Privacy Policy
Last updated: 16 July 2026
1. Who we are
Ossian Digital is a trading style of Ossian Media Ltd, a company registered in Scotland under company number SC763151.
Our registered office is:
Robbie & Co
42 Dudhope Crescent Road
Dundee
Scotland
DD1 5RR
Ossian Digital provides digital consultancy, systems architecture, artificial intelligence consultancy, automation, website and platform development, managed hosting, domain registration, business email, digital infrastructure, technical support, search engine optimisation, ecommerce and related professional services.
For most of the personal information described in this policy, Ossian Media Ltd is the data controller. This means that we decide why and how that information is used.
Some legacy or specific managed hosting services may be contracted through Ossian Hosting Ltd, registered in Scotland under company number SC709281. Where this applies, Ossian Hosting Ltd may act as a separate data controller for its own billing, account administration and legal obligations.
In this policy, references to Ossian Digital, we, us or our include Ossian Media Ltd and, where relevant to a particular service, Ossian Hosting Ltd.
2. How to contact us
Questions about this privacy policy or the way we use personal information should be directed to:
Greig Thomson
Founder and Director
Ossian Digital
Email: greig@ossiandigital.com
Telephone: 01382 671 040
Postal address:
Ossian Digital
c/o Robbie & Co
42 Dudhope Crescent Road
Dundee
Scotland
DD1 5RR
3. What this policy covers
This privacy policy applies when you:
-
visit our website;
-
contact us by email, telephone, social media, messaging service or contact form;
-
ask us for a quotation or proposal;
-
become a client or prospective client;
-
purchase or use our services;
-
receive hosting, domain, email or technical support from us;
-
attend a meeting, consultation, workshop or project session;
-
subscribe to business updates or other communications;
-
work with us as a supplier, contractor or professional adviser;
-
interact with a website, platform, automation or system that we operate on our own behalf.
This policy also explains the distinction between situations where we act as a data controller and situations where we process data on behalf of a client.
4. When we act as a data processor
Some of our services involve managing systems that contain personal information controlled by our clients.
For example, we may host or maintain:
-
client websites;
-
ecommerce systems;
-
booking systems;
-
customer portals;
-
contact forms;
-
email accounts;
-
databases;
-
customer relationship management systems;
-
reporting platforms;
-
workflow automations;
-
integrations between business systems.
In these circumstances, the client will normally be the data controller and we will act as a data processor on the client’s documented instructions.
The client remains responsible for:
-
identifying an appropriate lawful basis;
-
providing privacy information to its own customers, employees and users;
-
deciding what data is collected;
-
responding to individual rights requests;
-
ensuring that its instructions to us are lawful.
Our processing obligations may be set out in a contract, data processing agreement, service agreement or other written instruction.
This privacy policy primarily describes the information for which we act as a data controller.
5. The personal information we collect
The information we collect depends on the relationship you have with us and the services involved.
Identity and contact information
This may include:
-
your name;
-
job title;
-
employer or business name;
-
business and personal email addresses;
-
postal address;
-
telephone and mobile numbers;
-
social media or messaging contact details;
-
preferred method of communication.
Business and professional information
This may include:
-
your role and responsibilities;
-
information about your employer or business;
-
business requirements and objectives;
-
project responsibilities;
-
decision-making authority;
-
professional interests;
-
information supplied during consultations, meetings and project discussions.
Enquiry and project information
This may include:
-
information contained in enquiries;
-
meeting notes;
-
project briefs;
-
proposals and quotations;
-
specifications;
-
instructions and approvals;
-
project correspondence;
-
technical requirements;
-
content, files, images and documents supplied to us;
-
information about existing systems, suppliers and business processes;
-
records of work completed and decisions made.
Account, contract and financial information
This may include:
-
billing names and addresses;
-
company and VAT details;
-
purchase order information;
-
invoices and credit notes;
-
payment status;
-
transaction references;
-
bank payment information;
-
records of overdue accounts and payment arrangements;
-
contracts and service agreements.
We do not normally store complete payment card details. Card payments are generally processed by specialist payment providers.
Hosting, domain and technical information
This may include:
-
domain names;
-
registrant and administrative contact details;
-
hosting account information;
-
DNS records;
-
email account details;
-
server and application logs;
-
IP addresses;
-
login and security events;
-
device and browser information;
-
storage and bandwidth usage;
-
error reports;
-
malware and security alerts;
-
backup records;
-
support requests;
-
configuration and diagnostic information.
Where access credentials are required to provide a service, we use them only for the relevant operational purpose and apply appropriate access controls. We do not ask clients to send passwords unnecessarily or retain them longer than required.
Website and usage information
This may include:
-
IP address;
-
browser and device type;
-
operating system;
-
referring website;
-
pages viewed;
-
dates and times of visits;
-
approximate location derived from an IP address;
-
interactions with website features;
-
cookie preferences;
-
analytics and performance data.
Communications information
This may include:
-
emails;
-
support correspondence;
-
telephone notes;
-
meeting notes;
-
messages sent through platforms such as WhatsApp or social media;
-
records of communications sent to you;
-
your marketing and communication preferences;
-
records of unsubscribes and objections.
Supplier and contractor information
This may include:
-
business contact information;
-
contracts and terms;
-
payment information;
-
insurance or compliance documentation;
-
records of services provided;
-
correspondence and performance information.
6. Special-category and sensitive information
We do not normally need to collect sensitive personal information such as health information, biometric information, political opinions, religious beliefs, trade union membership or information about a person’s sexual life or orientation.
Please do not provide this type of information unless it is genuinely necessary for a specific service or we have asked for it.
Where sensitive information must be processed, we will identify an appropriate legal basis and apply additional safeguards.
We also ask that clients do not provide:
-
passwords unless they are required for an agreed technical task;
-
payment card numbers by ordinary email;
-
private encryption keys;
-
unnecessary identity documents;
-
confidential information relating to third parties that is not required for the project.
7. How we collect personal information
We may collect information directly from you when you:
-
contact us;
-
complete a form;
-
send an email or message;
-
telephone us;
-
attend a meeting;
-
request a quotation;
-
enter into a contract;
-
provide access to a system;
-
purchase a service;
-
make a payment;
-
request technical support;
-
subscribe to updates.
We may also receive information from:
-
your employer, colleague or business partner;
-
another person acting with your authority;
-
an existing client or professional referral;
-
publicly available business websites;
-
Companies House and other official registers;
-
social media and professional networking sites;
-
domain registration records;
-
hosting and technology providers;
-
payment providers and banks;
-
accounting systems;
-
security, fraud-prevention and technical monitoring services;
-
clients whose systems we manage;
-
suppliers and professional advisers.
Where we obtain personal information from another source, we will use it only where we have a lawful reason to do so.
8. Why we use personal information
We use personal information for the following purposes.
Responding to enquiries
We use contact details and information about your requirements to:
-
respond to questions;
-
arrange meetings;
-
understand your requirements;
-
prepare quotations and proposals;
-
discuss potential services.
Our lawful bases are taking steps before entering into a contract and our legitimate interest in responding to genuine business enquiries.
Providing contracted services
We use personal information to:
-
deliver agreed projects and services;
-
communicate with client contacts;
-
manage projects;
-
provide consultancy;
-
develop websites and platforms;
-
manage hosting, domains and email;
-
provide maintenance and support;
-
configure systems and integrations;
-
manage AI and automation projects;
-
maintain service records.
Our lawful bases are performance of a contract and our legitimate interests in delivering and managing professional services.
Managing accounts and payments
We use personal information to:
-
create client and supplier records;
-
issue quotations and invoices;
-
collect payments;
-
reconcile transactions;
-
manage credit control;
-
maintain accounting and tax records;
-
deal with disputes and overdue accounts.
Our lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in managing our business and recovering money owed to us.
Providing hosting, domain and email services
We use account and technical information to:
-
create and administer hosting services;
-
register, renew and transfer domain names;
-
manage DNS;
-
configure mailboxes;
-
maintain security;
-
monitor storage and bandwidth;
-
investigate faults;
-
maintain backups;
-
respond to abuse, malware and security incidents.
Our lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in maintaining secure and reliable services.
Security and fraud prevention
We may use technical and account information to:
-
protect systems and accounts;
-
detect unauthorised access;
-
identify malicious activity;
-
prevent fraud;
-
investigate security incidents;
-
maintain evidence of technical events;
-
protect our clients, suppliers and business.
Our lawful bases are our legitimate interests, compliance with legal obligations and, where relevant, the establishment or defence of legal claims.
Managing and improving our business
We may use information to:
-
review how services are delivered;
-
improve workflows and internal systems;
-
plan resources;
-
maintain quality and service standards;
-
train staff and contractors;
-
analyse business performance;
-
maintain records of decisions and work completed.
Our lawful basis is our legitimate interest in operating and improving the business.
Legal and regulatory purposes
We may use or retain information to:
-
comply with tax and accounting requirements;
-
respond to legal proceedings;
-
enforce contracts;
-
establish, exercise or defend legal claims;
-
comply with regulatory requirements;
-
respond to lawful requests from public authorities;
-
maintain insurance and compliance records.
Our lawful bases are compliance with legal obligations and our legitimate interests in protecting the business.
9. Artificial intelligence and automated systems
Ossian Digital provides AI consultancy and may use AI-assisted tools as part of its own operations and client delivery.
These tools may assist with activities such as:
-
summarising information;
-
drafting and editing content;
-
analysing documents or datasets;
-
generating or reviewing code;
-
classifying information;
-
identifying patterns;
-
planning systems and workflows;
-
supporting research;
-
automating administrative processes.
We apply the following principles when using AI-assisted tools:
-
only information reasonably required for the task should be used;
-
unnecessary personal information should be removed or minimised;
-
confidential information should not be entered into public or unsuitable AI services;
-
passwords, full payment card information and private security credentials should not be entered into AI systems;
-
appropriate business accounts, privacy settings and contractual safeguards should be used where available;
-
outputs should be reviewed by a person before they are relied upon for important business decisions;
-
AI-generated output should not be treated as automatically accurate.
Depending on the project, information may be processed through selected AI, cloud or automation providers. Where this involves personal information, we assess the purpose, provider and safeguards before use.
We do not ordinarily use personal information to make decisions based solely on automated processing that have legal or similarly significant effects on individuals.
Where an automated process is introduced for a client, the client is responsible for ensuring that the process is lawful, fair and appropriately explained to affected individuals.
10. Direct marketing and business updates
We may send occasional communications about:
-
developments within Ossian Digital;
-
changes to services;
-
relevant new capabilities;
-
managed services;
-
systems architecture;
-
artificial intelligence;
-
automation;
-
digital infrastructure;
-
events, guidance or business information that may be relevant to clients.
Service communications that are necessary to administer an active account, contract, domain, hosting service, security issue or project are not treated as optional marketing messages.
For direct marketing, we rely on:
-
consent where consent has been provided;
-
legitimate interests where it is appropriate and lawful;
-
the existing-customer provisions of electronic marketing law where the relevant requirements are met;
-
the business-to-business rules that apply to corporate subscribers.
Sole traders and some partnerships may be treated differently from limited companies under electronic marketing law.
Every marketing email will provide a straightforward way to unsubscribe or object.
You can stop marketing communications at any time by:
-
using the unsubscribe link in the message; or
-
emailing greig@ossiandigital.com.
We maintain a limited suppression record of people who have unsubscribed or objected. This allows us to ensure that they are not inadvertently added to future marketing lists.
Opting out of marketing will not prevent us from sending essential communications about an active contract or service.
We do not sell personal information or marketing lists.
11. Cookies and similar technologies
Our website may use cookies and similar technologies.
Cookies are small files or identifiers stored on or accessed from your device. They may be used to:
-
enable essential website functions;
-
protect the website and forms from abuse;
-
remember preferences;
-
measure performance;
-
understand how visitors use the website;
-
support embedded content;
-
improve services.
Cookies that are strictly necessary for the website or a service requested by the user may be used without consent.
Non-essential cookies, including most analytics, advertising and behavioural tracking cookies, will only be used where the required consent has been obtained.
Where a cookie preference tool is provided, you can use it to:
-
accept or reject non-essential cookies;
-
select cookie categories;
-
change or withdraw your preferences.
You can also manage cookies through your browser settings. Blocking some cookies may affect the way parts of the website operate.
Further information may be provided through a separate cookie notice or cookie settings panel.
12. Who we share personal information with
We share personal information only where reasonably necessary for the purposes described in this policy.
Recipients may include:
Hosting, infrastructure and domain providers
These may process information required to provide:
-
web hosting;
-
cloud infrastructure;
-
backups;
-
domain registration;
-
DNS services;
-
email hosting;
-
security monitoring;
-
content delivery.
Current providers may include 20i and the registrars, data centres and technical suppliers used through its services.
Business software and cloud providers
These may provide:
-
email and document storage;
-
calendar and communication tools;
-
project management;
-
file sharing;
-
customer management;
-
workflow automation;
-
reporting;
-
support systems.
Current examples may include Google Workspace, Microsoft, Trello and other specialist cloud platforms.
Accounting, payment and banking providers
These may include:
-
accounting software providers;
-
card payment processors;
-
banks;
-
payment services;
-
bookkeeping and accountancy advisers.
Current examples may include FreeAgent, Stripe and our banking providers.
Email communication providers
We may use specialist services to manage business updates, contact lists, unsubscribes and campaign delivery.
Current examples may include MailerLite or an equivalent service.
AI, automation and technical service providers
Where appropriate, we may use selected providers to support:
-
AI-assisted analysis;
-
content and code generation;
-
automation;
-
transcription;
-
system integrations;
-
technical delivery.
This may include business services supplied by organisations such as OpenAI, Google, Anthropic, Adobe and other specialist providers, depending on the work involved.
Contractors and specialist partners
We may share appropriate project information with:
-
developers;
-
designers;
-
photographers;
-
videographers;
-
copywriters;
-
consultants;
-
technical specialists;
-
managed service providers.
They receive only the information reasonably required for their role and are expected to maintain confidentiality and appropriate data protection standards.
Professional advisers and authorities
We may share information with:
-
accountants;
-
solicitors;
-
insurers;
-
auditors;
-
debt-recovery providers;
-
regulators;
-
courts;
-
law-enforcement bodies;
-
HM Revenue & Customs;
-
other public authorities.
We will only do this where required by law, necessary to protect our rights or reasonably required for professional advice.
Business restructuring
If Ossian Digital or one of its operating companies is sold, merged, reorganised or transfers part of its business, relevant personal information may be disclosed to advisers, prospective purchasers or successor organisations subject to appropriate confidentiality arrangements.
13. International transfers
Some of our suppliers and technology providers operate internationally or use infrastructure located outside the United Kingdom.
This means that personal information may occasionally be processed in another country.
Where personal information is transferred outside the United Kingdom, we use appropriate protections where required. These may include:
-
transferring information to a country recognised as providing adequate protection;
-
using approved contractual protections;
-
using the UK International Data Transfer Agreement;
-
using the UK Addendum to approved contractual clauses;
-
confirming that another lawful transfer mechanism applies;
-
applying additional technical and organisational safeguards where appropriate.
The precise protection used will depend on the provider, location and type of processing.
14. How we protect personal information
We use proportionate technical and organisational measures designed to protect personal information from:
-
unauthorised access;
-
accidental loss;
-
inappropriate alteration;
-
improper disclosure;
-
misuse;
-
destruction.
Measures may include:
-
access controls;
-
multi-factor authentication;
-
password-management systems;
-
encryption;
-
secure cloud services;
-
anti-malware and security monitoring;
-
backups;
-
role-based access;
-
software updates;
-
staff and contractor confidentiality requirements;
-
incident-management procedures;
-
limiting access to people who need the information.
No internet, email or storage system can be guaranteed to be completely secure. We therefore keep security measures under review and respond to identified risks.
If we become aware of a personal data breach, we will investigate it and take appropriate action. Where legally required, we will notify the Information Commissioner’s Office and affected individuals.
15. How long we keep personal information
We keep personal information only for as long as reasonably required for the purpose for which it was collected, including legal, accounting, security and contractual requirements.
Our standard retention approach is:
Enquiries that do not become projects
We will normally retain enquiry and proposal information for up to 24 months after the last meaningful contact.
Client, contract and project records
We will normally retain core client, contract, project and support records for up to six years after the end of the client relationship or completion of the relevant work.
Information may be retained longer where reasonably necessary for:
-
an ongoing service;
-
a dispute;
-
a legal claim;
-
insurance;
-
security;
-
professional record-keeping.
Financial and accounting records
Invoices, payment records, expense records and tax-related documents will normally be retained for at least six years after the end of the relevant financial year or for any longer period required by law.
Hosting and domain records
Core account, domain, renewal, transfer and support records may be retained for up to six years after the service ends.
Live server, access, security and diagnostic logs are generally kept for much shorter periods unless they are required for an investigation or legal purpose.
Backups
Backups are generally maintained on a rolling basis. Information deleted from a live system may remain in protected backup copies until those backups are overwritten through the normal retention cycle.
Marketing information
Marketing contact information will be retained while:
-
you remain a relevant business contact;
-
you continue to engage with us;
-
we have a lawful reason to contact you;
-
you have not unsubscribed or objected.
Inactive marketing records may be reviewed or removed after approximately 24 months.
Minimal suppression information may be kept for longer so that we can honour unsubscribe requests.
Legal claims and disputes
Information connected to a complaint, dispute, overdue account or legal claim may be retained until the matter has been resolved and any relevant limitation period has expired.
Client-controlled information
Where we act as a processor, retention and deletion will be governed by the client’s instructions, the service agreement and applicable backup arrangements.
We may anonymise information so that it can no longer identify an individual. Anonymised information may be retained for statistical, analytical or business-planning purposes.
16. Children’s information
Our website and services are intended for businesses and professional users. They are not directed at children.
We do not knowingly collect personal information directly from children for our own marketing or business-development purposes.
Some client websites or systems that we host or maintain may process children’s information. In those circumstances, the client is normally the data controller and is responsible for ensuring that the processing is lawful and appropriately explained.
17. Your data protection rights
Depending on the circumstances, you may have the right to:
Be informed
You have the right to understand how your personal information is collected and used.
Access your information
You may request confirmation that we process your information and ask for a copy of it.
Correct inaccurate information
You may ask us to correct inaccurate information or complete information that is incomplete.
Request deletion
You may ask us to delete personal information in certain circumstances.
This right is not absolute. We may need to retain information where there is a legal, contractual, security or legitimate reason to do so.
Restrict processing
You may ask us to restrict the way we use your information in certain circumstances.
Object to processing
You may object where we rely on legitimate interests.
You have an absolute right to object to the use of your personal information for direct marketing.
Data portability
Where applicable, you may ask to receive information you provided to us in a structured, commonly used and machine-readable format.
Withdraw consent
Where we rely on consent, you may withdraw it at any time.
Withdrawal does not affect processing that took place before consent was withdrawn.
Rights relating to automated decision-making
You may have rights where a decision with legal or similarly significant effects is made solely through automated processing.
We do not ordinarily use this type of decision-making for our own business activities.
18. Exercising your rights
To exercise a data protection right, contact:
Please describe:
-
the right you wish to exercise;
-
the information or service concerned;
-
any relevant dates or account details.
We may need to ask for information to confirm your identity before disclosing or changing personal information.
There is normally no fee for exercising a data protection right. We may charge a reasonable fee or refuse a request where the law permits us to do so, including where a request is manifestly unfounded or excessive.
We will respond within the period required by applicable data protection law.
19. Complaints
Please contact us first if you have concerns about how we use personal information. We would like the opportunity to investigate and resolve the issue.
You also have the right to complain to the UK data protection regulator:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Making a complaint to us does not affect your right to contact the Information Commissioner’s Office.
20. Third-party websites and services
Our website may contain links to websites, platforms or services operated by third parties.
We are not responsible for the privacy practices of third-party organisations. You should review their privacy information before providing personal information or using their services.
Where we recommend or integrate a third-party system for a client, that provider’s own privacy policy and contractual terms may also apply.
21. Changes to this privacy policy
We may update this policy when:
-
our services change;
-
we introduce new systems or suppliers;
-
legal requirements change;
-
our business structure changes;
-
we identify areas requiring clearer information.
The current version will be published on our website with its latest revision date.
Material changes may also be communicated directly where appropriate.
22. Company information
Ossian Digital is a trading style of Ossian Media Ltd.
Ossian Media Ltd
Registered in Scotland: SC763151
VAT number: GB 517 2269 93
Registered office:
Robbie & Co
42 Dudhope Crescent Road
Dundee
Scotland
DD1 5RR
Certain legacy or specific hosting services may be provided by:
Ossian Hosting Ltd
Registered in Scotland: SC709281
Registered office:
Robbie & Co
42 Dudhope Crescent Road
Dundee
Scotland
DD1 5RR
Email: greig@ossiandigital.com
Telephone: 01382 671 040