The short version
- We are a UK company and UK GDPR is our primary framework.
- Our platform processes cost and usage metadata, plus a narrow set of personal data, chiefly user accounts and cost-centre owner names.
- We never ingest AI prompt text, model responses, tool payloads or source code bodies. That is an architectural rule, not a setting.
- Under BYOC, nothing leaves your perimeter and we are a software provider, not a data processor.
- We do not sell personal data, and we do not use customer data to train models.
1. Who we are
This policy is issued by DIGIUSHER LIMITED (“DigiUsher”, “we”, “us”), a company registered in England and Wales under company number 14620155, with its registered office at London, United Kingdom. We also have presence in Amsterdam (Netherlands) and San Francisco (USA).
DigiUsher provides a Technology Value Realisation platform: a FOCUS-native control plane that measures and attributes the cost of cloud, AI, data platforms, Kubernetes, on-premise infrastructure and SaaS, and connects that cost to the business value it produces.
This policy applies to our website, our marketing and sales activities, and the DigiUsher platform. Where a signed agreement with a customer contains data protection terms, typically a Data Processing Agreement, those terms govern the processing of that customer’s data and take precedence over this policy in the event of conflict.
2. When we are a controller and when we are a processor
The distinction matters, because it determines who owes you what. We are explicit about it rather than blurring the two.
| Situation | Our role | What that means |
|---|---|---|
| You visit our website, download a datasheet, or contact sales | Controller | We decide why and how your data is used, and we answer your rights requests directly. |
| You are a user of a customer's DigiUsher tenancy (SaaS or Managed SaaS) | Processor | Your employer is the controller. We act on their documented instructions and forward your requests to them. |
| Your organisation runs DigiUsher under BYOC | Software provider | We do not process your data at all. Your organisation is both controller and processor within its own environment. |
| We process our own employee, contractor and supplier data | Controller | Handled under our internal privacy notices, not this policy. |
3. What the platform processes
The overwhelming majority of what DigiUsher ingests is not personal data at all. It is billing records, usage metrics, resource identifiers, token counts and rate cards. Personal data enters the platform in a narrow and predictable set of places:
- Platform user accounts. Name, work email address, role, authentication identifiers, and access logs for the people your organisation authorises to use DigiUsher.
- Cost-centre and resource ownership. Names or identifiers of individuals recorded as owners in resource tags, billing metadata, or your own ownership mapping, so that cost can be attributed to an accountable person or team.
- Engineering activity references. Where AI attribution is enabled, commit identifiers, pull-request state, and the commit author reference needed to join agent spend to delivered work.
- Audit records. Who changed a connector, a credential, an allocation rule, or a visibility setting, and when.
We do not process special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation) in the ordinary course of providing the platform. If a customer’s own tagging or metadata practice introduces such data, managing that is the customer’s responsibility as controller, and we ask to be told so we can help remove it.
4. What we deliberately never ingest
A cost platform observing AI and engineering workloads sits uncomfortably close to the most sensitive text in an organisation. We resolved that by architecture rather than by policy promise. The following are discarded at the ingestion boundary, by rule, irrespective of how a connector is configured.
Never ingested
- AI prompt text and system instructions
- Model responses and completions
- Tool-call payloads and arguments
- Retrieved document content (RAG context)
- Source code bodies and file contents
- Commit message bodies beyond the attribution trailer
- Customer end-user or consumer personal data held in your applications
Ingested instead
- Token counts: input, output, cached, batched
- Model and deployment identifiers
- Run identifiers and durations
- Cost, rate and commitment metadata
- Commit SHAs and diff statistics
- Pull-request state (open, merged, closed)
- Resource, cluster and namespace identifiers
We also do not use customer data, personal or otherwise, to train machine learning models, to build benchmark products, or for any purpose other than providing and supporting the services the customer has bought.
5. BYOC: your data does not reach us
Under the Bring Your Own Cloud deployment model, the entire platform (ingestion, the FOCUS data store, the allocation engine, dashboards, and the MCP endpoint) runs inside your own cloud account or datacentre. No cost, usage, telemetry or workload data crosses your boundary.
The legal consequence is significant and we state it plainly: in a BYOC deployment DigiUsher is a software provider, not a data processor within the meaning of UK GDPR and EU GDPR. There is no Article 28 processing of your data by us, because we do not have your data. For customers in regulated sectors this reclassifies us from data sub-processor to technology vendor, which materially reduces the scope of third-party risk assessment under FCA, PRA, MAS TRM, DORA and FedRAMP frameworks.
The only information we receive in a BYOC deployment is limited operational telemetry (platform version, uptime, and aggregated error rates) used solely to support the software and meet service commitments. It is not used to identify individuals and we will not attempt to re-identify anonymised or aggregated data.
6. Website, marketing and recruitment data
Here we are the controller. What we collect:
- Enquiries and demo requests. Name, work email, company, role, and anything you choose to tell us. Used to respond and to maintain a record of the conversation.
- Gated document downloads. Where a datasheet requires registration, the details you submit are used to send the document and to follow up once. We do not enrol you in an automated drip sequence without your consent.
- Website analytics. Aggregate usage measurement to understand which pages are useful. We keep this minimal and do not use it to build advertising profiles.
- Careers. Application materials, retained for the duration of the process and for a limited period afterwards if you agree.
Cookies. We use strictly necessary cookies and local storage to make the site work, for example remembering your light or dark theme preference. Any analytics or preference cookies beyond that are set only where permitted by your choices, and you can change those at any time.
7. Lawful bases for processing
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing the platform to a customer | Performance of a contract; or legitimate interests where we act for the customer as processor on their instructions |
| Responding to a sales enquiry or demo request | Legitimate interests (responding to a request you initiated) |
| Sending a requested document and one follow-up | Legitimate interests; consent where required by applicable marketing rules |
| Ongoing marketing communications | Consent, withdrawable at any time |
| Security monitoring, audit logging, fraud prevention | Legitimate interests; legal obligation |
| Complying with tax, accounting and regulatory duties | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
8. Sub-processors
Where we act as processor in a SaaS or Dedicated Managed SaaS deployment, we engage a small number of sub-processors, principally cloud infrastructure, support tooling, and observability. We impose data protection obligations on each of them by written contract equivalent to those we owe our customers, and we remain fully responsible to the customer for their performance.
- A current sub-processor list, naming each provider, its function and its processing location, is available on request and is maintained as a schedule to our Data Processing Agreement.
- We give customers at least 90 days’ written notice before adding or replacing a sub-processor that processes their personal data.
- Customers have 14 days from that notice to object on reasonable data protection grounds. If we cannot accommodate the objection, either party may terminate the affected services without penalty.
- Customers in regulated sectors may instead require prior written approval of each new sub-processor. We accommodate that where contractually agreed.
- Under BYOC there are effectively no sub-processors, because no third party touches your data.
9. International transfers
We are a UK entity. Where personal data is transferred out of the UK or the EEA to a country without an adequacy decision, we rely on appropriate safeguards: the ICO’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and the EU SCCs where the transfer originates in the EEA, together with a transfer risk assessment where required. Our SaaS is currently active in Europe, Middle East, Australia and United States.
Customers with data residency requirements can pin a Dedicated Managed SaaS deployment to a named region, or eliminate the question entirely with BYOC, where residency is determined solely by where you choose to run the software.
10. Security measures
We maintain SOC 2 Type II attestation and technical and organisational measures appropriate to the risk, including:
- AES-256 encryption at rest; TLS 1.2 or higher in transit
- Role-based access control on every surface, including the MCP endpoint, where an AI assistant inherits exactly the permissions of the person asking and never more
- Multi-factor authentication for administrative access; least-privilege provisioning; documented segregation of duties
- Read-only, narrowly scoped credentials for cost and usage ingestion. The optimisation pipeline holds no write credentials and instead raises a pull request for a human to approve
- Annual independent penetration testing with remediation tracked to closure
- Immutable audit logging of connector, credential, permission and visibility changes
- Security awareness training and background screening for personnel with access to customer data
- An organisation-wide aggregate-only mode that disables individual-level attribution views entirely, for works-council and comparable arrangements
No system is perfectly secure, and we will not claim otherwise. What we commit to is proportionate measures, independent verification, and candour if something goes wrong.
Our current attestations, penetration test summary, sub-processor list and completed security questionnaires are available in the Trust Center.
11. How long we keep data
| Category | Retention |
|---|---|
| Customer data in a SaaS tenancy | For the term of the agreement. On termination, returned in a machine-readable format or securely deleted within 60 days, with backups overwritten within 90 days. Written certification of deletion on request. |
| Platform audit logs | As configured by the customer, subject to any regulatory minimum applying to that customer. |
| Sales and enquiry records | Up to 24 months after the last meaningful contact, unless a contract is in place. |
| Marketing contacts | Until consent is withdrawn, or 24 months of inactivity, whichever is sooner. |
| Contractual, tax and accounting records | Six years from the end of the relevant financial year, as required by UK law. |
| Unsuccessful job applications | Six months, or longer with your agreement. |
12. Your rights
Under UK GDPR and, where applicable, EU GDPR you have the right to:
- Be informed about how your data is used. This policy is part of that.
- Access a copy of the personal data we hold about you
- Rectification of inaccurate or incomplete data
- Erasure where there is no overriding lawful reason for us to keep it
- Restriction of processing in certain circumstances
- Data portability in a structured, commonly used, machine-readable format
- Object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent where consent is the basis, without affecting prior lawful processing
- Not be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions about individuals.
How to exercise them. Email privacy@digiusher.com. Where we are the controller we respond within one month, extendable by two further months for complex requests, and we will tell you if we need that extension. Where we act as processor for a customer, we forward your request to them as controller and assist them in responding within five business days.
If you are a California resident, we act as a “service provider” under the CCPA/CPRA in respect of customer data: we do not sell or share personal information, and we do not combine it with data from other sources. Requests can be made through the same address.
13. Personal data breach notification
Where we act as processor, we notify the affected customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting their data. An initial notification may be brief where full facts are not yet established. We supplement it as information emerges, and we do not notify a supervisory authority or data subject on a customer’s behalf without their instruction unless the law requires it.
Where we are the controller, we report qualifying breaches to the Information Commissioner’s Office within 72 hours and notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
14. Children
DigiUsher is enterprise software sold to organisations. Our services are not directed at children, we do not knowingly collect personal data from anyone under 18, and we will delete any such data promptly if it comes to our attention.
15. Changes to this policy
We update this policy when our practices, our sub-processors, or the applicable law change. The last-updated date at the top of this page always reflects the current text. For changes that materially affect how we handle customer personal data, we notify affected customers directly rather than relying on a silent website update.
16. Contact and complaints
Privacy enquiries and rights requests
Security disclosures
You also have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk), or with your local supervisory authority in the EEA. We would ask you to raise it with us first so we have the opportunity to put it right.
This policy describes our data protection practices and does not itself constitute legal advice. Customers requiring contractual data protection commitments should refer to their signed agreement and Data Processing Agreement, which prevail over this policy in the event of any inconsistency.


