Legal
Privacy Policy
This policy explains what information we collect through the DGB Strategy diagnostic tools, why we collect it, how we protect it, and the rights you hold over it.
Last updated August 2026
1. Who controls your data
DGB Strategy is the data controller for information submitted through these tools. For any privacy question or request, contact us via DGBStrategy.co.uk.
2. What we collect
- Diagnostic submissions — company name, founder name, email address, technology stage, modality, your free-text answers, and the calculated readiness score.
- Account data — for team members with CRM access: email address, display name, and authentication credentials handled by our authentication provider.
- Technical data — we process your IP address transiently for rate limiting and abuse prevention. It is not stored alongside your submission.
3. Why we use it
- To generate your diagnostic output and readiness assessment.
- To prepare for and deliver workshop and advisory sessions.
- To follow up with you about your commercialisation position, where you invited it.
- To protect the service from spam, bots and abuse.
- To improve our methodology and benchmarks, using aggregated and anonymised data only.
4. Legal basis
We rely on legitimate interests (delivering the diagnostic you requested, operating and securing our service, and developing our advisory practice) and, where you have asked us to contact you or entered an engagement, consent or performance of a contract.
5. Confidentiality
We understand that commercialisation inputs can be commercially sensitive. Submissions are treated as confidential. They are not published, sold, or shared with other programme participants, investors or third parties without your permission.
6. Where your data is stored
Submissions and account records are stored in a managed, access-controlled cloud database with encryption in transit and at rest. Access is limited to authenticated DGB Strategy personnel holding an administrator role, enforced at the database level by row-level security policies. Some processing may take place outside the UK/EEA under appropriate safeguards.
7. How long we keep it
Diagnostic submissions are retained for up to 24 months from submission, unless you ask us to delete them sooner or an ongoing engagement requires a longer period. Account records are kept for as long as the account remains active.
8. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. You may also withdraw consent at any time and complain to the Information Commissioner's Office. To exercise any of these rights, contact us and we will respond within one month.
9. Cookies and local storage
We do not run advertising or third-party tracking cookies. We use your browser's local storage to save your in-progress sprint matrix answers on your own device, and secure storage for the session token of signed-in team members. Clearing your browser storage removes both.
10. Changes
We may update this policy. Material changes will be reflected on this page with an updated revision.
