Privacy Policy
Last updated 19 September 2026
This policy explains what personal data Dijital Mekan Ltd ("we", "us", "our") collects when you visit dijitalmekan.co.uk, contact us, or use the customer panel; why we collect it; who we share it with; and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are the data controller for this data.
1. Who we are and how to contact us
Dijital Mekan Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Questions about this policy or your data: info@dijitalmekan.co.uk. We aim to reply within five working days.
2. The data we collect
When you visit the website
- Technical and security data: your IP address, browser type, the pages requested and the time of the request, kept in server logs to keep the site secure and diagnose faults.
- Usage data: we do not currently run analytics or advertising tags on this website. If we introduce them, this policy will be updated and a cookie banner will ask for your consent first. See our Cookie Policy.
- Your cookie choices and appearance preference, stored in first-party cookies that contain no personal data.
When you contact us
- Messages: what you send us on WhatsApp, by e-mail or by phone, together with your name, number or address, so we can answer you.
When you create an account or subscribe
- Account details: your name, e-mail address and, if you choose one, a password (stored hashed, never in plain text). If you sign in with Google we receive your name and e-mail address from them.
- Business details: business name, website, industry, postcode, location and service area, phone number, logo, brand notes, goals and the answers you give during set-up, so we can deliver the service.
- Billing data: your plan, payment history, invoice references and the type and last four digits of your card. Full card details are collected and stored by Stripe, our payment provider, and never reach our servers.
- Access records: which of your digital accounts you have given us access to and their status. We never ask for, or store, the passwords to those accounts.
- Security and audit data: sign-in times, IP addresses and a short log of important actions (for example subscription changes or access grants), so we can keep your account safe and answer questions about what happened.
Data we receive from other people
When you use "Continue with Google" , the provider sends us your name, e-mail address and a unique account identifier. When you give us access to a platform such as Google Business Profile or Meta Business Suite, we see the information that platform shows to a manager.
3. Why we use it and our lawful basis
- To provide the service you subscribe to, including managing your digital accounts on your instructions and messaging you on WhatsApp: performance of a contract.
- To take payment, issue invoices and keep accounting records: performance of a contract and our legal obligations.
- To keep the website and panel secure, prevent fraud and misuse, and investigate problems: our legitimate interests in running a safe service.
- To send service e-mails such as payment receipts, failed payment notices, subscription changes and security alerts: performance of a contract. These are not marketing and you cannot opt out of them while you have an account.
- To send occasional news or offers by e-mail, only where you have agreed or where we may do so under the business-to-business rules in PECR. Every such e-mail has an unsubscribe link.
- To answer your enquiries: our legitimate interest in responding to people who contact us, and steps taken at your request before a contract.
4. How we use AI tools
We use artificial intelligence tools to help research, draft and analyse work for you. When we do, we keep the information shared with the tool to the minimum the task needs, and where client information is involved we use business accounts and settings intended for that purpose. Every decision about your business is made and reviewed by a person. We do not make decisions about you based solely on automated processing.
5. Who we share it with
We use a small number of service providers who process data on our behalf, under contracts that require them to protect it:
- Stripe (card payments, invoices and the billing portal).
- Our hosting provider (servers in the United Kingdom).
- Google (Google Workspace for our business e-mail and the service e-mails we send; Sign in with Google; Google Business Profile, Search Console, Analytics and Ads when we manage them for you).
- Meta (WhatsApp messaging; Facebook, Instagram and Meta Ads when we manage them for you).
- postcodes.io: when you type a postcode into a business form, the postcode alone is sent to this open-data service to find your area. Nothing else is sent.
- AI tool providers as described in section 4.
When we manage your digital accounts we act on your instructions within those platforms, and their own privacy policies apply to the data they hold. We may also share data where the law requires it, for example with HMRC, a court or a regulator. We do not sell personal data.
6. International transfers
Some of the providers above process data outside the United Kingdom, mainly in the European Economic Area and the United States. Where that happens we rely on the UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that your data has equivalent protection.
7. How long we keep it
- Account and business data: while you have an account and for 12 months after it closes, in case you return or a query arises. After that it is deleted or anonymised.
- Billing and invoice records: six years after the end of the financial year they relate to, as HMRC requires.
- Security and audit logs: 12 months.
- Enquiries from people who do not become customers: 12 months from the last message.
8. Your rights
You have the right to ask us to give you access to your personal data, to correct it, to delete it, to restrict how we use it, to receive a copy in a portable format, and to object to processing based on our legitimate interests. Where we rely on consent you can withdraw it at any time, which does not affect what was done before. To exercise any right, e-mail info@dijitalmekan.co.uk from the address on your account; we respond within one month and never charge for a reasonable request.
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.
9. Security
Data travels over HTTPS and is stored on access-controlled servers. Passwords are hashed with a modern algorithm, card details never touch our systems, and you can turn on two-step verification in your account settings. Access to your own platforms is always granted through manager or partner roles that you control and can remove at any time. If we ever discover a breach that puts you at risk we will tell you and the ICO without undue delay.
10. Cookies
Essential cookies keep you signed in and protect forms. We do not currently set analytics or marketing cookies. Full details are in our Cookie Policy.
11. Children
Our service is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
We will post any changes on this page and update the date at the top. Where a change is significant, we will also tell account holders by e-mail before it takes effect.