Privacy Policy
1) Who I am
Ddraig Digital ("me", "I") is a sole-trader in Wales and is committed to protecting your privacy. This Privacy Policy explains how I collect, use, disclose, and safeguard your data when you interact with our website (ddraigdigital.co.uk), my pages on social media platforms, use my services or give me access to your social pages for moderation purposes.
Registered address: 45 Alexandra Street, Shotton, Flintshire, CH5 1DL, Wales.
Email: laura@ddraigdigital.co.uk
For the purposes of data protection laws in the UK and EU, Ddraig Digital is the data controller for personal data described in this policy, unless otherwise stated.
2) Scope
This policy explains how I collect, use, share, and protect personal data when you:
visit my websites at ddraigdigital.co.uk (the "site")
purchase subscriptions or downloads
receive my emails or marketing
interact with me on social media
are a business contact, prospect, creator, affiliate, or supplier.
This policy applies worldwide. Section 15 sets out region-specific disclosures (e.g., UK/EU GDPR, California, Brazil, Canada, etc.).
3) Key terms
Personal data: Information that identifies or relates to an identifiable individual.
Processing: Any operation on personal data (collection, use, storage, disclosure, etc.).
UK GDPR: The UK General Data Protection Regulation and Data Protection Act 2018.
EU GDPR: The EU General Data Protection Regulation.
4) What I collect
I collect personal data in three ways:
A) You provide it to me
B) It’s collected automatically
C) I receive it from third parties.
A) Data you provide:
Account & contact: name, email, phone, billing address, company, role.
Subscription & purchase: plan, term, order history, invoices, VAT status, last 4 digits of card (processed by my payment processor; I don’t store full card details).
Support & sales: messages, feedback, attachments, call notes.
Marketing: email preferences, survey responses, competition entries.
Content inputs (for social media services): brand assets, captions, media files, instructions, approvals.
B) Data collected automatically:
Usage data: pages viewed, links clicked, time on page, referring URLs.
Device/technical: IP address, cookies, browser, OS, approximate location.
C) Data from third parties:
Payment providers: transaction confirmations, fraud signals.
Analytics/ads partners: attribution data, campaign performance.
Social platforms (when you connect accounts for my services): page IDs, tokens/permissions, insights/metrics, content performance.
Lead gen & enrichment (B2B): business contact data from public sources or vendors.
Special categories: I do not intentionally collect sensitive categories (e.g., health, religion). Please do not share such data with me.
5) Why I use your data (purposes & legal bases)
Under the UK/EU GDPR Imust have a legal basis. Below is a quick map:
Where we rely on consent, you can withdraw it at any time (see Section 14). Where I rely on legitimate interests, I balance those interests against your rights.
6) Cookies & similar technologies
I use cookies, pixels, and local storage to operate the site, remember preferences, analyse traffic, and run ads. Where required by law, I will ask for consent via a cookie banner.
Categories: Strictly necessary, Functionality, Analytics, Advertising
Main tools I may use: Google Analytics, Meta Pixel & PayPal
7) AI features & automated decisions
If I use AI features (e.g., content drafting, insights):
Inputs you provide may be sent to third-party AI providers under their terms.
I apply safeguards to avoid using your inputs to train public models where I can choose this setting.
I do not make decisions producing legal or similar significant effects solely by automated means without human review.
8) How I share information
I share personal data with:
Service providers/Processors who help me run my business (hosting, payments, cloud storage, CRM, analytics, email, advertising, productivity tools, customer support). They access data only to perform services for me under contracts.
Business partners (e.g., affiliates, resellers) with your direction or as permitted by law.
Social platforms when you request I manage or post content on your behalf.
Legal, compliance, and safety: to comply with law, enforce my terms, protect rights, or respond to lawful requests.
Business transfers: in connection with a merger, financing, or acquisition.
Third-party list:
Payments: PayPal
Analytics/ads: Google Analytics, Meta
Email & CRM: Mailchimp
9) International transfers
I am based in Wales and may transfer your data internationally. Where required, I use lawful transfer mechanisms, such as:
UK/EU Standard Contractual Clauses (SCCs) and UK Addendum/IDTA
Adequacy decisions, where available (e.g., UK/EU decisions for certain countries)
The EU–US Data Privacy Framework and UK Extension (for certified US recipients), where applicable.
You can request a copy of relevant transfer mechanisms (with redactions) by contacting me.
10) Data retention
I keep personal data only as long as necessary for the purposes set out above, including to meet legal, accounting, or reporting requirements. Typical retention periods:
Account/billing records: 6-7 years (tax/legal)
Support tickets: 24 months
Marketing contacts: until you unsubscribe or your consent is withdrawn, plus a short period to record the opt-out.
Content I produce for you: for the duration of the contract and for 6 months thereafter, unless you ask me to delete earlier (subject to backups/legal).
11) Security
I implement technical and organisational measures to protect personal data, including access controls, encryption in transit, least-privilege practices, and regular monitoring. No system is 100% secure. If I learn of a breach affecting you, I will notify you and/or regulators as required by law.
12) Your choices
Marketing: unsubscribe using the link in my emails or contact me .
Cookies: manage via my banner or browser settings (may impact functionality).
13) Your rights
Your rights depend on where you live. Subject to legal limits, you may have the right to:
Access your data and receive a copy
Correct inaccurate data
Delete your data
Object to or restrict processing
Data portability (receive data in a structured, machine-readable format)
Withdraw consent where processing is based on consent
Appeal certain decisions (e.g., under US state laws)
I will not discriminate against you for exercising these rights. I may need to verify your identity before acting on your request.
How to exercise your rights: email me at laura@ddraigdigital.co.uk with "Privacy request" in the subject. If you are an authorised agent (e.g., under California law), include proof of authority.
UK/EU (GDPR): you also have the right to complain to a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO). In the EU, see your local authority.
California (CCPA/CPRA): you have rights to know/access, delete, correct, opt-out of sale or sharing (for cross-context behavioural advertising), and to limit use/disclosure of sensitive personal information. I do not sell personal information for money. I may "share" for advertising purposes-see Cookies. Use my cookie controls to opt-out of targeted ads and email me to exercise rights.
Brazil (LGPD): you have rights including confirmation of processing, access, correction, anonymisation, portability, deletion, and information about sharing.
Canada (PIPEDA/Quebec Law 25): you have rights to access and correct personal information and to withdraw consent.
14) Children
My services are not directed to children. I do not knowingly collect personal data from children under 18. If you believe a child has provided me data, contact me to request deletion.
15) Social media services I provide (acting as processor)
When you ask me to manage or post to your social accounts, I process certain data on your instructions (e.g., page insights, content, comments). In these cases I act as your processor/service provider, and my Service Agreement and Data Processing Addendum (DPA) govern that processing. For your end-users’ data on those platforms, please ensure your own privacy notices are up to date.
16) Third-party links
l The Site may link to third-party websites or services. Their privacy practices are their own; please review their policies.
17) Changes to this policy
I may update this policy from time to time. The "Last updated" date shows the latest revision. Significant changes will be notified on the Site and/or by email where appropriate.
18) Contact me
Questions or requests about this policy? Contact me via:
Email: laura@ddraigdigital.co.uk
Address: 45 Alexandra Street, Shotton, Flintshire, CH5 1DL, Wales.
For UK residents: You can raise concerns with the ICO at ico.org.uk.