Legal
Privacy Policy
What we collect when you visit this website or work with us, why we collect it, who else sees it, and what you can ask us to do about it.
Effective 8 September 2026 · Digital Impact Enterprise LLC trading as Digital Impact Sites
Contents
- 1. Who we are
- 2. What this policy covers
- 3. What we collect, and where it comes from
- 4. Why we use it — and our legal basis
- 5. Cookies and website measurement
- 6. Who we share information with
- 7. Where your information is stored and sent
- 8. How long we keep it
- 9. How we protect it
- 10. Your rights and choices
- 11. Making a complaint
- 12. Websites we build for our clients
- 13. Demonstration websites
- 14. Children
- 15. Changes to this policy
- 16. How to contact us
Who we are
Digital Impact Sites is the trading name of Digital Impact Enterprise LLC, a limited liability company established in the United States at 1401 Brickell Avenue, Suite 330, Miami, Florida 33131, United States. Our Australian tax registration is ARN 3000 3233 9943, held under the Australian Taxation Office’s simplified GST registration for non-residents.
We design, build and host websites for businesses. In this policy “we”, “us” and “our” mean Digital Impact Enterprise LLC trading as Digital Impact Sites. “You” means whoever is reading it — someone browsing this site, someone who has sent us an enquiry, or a client.
We are the controller of the personal information described here. You can reach us any time at info@digitalimpactsites.com.
What this policy covers
It covers:
- digitalimpactsites.com and its subdomains, including the demonstration websites we publish to show our design styles;
- enquiries you send us — through the form on this site, or by email, WhatsApp or phone;
- information we handle while designing, building, launching and hosting a website for you as a client.
It does not cover the finished websites we build for clients once they are live — those belong to the client, and their privacy policy applies. See section 12. It also doesn’t cover other companies’ websites we link to; if you follow a link, you are on their terms.
What we collect, and where it comes from
When you send us an enquiry
You give us:
- your first and last name, and your email address;
- your current website address and Instagram handle, if you have them;
- the kind of work you focus on;
- anything you choose to write in the free-text brief;
- which design style you picked as a starting point;
- optionally, a photograph of yourself — only if you tell us there are no usable pictures of you online;
- a record that you accepted our terms and conditions, and when.
The brief is a free-text box, so please don’t put anything sensitive in it — health information, government identifiers, or another person’s details. We don’t need any of that to design a website.
Our form also carries a hidden field and measures how long it took to fill in. Both exist purely to spot automated submissions, and we use them for nothing else.
When you become a client
Through our onboarding form and our conversations, we collect:
- your business or brand name, tagline and description;
- your professional credentials, qualifications, memberships and registration body;
- the country you work in, how you see clients, and your practice locations;
- your legal entity name, for your own site’s footer and legal pages;
- your contact details and social media profiles;
- any files you upload — logos, photographs, documents, existing content.
When you pay us
Payments are taken by Stripe. Stripe collects your card details directly — we never see or store a full card number. What we receive back from Stripe is your name, email, billing address, the amount, whether the payment succeeded, and any business tax number you entered at checkout.
When you email or message us
We keep the correspondence and the contact details attached to it, as a record of what was discussed and agreed.
Automatically, when you visit
Our host records standard server information, and Google Analytics records the pages you view, roughly where you are (derived from your IP address, which Google truncates), your device and browser type, how you arrived, and whether you completed an enquiry or an onboarding form.
We deliberately never send names, email addresses or anything you typed to Google Analytics. What goes there is counts and categories, not people.
From public sources
This one matters, because it is how the free draft works. When you send us an enquiry — or before we approach you as a prospective client — we look at what you have already published: your existing website, your public social media profiles, your business listings. We use that material to design a draft of your new site.
It is information you have already made public, and we use only what is relevant to designing a website for you. If you would rather we didn’t, say so and we will stop and delete what we gathered.
Sensitive information
We don’t ask for it and we don’t want it. The professional registration details clients give us are business information rather than sensitive personal information. If you do send us something genuinely sensitive, we will use it only to do the work you asked us to do.
Why we use it — and our legal basis
Under Australian law we collect only what is reasonably necessary for the functions below. If you are in the UK or the EEA, the third column is the legal basis we rely on under the UK GDPR and the GDPR.
| Why | What we use | Legal basis |
|---|---|---|
| Answer your enquiry and design your free draft | Enquiry details, publicly published material | Steps taken at your request before a contract; our legitimate interest in replying to people who contact us |
| Build, launch, host and support your website | Onboarding information, files, contact details | Performance of our contract with you |
| Take payment and keep our books | Billing details received from Stripe | Contract; and legal obligation for tax records |
| Send service messages — your draft is ready, a review request, a renewal reminder, an invoice | Name, email | Contract; legitimate interests |
| Keep the site secure and block spam and abuse | Technical data, anti-bot signals | Legitimate interests |
| Understand how the site is used and improve it | Analytics data | Legitimate interests |
| Meet legal, tax and accounting obligations | Records of the engagement | Legal obligation |
| Send you occasional updates about our services, if you ask for them | Name, email | Consent — which you can withdraw at any time |
We do not sell personal information, and we do not share it with anyone for their own marketing. We also don’t make decisions about you by purely automated means.
Where your information is stored and sent
We are a United States company and most of our providers are based in the United States, so your information is stored and processed there and in the other countries those providers operate from.
If you are in Australia: before we disclose your information to an overseas recipient we take reasonable steps to satisfy ourselves that they will handle it consistently with the Australian Privacy Principles.
If you are in the UK or the EEA: transfers out are covered by the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or by the provider’s own Data Privacy Framework certification. Ask us and we will tell you which applies to a particular provider.
How long we keep it
- Enquiries that don’t become projects — up to 24 months, then deleted. We keep them that long because people often come back to us months later.
- Free drafts, and the material gathered to build them — up to 24 months after we last heard from you.
- Client records, agreements and project files — for the life of the engagement and seven years afterwards, which is what tax and accounting rules require of us.
- Billing records — seven years.
- Email correspondence — for as long as it is a useful business record, then deleted.
- Analytics — Google holds the underlying event data for 14 months and then deletes it automatically.
You can ask us to delete something sooner — see section 10 — and we will, unless we are required to keep it.
How we protect it
Everything on this site is served over an encrypted connection. Access to our client records, our mailbox and our payment systems is limited to the people who need it, and protected by strong, unique passwords and two-factor authentication.
Payment credentials never touch our systems — Stripe handles them directly. Files you upload go straight to storage over a single-use authorised link rather than passing through our servers.
No system is perfectly secure. If a breach ever happens that is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires.
Your rights and choices
Wherever you are, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong or out of date;
- delete it;
- stop using it for a particular purpose;
- stop contacting you.
If you are in the UK or the EEA, you also have the right to restrict how we process your information, to object to processing we base on legitimate interests, to receive your information in a portable format, and to withdraw consent at any time — withdrawing it doesn’t make what we did beforehand unlawful.
How to ask: email our Privacy Officer at info@digitalimpactsites.com and tell us what you want. There is no charge. We respond within 30 days, and within one month where the UK GDPR or the GDPR applies to you.
We may ask you to confirm who you are before we hand over personal information. That check protects you, not us.
Making a complaint
Please come to us first, at info@digitalimpactsites.com, marked for the attention of the Privacy Officer — most things are quicker to fix directly.
How we handle it. We acknowledge your complaint within five business days, tell you who is looking at it, and ask for anything else we need to understand what happened. We give you a written answer within 30 days — what we found, what we are doing about it, and what we will change. If we need longer we tell you why, and when to expect an answer.
If we can’t resolve it, you can complain to a regulator:
- Australia — the Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992.
- United Kingdom — the Information Commissioner’s Office, ico.org.uk.
- EEA — your national data protection authority.
- Elsewhere — your local privacy regulator.
Websites we build for our clients
When someone fills in a form on a website we built and host for a client, that information belongs to the client. They decide what it is used for; we handle it only on their instructions, as their service provider — a “processor”, in UK and EU terms. Their privacy policy governs it, not this one, and we never use their visitors’ information for our own purposes.
If you are a visitor to a site we built and you want your information removed, contact the business that runs it. If you can’t reach them, contact us and we will pass your request on.
Demonstration websites
The example websites on our subdomains exist to show our design styles. The businesses, practitioners, names, photographs, credentials and testimonials on them are invented. They are not real people, real clients or genuine reviews.
Their forms are part of the demonstration. Anything submitted through one reaches us as an enquiry, and is handled exactly as described in this policy.
Children
We sell to businesses, and this website is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, tell us and we will delete it.
Changes to this policy
We update this page when what we do changes. The effective date at the top always tells you which version you are reading. If a change materially affects how we handle information we already hold about you, we will tell current clients by email before it takes effect.
How to contact us
Privacy questions and requests: the Privacy Officer, info@digitalimpactsites.com
Billing: billing@digitalimpactsites.com
Post: Digital Impact Enterprise LLC, 1401 Brickell Avenue, Suite 330, Miami, Florida 33131, United States
Digital Impact Enterprise LLC is the controller of the information described in this policy. Our Privacy Officer is the person responsible for it, and is reachable at the addresses above. We are not required to appoint a data protection officer under the UK GDPR or the GDPR, and have not done so.
This policy sits alongside our terms and conditions, which cover using this website, the free draft, and the terms we work under if you become a client.
Questions about this document? Get in touch or email info@digitalimpactsites.com.