DigiProdPass Limited — Privacy Notice

DIGIPRODPASS LIMITED
Privacy Notice
Document reference: DPPL-PRIV-001
Document title
DigiProdPass Limited - Privacy Notice
Document reference
DPPL-PRIV-001
Version
2
Issue date
September 2025
Last reviewed
August 2026
Next review date
August 2027
Document owner
Compliance Manager, DigiProdPass Limited
Approver
Chief Operating Officer, DigiProdPass Limited
Classification
Public

Contents

1. Introduction

This Privacy Notice explains how DigiProdPass Limited (“DPPL”, “we”, “us” or “our”) collects, uses and otherwise processes personal data when you visit digiprodpass.com (the “Website”), engage with us as a prospective or existing customer, or otherwise interact with our products and services.

DPPL is the controller of the personal data described in this Notice. We process personal data in accordance with the United Kingdom General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”), the Data Use and Access Act (2025) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”). Where we process the personal data of individuals located in the European Economic Area, we also comply with Regulation (EU) 2016/679 (“EU GDPR”).

This Notice should be read together with our Cookie Policy, which sets out in detail how we use cookies and similar technologies on the Website.

2. Who we are and how to contact us

2.1 Controller

The controller of your personal data is:

DigiProdPass Limited

Registered office: First Floor, Units 8 & 9, Rutherford House, Manchester Science Park, Pencroft Way, Manchester M15 6JJ, United Kingdom

Company contact email: contact@digiprodpass.com

2.2 Data Protection Officer

DPPL has voluntarily designated a Data Protection Officer under Article 37(6) UK GDPR. Although we are not required to appoint a DPO under Article 37(1) UK GDPR, we have chosen to designate one as a matter of good practice. The DPO is the primary point of contact for any matter relating to the processing of your personal data, including the exercise of any of the rights set out in Section 8 of this Notice.

You can contact the DPO directly:

By email: dpo@digiprodpass.com

By post: Data Protection Officer, DigiProdPass Limited, First Floor, Units 8 & 9, Rutherford House, Manchester Science Park, Pencroft Way, Manchester M15 6JJ, United Kingdom

We will notify the Information Commissioner’s Office of our DPO’s contact details in accordance with Article 37(7) UK GDPR.

3. The personal data we collect

Depending on how you interact with us, we may process the following categories of personal data:

3.1 Information you provide directly

When you complete a contact form, request a demonstration, download a resource, or subscribe to a mailing list, you may provide us with: your first and last name; business email address; company or organisation name; country; job title or profession; field of activity; telephone number; and any free-text message or description you submit.

If you book an appointment or consultation through our website, we also collect your name, business email, chosen date and time, and any meeting subject or notes you provide (via Zoho Bookings).

3.2 Information collected automatically

When you visit the Website, the following may be collected automatically through cookies, similar technologies and server logs (subject to consent where required by PECR): IP address; device information (operating system, device type); browser information (type, version, language); referral URL; pages viewed; clicks; session duration and statistics; interaction events (mouse movements, scroll position, keypress events, touch events); and other usage data necessary for security, troubleshooting, and (where you have consented) analytics or behavioural targeting.

3.3 Information from third-party sources

We may receive limited contact details about you from publicly available business sources (for example, professional networking sites or company websites) where we contact you in a business-to-business capacity. Where we do, we will inform you of the source of the data on first contact, in accordance with Article 14 UK GDPR.

3.4 Special category data

DPPL does not knowingly collect, request or process special category personal data (Article 9 UK GDPR) or personal data relating to criminal convictions and offences (Article 10 UK GDPR). You are asked not to submit such data to us through the Website or any of our forms. If special category data is provided to us unsolicited (for example, within free-text message fields), we will not use it for any purpose and will delete it as soon as it is identified, unless we are required to retain it by law. In the limited circumstances where we may need to process such data (for example, to establish, exercise or defend a legal claim), we will rely on an appropriate condition under Article 9(2) UK GDPR (and, for criminal offence data, Article 10 UK GDPR together with the conditions in Schedule 1 to the DPA 2018).

4. Purposes for which we process personal data and the lawful basis for each

Lawful Bases for Processing:

We will only process (use) your personal information under the following legal bases: 

    a. Consent

• What is it?

o Consent is defined in Article 4(11):
any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

o Article 6(1)(a)
the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

    b. Contract

• What is it?

o Contract is the lawful basis we rely on where processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract.

o Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

    c. Legal Obligation

• What is it?

o Legal obligation is the lawful basis we rely on where processing is necessary for compliance with a legal obligation to which we are subject.

o Article 6(1)(c)
processing is necessary for compliance with a legal obligation to which the controller is subject;

    d. Vital Interests

• What is it?

o Vital interests is the lawful basis we rely on where processing is necessary in order to protect someone’s life.

o Article 6(1)(d)
processing is necessary in order to protect the vital interests of the data subject or of another natural person;

    f. Legitimate interests

• What is it?

o Legitimate interests is the lawful basis we rely on where processing is necessary for our legitimate interests or those of a third party, unless there is a good reason to protect your personal data which overrides those interests.

o Article 6(1)(f)
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In accordance with Article 13(1)(c)-(d) UK GDPR, the table below sets out, for each processing purpose, the categories of data we use, the lawful basis we rely on, and (where the basis is legitimate interests) the specific interest pursued.
Processing purpose
Categories of personal data used
Lawful Basis
Responding to enquiries submitted via our website forms (routed via Zoho Flow to Zoho CRM and Mailchimp)
Identification and contact details; message content; usage data.
Legitimate Interest- necessary to respond to requests and operate business
Managing enquiry, prospect and customer relationships (Zoho CRM)
Identification and contact details; company and role; interaction history.
Legitimate Interest – managing and developing our business relationships
Enabling visitors to book appointments and consultations (Zoho Bookings)
Name; business email; chosen date and time; meeting subject or notes.
Legitimate Interest, or Article 6(1)(b) where the booking is a step prior to entering a contract
Booking and conducting a product demonstration
Identification and contact details; company information; demo-specific information.
Legitimate Interest/Contract – where a demo is a step towards entering into a contract, we rely on Article 6(1)(b) (steps prior to a contract); where a demo is exploratory and not tied to a purchase, we rely on Article 6(1)(f) (legitimate interest in promoting our services).
Providing downloadable resources (eBooks, whitepapers, guides) requested by lead-form submission
Identification and contact details; company information; topic of interest.
Contract- if a use requests a resource, delivering this fulfils that request
Sending marketing emails, newsletters and product updates (via Mailchimp)
Email address; subscription preferences; engagement data (opens, clicks).
Consent- required under GDPR and PECR unless soft opt-in applies
Website analytics and performance measurement (Google Analytics 4, Ahrefs)
Online identifiers; usage data; session statistics.
Consent
Heat-mapping and session recording (Microsoft Clarity, Crazy Egg)
Online identifiers; clicks; interaction events; session duration.
Consent
Conversion tracking and behavioural advertising (LinkedIn Insight Tag)
Online identifiers; usage data; device information.
Consent
Tag management infrastructure (Google Tag Manager)
Online identifiers; usage data.
Consent
Spam and abuse prevention on webforms (Google reCAPTCHA)
Behavioural signals; online identifiers.
Legitimate interest- necessary to protect the website and prevent fraud
Hosting, operating and securing the Website (Webflow)
Identifiers and usage data necessary for site operation.
Legitimate interest- essential to deliver the website and ensure security
Compliance with legal obligations (e.g. responding to lawful requests; record-keeping for tax, accounting, regulatory purposes)
Any data necessary to comply with the obligation in question.
Legal obligation- required by law
Establishing, exercising or defending legal claims
Any relevant data.
Legitimate interests
Hosting of technical and organisational measures (TOMs) documentation on the Drata Trust Center for customer due diligence
Limited identifiers of authorised viewers (e.g. business email addresses).
Legitimate interest
To help explain the terms used in the table above: “online identifiers” means information such as your IP address, cookie identifiers and similar device or browser identifiers that can be used to recognise your device; “usage data” means information about how you interact with the Website, such as pages viewed, clicks, session duration and referral source; and “behavioural signals” means patterns of interaction (for example, mouse movements, scroll behaviour and form-completion patterns) used to distinguish genuine users from automated bots. None of these are used to identify you by name, and non-essential trackers are only used where you have given consent.

Where we rely on legitimate interests (Article 6(1)(f) UK GDPR), we have completed a Legitimate Interests Assessment (LIA) for the relevant activity. You may request a summary of the relevant LIA by contacting our DPO. An LIA has been completed for each processing activity in the table above that relies on legitimate interests as its lawful basis (including responding to enquiries, spam and abuse prevention, hosting and securing the Website, establishing or defending legal claims, and hosting our TOMs documentation for due diligence).

5. Cookies, similar technologies and consent

Cookies and similar technologies (collectively, "trackers") used on the Website are described in detail in our Cookie Policy. The Cookie Policy is the authoritative source for the categorisation, retention and provider of every tracker we use on the Website.

In summary:

Strictly necessary trackers (those required to deliver an information society service explicitly requested by you, within the meaning of Regulation 6(4) PECR) are loaded by default. These are limited to trackers required for the operation, security and accessibility of the Website.

All other trackers - including analytics, heat-mapping, session-recording, advertising and tag-management - are non-essential. They are blocked by default and only load after you have given affirmative consent through the cookie consent banner. The “Reject all” option is presented with the same prominence as “Accept all” on the first layer of the banner.

You can change your preferences at any time using the cookie preferences link in the Website footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

6. Recipients of your personal data

We share personal data only with the categories of recipient set out below.

6.1 Categories of recipient

Authorised personnel of DPPL who require access to perform their role (sales, marketing, product, customer support, legal, IT).

Authorised personnel of Technovative Solutions Ltd (TVS), the sister company within the DPPL/TVS group, where they provide shared corporate operations, ISMS, IT security and infrastructure under documented intercompany data protection arrangements that define each party's controller/processor roles and Article 28 UK GDPR obligations.

Processors and sub-processors engaged by DPPL under written contracts compliant with Article 28 UK GDPR (see Section 6.2 below).

Professional advisers (legal, accounting, audit) where necessary and under duties of confidentiality.

Public authorities, regulators, courts and law-enforcement bodies where we are legally required to disclose personal data.

6.2 Specific recipients and sub-processors

The table below lists the principal recipients and sub-processors that may receive personal data in connection with the operation of the Website and our services. The country of processing and the transfer mechanism (where applicable) is also shown.
Recipient
Purpose
Country of processing
Transfer mechanism
Technovative Solutions Ltd (TVS)
Group-shared corporate operations, ISMS, IT security and infrastructure under documented intercompany data protection arrangements.
United Kingdom
Intra-UK transfer.
Webflow, Inc.
Website hosting and content management.
United States
UK IDTA / EU SCCs as applicable.
Google LLC (Google Analytics 4, Google Tag Manager, reCAPTCHA)
Analytics, tag management, anti-bot protection. Non-essential trackers fire only after user consent.
United States
UK IDTA / EU SCCs as applicable.
Microsoft Corporation (Clarity)
Heat-mapping and session-recording (loaded only after user consent).
United States
UK IDTA / EU SCCs as applicable.
Crazy Egg, Inc.
Heat-mapping (loaded only after user consent).
United States
UK IDTA / EU SCCs as applicable.
Ahrefs Pte. Ltd.
Web analytics (loaded only after user consent).
Singapore
UK IDTA / EU SCCs as applicable.
LinkedIn Corporation (Insight Tag)
Conversion tracking and behavioural targeting (loaded only after user consent).
United States / Ireland
UK IDTA / EU SCCs as applicable.
Drata Inc. (Drata Trust Center)
Hosting of DPPL’s technical and organisational measures (TOMs) documentation for due-diligence purposes.
United States
UK IDTA / EU SCCs as applicable.
Mailchimp (Intuit Inc.)
Mailing list and newsletter delivery.
EEA / UK / United States
Adequacy / UK IDTA / EU SCCs as applicable.
Zoho Corporation Limited – Zoho CRM
Storing and managing enquiry, prospect and customer contact records
EU data centres (Amsterdam / Dublin); limited technical-support access from India
UK adequacy applies to the EU hosting (UK–EEA); India support access is under Zoho's SCC-based intragroup agreement; governed by the Zoho UK DPA
Zoho Corporation Limited – Zoho Flow
Routing website form submissions to Zoho CRM and Mailchimp
EU data centres (Amsterdam / Dublin); limited technical-support access from India
UK adequacy applies to the EU hosting (UK–EEA); India support access is under Zoho's SCC-based intragroup agreement; governed by the Zoho UK DPA
Zoho Corporation Limited – Zoho Bookings
Enabling visitors to schedule appointments and consultations via the website
EU data centres (Amsterdam / Dublin); limited technical-support access from India
UK adequacy applies to the EU hosting (UK–EEA); India support access is under Zoho's SCC-based intragroup agreement; governed by the Zoho UK DPA
This list is reviewed regularly. The current list of sub-processors is available on request from the DPO.

7. How long we keep your personal data

We retain personal data for no longer than is necessary for the purposes for which it was collected, in accordance with Article 5(1)(e) UK GDPR. The principal retention periods are:
Data category
Retention period
Contact form enquiries
Up to 60 months from the last meaningful interaction, unless a longer period is required by law or the enquiry develops into a contractual relationship (in which case the contractual retention period applies).
Demo requests
Up to 24 months from the last meaningful interaction, unless the request develops into an active commercial opportunity.
Lead magnet / downloadable resource forms
Up to 36 months from the last meaningful interaction, unless a longer period is required by law or the lead becomes an active commercial opportunity.
Newsletter subscriber data
Until you unsubscribe or withdraw consent. Suppression records (i.e. the fact that you have unsubscribed) are retained indefinitely so that we can honour your opt-out.
Email engagement data (opens, clicks)
Aggregated and anonymised at 24 months.
Website server logs and security logs
Up to 12 months, except where necessary for ongoing investigation of a security incident.
Cookie consent records
24 months from the date of consent or last interaction with the consent banner, whichever is later.
Records required for accounting, tax or regulatory compliance
As required by the applicable law (typically 6 years for accounting and tax records under UK law).
Records relating to legal claims
Until the limitation period for the relevant claim has expired.
Where the periods above use the phrase “last meaningful interaction”, this means the most recent substantive contact between you and DPPL - for example, replying to an email, opening a marketing message, downloading a resource, or attending a meeting. Inactivity beyond the relevant period will trigger review and, where appropriate, deletion or anonymisation of the data.

8. Your data protection rights

Under the UK GDPR you have the following rights in relation to your personal data. The exercise of these rights is free of charge in most cases and we will respond to a valid request within one month, in accordance with Article 12(3) UK GDPR. The period may be extended by up to two further months where necessary,
Right
What it means
Right of access (Art. 15)
To confirm whether DPPL processes your personal data and obtain a copy of it together with the supplementary information required by Article 15.
Right to rectification (Art. 16)
To have inaccurate personal data corrected and incomplete data completed.
Right to erasure (Art. 17)
To have your personal data deleted where one of the grounds in Article 17 applies (commonly: data no longer necessary, consent withdrawn, or unlawful processing).
Right to restriction (Art. 18)
To require DPPL to restrict (suspend) processing in defined circumstances, for example while accuracy is being verified.
Right to data portability (Art. 20)
To receive personal data you have provided to us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is carried out by automated means.
Right to object (Art. 21)
To object to processing based on legitimate interests (Article 6(1)(f)) or to direct marketing. Objection to direct marketing is absolute and DPPL will stop the processing.
Rights related to automated decision-making (Art. 22)
To not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. DPPL does not currently carry out such automated decision-making.
Right to withdraw consent (Art. 7(3))
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint (Art. 77)
To lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority. Contact details below.

8.1 How to exercise your rights

You may exercise any of the rights above by contacting our DPO at dpo@digiprodpass.com or by post (Section 2.2). To help us deal with your request efficiently, please:

Tell us which right you wish to exercise.

Provide enough information for us to identify you and the data your request relates to.

Where you are acting on behalf of someone else, provide written authority from that person.

We may ask you for additional information to verify your identity, in accordance with Article 12(6) UK GDPR. We will not refuse to act on your request without good cause.

8.2 Right to lodge a complaint with the ICO

If you are concerned about how DPPL has processed your personal data, we encourage you to contact our DPO in the first instance so that we can address the issue. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

Helpline: 0303 123 1113

Website: ico.org.uk

9. Automated decision-making and profiling

DPPL does not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing within the meaning of Article 22 UK GDPR. Where this position changes, this Notice will be updated and (where required) your prior consent will be obtained. To be clear, we do not carry out any solely automated decision-making that produces legal or similarly significant effects for you, and so the safeguards in Article 22(3) UK GDPR (such as a right to human intervention) do not currently apply. The limited profiling described below is used only to deliver and measure advertising and does not produce any legal or similarly significant effect on you.

Some of our marketing tools (for example, behavioural advertising trackers) involve a limited form of profiling based on online behaviour. These trackers operate only after you have given consent through the cookie consent banner, and you can withdraw your consent at any time.

10. Children

DPPL provides business-to-business services. The Website and our products are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. (Where a UK information society service is offered directly to a child, the age at which a child can consent on their own behalf is 13 under section 9 of the DPA 2018; below that age we would require parental consent. Because our services are business-to-business, we do not rely on children's consent.) If you believe that a child has provided personal data to us, please contact our DPO so that we can investigate and, where appropriate, delete the data.

11. Marketing

Where you have agreed to receive marketing from us, we may contact you by email to send newsletters, product updates, event invitations and other information about our products and services. Our marketing emails are sent using Mailchimp.

Lawful basis: We send marketing on the basis of your consent (Article 6(1)(a) UK GDPR) and in accordance with Regulation 22 PECR. Where the “soft opt-in” under Regulation 22(3) PECR applies – that is, where we obtained your contact details in the course of a sale or negotiations for a sale of our products or services, the marketing relates to our own similar products or services, and you were given a simple means to opt out at the time – we may rely on that soft opt-in instead of express consent.

How to opt out: You can opt out of marketing at any time, free of charge, by clicking the “unsubscribe” link in any marketing email, by adjusting your preferences where available, or by contacting us at contact@digiprodpass.com or our DPO at dpo@digiprodpass.com. Opting out of marketing will not affect the lawfulness of any marketing carried out before you opted out.

Service communications: Even if you opt out of marketing, we may still send you non-promotional service or administrative messages where these are necessary – for example, messages about your account, security or important changes to our terms or this Notice. These are not marketing messages and cannot be opted out of while you use the relevant service.

12. Security of your personal data

DPPL has implemented appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, in accordance with Article 32 UK GDPR. These measures include access controls, encryption in transit and at rest where appropriate, secure hosting, vulnerability and patch management, logging and monitoring, secure software development practices, vendor due-diligence and personnel training.

DPPL operates an Information Security Management System aligned with ISO/IEC 27001. Our technical and organisational measures (TOMs) are summarised on the Drata Trust Center and are available on request to customers and prospective customers under appropriate confidentiality terms.

13. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance. The version number, issue date and “Last reviewed” date in the document control box at the top of this Notice (and in the footer) will always show the current version. Where the changes affect processing carried out on the basis of your consent, we will obtain fresh consent from you where required.

We recommend that you review this Notice periodically. Material changes will, where reasonably practicable, be brought to your attention by email or by a notice on the Website.

14. Definitions and legal references

In this Notice:

“Personal data” means any information relating to an identified or identifiable natural person, as defined in Article 4(1) UK GDPR.

“Processing” has the meaning given in Article 4(2) UK GDPR.

“Controller” and “Processor” have the meanings given in Article 4(7) and 4(8) UK GDPR respectively.

“Special category data” means personal data within Article 9(1) UK GDPR.

“Tracker” means any technology - including cookies, unique identifiers, web beacons, pixels, embedded scripts, e-tags and fingerprinting - that enables the tracking of users by accessing or storing information on the user’s device.

“UK GDPR” means the UK General Data Protection Regulation as defined in section 3(10) DPA 2018.

“PECR” means the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), as amended.

“ICO” means the Information Commissioner’s Office, the UK supervisory authority for data protection.

Your consent preferences for tracking technologies can be managed through the cookie preferences link in the Website footer.
DPPL-PRIV-001 | Version 2 | Public