1. Who is responsible for your information?
Digital Triage is a trading name of G&M Medical Supply Ltd. When this notice says “Digital Triage”, “we”, “us” or “our”, it means G&M Medical Supply Ltd, the legal data controller responsible for your personal information.
Registered office30 Doreen Avenue
Congleton
Cheshire
CW12 3JE
See our Statutory Business Information for the company registration number, VAT status and full business contact details.
For privacy questions, requests or complaints, email Matt@digitaltriagehq.co.uk or use the contact page and state that your message is about privacy.
2. What information is collected?
Depending on how you use the website, Digital Triage may collect:
- Identity and contact information: your name, business name, email address, phone number and, where needed for billing or a contract, your physical billing address.
- Details you include in an enquiry, callback request or project brief.
- A website address you submit and the public page content inspected to create a Website Brief.
- The focus you select, the generated brief and whether you request the complete result.
- Financial records: invoices, payment status, transaction references and records of payments. We do not store full payment-card details; card payments are processed offsite by the payment provider.
- Technical and analytics information: limited information needed for security, rate limiting and service reliability, such as an IP address and request time. If we host your website, hosting infrastructure may also collect basic visitor and server analytics to monitor availability, performance and server load.
Please do not submit passwords, payment details, private account information or sensitive personal information through these forms.
3. Why is it used?
Personal information is used to:
- Respond to enquiries and callback requests.
- Create, store and provide the Website Brief you request.
- Assess a potential project, register you as a client and prepare or manage contracts.
- Design, build, host, maintain and manage your website.
- Issue payment links, process monthly subscriptions or one-off project invoices, and maintain financial records.
- Send important service messages about hosting, security, contracts or changes to relevant terms.
- Protect the service from abuse and diagnose technical problems.
- Keep records required for legal, tax or dispute purposes.
The main legal bases are taking steps at your request before entering a contract, performing a contract, Digital Triage’s legitimate interests in operating and protecting the business, and compliance with legal obligations. Consent will only be relied on where you are given a genuine choice, such as a future optional marketing sign-up.
4. Website Brief and AI processing
When you request a Website Brief, Digital Triage fetches publicly available content from the website address you provide. Relevant page content and your selected focus are sent through our managed application infrastructure to an AI service provider to generate the brief.
Your contact details are not included in the prompt used to generate the brief. They are attached to the stored brief only if you complete the form requesting the full result.
5. Where information is stored and who receives it
Information is shared only where needed to operate the business and deliver the services you request. This may include:
- Tide: used to generate payment links and process transactions. Full card details are handled by the payment provider rather than stored by Digital Triage.
- Hosting and application infrastructure providers: used for website hosting, application infrastructure, databases and AI-assisted Website Brief generation. If you choose a hosted package, website files and basic hosting analytics may be held by these providers.
- Internal systems: project details and contact information may be managed in a custom-built CRM and secure internal spreadsheets.
- Other service providers and professional advisers: providers supporting security, email delivery or business administration, and advisers where disclosure is legally necessary.
Service providers process information under their own terms or applicable data-processing obligations.
Digital Triage does not sell personal information. It is not shared with unrelated organisations for their own marketing.
6. Data security
We use appropriate technical and organisational measures intended to protect personal information. Access to hosting accounts, the CRM, internal spreadsheets and other business systems is restricted to people who need it and protected using secure authentication.
If a personal-data breach occurs, we will investigate it and follow applicable UK notification rules. Where required, we will notify the Information Commissioner’s Office within the applicable deadline and inform affected individuals without undue delay where the breach is likely to create a high risk to their rights and freedoms.
7. International processing
Some technology providers may process information outside the United Kingdom. Where this happens, Digital Triage will use providers and safeguards intended to protect information in line with applicable UK data-protection law.
8. Retention policy
Information is kept only for as long as it has a clear business or legal purpose:
- Unclaimed Website Briefs: available for completion for 24 hours, then removed through routine retention housekeeping.
- Enquiries, callback requests and claimed briefs: up to 12 months after the last meaningful contact if no client relationship begins.
- Client, contract and financial records: normally six years after the client relationship ends to meet HMRC, tax, legal and dispute-record requirements.
- Security and diagnostic records: kept for the shortest practical period needed to investigate abuse or service problems.
Information may be kept longer where there is a legal requirement, an active dispute or a request that must be documented. Backup copies may remain briefly until they are overwritten through the normal backup cycle.
9. Your rights
Depending on the circumstances, UK data-protection law may give you the right to access, correct, erase or restrict your information; object to certain processing; or receive information in a portable format. Where processing relies on consent, you can withdraw it at any time without affecting earlier processing.
Email Matt@digitaltriagehq.co.uk or use the contact page to make a request. We aim to respond to legitimate requests within one month, although the law allows more time in certain complex cases. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
10. Cookies and changes to this notice
This website does not currently use advertising cookies or behavioural tracking. Essential storage may be used where required for security or basic functionality. Read the Cookie Policy for details. If analytics or optional cookies are introduced, this notice and any required cookie controls will be updated first.
This notice may change when the service, suppliers or legal requirements change. The current version and update date will remain available on this page.