Last updated: 6 September 2026.
This Privacy Policy explains what personal information Digitalegy collects when you use digitalegy.io and its subdomains, why we collect it, who we share it with, how long we keep it, and the rights you can exercise over it. It applies to this website, to the forms and scheduling tools embedded in it, and to the marketing and sales communications we send. It does not govern personal information we process on behalf of a client under a services agreement; in that case the client is the controller and its own policy applies.
1. Who we are
Digitalegy is a trading name of DGY Group LLC ("Digitalegy", "we", "us", "our"), a limited liability company organised under the laws of the State of Wyoming, United States, with its registered office at 30 N Gould St, Sheridan, WY 82801, United States.
For the purposes of the EU and UK General Data Protection Regulation, DGY Group LLC is the controller of the personal information described here. For the purposes of Mexico's Federal Law on the Protection of Personal Data Held by Private Parties, DGY Group LLC is the responsable. For the purposes of the California Consumer Privacy Act, DGY Group LLC is the business.
You can reach us about anything in this policy at legal@digitalegy.io, or by post at the address above.
The Digitalegia acquisition
DGY Group LLC acquired Digitalegia, S.A.S. de C.V., a Mexican company that previously operated this business and collected personal information under its own privacy notice.
Two things follow, and they are the answer to "who is responsible for my data":
- Personal information collected by Digitalegia, S.A.S. de C.V. is now controlled by DGY Group LLC, and DGY Group LLC answers for it. If you gave your details to Digitalegia at any point, this policy is the one that now governs them, and you exercise your rights against us using the contact details above.
- We continue to use that information only for the purposes it was originally collected for. An acquisition does not give us a new licence to use it for something else. Where we would want to, we would ask you first.
Where Digitalegia, S.A.S. de C.V. still processes personal information, it does so as our processor, on our documented instructions and under a written agreement, not on its own account.
2. The information we collect
Information you give us
- When you book a call. Your name, email address, and anything you choose to enter in the scheduling form or the meeting notes. Scheduling runs on HubSpot Meetings.
- When you email us or reply to us. The contents of your message, your email address and any signature block it carries.
- When you buy a support plan. Your billing name, billing email, company name and the country of the billing address. Card details are entered directly into our payment processor and never reach our servers — we receive only the last four digits, the card brand and the authorisation result.
- When you apply for a role or send us a proposal. Whatever you include.
Information we collect automatically
Only after you consent through the cookie banner, and only in the categories you accept:
- Pages viewed, referring URL, approximate location derived from IP, device and browser type, and the time and duration of your visit.
- A first-party visitor identifier (
hubspotutk) that links your later form submission to the pages you looked at first, so we know which article brought you to us.
Before you make a choice, we set no analytics or advertising cookies at all. Our consent banner defaults to denied worldwide, not only in the EU, and Google Consent Mode v2 is wired to that default so tags stay dormant until you accept. See section 5.
Information we do not collect
We do not knowingly collect government identifiers, financial account numbers, health information, biometric data, precise geolocation, or any of the categories that the GDPR treats as special-category data or that the CCPA treats as sensitive personal information. Do not send us that kind of information. If you do, we will delete it.
3. Why we use it, and on what legal basis
| What we do | Why | Legal basis (EU/UK GDPR) |
|---|---|---|
| Answer your enquiry and hold the meeting you booked | To respond to you | Steps taken at your request prior to a contract; legitimate interests |
| Deliver, support and invoice the services you buy | To perform the contract | Performance of a contract |
| Send you marketing email about our services | To keep you informed | Consent, or legitimate interests in business-to-business marketing, always with a working unsubscribe |
| Measure which pages and campaigns work | To improve the site | Consent |
| Keep the site secure and prevent form abuse | To protect the service | Legitimate interests |
| Keep tax, accounting and contractual records | Because we must | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and you can object at any time using the contact details in section 1.
4. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months.
We do use service providers, which act as processors on our documented instructions:
| Provider | What it does for us | Where |
|---|---|---|
| HubSpot, Inc. | CRM, forms, scheduling, email, live chat, website analytics | United States and EU |
| Google LLC | Google Analytics 4 (property G-369461800) | United States |
| Our hosting provider | Serving this website | United States |
| Our payment processor | Taking payment for support plans | United States |
| Our email provider | Sending and receiving business email | United States |
| Digitalegia, S.A.S. de C.V. | Legacy processing on our instructions, following the acquisition | Mexico |
We also disclose personal information where the law requires it — to comply with a subpoena, court order or regulator, to establish or defend legal claims, or to protect the rights and safety of any person. If we are ever party to a merger, acquisition or sale of assets, personal information may transfer as part of that transaction, and we will give notice before it becomes subject to a different privacy policy.
5. Cookies and similar technologies
Our banner asks before anything non-essential is set, everywhere in the world, and your choice is remembered. You can change it at any time with the Cookie Settings control in the footer of every page.
| Cookie | Set by | Category | Purpose | Retention |
|---|---|---|---|---|
__hs_cookie_cat_pref, __hs_opt_out | HubSpot | Necessary | Records the choice you made in the banner | 13 months |
__cf_bm | Cloudflare | Necessary | Distinguishes humans from bots | 30 minutes |
hubspotutk | HubSpot | Analytics | Identifies a returning visitor and links a form submission to earlier visits | 6 months |
__hstc, __hssc, __hssrc | HubSpot | Analytics | Session and visit counting | 13 months / 30 minutes / session |
_ga, _ga_* | Analytics | Distinguishes users, measures sessions | 13 months | |
messagesUtk | HubSpot | Analytics | Links a live-chat conversation to a contact record | 13 months |
Necessary cookies are set without consent because the site cannot function or record your consent choice without them. Everything else waits for you.
Because we honour Global Privacy Control, a browser or extension that transmits a GPC signal is treated as a valid opt-out of sale and sharing under the CCPA and, where recognised, as an objection to targeted advertising.
6. International transfers
We are established in the United States, and our providers are largely United States companies. If you are in the EEA, the United Kingdom, Switzerland or Canada, your personal information will be transferred to the United States.
For transfers out of the EEA and the UK we rely on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum, together with the technical and organisational measures described in section 8. You can request a copy of the relevant transfer mechanism by writing to legal@digitalegy.io.
7. How long we keep it
- Contact and CRM records: for as long as the relationship is active, and for three years after the last meaningful interaction, after which the record is deleted or anonymised.
- Client contract records: for seven years after the end of the engagement, because tax and limitation periods require it.
- Analytics data: fourteen months at user and event level, which is the maximum retention Google Analytics 4 permits.
- Email correspondence: three years, unless it forms part of a contract record.
- Consent records: for as long as we rely on the consent, and three years afterwards, so that we can demonstrate it was given.
8. How we protect it
Access to the CRM is limited to the people who need it, protected by single sign-on and multi-factor authentication. The website is served over TLS. Payment card data never touches our infrastructure. We review access on a recurring basis and remove it when someone leaves.
No system is perfectly secure. If a breach affects your personal information and the law requires it, we will notify you and the relevant regulator within the applicable deadline.
9. Your rights
Everyone, wherever you are, may ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop sending you marketing. We apply the strongest of the rights below to every request we receive, regardless of where you live, because operating one standard is more reliable than operating four.
If you are in the EEA or the United Kingdom
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing carried out on the basis of legitimate interests or for direct marketing. Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of what we did beforehand. You may lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office.
If you are in California
You have the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of recipients; to delete it; to correct it; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights. We do not sell or share personal information and we do not use or disclose sensitive personal information for purposes requiring a right to limit. An authorised agent may make a request on your behalf with written permission that we can verify.
If you are in Canada, including Quebec
You may ask for access to and correction of your personal information, withdraw consent, and, under Quebec's Law 25, request that a link to information about you be de-indexed where the statutory conditions are met. Our privacy officer can be reached at legal@digitalegy.io. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
If you are in Mexico
Under the Federal Law on the Protection of Personal Data Held by Private Parties published on 20 March 2025, you may exercise your ARCO rights — access, rectification, cancellation and opposition — and you may revoke your consent to the processing of your personal information at any time. Send your request to legal@digitalegy.io stating your name, a means of contacting you, the documents that establish your identity or your representative's authority, a clear description of the personal information concerned and the right you are exercising. We will respond within twenty business days and, if the request is well founded, give effect to it within the following fifteen business days. If you are not satisfied, you may bring a protection-of-rights proceeding before the Secretaría Anticorrupción y Buen Gobierno, which took over these functions from INAI under that law.
How to exercise any of these rights
Write to legal@digitalegy.io. We will acknowledge within ten days and respond within the deadline the applicable law sets — thirty days under the GDPR, forty-five days under the CCPA, twenty business days in Mexico — and we will tell you if we need an extension and why. We will ask you to confirm your identity, and we will not charge you for a first request.
10. Children
This site is for a business audience. We do not direct it to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, write to legal@digitalegy.io and we will delete it.
11. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling of that kind.
12. Changes to this policy
We will post any change here and move the "last updated" date. If a change materially affects how we use personal information we already hold, we will give notice by email or a prominent notice on the site before it takes effect.
13. Contact
- DGY Group LLC, trading as Digitalegy
- 30 N Gould St, Sheridan, WY 82801, United States
- legal@digitalegy.io