Privacy Policy

Last updated: July 2026

At Digitally Baffled, we are committed to protecting your privacy and handling your personal data responsibly. This policy covers both our website and our mobile app, and explains what data we collect, why we collect it, how we use it, and your rights under UK data protection law. We have written it in plain English — because that is how we do everything.

1. Who we are

Digitally Baffled is a digital consultancy based in the United Kingdom. We provide digital transformation services to small businesses, including web design, digital marketing, ongoing support, and business setup services.

This privacy policy covers both our website (digitallybaffled.com) and the Digitally Baffled mobile app available on the Google Play Store. Where differences exist between the website and app, they are noted below.

For the purposes of UK GDPR and the Data Protection Act 2018, Digitally Baffled is the data controller for personal data collected through our website and app.

If you have any questions about this policy or how we handle your data, you can contact us at hello@digitallybaffled.com or by calling 07511 683542.

2. What data we collect

We collect personal data that you provide directly to us, including: your name, email address, phone number, company name, and any information you include in messages sent through our contact form or in-app chat.

When you use our app, we also collect: messages and voice notes you send through the in-app chat; files and images you upload; call session data (including video/voice call duration and AI-generated meeting summaries); invoice and service agreement status; project milestone progress; and your online / last-seen status within the app.

We may collect technical data automatically when you visit our website or use our app, such as your IP address, browser type, device type, operating system version, pages visited, and time spent. This is collected through cookies (website) and analytics tools.

If you enable push notifications in the app, we collect a unique push device token (provided by Firebase Cloud Messaging) so we can deliver notifications to your device. This token is not personally identifiable on its own.

If you enable biometric login (fingerprint or face recognition) in the native app, your biometric data never leaves your device. We only store a flag indicating that biometric authentication is enabled for your account; the actual biometric verification is performed by your device's operating system.

We do not handle your payment card details — card payments are processed securely by Stripe. We do process invoice and payment status information as part of providing our services.

We do not collect other sensitive personal data (such as health information, or data about protected characteristics).

3. How we use your data

We use the personal data you provide to respond to your enquiries, provide the services you have requested, and operate your client portal.

In the app specifically, we use your data to: deliver messages and voice notes between you and your account manager; notify you of incoming calls, new messages, invoices, and service agreements; process and display invoice and agreement status; track project milestone progress; and show your online status to your account manager so they know when you are available.

We may use your contact details to send you information about our services where you have indicated an interest. You can opt out of marketing communications at any time by contacting us.

We use technical and analytics data to understand how our website and app are used and to improve their performance and content.

We will never sell your personal data to third parties, and we will never use it for purposes incompatible with those described in this policy.

4. App permissions

The Digitally Baffled app may request the following permissions from your device. All permissions are optional except where noted, and you can manage or revoke them through your device settings at any time:

Notifications — required to alert you about incoming calls, new messages, invoices, service agreements, and project updates. Without this permission, you will not receive real-time alerts when your phone is locked.

Camera — used for video calls with your account manager. This permission is only requested when you initiate a video call.

Microphone — used for voice calls, voice notes, and meeting recording within the app. This permission is only requested when you use these features.

Biometric authentication — optional. Used to unlock the app with your fingerprint or face instead of typing your password. Your biometric data never leaves your device.

Internet access — required for the app to function, as it connects to our live services.

5. Legal basis for processing

We process your personal data on the following legal bases under UK GDPR:

Legitimate interests — to respond to enquiries, improve our services, operate the client portal and app, and communicate with clients about services they have engaged.

Contract performance — where we are providing services to you under a contract, we process your data as necessary to fulfil that contract (including delivering messages, invoices, and agreements through the app).

Consent — where we rely on consent (for example, for push notifications, marketing communications, or analytics cookies), you have the right to withdraw that consent at any time through your device settings or by contacting us.

6. How long we keep your data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.

Enquiry data is typically retained for up to 2 years from the date of last contact. Client data is retained for up to 6 years following the end of a contract, in line with standard business and tax record-keeping requirements.

Chat messages, voice notes, and file attachments are retained for the duration of your active engagement and for up to 2 years after contract completion, unless you request earlier deletion.

Push device tokens are deleted when you sign out of the app, disable push notifications, or uninstall the app.

You can request deletion of your data at any time (see Your Rights and Account Deletion below), subject to any legal obligations we have to retain it.

7. Who we share your data with

We do not sell or rent your personal data to any third party.

We share data with trusted third-party service providers who assist us in operating our business and app. These providers are contractually required to handle your data securely and only for the purposes we specify. The services we use include:

Lovable Cloud (database, authentication, and file storage) — hosts your account data, messages, voice notes, and uploaded files.

Firebase Cloud Messaging (Google) — delivers push notifications to your device. Only a device token and message preview are shared.

LiveKit — provides the infrastructure for video and voice calls within the app. Video and voice calls are encrypted in transit via LiveKit.

Stripe — processes invoice payments. We share only the necessary transaction details; Stripe handles payment card data under PCI-DSS standards.

Resend — delivers email notifications (e.g., new message alerts when you are offline).

Google Analytics 4 — website usage analytics (anonymised, only with your cookie consent).

Cloudflare Turnstile — used for spam prevention on our contact form.

We may disclose your data if required to do so by law, or in response to a valid request from a law enforcement or regulatory authority.

8. Cookies

Our website uses cookies to improve your browsing experience and to help us understand how the site is used. Cookies are small text files stored on your device.

We use essential cookies (required for the site to function), analytics cookies (to understand usage patterns), and preference cookies (to remember your settings such as dark/light mode).

Analytics cookies are only set after you give explicit consent via the cookie banner. We use Google Analytics 4 (GA4) to understand how visitors use our site — this data is anonymised and processed by Google in accordance with their privacy policy (policies.google.com/privacy). You can opt out of Google Analytics at any time by declining cookies or using the Google Analytics Opt-out Browser Add-on.

The mobile app does not use cookies. Technical preferences (such as dark mode) are stored locally on your device.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.

9. Your rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of access — you can request a copy of the personal data we hold about you.

Right to rectification — you can ask us to correct inaccurate or incomplete data.

Right to erasure — you can ask us to delete your personal data in certain circumstances.

Right to restrict processing — you can ask us to limit how we use your data.

Right to data portability — you can ask us to provide your data in a structured, machine-readable format.

Right to object — you can object to our processing of your data where we rely on legitimate interests.

To exercise any of these rights, please contact us at hello@digitallybaffled.com. We will respond within one month.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Account deletion

You can request deletion of your account and associated personal data at any time. When you request deletion, we will remove or anonymise: your profile information; chat messages and voice notes; uploaded files; call session history; invoice and agreement records; and push device tokens.

Some data may be retained where required by law (for example, financial records for tax purposes) or where necessary for our legitimate interests (for example, anonymised analytics data). Where data is retained for legal reasons, it is kept only for the minimum period required.

The easiest way to request deletion is our dedicated delete your account page — sign in and remove your account instantly, or submit a request by email if you can't. Alternatively, email us at hello@digitallybaffled.com with the subject "Account deletion request" and include the email address associated with your account. We will confirm receipt within 48 hours and complete the deletion within 30 days, unless we need to retain specific data for legal purposes (in which case we will inform you).

Uninstalling the app from your device will stop push notifications and delete locally stored data (such as cached messages and preferences), but it does not delete your account data from our servers. You must request account deletion separately.

11. Data security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, or disclosure.

All data transmitted through our website and app is encrypted using SSL/TLS. Video and voice calls are encrypted in transit via LiveKit. Access to personal data is restricted to those who need it to carry out their responsibilities.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay.

12. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices, app features, or legal requirements. The date at the top of this page will always show when it was last updated.

We encourage you to review this policy periodically. Continued use of our website or app following any changes constitutes your acceptance of the updated policy.

Questions about your data?

Email us at hello@digitallybaffled.com

or call 07511 683542 — we're available 24/7.