Trust & transparency

DIGIA BOOSTER LTD — Privacy Notice

We use the information you choose to provide to understand your needs, respond to your enquiry and, if agreed, deliver and administer our services. Our assessment is hosted by Wix and leads to human review, not an automatic paid contract. We do not sell enquiry details, enrol you in marketing through an assessment, or send your assessment to external generative-AI models. This notice explains the records, purposes, recipients, retention and choices involved.

1. Who is responsible and how to contact us

DIGIA BOOSTER LTD, company number 17224846, is the controller of the personal information it uses to run this website, handle enquiries and manage its customer relationships. Our registered office is First Floor, Swan Buildings, 20 Swan Street, Manchester, M4 5JW, United Kingdom. Contact hello@digiabooster.co.uk or telephone/WhatsApp +44 7398 704067 for a privacy question, rights request or complaint. You may also write to the registered office; it is not a walk-in consultation venue.

This notice covers our own business enquiries and service administration. If an engagement involves processing information held by a client about other people, the parties must separately identify their roles, permitted data, systems and processing terms before that work begins. A general enquiry or agreement does not authorise us to import a client's customer database.

2. Information we receive and where it comes from

You provide the contact and business context entered in the assessment or a message: your name, email address, telephone number where supplied, business name or website where supplied, and the business needs you describe. Qualification answers may cover your current situation, goals, services of interest, indicative budget, timing, available resources and consultation preference. We also retain the relevant acknowledgement wording or version, your acknowledgement choices and submission time. Fields marked as required on the form are needed to process that route; optional fields are your choice.

When a conversation develops, records may include correspondence, consultation arrangements, staff findings, strategy and proposal drafts, the exact versions reviewed or agreed, approval and acceptance records, delivery evidence, invoices, payment status and refund or complaint correspondence. Payment records identify the order, amounts and transaction reference; do not send full card details, bank passwords or security codes through the assessment, email or WhatsApp.

Wix supplies submission and contact identifiers, status and technical event information used to connect the correct enquiry to our private staff workflow. When you load the website or Wix assessment, the hosting service receives technical request information such as IP address, browser/device information, requested address and time. Wix may also process information for its own platform purposes described in its privacy notice.

Most enquiry information comes directly from you or a representative you have authorised. If we examine a business website or public company information in response to your request, we use information relevant to that request, record the source and explain material findings. We do not buy personal contact lists for this enquiry process. Please do not include health information, identity documents, passwords, children's information or other people's confidential records. If a task genuinely needs restricted information, we agree a suitable separate route first.

3. The assessment and human-review process

The assessment link opens a Wix-hosted form. The public website does not attach or prefill your answers into that link. You decide whether to submit the form. Submitted information is held in Wix's form/contact services; our private workflow uses linked identifiers and relevant review records to manage the enquiry. Its journal records changes, proposal versions, content fingerprints and staff approval so the team can check which content was reviewed. An identifier or fingerprint is not treated as anonymous simply because it omits your name.

Rules-based preparation can organise the qualification choices into a staff draft. A person reviews the request and any findings, strategy, scope, price and proposal before deciding the next step. Our assessment process does not make a solely automated decision with legal or similarly significant effects. A rules-based summary is not a website audit or a verified statement about your business. You can ask us to correct information or explain a recommendation.

We do not use live generative AI to analyse your assessment, and do not send assessment answers or contact details to an external generative-AI model in this workflow. Submitting an assessment is not a purchase, appointment confirmation, contract acceptance or marketing subscription. Internal staff approval is not your acceptance and does not by itself send an offer or authorise payment. A consultation and any paid engagement are confirmed separately.

4. Why we use information and our lawful bases

Requested steps before a contract and performance of a contract: where you are the individual who may contract with us, we use the information necessary to respond to your requested assessment or quote, arrange a requested consultation, agree scope and perform the service. This is the contract basis under Article 6(1)(b) UK GDPR. It is not a basis for unrelated advertising or collecting information we do not need.

Legitimate interests: for contacts acting for a company, general enquiries, proportionate staff review, business correspondence, security, preventing duplicate or fraudulent requests, and establishing or defending legal claims, we rely where appropriate on Article 6(1)(f). Our interests are to operate a responsive, secure business and maintain an accurate account of agreed work. We consider necessity and the effect on your rights, limit access and retention, and you can object. We do not treat our commercial preference as automatically overriding your interests.

Legal obligations: we keep required accounting/tax information and deal with legally required disclosures, information-rights requests and regulatory duties under Article 6(1)(c). Only information necessary for the relevant obligation is retained or disclosed. Consent: if we later offer optional marketing or another activity that requires consent, we ask separately and explain how to withdraw it. A privacy-notice acknowledgement confirms that the notice was presented; it is not blanket consent to every use.

You are not generally required by law to make an enquiry. Without a usable reply route or enough information to understand your request, we may be unable to respond or prepare a meaningful proposal. You can use email or another contact option instead of the online assessment. If a later contract or invoice needs particular information, we explain that requirement at the relevant step.

5. Who can receive the information

Access within Digia Booster is limited to people who need the information for the enquiry, agreed service, administration or security. Wix provides the hosted assessment, contact services and infrastructure for the private workflow. For information Wix processes on our behalf, we act as controller and Wix acts as processor under its Data Processing Addendum. Wix uses subcontractors for services such as infrastructure, security and communications. That does not mean we have enabled every optional Wix feature.

Our business email service and, when needed for a confirmed consultation, the appointment or online-meeting provider handle the contact and communication data needed for that step. We explain the meeting route when confirming it. If you choose WhatsApp or a social link, that service also processes information under its own terms. No assessment answers are prefilled into those links. We do not automatically post your enquiry to social media or send it to another customer.

After an engagement is agreed, necessary information may be shared with an authorised contractor, accountant, professional adviser, bank or payment provider for the stated task. We limit what is shared and use appropriate confidentiality or processing terms. We may also disclose information where law requires it or where necessary and lawful to address a genuine legal claim or security incident. We do not sell personal information or authorise a contractor to use enquiry details for its own marketing.

Wix's processing terms and provider information are available at https://www.wix.com/about/privacy-dpa-users and https://support.wix.com/en/article/list-of-wixs-sub-processors. Wix's own privacy notice is at https://www.wix.com/about/privacy. Contact us if you need the relevant documents in an accessible form or details of a provider used for your particular engagement.

6. Website requests, cookies and external services

Our public website does not add advertising pixels, marketing analytics, session replay or application-set browser storage. Loading a page still sends technical requests to its host; it does not mean no personal information is processed. The Wix-hosted assessment is a separate service and may use cookies or similar technologies for its operation, security and the platform purposes explained by Wix. This notice does not label every provider cookie as strictly necessary or promise a cookie-free visit.

Where an optional use requires consent, it must remain off unless you choose it through the applicable consent controls. We do not enable new optional tracking for Digia Booster merely because you submit an assessment or acknowledge this notice. Browser settings can also restrict cookies, although that may affect a service's operation. External websites and communications services have their own information and choices; following a link does not authorise us to share your assessment answers with it.

7. Processing outside the United Kingdom

Wix and its providers operate internationally. Wix's published Data Processing Addendum describes an initial transfer to Wix.com Ltd. in Israel and onward processing by providers in other countries. This is a description of the provider's arrangements, not a claim that your records are stored in a particular data centre or only in the UK. Its current subprocessor list identifies provider locations and transfer mechanisms.

For the initial transfer to Wix.com Ltd. in Israel, we rely on the UK's adequacy regulations and, where the EU GDPR applies, the European Commission's adequacy decision for Israel. For onward restricted transfers not covered by an applicable adequacy arrangement, Wix describes using standard contractual clauses together with additional safeguards; the appropriate UK-approved transfer mechanism is required where UK rules apply. Wix's DPA and subprocessor information explain its arrangements. We must assess any additional provider or transfer we introduce; your acknowledgement of this notice is not a substitute for those safeguards. Ask hello@digiabooster.co.uk for information or a copy of the safeguards relevant to your data, subject to lawful redaction of unrelated or confidential material.

8. How long we keep information

We keep information only for a stated purpose and use the schedule below for records we control. It is a staff-administered retention policy, not a claim that an automatic deletion system has been installed. A shorter period applies when the information is no longer needed. A specific legal duty or documented dispute may justify retaining a limited record for longer, as explained in section 9.

Enquiries, assessment answers, unaccepted proposals and consultation-only records: 12 months after the last meaningful contact about the request, if no engagement is agreed. This allows a reasonable period to revisit the same enquiry. An internal status update or routine reminder does not restart the period. We remove unnecessary contact duplicates and delete or irreversibly anonymise the associated form, contact, review-journal and correspondence records when due, unless a documented exception applies.

Spam, rejected duplicate submissions and standalone security/troubleshooting logs under our control: normally 90 days after receipt or creation. We retain only the limited details needed for a genuine incident or to prevent repeated abuse for longer, with a recorded reason and review date. Necessary contractual approval or delivery evidence is part of the contract record below, not an indefinite general security log.

Agreed proposals, identified policy versions, acceptance and necessary approval/delivery records, essential contractual correspondence and related settlement records: during the engagement and normally for six years after its end or final settlement, whichever is later, to establish what was agreed and address claims. We keep only relevant evidence rather than all working material. A live claim, legal requirement or a different applicable limitation period may require a justified extension.

Accounting and tax records, including invoices and payment/refund records: six years from the end of the company financial year they relate to, or longer where the relevant tax or accounting rules require it. This accounting period does not justify keeping every initial enquiry or unrelated document for six years.

Superseded working files and unnecessary copies: normally removed within 90 days after final delivery or handover, once any agreed review is resolved. Information needed for an ongoing support service remains only while needed for that service or the limited evidence periods above. Client-held personal datasets, access credentials or restricted records require their own agreed handling and return/deletion schedule; they are not automatically placed under the six-year contract-record rule.

9. How retention, deletion and exceptions are managed

A responsible staff member will review records due for disposal each month and arrange deletion or irreversible anonymisation within 30 days after the applicable retention date. The review covers linked form submissions, contact records, private workflow records and working copies within our control, including relevant correspondence. We record the category, disposal decision, date and any exception without creating an unnecessary new copy of the underlying personal information. Information-rights requests are handled within their own legal deadlines, not postponed until a monthly review.

If a complaint, legal claim, investigation or specific legal duty requires a hold, we restrict it to necessary records, record the reason and next review date, and review continuing need at least every six months. An unresolved commercial balance is not a blanket reason to keep unrelated personal information. When the justification ends, disposal resumes. Replacing a name with an identifier or retaining a content fingerprint that remains linkable to a person is not treated as irreversible anonymisation.

Deletion must consider backups and processor-held copies as well as the active screen. We use the available provider deletion process and seek the processor's assistance where needed. If a backup cannot be selectively erased immediately, the information must remain beyond ordinary use and any necessary restoration must reapply the deletion decision. Wix's own system-log and backup cycles are governed by its service arrangements; this schedule does not claim a verified immediate expiry for every provider copy. We explain relevant limitations when responding to a request rather than claiming deletion we cannot confirm.

10. Protecting information

We use restricted staff access and a private review workflow, and limit the information used at each step. Staff must use approved access methods and only disclose material needed for the task. We do not ask you to send passwords or full payment-card information in the assessment. If information is inaccurate, misdirected or unnecessarily sensitive, tell us promptly so we can address it.

No website or communications service can be guaranteed completely secure. We assess incidents, take appropriate protective steps and make notifications where the law requires them. Our use of a provider does not give Digia Booster a certification or compliance guarantee belonging to that provider.

11. Your rights and complaints

Depending on the processing and applicable law, you can ask for access to your personal information, correction, deletion or restriction, and request portability of information where the legal conditions apply. If we rely on consent, you can withdraw it without affecting processing that was lawful before withdrawal. These rights are not all absolute: for example, we may need to retain a limited invoice or claim record. We explain any restriction rather than treating the whole record as exempt.

Your right to object: You can object at any time to processing based on our legitimate interests, for reasons relating to your particular situation. You may tell us verbally or in writing using any contact route in section 1; no special form is needed. We stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or need it to establish, exercise or defend legal claims. We consider your objection individually and explain any decision to continue.

Contact hello@digiabooster.co.uk, call or write to the address in section 1. You do not need a special form or legal wording. We may ask for proportionate information to verify identity or authority and avoid disclosing someone else's records. We respond to rights requests without undue delay and normally within one month. Where the law permits extra time for complexity or multiple requests, we explain the reason and timeframe within the initial month; a permitted extension is no more than two further months. We explain any legally permitted clarification or identity-check effect on the deadline. Requests are normally free.

For a complaint about our use of information, tell us what happened and the outcome you seek using any contact route above. We acknowledge a data-protection complaint within 30 days, investigate appropriately without undue delay and communicate the outcome, keeping you informed if it needs longer. That acknowledgement period does not replace the deadline for an information-rights request made at the same time.

You can complain to the UK's Information Commissioner's Office at https://ico.org.uk/make-a-complaint or telephone 0303 123 1113. You may also have the right to complain to the supervisory authority where you live or work, including in the EEA where its data-protection law applies. You do not waive regulatory or legal rights by raising a concern with us.

12. Scope and changes to this notice

This enquiry service is intended for adults and authorised business representatives, not for collecting children's information. If you believe information about a child or another person's restricted information has been submitted, contact us so we can assess and minimise it appropriately.

This version is dated 10 September 2026. We review the notice when the actual service, providers, purposes or retention arrangements change and bring material new uses to your attention before they begin. A new notice is not permission to repurpose earlier information incompatibly or to bypass a required choice, safeguard or legal basis. The separate proposal and Terms, Refunds & Cancellation policy explain the commercial agreement; acknowledging this notice is not acceptance of paid work.