Depth Digital serves businesses and individuals in the United Kingdom, European Union and elsewhere. We aim to use only the information reasonably needed to discuss, deliver and support a project.
Who we are
Depth Digital is the trading name of Jelena Osipova, a sole trader established in England, United Kingdom. For the personal information described in this notice, Jelena Osipova trading as Depth Digital is the data controller. This means we decide why and how that information is used.
This notice is intended to meet the transparency requirements of the UK General Data Protection Regulation, the Data Protection Act 2018 and, where it applies to our activities, the EU General Data Protection Regulation.
Depth Digital, England, United Kingdom
What this notice covers
This notice applies when you:
- visit the Depth Digital website;
- send an enquiry or complete a project brief;
- contact us by email, telephone or WhatsApp;
- meet us through Zoom, Google Meet, Microsoft Teams or another agreed channel;
- request a quotation, enter into a contract or receive our services;
- make a payment through Square; or
- supply text, images, files, account details or other material for a project.
It does not govern a third party’s independent use of your information on its own website or service. Those providers publish their own privacy information.
Personal information we collect
The information we collect depends on how you interact with us and what your project requires. It may include:
Identity, contact and business information
- your name, business or organisation name and job role;
- email address, telephone number and WhatsApp contact details;
- country, general location and business address where relevant; and
- the names and contact details of other authorised project contacts.
Enquiry and project information
- your project objectives, audience, preferred design direction and functional requirements;
- budget, target launch date, business priorities and decision-making information;
- website copy, branding, images, documents, uploads, links and other project files;
- information about products, services, team members, locations and business processes that you choose to provide; and
- feedback, approvals, support requests and correspondence throughout the project.
Payment and transaction information
Payments are processed by Square. We may receive the payer’s name and contact details, payment status, amount, date, invoice or transaction reference and information needed for refunds and accounting. We do not normally receive or store your complete payment-card number or card security code.
Meeting and communication information
We keep the content of messages and may keep useful project notes from calls or online meetings. We do not record meetings unless everyone is told in advance and an appropriate legal basis is established.
Website and security information
Our hosting and security providers may process technical request information such as IP address, browser and device type, operating system, requested URL, referring page, date and time, and security or diagnostic events. We do not currently use this information for behavioural advertising.
Saved project-brief information
If you choose “Email my secure link” in the client project brief, we process the email address you provide, an encrypted copy of the draft answers, a random access token, expiry information and limited technical records needed to operate and protect that feature. Hashed email and IP-based records are used to limit abusive or repeated email requests.
Please do not send special-category information, criminal-offence information, passwords or unnecessary personal information through our forms or project files. If a project genuinely requires sensitive information, agree a suitable method with us first.
How we collect information
We collect information:
- directly from you through forms, the client project brief, email, telephone, WhatsApp, meetings, files, contracts and payment activity;
- from an organisation or person who authorises you or introduces you as a project contact;
- from public business sources, such as a company website, professional profile or public register, when relevant to an enquiry or project; and
- automatically through essential hosting, network and security processes when your browser requests the website.
If you provide information about another person, you should have authority to do so and should make this notice available to them where appropriate.
Why we use information and our legal bases
| Purpose | Information normally used | Legal basis |
|---|---|---|
| Responding to enquiries, understanding a brief and preparing a quotation | Contact, business and project information; communications | Taking steps at your request before a contract and our legitimate interest in responding to genuine enquiries |
| Entering into, managing and delivering a project | Contact, project, content, files, approvals and communication information | Performance of a contract or steps before a contract; legitimate interests where our contract is with your organisation rather than you personally |
| Taking payments, issuing invoices, handling refunds and keeping tax records | Contact, transaction and accounting information | Performance of a contract, compliance with legal obligations and legitimate interests in administering our business |
| Operating, securing, troubleshooting and improving the website and services | Technical request, security and limited usage information | Legitimate interests in providing a reliable, secure service and protecting users and our business |
| Saving an optional encrypted project-brief draft and sending a continuation link | Email address, encrypted draft, token and expiry information | Your request for the feature and our legitimate interests in providing a useful and secure service |
| Providing support and retaining a project archive | Project files, contact details, decisions, correspondence and technical records | Performance of a contract and legitimate interests in providing future support, maintaining continuity and handling legal claims |
| Showing completed work in our portfolio or case studies | Published project visuals, business name, project description and agreed attribution | Contractual permission and our legitimate interests in showing our work; consent where required for identifiable individuals or material that needs separate permission |
| Establishing, exercising or defending legal rights and meeting regulatory requests | Relevant records from any category | Legal obligations and legitimate interests in protecting legal rights |
We do not currently use personal information to send newsletters or unsolicited marketing. If that changes, we will provide appropriate information and any consent or opt-out mechanism required by law.
Where we rely on legitimate interests, we consider whether the use is necessary and balanced against your rights and reasonable expectations. You may object to processing based on legitimate interests as explained below.
Information you must provide
Fields marked as required are needed to send an enquiry or project brief. We may also need certain identity, contact, project and payment information to prepare a quotation, form a contract or deliver the service.
You may choose not to provide optional information. If required information is not supplied, we may be unable to respond properly, provide an accurate proposal, enter into a contract or complete part of the project.
Website forms and saved project briefs
Web3Forms
Final client project-brief submissions use Web3Forms, operated by Web3Creative. Information entered into that form is sent to Web3Forms and forwarded to inboxes authorised by Depth Digital. Web3Forms and its infrastructure providers process that information to transmit, secure and operate the form service.
Web3Forms states that submission data is retained for a maximum of three years unless a shorter plan period applies or it is deleted earlier. It operates from India and may use infrastructure in multiple regions. Its Data Processing Agreement incorporates Standard Contractual Clauses and the UK Addendum where required.
See the Web3Forms Privacy Policy and Data Processing Agreement.
Browser and encrypted online drafts
The client project brief saves a working draft in your browser so you can move between sections. That local copy stays on the device until you submit the brief, clear the draft or browser storage is removed.
If you request a secure continuation link, an encrypted copy is stored through our Cloudflare Worker and database service for up to 30 days. The online copy is removed after a successful final submission, when you use the clear function, or when it expires. The continuation email address is used only to provide that feature and is not inserted into the project brief unless you separately enter it there. Resend, operated by Plus Five Five, Inc., delivers the continuation email.
Anyone who has the private continuation link may be able to open the saved draft. Keep it confidential and clear the online copy if the link may have been exposed.
Who receives personal information
Access within Depth Digital is restricted to team members shown on our website who need the information for their role. Website developers do not have routine access to client personal information. Exceptional technical access would be limited, authorised and subject to confidentiality.
We may use the following service providers, depending on how you contact us and how the project is delivered:
| Provider or recipient | Why information may be processed |
|---|---|
| Cloudflare | Website hosting, content delivery, security, domain and email routing, and the encrypted online project-brief feature through Workers and database services |
| Web3Forms / Web3Creative | Receiving and forwarding final project-brief submissions |
| Resend / Plus Five Five, Inc. | Sending the optional project-brief continuation email to the address requested by the visitor |
| Microsoft | Outlook email and Microsoft Teams meetings where used |
| Gmail inbox delivery and Google Meet where used | |
| WhatsApp / Meta | Messages and calls initiated through WhatsApp |
| Square | Payment processing, refunds, receipts, fraud prevention and transaction records |
| Zoom | Online meetings where agreed |
| Professional advisers and authorities | Accounting, legal advice, insurance, dispute handling or compliance with a lawful request |
We may also disclose relevant information if the business or its assets are reorganised, transferred or sold, subject to appropriate confidentiality and data-protection requirements.
We require service providers acting as processors to use information only for authorised purposes and to protect it appropriately. Some providers also act as independent controllers for parts of their service, such as payment fraud prevention or account administration.
Provider notices include: Cloudflare, Resend, Microsoft, Google, WhatsApp, Square and Zoom.
International transfers
Depth Digital operates from England, but we serve clients internationally and use providers with global infrastructure. As a result, personal information may be accessed or processed outside the United Kingdom and, where relevant, outside the European Economic Area.
For example, Web3Creative operates from India and states that its subprocessors may process information in multiple regions. Resend states that its primary processing operations take place in the United States. Cloudflare, Microsoft, Google, Meta, Square and Zoom also operate international networks.
Where data-protection law requires a transfer mechanism, we rely on measures such as a United Kingdom adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, European Commission Standard Contractual Clauses, and contractual and technical safeguards offered by the provider. You may contact us for more information about the safeguards relevant to your information.
How long we keep information
We keep personal information only for as long as reasonably needed for the purpose described, including support, accounting and legal obligations. Our normal guide periods are:
| Record | Normal retention period |
|---|---|
| Enquiries that do not become client projects | Up to 12 months after the last meaningful contact, unless a longer period is needed for a dispute or you ask us to retain it |
| Client, contract and project-administration records | Normally six years after the project or client relationship ends |
| Invoices, payments and tax or accounting records | Normally six years from the end of the relevant accounting or tax period |
| Project files and support archive | Normally six years after completion, or longer where future support is requested, the contract provides for it, or a legal claim reasonably requires it |
| Encrypted online project-brief draft | Up to 30 days, and removed earlier after successful submission or when cleared |
| Web3Forms submission copy | Subject to the service configuration and Web3Forms’ stated maximum physical retention of three years; our inbox copy follows the relevant enquiry or client-record period |
| Technical and security records | According to the provider’s settings and normal security-log cycles, or longer where needed to investigate an incident |
| Portfolio and case-study materials | While the work remains relevant and its use remains permitted, subject to applicable rights and any agreement with the client |
Backups may retain residual copies until they are overwritten through the normal secure backup cycle. We may keep a minimal record after deletion where needed to show that a request was fulfilled, honour an objection or meet a legal obligation.
Deletion requests and project archives
You may ask us to delete your personal information by emailing info@depth-digital.com. We will assess the request under applicable law and delete or anonymise information where the right applies.
We may need to retain limited information where it is required for tax, accounting, contractual, fraud-prevention or legal-claims purposes. Deleting a client’s contact information does not automatically require deletion of a published project image or case study where that material is not personal information or where continued use is permitted by contract or another lawful basis. If a portfolio item identifies you personally, tell us what you would like removed and we will assess it specifically.
Cookies, analytics and browser storage
We do not currently use advertising cookies, behavioural tracking cookies or a marketing analytics service on this website.
Cloudflare may use strictly necessary cookies or similar technology to deliver security, traffic management and abuse-prevention features. For example, a security challenge may set a clearance cookie so that a verified visitor can continue to use the site. These technologies are used for site operation and security rather than advertising.
The client project brief uses first-party browser storage to remember unfinished answers on the device being used. This draft remains until the brief is successfully submitted, the visitor uses the clear function or the browser’s stored website data is removed.
The fonts and animation libraries needed to display this website are hosted as part of the Depth Digital website package and are delivered through Cloudflare. They are not requested from Google Fonts or jsDelivr.
See our dedicated Cookie Notice. If we introduce non-essential cookies or analytics later, we will update that notice and add an appropriate consent control before using them where consent is required.
How we protect information
We use proportionate organisational and technical safeguards, including:
- HTTPS encryption for the website and Cloudflare network protection;
- strong, unique passwords and two-step verification where available;
- password-protected and encrypted devices;
- restricted access based on a genuine business need;
- secure backup arrangements;
- encryption of optional online project-brief drafts; and
- careful selection of service providers and secure communication methods.
No internet transmission or storage method is completely secure. Please use the project upload facilities only for appropriate files and contact us before sending unusually sensitive information.
Your data-protection rights
Depending on the circumstances and the law that applies, you may have the right to:
- ask for access to your personal information and a copy of it;
- ask us to correct inaccurate or incomplete information;
- ask us to erase your information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests;
- receive certain information in a portable format or have it sent to another organisation;
- withdraw consent at any time where consent is the legal basis, without affecting earlier lawful use; and
- complain to a data-protection authority.
These rights are not absolute and exemptions may apply. To exercise a right, email info@depth-digital.com. Please describe your request clearly. We may ask for reasonable proof of identity and authority before disclosing or changing information.
We normally respond within one month. The law may allow an extension for a complex request, in which case we will explain the reason and expected timing. We do not normally charge a fee, although the law permits a reasonable fee or refusal in limited cases involving manifestly unfounded or excessive requests.
Questions and complaints
Please contact us first at info@depth-digital.com so we can investigate and try to resolve your concern.
You also have the right to complain to the UK Information Commissioner’s Office. You can use the ICO’s complaint service or call 0303 123 1113. If the EU GDPR applies to you, you may also be entitled to complain to the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred.
Children
Our services are intended for businesses and adults who can enter into a project agreement. We do not knowingly collect information directly from children through this website. If you believe a child has provided personal information without suitable authority, contact us so we can assess and remove it where appropriate.
Automated decisions and AI tools
We do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects.
Depth Digital may use artificial-intelligence tools to help draft or refine general website content. We do not intentionally enter client personal information, confidential project information or uploaded client files into those tools. AI output is reviewed by a person before it is used.
Third-party websites and services
Our website may link to third-party websites or services. Following a link may allow that third party to collect or receive information under its own terms. We do not control independent third-party websites and encourage you to read their privacy information.
Changes to this notice
We may update this notice when our website, services, providers or legal obligations change. The current version will be published on this page with a revised “last updated” date. If a change materially affects how we use existing personal information, we will take additional steps to inform affected people where required.
Contact us
For privacy questions, requests or concerns, contact:
Sole trader established in England, United Kingdom