Privacy and data

Privacy Policy

This policy explains what information we collect, why we use it, who we may share it with and the rights available to you.

Effective
4 August 2026
Reviewed
4 August 2026

Information we collect

Depending on how you interact with us, we may collect:

  • your name, job title and organisation;
  • your email address, telephone number and other contact details;
  • information you include in an enquiry, email, meeting or contact form;
  • information required to prepare proposals, contracts, invoices or deliver services;
  • records of our communications with you;
  • technical information such as your IP address, browser, device type and website activity;
  • your cookie and consent preferences;
  • information supplied by your organisation or another person who introduces us; and
  • information necessary to protect our website, systems and services from misuse or security threats.

Please avoid sending sensitive personal information through the website unless we have specifically asked you to provide it using an appropriate method.

Lawful bases

The lawful basis we rely on depends on why we are using the information.

Contract

We use personal information where it is necessary to enter into or perform a contract with you or your organisation.

Legitimate interests

We may use information where it is reasonably necessary to operate and develop our business, respond to enquiries, maintain professional relationships, improve our services or protect our systems.

We consider the effect on your rights before relying on legitimate interests.

Legal obligation

We may process information where this is necessary to comply with tax, accounting, regulatory or other legal requirements.

Consent

We rely on consent where required, including for non-essential cookies and similar website technologies. You can withdraw your consent at any time.

Cookies and artificial intelligence

We use cookies and similar technologies to operate the website, remember preferences and, where you consent, understand how the website is used. Google Tag Manager may manage tags, but non-essential analytics or advertising tags must remain blocked until the appropriate consent has been given. See our Cookie Policy for more information.

We may use artificial intelligence tools to assist with research, analysis, drafting, software development and administration. AI tools support our work but do not replace professional judgement or responsibility. Where AI may process personal information, we consider the purpose, risks, supplier terms and safeguards before use. See our AI Usage Statement for more information.

Sharing and international transfers

We may share personal information with trusted service providers that help us operate our business, including providers of:

  • website hosting and content delivery;
  • content management;
  • email, documents and business communications;
  • analytics and consent management;
  • accounting and payment services;
  • project management and software development tools;
  • data storage, backup and cyber security services; and
  • legal, insurance and professional advice.

These providers may include Cloudflare, Sanity, Google, CookieYes and other suppliers used for particular client engagements.

We may also disclose information where required by law, to protect our rights or the rights of another person, or in connection with a business sale or restructuring.

We do not sell personal information.

International transfers

Some of our suppliers may process information outside the United Kingdom.

Where personal information is transferred internationally, we use an appropriate legal mechanism such as:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another legally recognised safeguard.

Retention and security

We retain personal information only for as long as it is reasonably required for the purpose for which it was collected.

Our typical retention periods are:

  • general enquiries: up to 24 months after our last meaningful contact;
  • unsuccessful proposals: normally up to 24 months;
  • client project records: for the duration of the engagement and an appropriate period afterwards;
  • contracts, invoices and accounting records: normally at least six years after the relevant financial period;
  • website analytics: for the period configured within the analytics service;
  • cookie consent records: for the period needed to demonstrate and manage consent; and
  • security records: for as long as reasonably required to investigate incidents and protect our systems.

We may retain information for longer where required by law, a dispute, an insurance requirement or another legitimate reason.

How we protect information

We use proportionate technical and organisational safeguards intended to protect personal information against unauthorised access, loss, alteration or disclosure.

These include access controls, multi-factor authentication, secure cloud services, encryption where appropriate, software maintenance, backups and incident-management procedures.

No system can be guaranteed to be completely secure. Our Security Overview explains our general approach in more detail.

Your rights and complaints

Depending on the circumstances, you may have rights to access, correct or delete personal information, restrict or object to processing, receive certain information in portable form, withdraw consent and object to solely automated decisions. These rights are not absolute and exemptions may apply. Email hello@dumdumdigital.com to exercise a right; we may need to confirm your identity.

Please contact us first if you have concerns about how we have handled your information. You also have the right to complain to the Information Commissioner's Office.

We may update this policy as our services, suppliers or legal obligations change. The latest version will be published on this page with its revision date.

How we use personal information

We may use personal information to:

  • respond to enquiries;
  • arrange meetings and discuss potential work;
  • prepare proposals and contracts;
  • provide and manage services;
  • communicate with clients, suppliers and professional contacts;
  • administer payments, invoices and accounting records;
  • improve our website, services and business operations;
  • understand how people use our website;
  • maintain the security and availability of our systems;
  • establish, exercise or defend legal rights; and
  • meet legal, regulatory and contractual obligations.

Data protection contact

DumDum Digital’s data protection contact is:

Ben Budd

Shortlancer Limited trading as DumDum Digital

Email: hello@dumdumdigital.com

Registered office: 4 Chichele Street, Higham Ferrers, Rushden, England, NN10 8HT

Please contact Ben if you have questions about how we use personal information, wish to exercise a data protection right or want to raise a concern about our handling of your information.