Privacy notice
What personal data we collect, why, and your rights (UK GDPR).
Draft — to be reviewed by a qualified UK solicitor before taking paying customers. Bracketed items still need completing.
Last updated 8 October 2026
Who we are
[Legal entity name to be confirmed], trading as DigiFront (registered office [registered office address]; ICO registration [ICO registration number]), is the data controller for personal data collected through this website and for running our customer accounts.
Contact our privacy lead at privacy@digifront.example. Our service is run from the UK and Spain; both apply equivalent data-protection standards.
What we collect, why, and our lawful basis
- Enquiries — your name, business details, contact details and message — to reply and discuss our services (legitimate interests).
- Customers — account, billing and onboarding information — to provide the service you've bought (contract) and keep accounting records (legal obligation).
- Marketing emails — only if you tick the separate, optional box; withdraw any time (consent). We keep a record of your consent.
- Demo assistant chats and demo bookings — to run the demonstration (legitimate interests). Please don't share sensitive information.
- Demo call-backs — your first name and mobile number, to place the one demo call you asked for (consent). The call is with an AI and may be recorded and transcribed.
- Confirmation texts — if you give a UK mobile when booking or leaving a message, we text you a confirmation (legitimate interests). These are service messages, never marketing.
- Anonymous statistics — page views and clicks, with no cookies and no personal identifiers.
When we act for our customers
When we run a website, assistant or receptionist for one of our business customers, that business is the controller of their customers' data and we process it on their behalf under our Data Processing Agreement. Please contact the business directly about that data; we'll help them respond.
Who we share data with
Trusted service providers (sub-processors) that help run the platform — hosting, payments, AI, voice, telephony, texting and email. The full list, what each does and where it processes data is on our Sub-processors page.
Some providers are based in the USA. Transfers are protected by the UK International Data Transfer Addendum or the UK–US Data Bridge, as applicable.
How long we keep it
- Unconverted enquiries: 24 months.
- Customer and billing records: 6 years after the contract ends (tax law).
- Demo chats, demo bookings and demo call records: 90 days.
- Call recordings for customers' receptionists: 90 days; call summaries: for the life of the account.
- Text-message logs: 12 months.
Your rights
You can ask for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, ask us to transfer it, and withdraw consent at any time. Use the form on our Your data rights page or email us; we'll respond within one month.
You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) — though we'd appreciate the chance to put things right first.
Security
Data is encrypted in transit, stored on access-controlled servers, backed up nightly and only accessible to people who need it. Card and bank details are handled by Stripe and GoCardless and never reach our servers.