser. Similar tools include pixels, tags, local storage and scripts that read information from your device. We group ours into three categories. Only strictly necessary ones run without your consent.

Strictly necessary (always on)

NameProviderPurposeDuration
cookieyes-consentDigiAOS via CookieYes (first party)Remembers your cookie choices12 months

The contact form sets no cookies. Our fonts are hosted on our own server, so loading the site sends nothing to font providers.

Analytics (only with your consent)

NameProviderPurposeDuration
_gaGoogle Analytics 4 (first party)Tells visits from the same browser apartUp to 2 years
_ga_<ID>Google Analytics 4 (first party)Keeps track of the current sessionUp to 2 years
_clckMicrosoft Clarity (first party)Recognises the same browser across visitsUp to 1 year
_clskMicrosoft Clarity (first party)Joins page views into one session recording1 day
CLID, MUIDMicrosoft Clarity / Bing (third party)Identifies the browser across Microsoft services and sites; Microsoft may also use it for advertisingUp to 1 year

Marketing (only with your consent)

NameProviderPurposeDuration
_gcl_auGoogle Ads (first party)Measures conversions from Google ads90 days
_gcl_awGoogle Ads (first party)Stores the ad click ID so a conversion can be credited90 days
IDE, test_cookieGoogle (doubleclick.net, third party)Remarketing and ad measurement; checks whether cookies work13 months; 15 minutes
_fbpMeta Pixel (first party)Identifies the browser for ad delivery and measurement90 days
_fbcMeta Pixel (first party)Stores the click ID from a Meta ad90 days
frMeta (facebook.com, third party)Ad delivery, measurement and relevance90 days
li_sugr, bcookie, lidc, UserMatchHistory, AnalyticsSyncHistory, li_fat_idLinkedIn Insight Tag (mostly third party)Measures LinkedIn ads, builds ad audiences, routes requestsFrom 24 hours to 1 year
sib_cuidBrevo (first party)Identifies the browser; if you are a subscriber and have clicked one of our emails, links your visits to your newsletter contactUp to 6 months

Not every tool above is active at all times. We switch tools on and off as our marketing needs change, and we keep this list up to date. Browsers such as Safari and Chrome may shorten these lifetimes. Google Tag Manager, which loads the other tools, sets no cookies of its own.

5. Emails and newsletters

We send newsletters and marketing emails with Brevo. If you sign up, we ask you to confirm your address (double opt-in) and keep a record of when and how you agreed. Every email has an unsubscribe link, and unsubscribing takes effect immediately and costs nothing.

Brevo tells us whether an email was opened and which links were clicked, so we can see what is useful and stop sending what isn’t. You can avoid this by unsubscribing or by blocking images in your email app.

To existing clients, we may send information about services similar to those you bought from us without prior consent, where the law allows it. We don’t track opens or clicks in these emails unless you have consented. You can object at any time, and we will stop. We keep your address on a suppression list so we don’t email you again by mistake.

6. Who we share data with

We don’t sell personal data for money. We share it only with the providers below, with professional advisers (accountants, lawyers, auditors) under confidentiality, with authorities where the law requires it, and with a buyer or successor if our business is reorganised or sold.

ProviderWhat they do for usRoleLocation and safeguard
Hostinger International Ltd (Cyprus)Website hosting and delivery network, contact form delivery, emailProcessorWebsite server in the UK, backups in Germany; delivery network and email security sub-processors in other countries, including the US. UK: EU adequacy decision; elsewhere: Standard Contractual Clauses
Our CRM providerStores business contacts, conversations and dealsProcessorWhere the provider stores data; any transfer uses an approved safeguard
Sendinblue SAS, doing business as Brevo (France)Newsletters and marketing emailsProcessorEU; sub-processors in the US (Data Privacy Framework) and India (Standard Contractual Clauses)
Google LLC, USA (Google Tag Manager, Google Analytics 4)Loading site tools; website statisticsProcessorUS and other countries; Standard Contractual Clauses and Data Privacy Framework
Google LLC, USA (Google Ads)Ad measurement and remarketingIndependent controllerUS and other countries; Standard Contractual Clauses and Data Privacy Framework
Meta Platforms, Inc., USA; for people in the EU/EEA, Meta Platforms Ireland Ltd (Meta Pixel and Conversions API)Ad measurement and audiences on Facebook and InstagramJoint controller for collecting and sending the data; independent controller afterwardsUS and other countries; Standard Contractual Clauses and Data Privacy Framework
Microsoft Corporation, USA (Microsoft Clarity)Session recordings and heatmapsIndependent controller; Microsoft also uses the data for its own purposes as described in its Privacy StatementUS and other countries; Standard Contractual Clauses and Data Privacy Framework
LinkedIn Corporation, USA; for people in the EU/EEA and Switzerland, LinkedIn Ireland Unlimited Co. (Insight Tag)Ad measurement and audiences on LinkedInJoint controller for collection; independent controller afterwardsUS and other countries; Standard Contractual Clauses and Data Privacy Framework
CookieYes Ltd (United Kingdom)Cookie banner and consent recordsProcessorUK (EU adequacy decision); any sub-processors outside the UK and EU use Standard Contractual Clauses

Joint controllership with Meta: we are jointly responsible with Meta for collecting data through the Meta Pixel and sending it to Meta (CJEU, Fashion ID, C-40/17). Meta’s Controller Addendum sets out who does what. Meta is responsible for handling your rights over data it holds afterwards. The same applies to the LinkedIn Insight Tag and Google Ads tags: we are responsible for asking your consent and informing you before data is collected on our site; LinkedIn and Google are responsible for what they do with it afterwards and for your rights requests about it. See Meta’s Privacy Policy, Google’s Privacy Policy, Microsoft’s Privacy Statement and LinkedIn’s Privacy Policy for how they use data themselves.

7. International transfers

DigiAOS LLC is based in the United States. When you send us data directly, for example through the contact form or by email, it comes straight to us in the US. The GDPR does not count this as a transfer, but the EU and UK GDPR still apply to how we handle it.

When we pass personal data to providers in other countries, including providers in the US, we protect it with:

  • Standard Contractual Clauses approved by the European Commission (Decision 2021/914), with the UK Addendum for UK data;
  • adequacy decisions for countries the EU or UK recognise as giving equivalent protection, such as the United Kingdom (EU decision renewed until 2031) and Switzerland;
  • the EU–US Data Privacy Framework (Decision 2023/1795) and its UK and Swiss extensions, where the provider is certified. The EU General Court upheld the Framework in September 2025 and an appeal is pending at the EU Court of Justice. If the Framework falls, the Standard Contractual Clauses continue to apply.

Our team may access data from different countries, for example while travelling. They do so through the same secured systems, under the same rules. You can ask us for a copy of the safeguards that apply.

8. How long we keep data

DataHow long
Enquiries that don’t lead to work12 months after our last contact
Business contacts in our CRM3 years after our last interaction, unless you ask us to delete them sooner
Client records, contracts and invoicesFor the length of the relationship, then as long as the tax and accounting laws that apply to us require, usually up to 7 years after the end of the tax year
Newsletter subscriptionUntil you unsubscribe. Proof of consent is kept 3 years after that
Unsubscribe and objection listAs long as needed to respect your choice (email address only)
Google Analytics 4 data14 months
Session recordings (Microsoft Clarity)30 days for recordings (a random sample and any we mark as favourites up to 9 months); heatmaps and click data 9 months
Advertising data held by Google, Meta and LinkedInAccording to their own policies; our ad audiences expire after at most 540 days
Spam-protection IP hash1 hour
Server logsUp to 30 days, unless needed to investigate a security incident
Cookie consent record12 months

9. Your rights

Wherever you live, you can ask us to:

  • see the personal data we hold about you and get a copy;
  • correct data that is wrong or incomplete;
  • delete your data;
  • restrict how we use it while a question is being resolved;
  • move data you gave us to another provider in a common format;
  • withdraw consent at any time, for example in the cookie settings or by unsubscribing.

Right to object. You can object at any time to processing based on our legitimate interests. You can object to direct marketing, including any profiling for it, without giving a reason, and we will stop.

Write to info@digiaos.com. We reply within one month (extendable by two months for complex requests, in which case we tell you why). We may need to confirm your identity first. Using your rights is free, unless a request is manifestly unfounded or excessive, and we won’t treat you differently for using them. Some rights have legal limits. For example, we keep invoices and accounting records for as long as tax law requires, even if you ask us to delete them.

10. Security

The site is served only over encrypted connections (HTTPS). Access to our systems is limited to people who need it and protected by strong passwords and two-factor authentication where available. Providers are bound by data processing agreements. If a breach puts your rights at risk, we notify the relevant data protection authorities without undue delay and, where feasible, within 72 hours of becoming aware of it, tell you without undue delay where the law requires it, and follow the US state breach-notification laws that apply.

11. Automated decisions and profiling

We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects. If you accept marketing cookies, advertising platforms may use your visits to show you our ads elsewhere (remarketing) or to measure their results. You can prevent this by rejecting marketing cookies.

12. United Kingdom

If you are in the UK, the UK GDPR and the Data Protection Act 2018 give you the same rights as described above. You can complain to us first at info@digiaos.com. We acknowledge complaints within 30 days and respond without undue delay. You can also complain to the UK regulator, the Information Commissioner’s Office (ICO). From 30 September 2026 it becomes the Information Commission and is still known as the ICO. Its address is Wycliffe House, Water Lane, Wilmslow SK9 5AF; phone 0303 123 1113; ico.org.uk/make-a-complaint. Transfers from the UK to certified US companies rely on the UK Extension to the Data Privacy Framework; other transfers use the UK Addendum or IDTA.

13. United States

Depending on your state of residence and whether a law’s thresholds apply to us, you may have rights under state privacy laws such as those of California, Colorado, Connecticut, Virginia, Texas and others. We honour the following requests from all US residents regardless of thresholds.

What we collect

In the last 12 months we have collected these categories: identifiers (name, email, IP address, cookie and advertising IDs); professional information (company, role); commercial information (services discussed or bought); internet activity (pages viewed and interactions on our site, email opens and clicks); and approximate location. We collect them from you, from your device, and from public business sources, for the purposes in section 2. We keep them for the periods in section 8. We don’t collect sensitive personal information.

“Sale”, “sharing” and targeted advertising

We don’t sell personal data for money. But if you accept marketing cookies, letting Google, Meta, Microsoft or LinkedIn collect data through our site for advertising may count as a “sale”, “sharing” or “targeted advertising” under some state laws. The categories involved are identifiers and internet activity. You can opt out at any time by choosing Reject all in the cookie settings, by turning on Global Privacy Control in your browser where your state recognises it, or by emailing us. We don’t knowingly sell or share the data of anyone under 18.

Your rights

You can ask to know what we collect and how we use it, to access, correct or delete it, and to opt out of sale, sharing and targeted advertising. Email info@digiaos.com. We confirm receipt within 10 business days and respond within 45 days (extendable once by 45 days). We verify requests by matching the details you give with our records. You can use an authorised agent with your signed permission. If we refuse a request, you can appeal by replying to our answer with “Appeal” in the subject line. We decide appeals within 45 days and tell you the outcome and reasons in writing. If you disagree, you can contact your state attorney general. We don’t discriminate against anyone for using these rights.

California

In the last 12 months, if you accepted marketing cookies, we may have “sold” or “shared” (as California law defines these terms) identifiers and internet activity to advertising providers: Google, Meta, Microsoft and LinkedIn. We disclosed the categories listed above to our service providers (section 6) for business purposes. We act on opt-out requests within 15 business days. We don’t respond to Do Not Track signals. Third parties listed in section 6 may collect data about your online activity over time and across websites if you accept marketing or analytics cookies.

14. Other countries

  • EU and EEA: you can also complain to the data protection authority in the EU or EEA country where you live or work, or where the issue happened. You can find yours at edpb.europa.eu.
  • Switzerland: the revised Federal Act on Data Protection gives you the rights above. Data may be transferred to the countries listed in sections 6 and 7 under the safeguards described there. You can contact the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
  • Canada (including Quebec): tracking and advertising tools are off by default and run only if you turn them on in the cookie settings. Your data may be processed outside Canada, where different laws apply. The person responsible for protecting personal information is our privacy lead, reachable at info@digiaos.com. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information.
  • Brazil: under the LGPD you have the rights above plus the right to information about who we share data with. As a small-scale processing agent we have not appointed a data protection officer (encarregado); contact us at info@digiaos.com. You can complain to the ANPD.
  • Australia: you can complain to us first, and then to the Office of the Australian Information Commissioner (oaic.gov.au). Your data may be processed in the EU, the UK and the US.
  • Everywhere else: we apply the protections in this policy to everyone, even where local law requires less.

15. Children

Our services are for businesses. This site is not directed at children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

16. Changes to this policy

We update this policy when our tools, purposes or the law change, and review it at least once a year. The date at the top shows the latest version. If a change significantly affects how we use your data, we will tell you on this site, and by email if you are a client or subscriber. If we add new cookie categories or tools that need consent, we ask for your consent again.

17. Contact and complaints

Questions or requests: info@digiaos.com, or write to DigiAOS LLC, [registered address], USA.

If you are unhappy with how we handle your data, please tell us first so we can fix it. You also have the right to complain to the data protection authority in the country where you live or work. In the EU and EEA you can find yours at edpb.europa.eu; in the UK it is the ICO (section 12).