Уведомление о UK GDPR и защите данных
UK GDPR · Transparency
UK GDPR & Data Protection Notice
How Digily Link processes the personal data of its visitors, account holders, subscribers and partners, and the rights you have under the UK GDPR and the Data Protection Act 2018.
This notice is a transparency document, not a consent form. Where an optional activity requires consent, your choice is collected separately, and refusing it does not affect your basic membership or the essential parts of the service.
1. Who is the controller?
The controller for personal data processed on the Digily Link platform is:
- Company: Dijital Mekan Ltd, registered in England and Wales, company number 14955219
- Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- Email: support@digily.link
Digily Link is the brand and platform name under which the service at digily.link and its related domains is provided. The supervisory authority for data protection in the United Kingdom is the Information Commissioner's Office (ICO).
2. Who does this notice cover?
This notice covers platform visitors, account holders, team members, paid plan customers, visitors of user profiles and short links, email subscribers, people who contact support or report a violation, developers using the API, and participants in the affiliate and partner programs.
When a Digily Link user collects data from their own visitors through a contact form, an appointment block or an email or phone collector on their profile, that profile owner is an independent controller and their own privacy information applies. For the hosting and transmission Digily Link performs on the user's documented instructions, the Data Processing Addendum applies.
3. What we process, why, and on what lawful basis
| Data / data subjects | Purposes | UK GDPR lawful basis |
|---|---|---|
| Identity and contact: name, username, email, phone, address, business or representative details | Registration, account management, verification, communication, support, contracts and program applications | Art. 6(1)(b) contract; 6(1)(c) legal obligation; 6(1)(f) legitimate interests |
| Account and security: password hash, account ID, role, session, IP address, device and browser, timestamps, security events | Sign-in, security, preventing unauthorized access and abuse, audit | Art. 6(1)(b); 6(1)(c); 6(1)(f) |
| Customer transactions and invoicing: plan, amount, currency, transaction status, invoicing and tax details, limited payment data | Collection, invoicing, accounting, refunds, subscription and dispute management | Art. 6(1)(b); 6(1)(c); 6(1)(f) |
| Profile and content: text, images, files, links, domain choice, theme, vCard, email signature and anything you publish | Providing the publishing and hosting features you request; content safety and violation handling | Art. 6(1)(b); 6(1)(f) |
| Profile forms and appointments: name, email, phone, message, appointment date and time, and other fields the profile owner chose | Hosting, displaying and delivering form and appointment records on behalf of the profile owner as controller | The profile owner's documented instructions under the Data Processing Addendum; Art. 6(1)(f) for platform security |
| Usage and traffic: page and click events, referrer URL, short link statistics, approximate location, error and performance logs | Delivering the service, capacity, security, statistics, product improvement | Art. 6(1)(b) and 6(1)(f) for essential processing; Art. 6(1)(a) consent for optional analytics and advertising |
| Social sign-in, where enabled: account identifier, name, email and the limited profile data you permit, plus the sign-in token | Registration or sign-in with a social account you choose, and security | Art. 6(1)(b); 6(1)(f) |
| Push notifications: permission state, web push subscription endpoint or token, browser and device, notification content and interaction | Sending the service and security notifications you request through Digily Link's own push infrastructure; sending marketing notifications only where the required marketing preference exists; deleting the subscription as soon as permission is withdrawn | Art. 6(1)(b); Art. 6(1)(a) consent for marketing, together with PECR |
| Support, reports and legal: correspondence, attachments, complaints, rights claims, legal requests | Responding to requests, investigating alleged violations, defence of legal claims, complying with lawful orders | Art. 6(1)(c); 6(1)(f) |
| Partner data: application details, social and business profile, referral code, attribution records, clicks, customer transactions, commission, payout account details, tax documents | Eligibility, referral attribution, commission calculation, payment, fraud checks and program management | Art. 6(1)(b); 6(1)(c); 6(1)(f) |
| Marketing preferences: channel, opt-in or opt-out, campaign interaction | Sending the announcements you asked for and keeping a record of consents and objections | Art. 6(1)(a) consent and PECR; Art. 6(1)(c) and 6(1)(f) for the suppression record |
Special category data is only processed where it is genuinely necessary for a specific feature and an Article 9 condition applies. Please do not upload special category data to profiles or support forms unless it is truly needed.
4. How we collect data
Personal data comes from registration, account, profile, payment and invoicing, partner application, support, contact and violation report forms; from email, phone and WhatsApp correspondence; from logs, cookies and similar technical records created while the platform, short links and user profiles are used; from payment, security, hosting and message delivery providers; and from team administrators, rights holders or competent authorities.
Mandatory fields are needed to enter into or perform the contract or to meet a legal obligation. Without them, an account may not be opened, or a payment, invoice or partner commission may not be processed. Leaving optional fields empty does not block the core service.
5. Who receives data?
- Hosting and infrastructure providers: running the servers, storage and backups the platform depends on;
- Cloudflare: CDN, WAF, DNS and bot protection in front of the platform;
- Payment providers shown at checkout (for example Stripe or PayPal, depending on configuration): collection, refunds and fraud prevention;
- Email and message delivery providers: transactional and, where permitted, marketing messages;
- Accountants, auditors and professional advisers: bookkeeping, tax and legal compliance;
- Solicitors and dispute advisers: establishing, exercising or defending legal claims;
- Courts, law enforcement, HMRC, the ICO and other competent authorities: where a valid and binding request requires it.
Each disclosure is limited to the data needed for its purpose and relies on an appropriate lawful basis.
6. International transfers
Some providers, including Google, Meta, Cloudflare and integrations chosen by profile owners, may process data outside the United Kingdom, including in the European Economic Area and the United States. Where that happens, the transfer relies on UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, or another safeguard permitted under the UK GDPR. You can ask for details of the safeguard used for a specific provider at support@digily.link.
7. Retention and deletion
Data is kept for as long as needed for its purpose, for the duration of the contractual relationship and for the retention periods set by tax, commercial, consumer and limitation rules. Illustrative periods are listed in the Privacy Notice.
When account deletion completes, account, profile and content data are removed from the active systems. Short-term rolling backups kept for disaster recovery may hold deleted data for a limited period before being overwritten; if a backup ever has to be restored, earlier deletions are applied again. Invoicing, payment, tax, security, fraud and dispute records may be kept separately from the active profile for as long as a statutory retention period or a legal claim requires. When the period ends and no continuing legal ground remains, data is deleted or anonymised.
8. Your rights
Under the UK GDPR you have the right to:
- ask whether we process your personal data and receive a copy of it (access);
- have inaccurate data corrected and incomplete data completed (rectification);
- have data erased where the conditions of Article 17 are met (erasure);
- restrict processing in the situations set out in Article 18 (restriction);
- receive the data you provided in a structured, commonly used, machine readable format and have it transmitted to another controller where technically feasible (portability);
- object to processing based on legitimate interests, and to direct marketing at any time (objection);
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except in the cases the law allows.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve your concern first, but you do not have to contact us before going to the ICO.
9. How to make a request
Send your request to support@digily.link, preferably from the email address registered on your account, and describe what you would like us to do. Please do not attach documents or special category data that are unrelated to the request.
Requests are answered free of charge and without undue delay, at the latest within one month. That period can be extended by two further months for complex or numerous requests, in which case we tell you within the first month. To protect your identity and your account, we may ask for reasonable additional verification. Manifestly unfounded or excessive requests may be refused or charged as the UK GDPR allows.
10. Updates and contact
If a processing purpose or data flow changes, the necessary information is provided before the new processing starts, and the current version of this notice is always published on this page. This general notice does not replace the short, activity-specific information shown at the moment data is collected, for example during registration, checkout, partner application, contact or cookie choices.
Questions and data protection requests: support@digily.link.