Legal / GDPR
GDPR and your rights.
This page explains how Divert Digital Ltd approaches the UK General Data Protection Regulation, the Data Protection Act 2018 and related data-protection requirements. It should be read with our Privacy policy and Cookie policy.
Who is responsible for your data?
Divert Digital Ltd is the controller for personal information we collect directly through this website, enquiries, meetings and our business relationship with you. Our registered address is 3D1, Zetland House, 5-25 Scrutton St, London EC2A 4HJ. Company number: 07046206.
For privacy or data-protection questions, contact tristan@divertdigital.com. We do not currently appoint a separate data-protection officer; this contact point handles data-protection requests.
What data may we process?
Depending on how you interact with us, this may include your name, work email, telephone number, organisation, role, project requirements, correspondence, meeting notes, proposals, contracts, invoices and support records. Website access may also involve technical information such as IP address, browser, device, referring page and pages visited.
Why do we process it?
We process personal data to respond to enquiries, arrange calls, prepare proposals, deliver and support digital projects, administer contracts and accounts, maintain business records, secure our systems, improve our services and comply with legal obligations.
Our lawful bases
We rely on the lawful basis that fits the processing: taking steps at your request before a contract, performing a contract, complying with a legal obligation, pursuing legitimate interests in operating and improving our business, or your consent where consent is required. Where we rely on consent, you can withdraw it at any time; withdrawal does not affect processing that took place before withdrawal.
Processors and sharing
We may use carefully selected service providers for hosting, security, email, scheduling, project delivery, payments, accounting and business administration. They process information only for agreed purposes and under appropriate contractual controls. We do not sell personal data.
Some providers may process data outside the UK. Where that happens, we use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful safeguard as applicable. We will disclose information where required by law, to protect our rights or to protect someone’s safety.
How long do we keep it?
We keep personal data only for as long as reasonably necessary for the purpose it was collected, including to deliver services, maintain accurate financial and project records, resolve disputes and meet legal obligations. Retention varies by record type. When information is no longer required, we securely delete it or anonymise it.
Security and incidents
We use reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse or alteration. No internet transmission or storage system can be guaranteed completely secure. If a personal-data breach creates a risk to people’s rights and freedoms, we will assess it and notify the Information Commissioner’s Office and affected people where required by law.
Your rights
Subject to legal exceptions, you may request access to your personal data; correction of inaccurate or incomplete data; deletion; restriction of processing; data portability for information you provided; or object to processing based on legitimate interests. You may also object to direct marketing and withdraw consent where consent is the lawful basis.
To exercise a right, email tristan@divertdigital.com with “Data protection request” in the subject and enough information for us to identify the relevant records. We may need to verify your identity. We normally respond within one month, although the period may be extended by up to two further months for complex or multiple requests; if so, we will explain why.
Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner’s Office, the supervisory authority for UK data protection: ico.org.uk/make-a-complaint.
Last updated: September 2026