Privacy Policy

Last updated: 2 October 2026

1.About this Privacy Policy

Somebody Digital respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:

  • visit or use our website at www.somebodydigital.com (the “Website”);
  • contact us or submit an enquiry;
  • communicate or do business with us;
  • receive marketing or other communications from us;
  • apply to work with us; or
  • otherwise interact with Somebody Digital.

It also explains your rights in relation to your personal data.

For the purposes of applicable data protection law, the controller is:

Somebody Digital Limited, trading as Somebody Digital

Isle of Man registration number: 021989V

Registered office: First Floor, 11-13 Hill Street, Douglas, Isle of Man IM1 1EF

Email for privacy enquiries: privacy@somebodydigital.com

In this Privacy Policy, “Somebody Digital”, “we”, “us” and “our” refer to Somebody Digital Limited.

2.Data protection law

We process personal data in accordance with applicable data protection legislation, including the Isle of Man Data Protection Act 2018, the Data Protection (Application of GDPR) Order 2018 and the GDPR and LED Implementing Regulations 2018, as amended from time to time.

The version of the General Data Protection Regulation applied as part of Isle of Man law is commonly referred to as the Applied GDPR.

The Unsolicited Communications Regulations 2005 may also apply to certain electronic direct-marketing activities.

Because we operate internationally, other data protection legislation may apply to particular processing activities. This may include the UK GDPR and UK Data Protection Act 2018 in relation to relevant activities involving individuals in the United Kingdom and the EU GDPR in relation to relevant activities involving individuals in the European Economic Area.

Where another applicable law provides individuals with additional rights or protections, we will comply with those requirements to the extent that they apply.

3.When we act for our clients

As a digital marketing agency, we sometimes process personal data on behalf of our clients, for example in connection with advertising, analytics, attribution, CRM, campaign management, conversion optimisation or other marketing activities.

Where we process personal data solely on a client’s instructions, the client will normally be the controller and Somebody Digital will act as a processor.

In those circumstances, the client’s own privacy notice will normally explain how and why that personal data is processed. Requests concerning that processing should generally be directed to the relevant client.

This Privacy Policy primarily describes circumstances in which Somebody Digital acts as a controller and determines why and how personal data is processed.

4.Personal data we collect

The personal data we collect depends on how you interact with us.

Information you provide to us

This may include:

  • your name;
  • business or personal email address;
  • telephone number;
  • job title;
  • employer or organisation;
  • information contained in an enquiry or message;
  • correspondence with us;
  • details provided when arranging meetings or discovery calls;
  • information provided during proposals or sales discussions;
  • information associated with a client, supplier or business relationship;
  • billing and payment-related information;
  • CVs, employment history and other information supplied when applying to work with us; and
  • any other information you choose to provide.

Please avoid providing special category or highly sensitive personal data unless it is necessary and appropriate to do so.

Information collected when you use our Website

Depending on your choices and the technologies enabled on the Website, we may collect:

  • IP address;
  • browser and device information;
  • operating system;
  • approximate location derived from IP address;
  • referring website or source;
  • pages viewed;
  • links or buttons clicked;
  • dates, times and duration of visits;
  • Website interaction and performance information;
  • cookie and similar technology identifiers;
  • advertising attribution information; and
  • security and fraud-prevention information.

Our Website may use third-party technologies for analytics, advertising, security and Website functionality. These may include services provided by Google and other technology providers.

Our current use of cookies and similar technologies is described in our separate Cookie Policy and through the consent-management tool available on the Website.

Information obtained from other sources

In a business-to-business context, we may also receive personal data from:

  • your employer or colleagues;
  • clients and prospective clients;
  • referrals and introductions;
  • business partners;
  • publicly available professional sources, such as company websites and professional networking platforms;
  • event organisers;
  • advertising and analytics providers; and
  • other lawful business information sources.

We may combine information obtained from those sources with information we already hold.

5.How and why we use personal data

We only process personal data where we have a lawful basis for doing so.

Enquiries and prospective clients

We use personal data to:

  • respond to enquiries;
  • arrange meetings;
  • understand requirements;
  • prepare proposals;
  • assess whether our services are suitable; and
  • communicate about a potential commercial relationship.

We generally do this because it is necessary for our legitimate interests in operating and developing our business and, where applicable, to take steps requested before entering into a contract.

Clients and business relationships

We process personal data to:

  • establish and manage client relationships;
  • deliver services;
  • communicate with client personnel;
  • administer contracts, statements of work and projects;
  • manage invoicing and payments;
  • provide reports and account support;
  • maintain business records; and
  • resolve issues or disputes.

Depending on the circumstances, the lawful basis may be performance of a contract, steps taken before entering into a contract, our legitimate interests in managing our business relationships, or compliance with a legal obligation.

Where our contractual customer is a company rather than an individual, we will generally process the personal data of its employees and representatives on the basis of our legitimate interests in managing that business relationship.

Marketing and business development

We may use business contact information to communicate with existing clients, prospective clients and other business contacts about services, insights, events, content or opportunities that we reasonably believe may be relevant to them.

Depending on the circumstances and jurisdiction, we may rely on:

  • consent;
  • our legitimate interests in developing and promoting our business; or
  • another lawful basis permitted by applicable law.

We will comply with applicable electronic marketing laws, including the Unsolicited Communications Regulations 2005 where relevant.

You can opt out of direct marketing at any time by using an unsubscribe link where provided or by contacting us.

Opting out of marketing will not prevent us from sending communications that are necessary to administer an existing business relationship.

We may retain a limited suppression record after an opt-out so that we can ensure that your preference continues to be respected.

Website operation, security and improvement

We may process technical and usage data to:

  • operate and secure the Website;
  • diagnose technical problems;
  • prevent fraud, misuse and malicious activity;
  • understand how the Website is used;
  • improve content, navigation and user experience;
  • measure Website performance; and
  • protect our systems and business.

We generally rely on our legitimate interests for processing necessary to operate and secure the Website.

Where consent is required for analytics, advertising or other non-essential technologies, we will rely on your consent.

Analytics, advertising and attribution

Subject to your cookie and consent choices and applicable law, we may use analytics and advertising technologies to:

  • understand Website audiences;
  • measure campaign effectiveness;
  • identify how visitors reached the Website;
  • attribute enquiries or conversions to marketing activity;
  • improve our marketing; and
  • deliver or measure relevant advertising.

Where these technologies require consent under applicable law, they will not be used until the required consent has been obtained.

Further information is provided in our Cookie Policy and consent-management tool.

Recruitment

If you apply to work with us, we may use your information to:

  • assess your application;
  • communicate with you;
  • conduct interviews;
  • verify relevant information; and
  • manage our recruitment process.

We generally process this information because it is necessary to take steps in connection with potential employment or engagement and because we have a legitimate interest in recruiting suitable personnel.

Legal and regulatory purposes

We may also process personal data where necessary to:

  • comply with legal, tax, accounting or regulatory obligations;
  • establish, exercise or defend legal claims;
  • enforce our agreements;
  • respond to lawful requests from courts, regulators or public authorities; and
  • protect our rights, property, personnel, clients or others.

6.Cookies and similar technologies

Cookies are small files or pieces of information placed on or accessed from your device when you visit a website. Similar technologies include pixels, tags, scripts, local storage and advertising identifiers.

We may use these technologies for purposes including:

  • essential Website functionality;
  • security;
  • remembering preferences;
  • analytics;
  • performance measurement;
  • conversion tracking; and
  • advertising.

We use a consent-management mechanism so that visitors can control non-essential technologies where appropriate.

You can change or withdraw your choices through the cookie controls available on the Website.

The cookies and similar technologies currently in use, together with information about their providers, purposes and durations, are described in our separate Cookie Policy or Cookie Declaration.

7.Sharing personal data

We do not sell personal data.

We may disclose personal data where reasonably necessary to:

  • our employees, consultants and contractors who require it to perform their roles;
  • companies within our corporate group, where applicable;
  • Website hosting and technology providers;
  • CRM and business-management providers;
  • cloud storage and productivity providers;
  • email and communications providers;
  • analytics and measurement providers;
  • advertising platforms, where permitted and subject to applicable consent requirements;
  • payment and accounting providers;
  • professional advisers, including lawyers, accountants, auditors and insurers;
  • recruitment providers;
  • prospective buyers, investors or advisers in connection with a corporate transaction or restructuring; and
  • regulators, courts, law-enforcement bodies or public authorities where disclosure is required or permitted by law.

Service providers that process personal data on our behalf are required to process it appropriately and in accordance with our instructions and applicable data protection requirements.

8.International transfers

Somebody Digital operates internationally, and some of our employees, contractors, suppliers and technology providers may be located outside the Isle of Man.

As a result, personal data may be transferred to or accessed from other jurisdictions.

Where applicable data protection law restricts an international transfer, we will take appropriate steps to ensure that the transfer is lawful.

Depending on the circumstances, these steps may include:

  • transferring information to a jurisdiction recognised as providing an adequate level of protection;
  • using approved contractual safeguards;
  • implementing supplementary technical or organisational safeguards where appropriate; or
  • relying on another lawful transfer mechanism or applicable exception.

Where UK GDPR or EU GDPR applies to particular processing, we will also comply with the international transfer requirements of those regimes where applicable.

You may contact us if you would like further information about safeguards relevant to a particular transfer.

9.Data retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including satisfying legal, accounting, regulatory and reporting requirements.

As a general guide:

  • enquiry and prospective-client information will normally be retained for up to 24 months after the last meaningful interaction, unless a business relationship develops or there is another reason to retain it;
  • client and contractual records may normally be retained for up to six years after the relevant relationship ends, subject to legal, accounting and dispute-related requirements;
  • recruitment information for unsuccessful applicants will normally be retained for up to 12 months after completion of the relevant recruitment process, unless a different period has been agreed;
  • marketing information will be retained while it remains relevant to our business relationship or marketing activities, subject to your right to opt out;
  • suppression information may be retained for as long as reasonably necessary to ensure that an opt-out continues to be honoured; and
  • cookie and analytics information will be retained in accordance with the periods identified in our Cookie Policy, consent platform or relevant provider settings.

We may retain information for longer where reasonably necessary to establish, exercise or defend legal claims, meet regulatory requirements or comply with another legal obligation.

We may retain anonymised information indefinitely where it can no longer identify an individual.

10.Your data protection rights

Depending on the circumstances and applicable law, you may have the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • request portability of certain personal data;
  • withdraw consent where processing is based on consent; and
  • request safeguards in relation to certain decisions made solely by automated processing.

These rights are not absolute and exemptions may apply.

Withdrawing consent does not affect the lawfulness of processing that took place before consent was withdrawn.

We do not currently use Website visitor or business-contact information to make decisions based solely on automated processing that produce legal or similarly significant effects.

To exercise your rights, email privacy@somebodydigital.com.

We may need to verify your identity before responding to certain requests.

11.Complaints

If you have a concern about how we process your personal data, we would appreciate the opportunity to address it directly. You can contact us at privacy@somebodydigital.com.

You also have the right to raise a complaint with the:

Isle of Man Information Commissioner

PO Box 69
Douglas
Isle of Man
IM99 1EQ

Email: ask@inforights.im

Telephone: +44 (0)1624 693260

Website: www.inforights.im

Where another data protection regime applies to your personal data, you may also have the right to complain to the relevant supervisory authority in that jurisdiction.

12.Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, destruction or loss.

Access to personal data is limited to personnel and service providers who reasonably require it for legitimate business purposes.

No internet transmission or electronic storage system can be guaranteed to be completely secure, and we cannot guarantee absolute security.

13.Children

Our Website and services are directed principally at businesses and business professionals and are not intended for children.

We do not knowingly seek to collect personal data from children through the Website.

If you believe that a child has provided personal data to us inappropriately, please contact privacy@somebodydigital.com.

14.Third-party websites and services

Our Website may contain links to websites, platforms or services operated by third parties.

Those third parties are responsible for their own privacy practices. This Privacy Policy does not govern third-party websites or services, and we recommend reviewing the relevant third party’s privacy information before providing personal data.

15.Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, Website, technology or legal obligations.

The latest version will be published on the Website and the “Last updated” date above will be amended.

Where a change materially affects how we process personal data, we will take additional steps to notify affected individuals where required or appropriate.

16.Contact us

Questions about this Privacy Policy, our use of personal data or the exercise of data protection rights should be directed to:

Somebody Digital Limited

First Floor
11-13 Hill Street
Douglas
Isle of Man
IM1 1EF

Isle of Man registration number: 021989V

Email: privacy@somebodydigital.com

Scroll to Top