Digital Optimizer
Enterprise Privacy, GDPR & Data Governance

Privacy Policy & Data Security

How Digital Optimizer collects, secures, and safeguards client business data, visitor analytics, and digital advertising intelligence.

Last Updated: January 2026 UK GDPR & EU GDPR Compliant Google Consent Mode v2 Standard
Zero Data Selling
We never sell or broker data
256-Bit SSL/TLS
Enterprise encryption at rest & in transit
Full Data Control
Instant export & erasure requests
UK DPA 2018 & GDPR
Strict European regulatory alignment
Controller Identity Section 1.0

1. Who We Are & Data Controller Identity

Digital Optimizer ("Agency", "we", "us", or "our") operates the website digitaloptimizer.co.uk and delivers premium performance marketing, social media acquisition, Google Ads management, search engine optimization (SEO), and custom web engineering services.

For the purposes of the General Data Protection Regulation (EU GDPR), the UK Data Protection Act 2018 (UK GDPR), and international data privacy statutes, Digital Optimizer acts as the Data Controller for information collected directly through our website, contact forms, and client onboarding workflows. When managing client ad accounts and analytics platforms, we act as a Data Processor operating under explicit contractual mandates.

Organization: Digital Optimizer Agency
Primary Location: United Kingdom
Privacy Email: [email protected]
Official Phone: +44 7508 656103
Personal Data Section 2.0

2. Information We Collect Directly From You

We collect personal information that you voluntarily submit to us when requesting a digital marketing audit, filling out strategic inquiry forms, scheduling video discovery calls, or executing an enterprise retainer:

Contact & Identity Data
  • Full Name & Business Job Title
  • Corporate Email Address & Phone Number
  • Company Name, Website URL, & Industry Sector
  • Physical Business / Billing Address
Project & Campaign Data
  • Monthly Ad Spend Budgets & Target ROAS
  • Current Revenue Metrics & Acquisition Goals
  • Target Audience Demographics & Geography
  • Technical Briefs, Wireframes & Design Assets
Payment & Commercial Billing Information: When purchasing agency services, invoices are settled via secure Electronic Bank Transfer (BACS/SEPA/Wire) or PCI-DSS Level 1 compliant processors (such as Stripe). We do not store raw credit card numbers or sensitive banking PINs on our web servers.
Automated Data Section 3.0

3. Automated Technical Data & Device Analytics

As you navigate through digitaloptimizer.co.uk, our servers and analytics infrastructure automatically log standard technical telemetry to ensure optimal performance, security, and responsive styling:

  • Device & Browser Information: Browser type (Chrome, Safari, Firefox), version, operating system (Windows, macOS, iOS, Android), screen resolution, and language preferences.
  • Network & Connection Metrics: Anonymized Internet Protocol (IP) address, approximate geographic location (city/country level), Internet Service Provider (ISP), and connection speeds.
  • Usage & Clickstream Data: Uniform Resource Locators (URLs) visited, referral URLs, time spent on each service page (SMM, Google Ads, Web Dev, SEO), bounce rates, and navigation paths.
  • Performance Diagnostics: Core Web Vitals timings (LCP, FID, CLS), server latency, and error diagnostic logs to maintain sub-500ms page load speeds.
Marketing Technology Section 4.0

4. Marketing Pixels, Conversion APIs & Analytics Tags

As an elite digital performance agency, we implement industry-standard measurement technologies to assess the effectiveness of our campaigns and measure visitor engagement:

Google Analytics 4 & Google Ads

We use Google Tag Manager (GTM) and GA4 to track anonymized user sessions, conversions, and campaign attribution without capturing unmasked Personally Identifiable Information (PII).

Meta Pixel & Conversions API (CAPI)

Meta conversion signals measure advertising ROI on Facebook and Instagram. Server-side CAPI events are securely hashed using SHA-256 protocols before transmission.

TikTok Pixel & LinkedIn Insight

Measures video interaction metrics, B2B company demographics, and creative campaign performance for our paid social testing sprints.

User Session & Heatmap Tools

Tools like Microsoft Clarity or Hotjar record anonymized mouse scrolls and click paths. All text input fields containing passwords or personal numbers are strictly masked.

Google Consent Mode v2 Alignment

Our website respects user privacy preferences via Google Consent Mode v2. If a visitor declines marketing cookies, analytics and advertising tags dynamically adjust to cookieless ping signals without storing persistent identifiers.

Data Utilization Section 5.0

5. How We Use Your Information

Digital Optimizer processes collected data strictly for legitimate commercial and operational purposes:

Service Fulfillment & Strategy Architecture: Delivering bespoke Social Media Marketing campaigns, building Google Ads architectures, optimizing technical SEO, and deploying custom high-converting web applications.
Performance Reporting & ROAS Modeling: Generating comprehensive weekly and monthly performance dashboards tracking CPA, ROAS, organic rankings, and revenue growth.
Client Communication & Strategic Advisory: Responding to consultation inquiries, scheduling sprint reviews, and providing proactive growth recommendations.
Invoicing, Billing & Accounting: Processing monthly retainers, issuing SOW milestone invoices, and fulfilling statutory tax compliance requirements.
Security & Fraud Prevention: Protecting our infrastructure, preventing malicious bot submissions, and safeguarding client access tokens.
Regulatory Compliance Section 6.0

6. Legal Bases for Processing (UK GDPR & EU GDPR)

Under Article 6 of the General Data Protection Regulation, we rely on the following lawful grounds to process your personal data:

Client Data Protection Section 7.0

7. Client Account Privacy, IP Whitelisting & Non-Leakage

When clients grant Digital Optimizer access to their Meta Business Managers, Google Ads accounts, Search Consoles, CMS portals, or hosting servers, we enforce strict enterprise safeguards:

Delegated Partner Access: We never request root passwords. Access is granted via official agency partner IDs (e.g., Google Ads MCC Manager, Meta Business Partner Manager).
Zero Cross-Client Data Pooling: Data, conversion events, custom audience lists, and customer email hashes from one client are never shared, pooled, or leveraged to train models for any other client.
Principle of Least Privilege: Internal team members are granted access strictly on a need-to-know basis corresponding to their active channel sprint (e.g., Media Buyers access ad accounts; Web Engineers access GitHub repositories).
Cookie Policy Section 8.0

8. Cookie Classification & User Opt-Out Controls

Cookies are small text files stored on your device that allow us to enhance site navigation, analyze performance, and deliver tailored marketing:

How to Control Cookies: You can manage or disable cookies at any time through your web browser settings (Chrome, Safari, Firefox, Edge). To opt out of Google Analytics tracking across all websites, you can install the Google Analytics Opt-out Browser Add-on.

Sub-Processors Section 9.0

9. Third-Party Service Providers & Sub-Processors

We partner with vetted, enterprise cloud infrastructure providers to operate our digital agency ecosystem. All sub-processors maintain certified SOC 2, ISO 27001, or GDPR Data Processing Addendums (DPAs):

Cloud Hosting & CDN: Vercel Inc., Cloudflare, Google Cloud Platform (GCP)
Payment Gateway: Stripe Payments Europe Ltd (PCI-DSS Level 1)
Analytics & Tag Management: Google LLC (Google Tag Manager / GA4)
Ad Networks: Meta Platforms Inc., ByteDance (TikTok), LinkedIn Corporation
Global Data Section 10.0

10. International Data Transfers & Standard Contractual Clauses

As a global agency serving clients worldwide, your data may be processed in servers located outside the UK or European Economic Area (EEA), such as the United States. Where international transfers occur, we implement legal safeguards including:

  • UK International Data Transfer Addendum (IDTA): Issued by the Information Commissioner's Office (ICO).
  • Standard Contractual Clauses (SCCs): Adopted by the European Commission ensuring equivalent data protection levels.
  • EU-U.S. Data Privacy Framework: Verifying certified participating vendors for transatlantic data compliance.
Lifecycle Section 11.0

11. Data Retention Periods & Automated Erasure

We retain personal data only for as long as necessary to fulfill the operational purposes outlined in this policy:

12 Months
Inquiry & Audit Leads

Form submissions without active contracts are purged after 12 months.

Duration + 30 Days
Active Client Retainers

Campaign tracking tokens revoked 30 days after project completion.

6 Years
Statutory Financial Records

Invoices and accounting logs retained as required by tax law.

User Rights Section 12.0

12. Your Legal Rights (UK GDPR, EU GDPR, CCPA / CPRA)

Depending on your geographic location, you possess powerful legal rights regarding your personal information:

Right of Access & Portability

Request a complete copy of the personal data we hold about you in a structured, machine-readable format (JSON/CSV).

Right to Rectification

Request immediate correction of inaccurate or incomplete personal contact details or business information.

Right to Erasure ("To Be Forgotten")

Request the permanent deletion of your personal records where no overriding legal retention obligation exists.

Right to Object & Restrict

Object to direct marketing communications or request that we restrict active data processing operations.

30-Day Response SLA

We respond to all verified Data Subject Access Requests (DSAR) free of charge within thirty (30) calendar days. To exercise any of these rights, email our Data Protection team at [email protected].

Security Architecture Section 13.0

13. Technical Security Measures & Incident Response

Digital Optimizer employs multi-layered technical and organizational safeguards:

  • Encryption Everywhere: All web traffic is strictly encrypted using modern TLS 1.3 cryptographic protocols with HSTS preloading.
  • Multi-Factor Authentication (MFA): Hardware and app-based MFA is mandatory across all internal agency management tools, code repositories, and ad platforms.
  • Automated Vulnerability Scanning: Continuous dependency audits, static code analysis, and DDoS protection via Cloudflare enterprise proxy shielding.
  • 72-Hour Breach Notification: In the unlikely event of a verified data breach impacting personal records, we will notify the UK Information Commissioner's Office (ICO) and affected individuals within 72 hours in accordance with GDPR requirements.
Official Inquiries Section 14.0

14. Data Protection Officer (DPO) & Contact Information

For questions regarding this Privacy Policy, data subject access requests, or specific compliance inquiries, please contact our Data Protection Officer:

Data Privacy & Compliance Office
Dedicated Privacy Email
[email protected]
Direct Telephone Inquiries
+44 7508 656103