Privacy Policy
Privacy policy
Last updated: 18 August 2026
Digital Gambit Ltd ("Digital Gambit", "we", "us" or "our") is committed to handling personal information lawfully, fairly and transparently. This privacy policy explains what personal information we collect, how and why we use it, who we share it with, how long we keep it and the rights available to you. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Digital Gambit Ltd is the controller of the personal information described in this policy.
This policy should be read together with our Cookie Policy. We keep this policy under review and will publish updates on our website. Where a change is significant, we may also bring it to your attention by other appropriate means.
Who this policy applies to
This policy applies to people who:
Visit or use our website
Contact us or make an enquiry
Are clients, prospective clients, suppliers, professional advisers or other business contacts
Receive relevant business-to-business communications from us
Interact with us through social media or attend an event involving us
Visit our premises
Apply to work with us as an employee, contractor or freelancer
When we process personal information solely on behalf of a client as part of delivering digital services, that client will normally be the controller and we will act as its processor. That processing is governed by our agreement with the client and the client's own privacy information.
Who this policy applies to
Depending on how you interact with us, we may collect:
Identity information, such as your name, job title, employer or organisation
Contact information, such as your business or personal email address, postal address and telephone number
Business relationship information, including enquiries, proposals, contracts, correspondence, meeting notes and records of the services we provide or discuss with you
Marketing information, including your communication preferences and a record of whether you have objected or opted out
Technical and usage information, such as IP address, browser and device information, cookie identifiers, pages viewed, referral source and interactions with our website, where permitted by your cookie choices
Financial and transaction information, such as bank details, payment records, invoices and relevant tax information. Card payments, if offered, are normally handled by a payment provider and we do not intend to retain complete payment-card details
Recruitment information, such as your CV, employment history, portfolio, qualifications, references, interview notes, right-to-work information and other information you choose to provide
Any other information you provide voluntarily when communicating or working with us
Please do not provide special-category information, such as health, ethnicity, religion or trade-union information, unless it is relevant and necessary. If we need to process this type of information, we will identify an appropriate legal basis and additional condition under data protection law.
How do we collect this information?
We collect personal information:
Directly from you, including through our website, email, telephone, meetings, contracts, applications and other correspondence
From your employer, organisation, colleagues, professional advisers or other people involved in a project or business relationship
From publicly available professional sources, such as company websites, Companies House, professional networking platforms, business directories, event listings and relevant press coverage
From service providers that support our website, analytics, hosting, communications, payments, recruitment and business administration
Automatically when you use our website, through cookies and similar technologies, subject to your choices and our Cookie Policy.
How and why we use personal information
We use personal information only where we have a lawful basis. Depending on the circumstances, we may use it to:
Respond to enquiries and take steps requested before entering into a contract
Prepare proposals, enter into and manage contracts, deliver services, provide support and administer client and supplier relationships
Manage invoices, payments, accounts, taxation and financial records
Operate, secure, maintain and improve our website, systems and services
Understand website use and measure the effectiveness of our communications, where analytics or advertising technologies have been accepted
Protect our business, clients, systems, staff and visitors; prevent fraud or misuse; and establish, exercise or defend legal claims
Meet legal, regulatory, insurance, accounting and professional obligations
Assess applications and make recruitment and resourcing decisions
Maintain professional relationships and send relevant business-to-business communications about our services
Our lawful bases
The lawful bases on which we generally rely are:
Contract: where processing is necessary to enter into or perform a contract with you
Legitimate interests: where processing is necessary for our legitimate business interests or those of a third party and those interests are not overridden by your rights. These interests may include running and developing our business, delivering and improving services, maintaining business relationships, securing our systems, recovering debts and promoting relevant services to organisations
Legal obligation: where processing is necessary for us to comply with the law
Consent: where you have given a clear choice for a particular use. You may withdraw consent at any time, although this will not affect processing that took place before withdrawal
Where we process special-category information, we will also identify an applicable condition under Article 9 of the UK GDPR and, where required, the Data Protection Act 2018.
Business-to-business marketing
We may use business contact information to contact companies and their representatives about services that we reasonably believe may be relevant to their organisation. We may obtain this information directly from you or from publicly available professional sources, including company websites, Companies House, professional networking platforms, business directories and relevant industry sources.
For relevant communications to corporate bodies, we generally rely on our legitimate interests in promoting and developing our services. Before using named business contact information, we consider whether the proposed use is necessary, proportionate and within the recipient's reasonable expectations. We do not assume that information is suitable for marketing merely because it is publicly available. Different electronic-marketing rules apply to individuals, sole traders and some partnerships. Where consent is required by the Privacy and Electronic Communications Regulations (PECR), we will obtain it or ensure that another valid exception applies before sending marketing.
Every marketing communication will identify us and provide a straightforward way to opt out. You have the right to object to direct marketing at any time. You can do so by using any unsubscribe option provided, replying to the message or emailing info@digitalgambit.co.uk. We will stop the relevant marketing and may retain limited contact information on a suppression list so that we can respect your preference in the future.
Our website, cookies and analytics
Our website uses cookies and similar technologies. Some are strictly necessary for the website to function and do not require consent. We will ask for your consent before using non-essential analytics, advertising or similar technologies where consent is required. You can accept, reject or change your choices through our cookie controls. Further information is available in our Cookie Policy.
If enabled by your choices, we may use services such as Google Analytics to understand how visitors find and use our website and Google Ads to measure or support advertising. These services may collect identifiers, IP-derived location, device and browser information, referral information and details of website interactions. We receive reports and insights from these services, but the service provider may also process information in accordance with its own terms and privacy information.
You can learn more about Google's use of information on its privacy and data pages. You may also be able to use Google's Analytics Opt-out Browser Add-on and Ads Settings.
Our website may link to third-party websites. We do not control those websites and this policy does not govern their handling of personal information. Please review the privacy information provided by the relevant third party.
Social media
If you interact with us through a social-media platform, we may receive information made available through your profile and your communications with us. The platform provider will also process information under its own terms and privacy policy and may use cookies or similar technologies. Please avoid sending sensitive or confidential information through public social-media channels.
Who we share personal information with
Where necessary for the purposes described in this policy, we may share personal information with:
Our staff, contractors and freelancers who need it to perform their roles
Website hosting, cloud infrastructure, IT support, security, email, communications, CRM, analytics, payment, accounting, recruitment and document-management providers
Accountants, auditors, insurers, lawyers and other professional advisers
Clients, suppliers and delivery partners where this is necessary for a project or business relationship
Government bodies, regulators, law-enforcement agencies, courts or other parties where disclosure is required or permitted by law
A prospective buyer, investor or successor if we reorganise, sell or transfer all or part of our business, subject to appropriate confidentiality and data-protection safeguards
We require service providers handling personal information for us to protect it, use it only for agreed purposes and comply with applicable data-protection requirements. We do not sell personal information.
International transfers
Some service providers may process personal information outside the United Kingdom. Where the destination is not covered by UK adequacy regulations, we use an appropriate safeguard where required, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another legally recognised mechanism. For qualifying transfers to participating US organisations, we may rely on the UK Extension to the EU-US Data Privacy Framework.
We also carry out any risk assessment required for the transfer and apply additional technical or organisational safeguards where appropriate. You may contact us for more information about the safeguards relevant to your information.
How long we keep personal information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, regulatory, security and dispute-resolution requirements. In deciding retention periods, we consider the amount, nature and sensitivity of the information, the risks associated with it and the applicable limitation and record-keeping periods.
Our usual retention approach is:
Client, supplier, contractual and project records: normally for up to six years after the relationship or relevant contract ends, unless a longer period is required for a particular legal, insurance or contractual reason
Financial and tax records: normally for at least six years after the end of the relevant accounting period, or longer where the law requires
Unsuccessful recruitment applications: normally for up to six months after the recruitment process ends, unless you agree that we may retain the information for future opportunities
Prospective-client and business-development records: normally for up to 24 months after the last meaningful interaction, unless the relationship continues, a longer period is justified or you object sooner
Suppression records: retained for as long as reasonably necessary to ensure that we continue to respect an objection or opt-out
Website and analytics information: retained in accordance with our cookie settings and the retention periods configured in the relevant service, as explained in our Cookie Policy
We may retain information for longer if required for an ongoing complaint, investigation, legal claim or other legal obligation. We may also anonymise information so that it no longer identifies anyone and use the resulting information for statistical or service-improvement purposes.
How we protect personal information
We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, destruction or unauthorised access. These measures may include access controls, authentication, encryption where appropriate, secure configuration, backups, supplier due diligence, staff awareness and incident-management procedures.
No internet transmission or storage system can be guaranteed to be completely secure. If we become aware of a personal-data breach, we will investigate and notify affected individuals and the Information Commissioner's Office where the law requires us to do so.
Your data-protection rights
Depending on the circumstances, you may have the right to
Be informed about how your personal information is used
Request access to the personal information we hold about you
Ask us to correct inaccurate or incomplete information
Ask us to erase your information in certain circumstances
Ask us to restrict processing in certain circumstances
Object to processing based on legitimate interests
Object at any time to the use of your information for direct marketing
Receive certain information in a portable format or ask us to transfer it, where the right to data portability applies
Withdraw consent at any time where we rely on consent
Not be subject to a decision based solely on automated processing that has legal or similarly significant effects, where the relevant legal protections apply
These rights are not absolute and exemptions may apply. We may ask for information reasonably necessary to confirm your identity and understand your request. We do not normally charge a fee, but the law allows a reasonable fee or refusal in limited circumstances. We aim to respond within one month, although the law permits an extension for complex or numerous requests.
Complaints
If you have concerns about our use of your personal information, please contact us first so that we can investigate and try to resolve the issue.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator. Visit ico.org.uk for further information. If you are located outside the UK, you may also have the right to contact your local data-protection authority.
Contact us
Digital Gambit Ltd 167-169 Great Portland Street 5th Floor London W1W 5PF Email: info@digitalgambit.co.uk