Privacy Policy

Our services are designed to transform ideas into impactful digital experiences that drive real results. We combine creativity, strategy.

Discover the creativity, strategy, and innovation behind each project we undertake. From branding and web design to digital campaigns and interactive experiences.

Legal information

Privacy policy

How Digital Ad Astra Ltd collects, uses, shares and protects personal information — written in plain language, because you should be able to understand exactly what happens with your data.

UK GDPR & EU GDPRUS state privacy lawsNever sold for moneyYou stay in control

The short version

  • We collect only what we need — mainly what you send us through our forms and what our website records automatically.
  • We never sell your data for money and we never use it to make decisions that legally affect you.
  • Advertising cookies need your consent where the law requires it, and you can withdraw it at any time.
  • You can ask us to see, correct, delete or move your data — email info@digitaladastra.com.
Who we are

This privacy policy is issued by Digital Ad Astra Ltd, a company registered in England and Wales (“Digital Ad Astra”, “we”, “us” or “our”). We are a subscription-based digital marketing agency and we operate the website digitaladastra.com (the “Website”). We have teams and offices in Tampa (Florida, USA), London (United Kingdom) and Sarajevo (Bosnia and Herzegovina).

For the personal information described in this policy, Digital Ad Astra is the “controller” (the organisation that decides why and how the data is used), except where we act on behalf of a client — see “Client campaigns and our role as processor” below.

Contact for anything privacy-related: info@digitaladastra.com.

What this policy covers

This policy applies when you visit our Website, fill in a form, subscribe to our newsletter, book or attend a call with us, email or message us, follow or interact with our social media channels or advertising, become a client, or otherwise deal with us as a prospect, client, supplier, partner or job applicant.

It does not cover websites run by other companies that we link to or that link to us. Please read their policies separately.

By using the Website you acknowledge this policy. Where the law requires your consent (for example for non-essential cookies or marketing emails), we ask for it separately and you can withdraw it at any time.

Information we collect

Information you give us

  • Identity and contact details — name, business name, job title, email address, phone number, country or city.
  • Enquiry details — the content of your message, your goals, budget range, services you are interested in, and any files or links you send.
  • Newsletter details — your email address and the date you subscribed.
  • Client and billing details — business details, billing address, tax or VAT number, invoices and payment status. Payments are handled by third-party payment providers; we do not store full card numbers.
  • Communications — emails, messages, call notes and recordings or transcripts of meetings (we tell you before we record anything).
  • Account and access details — where you give us access to ad accounts, analytics, CRM or other tools so we can do our work. Please grant access through the platform’s own permission settings and never send us your passwords in plain text.

Information collected automatically

  • Device and technical data — IP address, browser type and version, operating system, device type, screen size, language and time zone.
  • Usage data — pages viewed, links clicked, time on page, referring website or ad, approximate location (city or country level derived from your IP address) and general interaction events.
  • Cookie and pixel identifiers — see “Cookies, pixels and similar technologies”.

Information from other sources

  • Advertising and social platforms (for example when you submit a lead form on an ad or message us on social media).
  • Business directories, professional networks and publicly available sources, for B2B outreach and due diligence.
  • Referrals from clients, partners or colleagues.

Sensitive information. We do not need “special category” data (such as health, religion, political opinions or biometric data) and ask that you do not send it to us. Our Website is not designed for it.

How and why we use it

We only use personal information when the law lets us. Under UK and EU GDPR, these are the purposes and the legal bases we rely on:

PurposeExamplesLegal basis
Respond to youAnswering enquiries, booking and running calls, preparing proposals.Legitimate interests; steps at your request before a contract.
Deliver our servicesRunning campaigns, reporting, invoicing, client support.Performance of a contract; legal obligation.
Newsletter & marketingSending updates, offers and insights by email.Consent, or (for existing business contacts, where allowed) legitimate interests with an easy opt-out.
Analytics & improvementUnderstanding how the Website performs and how to improve it.Consent (non-essential cookies); legitimate interests (aggregated, privacy-friendly measurement).
Advertising & retargetingMeasuring and optimising our own ads; showing relevant ads on other platforms.Consent.
Security & fraud preventionSpam filtering, abuse detection, backups, logs.Legitimate interests; legal obligation.
Legal & complianceAccounting, tax, responding to lawful requests, defending legal claims.Legal obligation; legitimate interests.

Where we rely on legitimate interests, we have weighed them against your rights and expectations. You can ask us for details of that assessment and you can object at any time (see “Your rights”).

Automated decisions and AI tools

We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect. We may use AI-assisted tools (for example for drafting, translation, analytics or ad optimisation). We do not knowingly enter personal data of website visitors or enquirers into public AI tools, and we choose providers that contractually restrict use of your data for training their models where that option is available.

Cookies, pixels and similar technologies

Cookies are small files stored on your device. We also use similar technologies such as tracking pixels, tags, local storage and software development kits. They fall into four groups:

  • Strictly necessary — keep the Website secure and working (for example form protection, load balancing and remembering your cookie choice). These do not require consent.
  • Functional — remember preferences and make embedded features work.
  • Analytics — help us understand traffic and performance. We may use tools such as Google Analytics or similar services.
  • Advertising — measure our campaigns and show relevant ads on other platforms. We may use tools such as the Meta (Facebook and Instagram) Pixel, Google Ads tags and similar services from other advertising platforms.

Consent and control. Where the law requires it (for example in the UK and EU), we set analytics and advertising cookies only after you agree through our cookie settings, and you can change your mind at any time. You can also block or delete cookies in your browser settings, use your browser’s “Do Not Track” or Global Privacy Control signal where supported, or opt out of interest-based advertising through your platform ad settings and industry tools such as optout.aboutads.info and youronlinechoices.com. Blocking some cookies may affect how the Website works.

Third parties that provide these technologies may collect data about you across different websites and may combine it with other information they hold. Their use of that data is governed by their own privacy policies.

Email and marketing messages

If you subscribe to our newsletter or ask us to keep you updated, we will send you marketing emails until you unsubscribe. Every email includes an unsubscribe link, or you can write to info@digitaladastra.com and we will stop. For business-to-business outreach we follow the applicable electronic-marketing rules (for example PECR in the UK and CAN-SPAM in the US), we identify ourselves clearly, and we honour opt-outs promptly.

We will never add you to a list you did not ask to join and we will not share your email address with third parties for their own marketing.

Service messages (for example about an active project, invoice or security issue) are not marketing and may still be sent if you are a client.

Who we share it with

We do not sell your personal information for money. We share it only as needed, with:

  • Service providers (processors) acting on our instructions — website hosting and security, email and form delivery, CRM and booking tools (for example GoHighLevel or similar), analytics, cloud storage, project management, accounting and payment providers, and communication and meeting tools.
  • Advertising and social platforms such as Meta and Google, when you interact with our ads or when our tags run with your consent.
  • Our team and contractors in the UK, US and Bosnia and Herzegovina who need access to do their jobs and are bound by confidentiality.
  • Professional advisers — lawyers, accountants, insurers and auditors.
  • Authorities and courts where we are legally required, or to protect our rights, property or safety and those of others.
  • A buyer or successor if our business is reorganised, merged or sold. Your information would stay protected by this policy or a notice of change.

Where a provider processes data for us, we use written agreements that require it to protect the data and to use it only for our purposes.

US state law note: some US laws treat the use of advertising cookies and pixels as “sharing” for cross-context behavioural advertising, or as a “sale”, even if no money changes hands. If you want to opt out, use the cookie settings, send a Global Privacy Control signal, or email us (see “US state privacy rights”).

International transfers

We work across the UK, the United States, the European Economic Area and Bosnia and Herzegovina, and many of our providers are based in or use servers in the US and elsewhere. This means your information may be transferred to, stored in, or accessed from countries outside your own.

When we transfer personal data out of the UK or EEA, we make sure a lawful safeguard applies — for example an adequacy decision (including the UK–US Data Bridge or EU–US Data Privacy Framework where the recipient participates), the UK International Data Transfer Addendum or EU Standard Contractual Clauses, together with additional protections where appropriate. You can ask us for a copy of the safeguard that applies by emailing info@digitaladastra.com.

How long we keep it

We keep personal information only as long as needed for the purposes in this policy, and then delete or anonymise it. Typical periods:

  • Enquiries and leads who do not become clients — up to 24 months after our last contact, unless you ask us to delete earlier.
  • Newsletter subscribers — until you unsubscribe, plus a minimal record that you opted out so we respect it.
  • Clients and contracts — for the length of the relationship and then up to 6 years, to meet accounting, tax and legal-claim requirements.
  • Cookies and analytics data — according to each cookie’s lifespan (generally from a session up to 24 months) and the retention settings of the analytics tool.
  • Backups and security logs — for a short rolling period, then overwritten.

We may keep data longer where the law requires it or where we need it to establish, exercise or defend a legal claim.

How we protect it

We use appropriate technical and organisational measures to protect personal information, including encrypted connections (HTTPS), access controls and least-privilege permissions, strong authentication on key systems, regular software updates, backups, and confidentiality obligations for our team and contractors. We choose reputable providers and review how they handle data.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach occurs that is likely to put your rights at risk, we will notify you and the relevant regulator as required by law, and without undue delay.

You can help by using strong, unique passwords, granting platform access through official permission tools, and not sending sensitive details by unprotected email.

Your rights (UK & EU)

If UK GDPR or EU GDPR applies to you, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete your data in certain cases (“right to be forgotten”).
  • Restriction — ask us to pause using your data in certain cases.
  • Portability — receive data you gave us in a structured, commonly used format, and have it sent to another provider where technically possible.
  • Objection — object to processing based on legitimate interests, and always object to direct marketing.
  • Withdraw consent — at any time, without affecting earlier lawful processing.
  • Complain — to a data-protection authority (see “Complaints”).

How to use them: email info@digitaladastra.com with “Privacy request” in the subject. We may need to verify your identity before we act, to protect you from someone impersonating you. We will respond within one month (we may extend by up to two further months for complex requests and will tell you why). There is normally no fee; we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.

US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another US state with a consumer privacy law, you may have some or all of these rights, subject to the law’s conditions and exceptions:

  • to know what personal information we collect, use, disclose and share, and to access a copy;
  • to correct inaccurate information and to request deletion;
  • to opt out of the “sale” or “sharing” of personal information, and of targeted advertising or profiling;
  • to limit the use of sensitive personal information (we do not collect it for purposes that would trigger this right);
  • to not be discriminated against for exercising your rights.

Categories collected in the last 12 months: identifiers (name, email, phone, IP address, online identifiers); commercial information (enquiries, services of interest, subscription details); internet and device activity (browsing and interaction data); approximate geolocation; professional information (business and job title); and communications. Sources are described in “Information we collect”. Purposes are described in “How and why we use it”. Disclosed to the categories of recipients listed in “Who we share it with”.

Sale and sharing. We do not sell personal information for money. Advertising and analytics technologies on the Website may involve “sharing” or a “sale” as defined by some state laws. You can opt out through our cookie settings, a Global Privacy Control signal (which we treat as a valid opt-out request), or by emailing info@digitaladastra.com with “Do not sell or share my personal information”.

Exercising rights. Email us with “Privacy request”. You may use an authorised agent; we may verify your identity and the agent’s authority. We respond within 45 days (extendable once by 45 days where permitted). If we decline a request you may appeal by replying with “Appeal” in the subject line, and you may contact your state attorney general.

We do not knowingly sell or share personal information of consumers under 16.

Bosnia and Herzegovina residents

If you are in Bosnia and Herzegovina, we handle your personal data in line with the Law on Protection of Personal Data of Bosnia and Herzegovina and, where it applies to us, the GDPR. You have the right to information, access, correction, deletion, restriction and objection, and the right to complain to the Personal Data Protection Agency in Bosnia and Herzegovina (azlp.ba). Use the contact details in this policy to exercise your rights.

Client campaigns & our role as processor

When we run advertising, websites, funnels, CRM automations or email campaigns for our clients, we often handle personal data about the client’s own customers and leads (for example people who fill in a lead form or message a client’s page). In that situation the client is the controller and Digital Ad Astra is a processor / service provider. We process that data only on the client’s documented instructions, under a data-processing agreement, and we do not use it for our own purposes.

If your data is held by one of our clients and you want to exercise a right, please contact that business directly. If you contact us instead, we will pass your request on to the relevant client as required.

Clients are responsible for having a lawful basis, a privacy notice and valid consent (including cookie consent) for the tracking and data collection on their own websites and ads.

Children

Our Website and services are for businesses and are not directed at children under 16 (or the higher minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has given us personal information, email info@digitaladastra.com and we will delete it promptly.

Complaints

We would like the chance to fix any concern first, so please contact us at info@digitaladastra.com. You always have the right to complain to your data-protection authority:

  • United Kingdom — Information Commissioner’s Office (ICO), ico.org.uk, tel. 0303 123 1113.
  • EU / EEA — the supervisory authority in the country where you live, work or where the issue occurred (a list is available at edpb.europa.eu).
  • Bosnia and Herzegovina — Personal Data Protection Agency (AZLP).
  • United States — your state attorney general or the Federal Trade Commission.
Changes to this policy

We may update this policy from time to time, for example when our services, tools or the law change. The “Last updated” date at the top shows the latest version. If we make a material change we will take reasonable steps to tell you (for example with a notice on the Website or by email) and, where the law requires, ask for your consent again. Please check this page periodically.

Contact us

Digital Ad Astra Ltd
Email: info@digitaladastra.com (subject: “Privacy request”)
Offices: Tampa, FL (USA) · London (UK) · Sarajevo (Bosnia and Herzegovina)

You can also use our contact page.

Questions about your data?

Ask us anything, in plain English. A real person answers.

Email privacy request →
Cart (0 items)