Privacy Policy
Last updated: 13 July 2026
Thank you for choosing to be part of our community at Transparent Digital Services Limited (the "Company", "we", "us", "our"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at contact@transparentdigitalservices.com.
When you visit our website transparentdigitalservices.com (the "Website"), or use the Lupe client portal at lupe.transparentdigitalservices.com or the dedicated branding workspace at lupedata.com (the "Portal"), and more generally, use any of our services (the "Services"), we appreciate that you are trusting us with your personal information. We take your privacy very seriously.
This privacy notice has been updated to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA), key provisions of which came into force on 5 February 2026. If there are any terms in this notice that you do not agree with, please discontinue use of our Services immediately.
Table of Contents
- What information do we collect?
- How do we use your information?
- What is our lawful basis for processing?
- Will your information be shared with anyone?
- Who will your information be shared with?
- Cookies and tracking technologies
- International data transfers
- How long do we keep your information?
- How do we keep your information safe?
- What are your privacy rights?
- How to make a data protection complaint
- Controls for Do-Not-Track features
- Updates to this notice
- How to contact us
- Review, update or delete your data
- Commercial relationships, billing, and payments
1. What Information Do We Collect?
In short: We collect personal information that you provide to us, and some information collected automatically when you use our services.
Personal Information You Provide
We collect personal information that you voluntarily provide to us when you express an interest in obtaining information about us or our Services, when you use our Website or Portal, or when you contact us directly. This may include:
- Email addresses and phone numbers
- Login credentials for the Portal (stored securely — passwords are hashed and never stored in plain text)
- Two-factor authentication data (encrypted TOTP secrets stored at rest)
- Company name and account details for Portal clients
- Tracking platform configuration data entered into the Portal (GTM container IDs, platform IDs, API keys — API keys are encrypted at rest)
- Any other information you choose to provide when contacting us
All personal information you provide must be true, complete and accurate. Please notify us of any changes to such information.
Information Automatically Collected
We automatically collect certain information when you visit, use or navigate our Website. This information does not directly reveal your identity but may include device and usage data:
- Log and usage data: IP address, browser type and settings, pages and files viewed, date/time stamps, and other activity information
- Device data: Device type, operating system, browser, and hardware information
- Location data: Approximate location based on IP address. You may opt out by disabling location settings on your device
We also collect information through cookies and similar technologies. Please see our Cookie Policy for full details.
Portal-Specific Data
For registered Portal users (clients and employees), we additionally collect and process:
- Account login history and session data for security purposes
- Failed login attempts and account lockout events
- Two-factor authentication setup and backup code usage records
- Password reset request logs (tokens stored as hashed values only)
- Client tracking configuration data including domain names, GTM container references, and platform identifiers
- API keys for Stape and CookieYes integrations (encrypted at rest using AES-256)
- Container health status data retrieved from third-party APIs on behalf of clients
2. How Do We Use Your Information?
In short: We process your information to provide our services, fulfil contractual obligations, ensure security, and where you have given consent, for marketing.
We use the information we collect or receive for the following purposes:
- To operate and maintain the Portal — managing client accounts, processing logins, maintaining secure sessions, and delivering tracking infrastructure data to authorised users
- To fulfil our service contract with you — providing the tag management and tracking dashboard services you have engaged us to deliver
- To ensure the security of our services — monitoring for suspicious login activity, enforcing account lockouts, managing 2FA, and protecting against unauthorised access
- To communicate with you — responding to enquiries, sending password reset emails, and sending service notifications
- To send marketing communications — where you have opted in, or where we have a legitimate interest in doing so. You may opt out at any time
- For analytics and service improvement — understanding how visitors use our Website using aggregated, anonymised data
- To comply with legal obligations — retaining records as required by applicable law
3. What Is Our Lawful Basis for Processing?
In short: We rely on contract, legitimate interests, legal obligation, and consent — depending on the type of processing.
Under the UK GDPR (as updated by the DUAA 2025), we must have a lawful basis for processing your personal data. We rely on the following:
- Performance of a contract: Processing necessary to deliver the Portal services you have contracted with us for — including authentication, session management, and tracking data management
- Legitimate interests: Processing for security monitoring, fraud prevention, service improvement, and direct marketing to existing clients where our interests are not overridden by your rights
- Legal obligation: Where we are required to process data to comply with applicable law, including responding to lawful requests from authorities
- Consent: For non-essential cookies, marketing to new contacts, and any processing where we have specifically asked for your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing
4. Will Your Information Be Shared With Anyone?
In short: We only share information with your consent, to comply with laws, to provide our services, or to fulfil business obligations.
We may share your data in the following circumstances:
- Service providers and processors: Third-party vendors who assist us in operating our services (hosting, email delivery, analytics). These parties are contractually bound to process data only on our instructions and to maintain appropriate security
- Business transfers: In connection with any merger, sale, or acquisition of all or part of our business, your data may be transferred as part of that transaction
- Legal requirements: Where we are required by law, court order, or governmental authority to disclose your information
- Vital interests: Where necessary to prevent fraud, protect safety, or investigate suspected policy violations
We do not sell, rent or trade your personal information to third parties for their own promotional purposes.
5. Who Will Your Information Be Shared With?
In short: We share data only with infrastructure providers and, where applicable, advertising platforms where you have consented.
| Category | Provider / Purpose | Data Location |
|---|---|---|
| Cloud hosting | DigitalOcean — Website and Portal hosting, managed database | London, UK |
| Email delivery | Google Workspace — transactional emails (password resets, notifications) | EU / UK |
| Retargeting platforms | Facebook Custom Audience, Google Ads Remarketing — only where consent has been given via our cookie banner | USA (Standard Contractual Clauses apply) |
| Third-party APIs | Stape, CookieYes — accessed on behalf of Portal clients to retrieve container health and consent status data | Subject to each provider's terms |
| Payment Gateways | Stripe, Inc. — Processing of subscription billing, invoices, and credit card processing operations on behalf of the portal ecosystem | Global / UK / EU |
6. Cookies and Tracking Technologies
In short: We use cookies and similar technologies. Full details are in our Cookie Policy.
We use cookies and similar storage and access technologies on our Website and Portal. Specific information about which technologies we use, why, and how you can manage or refuse them is set out in our Cookie Policy, which has been updated to reflect the requirements of the DUAA 2025 and the ICO's finalised guidance published on 29 April 2026.
7. International Data Transfers
In short: Some data may be transferred outside the UK. We ensure appropriate safeguards are in place.
Where we transfer personal data to countries outside the United Kingdom, we do so in accordance with the UK GDPR international transfer requirements as updated by the DUAA 2025. The DUAA introduced a new data protection test requiring that the destination country provides protection that is "not materially lower" than UK standards.
For transfers to the United States (such as to Facebook and Google for advertising purposes, where consent has been given), we rely on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms. Our primary hosting and database infrastructure is located in the United Kingdom (DigitalOcean, London).
The ICO published updated guidance on international transfers on 15 January 2026, which we have taken into account in our transfer practices.
8. How Long Do We Keep Your Information?
In short: We keep your information for as long as necessary for the purposes set out in this notice, and no longer than required by law.
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law (for example, for tax or accounting purposes). Our general retention periods are:
- Website visitor data: Up to 13 months for aggregated analytics data; raw log data deleted after 90 days
- Portal account data: Retained for the duration of the client or employee relationship, plus up to 2 years after account closure unless a longer period is required by law
- Security logs (login attempts, session data): 90 days
- Password reset tokens: Deleted immediately after use or expiry (15 minutes)
- Marketing contact data: Until you unsubscribe or request deletion, or after 2 years of inactivity
- Financial and contractual records: Up to 7 years as required by UK tax law
When retention periods expire, we securely delete or anonymise the data. Where immediate deletion is not possible (for example, in backup archives), we isolate the data from further processing until it can be deleted.
9. How Do We Keep Your Information Safe?
In short: We implement appropriate technical and organisational security measures to protect your data.
We have implemented the following technical and organisational security measures:
- All Portal communications are encrypted in transit using TLS (HTTPS)
- Passwords are hashed using bcrypt with a high cost factor — never stored in plain text
- Sensitive API keys are encrypted at rest using AES-256 encryption
- The Portal database is accessible only via a private VPC network — not exposed to the public internet
- Two-factor authentication (TOTP) is available for all Portal accounts
- Account lockout after 3 failed login attempts, with a 20-minute lockout period
- Session tokens stored in httpOnly cookies, inaccessible to client-side JavaScript
- Automatic session expiry after 90 minutes of inactivity
Despite our safeguards, no electronic transmission over the internet can be guaranteed to be 100% secure. You should only access the Portal and Website within a secure environment. We will notify you of any data breach affecting your personal data as required by UK GDPR.
10. What Are Your Privacy Rights?
In short: Under the UK GDPR, you have significant rights over your personal data. These are set out below.
As a UK resident, you have the following rights under the UK GDPR and the Data (Use and Access) Act 2025:
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request). We must respond within one month.
Right to Rectification
Request that we correct inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data in certain circumstances (the "right to be forgotten").
Right to Restriction
Request that we restrict the processing of your data in certain circumstances, for example while a complaint is being resolved.
Right to Data Portability
Receive your personal data in a structured, machine-readable format and have it transferred to another controller where technically feasible.
Right to Object
Object to processing based on legitimate interests, including direct marketing. We must stop processing unless we can demonstrate compelling grounds.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. This does not affect the lawfulness of prior processing.
Right to Complain DUAA 2025
Lodge a complaint directly with us before escalating to the ICO. We must acknowledge within 30 days and respond without undue delay.
To exercise any of these rights, please contact us using the details in Section 14. We will respond within one calendar month. We may need to verify your identity before processing your request.
For Subject Access Requests, note that under the DUAA 2025, we may pause the response clock where we reasonably need clarification from you about the scope of your request.
11. How to Make a Data Protection Complaint
In short: You have a new statutory right to complain to us directly before escalating to the ICO. We will respond within 30 days.
The Data (Use and Access) Act 2025 introduced a new statutory right to complain directly to data controllers about infringements of data protection law. This right comes into full force on 19 June 2026.
Our Complaints Procedure
If you believe we have processed your personal data unlawfully or in breach of your rights:
- Step 1: Submit your complaint to us by email at contact@transparentdigitalservices.com, marked FAO Data Protection Complaint. Please include your name, contact details, and a description of your concern.
- Step 2: We will acknowledge your complaint within 30 days and provide a reference number.
- Step 3: We will investigate and respond to your complaint without undue delay, informing you of both progress and the final outcome.
- Step 4: If you are not satisfied with our response, you may escalate your complaint to the ICO (details below).
You also retain the right to lodge a complaint directly with the ICO at any time:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems include a Do-Not-Track (DNT) feature that signals your preference not to have your online browsing activities tracked. As there is currently no uniform technology standard for recognising and implementing DNT signals, we do not respond to DNT browser signals. We rely instead on our cookie consent mechanism, which gives you granular control over which technologies are active on your device. Please see our Cookie Policy for details.
13. Do We Make Updates to This Notice?
In short: Yes. We will update this notice as required by law or as our practices change.
We may update this privacy notice from time to time to reflect changes in law, regulation, or our data processing activities. The updated version will be indicated by a revised date at the top of this page and will be effective from the date of publication.
Where changes are material — for example, a new type of processing or a significant change to your rights — we will notify registered Portal users by email and, where appropriate, display a prominent notice on our Website.
We encourage you to review this notice periodically to stay informed of how we are handling your personal information.
14. How Can You Contact Us About This Notice?
Transparent Digital Services Limited
Registered in England and Wales
Registered office: 303 The Pillbox, 115 Coventry Road, London, E2 6GG
Email: contact@transparentdigitalservices.com
For data protection queries, please mark correspondence: FAO Data Protection
15. How Can You Review, Update or Delete Your Data?
Based on applicable UK law, you have the right to request access to, correction of, or deletion of the personal information we hold about you. To submit such a request:
- Email us at contact@transparentdigitalservices.com marked FAO Data Protection
- Or write to us at our registered office above
We will verify your identity before processing your request and will respond within one calendar month. For Subject Access Requests, we may ask for clarification of the scope of your request, in which case the response deadline is paused until we receive your clarification (as codified by the DUAA 2025).
To review, update, or delete your Portal account data, you may also contact your designated TDS account manager directly.
16. Commercial Relationships, Billing, and Payments
In short: Financial operations for the Lupe SAAS platform are owned and billed directly by Transparent Digital Services Limited as the legal entity and Merchant of Record.
16.1 Corporate Identity and Merchant of Record Structure
The Lupe application, located at lupedata.com and its subdomains, functions as a proprietary product and software service operated entirely under a commercial trading name format. It is not a standalone incorporated entity. You explicitly acknowledge and agree that **Transparent Digital Services Limited** remains the overarching corporate framework, legal contracting party, and the absolute Merchant of Record for any commercial service contracts, upgrades, or subscription transactions initiated inside the platform ecosystem.
16.2 Bank Statement Disclosures and Statement Descriptors
To preserve complete clarity across banking networks and actively prevent erroneous chargebacks or merchant processing suspensions, all recurring automated transactions or invoice payments finalized through our platform are directed into our integrated corporate ledger. Consequently, financial charges appearing on your company credit cards, corporate bank accounts, or financial statements will present under the public billing descriptors "LUPE DATA" or "LUPE* [Transparent Digital Services]".
16.3 Third-Party Financial Sub-Processing (Stripe Integration)
Online checkout systems, automated credit card authorization pipelines, and recurring software-as-a-service billing cycles are managed securely by our technical gateway integration provider, Stripe, Inc. and its global subsidiaries ("Stripe").
- Data Security: Transparent Digital Services Limited maintains strict separation of duties. Raw, unencrypted corporate card numbers or verification security keys are never processed, written, or archived within our localized application databases. Financial properties are handled entirely via tokenized elements through Stripe's PCI-DSS compliant infrastructure.
- API Snapshots: To display real-time dashboard accuracy within the client detail views, our application models consume secure, tokenized snapshots (including data values such as tier titles, status indicators, and payment timestamps) via Stripe webhooks and structural API requests.
16.4 Enterprise Track Accommodations and Localized Invoicing
For large-scale enterprise partners, matrix setups containing localized multi-territory ad account variables, or entities managing complex digital asset portfolios outside automated online tracks, customized financial handling may be deployed. In these cases, manual invoicing schedules may bypass standard Stripe automated capture, moving instead through verified, static commercial accounting workflows directed strictly by the central administrative offices of Transparent Digital Services Limited.
16.5 Invitation-Only Beta Exclusions and Liability Waivers
While the Lupe tool actively navigates its invite-only pre-release and optimization development phase, all localized data deployments remain under strict beta parameters. Any billing operations executed during this operational testing cycle are subject to full liability disclaimers, waiving any standard commercial platform software guarantees, public public-liability parameters, or data environment downtime financial penalties.