Privacy Policy

Last updated: 13 June 2026

DP Online Marketing Ltd (trading as "DPOM", "we", "us" or "our") is committed to protecting your personal data and respecting your privacy. This policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have under UK data protection law.

This policy applies to our website at https://www.dpom.co.uk and to the services we provide as a digital marketing agency.


The short version

If you only read one part, read this.

  • We are a UK digital marketing agency. We collect personal data mainly when you enquire with us, become a client, visit our website, chat with us online, or call us.
  • When you submit an enquiry (by form, live chat or phone) we store your details in our own CRM so we can respond and provide our services.
  • Our website uses cookies and similar technologies. Strictly necessary cookies are always on. Advertising and analytics cookies only run if you click "Accept" on our cookie banner. You can change your choice at any time using the cookie settings button on the site.
  • Phone calls to us may be answered, recorded and transcribed by an AI voice agent. Our live chat is handled by an AI assistant. We explain this in full below.
  • When you arrive from a Google Ads click, we record the advertising identifiers (such as the Google Click Identifier) so we can tell which adverts generate genuine enquiries.
  • We share data with trusted service providers (for example Google, Stripe and our telephony providers). Some are based outside the UK, and we use approved safeguards for those transfers.
  • You have rights over your data, including the right to access it, correct it, delete it, and object to certain uses. You can also complain to the Information Commissioner's Office (ICO).

The rest of this document sets all of this out formally.


1. Who we are (the data controller)

DP Online Marketing Ltd is the "data controller" responsible for your personal data. This means we decide how and why your personal data is processed.

Detail Information
Legal entity DP Online Marketing Ltd (trading as "DPOM")
Registered office The Cottage, Lindpet House, Market Place, Grantham, Lincolnshire, NG31 6LJ, United Kingdom
Company number 07767923
ICO registration number ZC173908
VAT number 154 2509 24
Privacy contact privacy@dpom.co.uk
Website https://www.dpom.co.uk

We are not required to appoint a statutory Data Protection Officer. The privacy contact above (privacy@dpom.co.uk) is your point of contact for any data protection matter.

If you have any questions about this policy or about how we handle your personal data, please contact us using the details above.


2. The law that applies

We process personal data in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)
  • The Data Protection Act 2018
  • The Privacy and Electronic Communications Regulations 2003 (PECR), which govern cookies and electronic marketing

We are a UK company. Visitors from the European Union and elsewhere may also use our website, and we handle their data in line with the standards described in this policy.


3. What this policy covers

This policy covers personal data we collect about:

  • Website visitors and enquirers, including people who fill in a form, use our live chat, or call us.
  • Clients and customers, where we process data to deliver our services, take payment and meet our contractual and legal obligations.
  • Suppliers and contacts, where we hold business contact details.

Where we act as a processor on behalf of a client (for example handling end-customer data inside marketing campaigns or tools we manage for that client), the client is the controller for that data and their own privacy policy applies. Our handling of that data is governed by our contract and, where appropriate, a data processing agreement (DPA) with that client.


4. What we do

DPOM is a UK digital marketing agency and a Google Partner. Our services include:

  • Google Ads management
  • Search engine optimisation (SEO)
  • Social media management and advertising
  • Website design and hosting
  • An AI phone-answering and business-numbers product ("Relay", with a brand voice known as "James")

Several of the data uses described in this policy relate directly to running and measuring these services.


5. The personal data we collect

5.1 Information you give us

When you enquire with us or become a client, we may collect:

  • Your name
  • Your business name
  • Your email address
  • Your phone number
  • The service you are interested in
  • Any free-text message or information you choose to share with us

We collect this through our website forms, our live chat, and over the phone. Enquiry and lead data is stored in DPOM's own customer relationship management system (CRM).

For clients and customers, we also process the data needed to deliver our services, set up and manage your account, raise invoices, take payment and administer our contract with you.

5.2 Information we collect automatically

When you visit our website, we may automatically collect:

  • Your IP address
  • Your browser type, device type and operating system
  • The pages you view and the order in which you view them
  • The website or source that referred you to us
  • On-site behaviour and interaction data, including heatmap and session interaction data captured through DPOM's own first-party analytics tool ("Nebula/Prism")

We use this information to operate, secure, measure and improve our website.

5.3 Advertising click identifiers

When you arrive at our website by clicking one of our Google adverts, your browser carries advertising parameters in the link. We capture and store these as first-party data so that, if you go on to enquire, we can attribute that enquiry to the advert that brought you to us. These parameters include:

  • The Google Click Identifier (gclid)
  • Similar Google identifiers such as gbraid and wbraid

In plain terms: this lets us tell which adverts actually generate genuine enquiries, so we can measure and manage our advertising properly and avoid wasting budget. This data is stored first-party (by us, on our own domain) and is linked to your enquiry if you submit one.

5.4 Phone calls

Inbound phone calls to us may be answered, recorded and transcribed by an AI voice agent. We use call answering, recording and transcription to handle your enquiry, keep an accurate record of what was discussed, train and improve our service, and resolve any later queries or disputes.

This service is provided using our telephony and AI voice providers (Twilio and Retell AI). Where we record a call, we will make this clear at or before the start of the call. If you do not wish to be recorded, please let us know or contact us by another method (for example email or our website form).

5.5 Live chat

If you use the live chat on our website, your messages are processed by an AI assistant to understand and answer your questions. The AI processing is provided by our AI provider (Anthropic). Please do not share sensitive personal information or payment details through live chat.

5.6 Client and customer data

To deliver our services, manage billing and administer our contracts, we process data about our clients and their nominated contacts. Depending on the service, this may include account details, billing information, advertising and analytics account access we are authorised to use on the client's behalf, and correspondence.

5.7 Sensitive data

We do not seek to collect special category data (such as data about health, race, religion or political views). Please do not send us sensitive personal information unless we have specifically asked for it and explained why.


6. Cookies and similar technologies

6.1 What cookies are

Cookies are small text files placed on your device when you visit a website. Similar technologies (such as pixels, tags and local storage) work in comparable ways. We use them to make our website work, to measure how it is used, to attribute enquiries to their source, and (with your consent) for advertising.

Our website uses Google Consent Mode v2 together with a cookie banner that lets you "Accept" or "Reject" non-essential cookies.

  • Strictly necessary cookies are always active because the site cannot function properly without them. These do not require your consent.
  • Advertising and analytics cookies are switched off by default and only run if you click "Accept".
  • You can change or withdraw your consent at any time using the cookie settings button on our website.

If you do not consent to advertising and analytics cookies, our Google advertising and analytics tags do not set those cookies and do not read or write identifiers on your device. In that situation, Google may instead use anonymous, aggregated "conversion modelling" to estimate results without tracking you individually. Modelling does not identify you.

6.4 Enhanced Conversions (advertising measurement)

When you consent to advertising cookies and you submit an enquiry, we may use a Google feature called Enhanced Conversions. This sends Google a hashed (irreversibly scrambled) version of contact details such as your email address or phone number, so Google can match an advertising click to a conversion and measure how well our adverts perform.

The hashing is one-way, so the values cannot be turned back into your original details by us or by Google through this process. This data is pseudonymised and is used only for conversion measurement.

The cookies below are grouped by category. Exact cookies, providers and durations can change as tools are updated, so please treat the durations as indicative.

These cookies are necessary for the website to work, to keep it secure, and to attribute enquiries correctly. Lawful basis: legitimate interests (necessary for the operation and security of the site and for accurate lead attribution).

Cookie / item Provider Purpose Typical duration
Session / security cookie(s) DPOM (first-party) Maintains your session and helps keep the site secure Session
dpom_vid DPOM (first-party) A first-party visitor identifier used to recognise a browser across pages and visits for core site functionality Up to 1 year
dpom_landing DPOM (first-party) Stores the landing URL and advertising click identifier (such as gclid) so that, if you enquire, the enquiry can be attributed to the advert or source that brought you here 90 days

Analytics and lead attribution

These help us understand how the site is used and which sources generate enquiries. Lawful basis: legitimate interests. We treat first-party analytics and lead attribution as operationally necessary to run, measure and protect our business and our advertising.

Cookie / item Provider Purpose Typical duration
wc_* (lead-source cookies) WhatConverts Tracks the source of calls and form enquiries so leads can be attributed to the correct campaign or channel Up to 1 year
Nebula/Prism first-party analytics DPOM (first-party) DPOM's own analytics and session interaction (including heatmap) measurement to understand and improve the site Up to 1 year

These cookies are set by Google and Meta to measure advertising and to support marketing. They only run after you consent. Lawful basis: consent.

Cookie / item Provider Purpose Typical duration
_gcl_au Google (via Google Tag Manager) Used by Google to measure ad conversions and attribute them to campaigns Approx. 90 days
_gcl_aw Google (Google Ads, tag AW-963567192) Stores ad-click information for conversion measurement Approx. 90 days
_ga Google (Google Analytics 4) Distinguishes users for analytics measurement Up to 2 years
_fbp Meta (Facebook Pixel) Used by Meta to deliver and measure advertising Approx. 90 days

Notes on advertising and analytics:

  • Google Analytics 4 and Google Ads tags are deployed through Google Tag Manager.
  • We no longer use Bing/Microsoft tracking or Twitter/X tracking. These have been removed.

6.6 Managing cookies in your browser

In addition to our cookie settings button, most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may stop parts of the site from working. For more general guidance you can visit aboutcookies.org or the ICO's cookie guidance.


7. How and why we use your data (and our lawful bases)

Under UK GDPR we must have a lawful basis for each use of your personal data. The table below maps our main activities to their lawful bases.

What we do Why Lawful basis
Respond to enquiries and provide quotes To answer you and progress a potential engagement Legitimate interests (responding to enquiries); steps towards a contract at your request
Deliver our services and manage your account To provide what you have asked us to provide Performance of a contract
Take payment and issue invoices To get paid and keep financial records Performance of a contract; legal obligation (accounting and tax)
Answer, record and transcribe phone calls To handle enquiries, keep accurate records and improve service Legitimate interests; performance of a contract where you are a client
Operate live chat (AI assistant) To answer questions efficiently Legitimate interests
Essential analytics, lead attribution and click-fraud / fraud prevention To run, measure, secure and protect our website and advertising Legitimate interests
Advertising and marketing cookies and pixels To measure and improve advertising Consent
Marketing emails to individuals where consent is required To keep you informed about relevant services Consent (or the PECR "soft opt-in" for existing customers, where it applies)
B2B outreach and relationship management To develop appropriate business relationships Legitimate interests
Keep accounting and tax records To comply with the law Legal obligation
Secure and improve our website and systems To protect and enhance our services Legitimate interests

Our legitimate interests, explained

Where we rely on "legitimate interests", this means we use your data in ways you would reasonably expect and that have a minimal privacy impact, for purposes that are genuinely in our interests as a business (such as responding to you, attributing enquiries to their source, preventing fraud and click-fraud, and securing and improving our site). We balance our interests against your rights and freedoms, and we do not use legitimate interests where your interests override ours. You have the right to object to processing based on legitimate interests (see Section 11).


8. Marketing and your preferences

If we send you marketing communications, we will only do so where we are permitted to under UK GDPR and PECR, for example with your consent or, for existing customers, under the "soft opt-in" for similar products and services.

You can opt out of marketing at any time by:

  • Clicking the "unsubscribe" link in any marketing email, or
  • Contacting our privacy contact (see Section 1).

Opting out of marketing will not stop service-related or transactional messages that we need to send you (for example about your account, invoices or support).


9. Who we share your data with

We share personal data only where necessary, and we require our service providers to protect it and to use it only for the purposes we specify. The categories and named processors below are the main ones we use.

The list below reflects our current main providers and is kept up to date as our tools change.

Provider What they help us with Notes
Google (Ads, Analytics, Tag Manager, Workspace/Gmail) Advertising, analytics, tag management and business email International transfers may apply
Meta Platforms Facebook Pixel for advertising measurement International transfers may apply
WhatConverts Call and lead tracking and attribution International transfers may apply
Twilio Telephony for our phone services International transfers may apply
Retell AI AI voice agent for answering and transcribing calls International transfers may apply
Anthropic AI assistant (Claude) processing of live chat and enquiries International transfers may apply
Stripe Payment processing International transfers may apply
Xero Invoicing and accounting International transfers may apply
SocialPilot Scheduling and publishing social media posts International transfers may apply
Brevo Sending transactional email International transfers may apply
IONOS Website hosting UK / EU data centres

We may also share personal data:

  • With professional advisers (such as accountants, lawyers and insurers) where necessary.
  • With law enforcement, regulators or other authorities where we are required to by law.
  • With a buyer or successor if we sell or reorganise our business, in which case data would be transferred under appropriate confidentiality and data protection terms.

We do not sell your personal data.


10. International data transfers

Some of the providers listed above are based outside the United Kingdom, including in the United States. Where we transfer personal data outside the UK, we make sure it is protected by one of the safeguards recognised under UK GDPR, for example:

  • A finding of "adequacy" by the UK government (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified), or
  • The International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (SCCs), together with any additional safeguards needed.

You can ask us for more information about the safeguards that apply to a particular transfer by contacting our privacy contact.


11. Your rights

Under UK GDPR you have the following rights over your personal data:

  • The right to be informed about how we use your data (which this policy provides).
  • The right of access to the personal data we hold about you (a "subject access request").
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure ("the right to be forgotten") in certain circumstances.
  • The right to restrict processing in certain circumstances.
  • The right to data portability, to receive certain data in a portable format.
  • The right to object to processing based on legitimate interests, and to direct marketing at any time.
  • Rights in relation to automated decision-making and profiling, where such processing produces legal or similarly significant effects. We do not currently make solely automated decisions that have legal or similarly significant effects on you. Our AI tools support our team rather than make such decisions about you on their own.
  • The right to withdraw consent at any time, where we rely on consent (for example for advertising cookies, which you can change using the cookie settings button, or for marketing emails, which you can unsubscribe from).

How to exercise your rights

To exercise any of these rights, please contact our privacy contact (see Section 1). We will respond within one month, although we may extend this by a further two months for complex or numerous requests, in which case we will let you know. We may need to verify your identity before acting on a request. There is normally no charge, although we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.


12. How long we keep your data

We keep personal data only for as long as we need it for the purposes set out in this policy, and to meet our legal, accounting and contractual obligations. In general:

  • Enquiry and lead data: kept while we follow up and for up to 24 months after our last contact with you.
  • Client and contract data: kept for the duration of our relationship and for up to 6 years afterwards.
  • Financial and tax records: kept for the period required by law (at least six years).
  • Call recordings and transcripts: kept for up to 12 months.
  • Website analytics and cookie data: kept in line with the durations described in the cookie table and the relevant providers' settings.

When we no longer need personal data, we securely delete or anonymise it.


13. How we keep your data secure

We take appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (for example HTTPS/TLS on our website).
  • Access controls, so that staff and providers can only access the data they need.
  • Encrypted, off-site backups.
  • Use of reputable service providers who are contractually required to protect personal data.

No method of transmission or storage is completely secure, but we work to protect your data and to respond appropriately to any security incident, including notifying the ICO and affected individuals where we are required to.


14. Children's privacy

Our services are business-to-business and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.


Our website may contain links to third-party websites and services. This policy does not apply to those sites. We are not responsible for the privacy practices or content of websites we do not control, and we encourage you to read their privacy policies before providing any personal data.


16. Changes to this policy

We may update this policy from time to time, for example to reflect changes in our services, the tools we use, or the law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, take additional steps to bring the changes to your attention. Please check this page periodically.


17. How to complain

If you have a concern about how we handle your personal data, please contact our privacy contact first (see Section 1) and we will do our best to resolve it.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. You can find out how to raise a concern at ico.org.uk. We would, however, appreciate the chance to address your concerns before you approach the ICO.