legal

Privacy Policy

VersionDraft 0.1
Effective dateeffective date
Last updated11 August 2026
Applies toDemand Graph websites, landing pages, managed services, and client-user console
Privacy contactprivacy email and postal address
status
Draft — not approved for publication. The final policy must reflect the selected markets, production providers, consent configuration, retention schedule, and qualified legal review.

This Privacy Policy explains how Demand Graph (Demand Graph, we, us, or our) handles personal information when people visit our own website, contact us, use a Demand Graph account, or interact with a website, landing page, form, booking surface, or connected service that we operate for a business client (a Client).

1. Who is responsible for your information?

Responsibility depends on the activity:

SituationWho decides why information is used?How to exercise rights
You visit Demand Graph's own website, contact our sales team, contract with us, use a Demand Graph account, or interact with us as a supplierDemand Graph generally acts as the controller, business, or data fiduciary, depending on applicable lawContact Demand Graph using section 15
You interact with a Client's page, form, campaign, booking surface, or connected channelThe Client generally acts as controller, business, or data fiduciary; Demand Graph generally processes information for that Client under instructionsContact the Client first; Demand Graph will assist the Client as required
We process account security, billing, fraud prevention, legal compliance, or our own business recordsDemand Graph may act independently for those limited purposesContact Demand Graph using section 15

The page or communication through which you arrived should identify the relevant Client. If you cannot identify it, contact us with the page address and approximate interaction date. For Client-controlled processing, the Client's privacy notice provides the activity-specific purposes, legal basis, and choices and should be read with this policy.

Demand Graph details: Demand Graph, entity type, registered address, country of establishment, and registration number if applicable.

2. Information we handle

Depending on how you interact, we may handle:

  • Contact and lead information: name, email address, telephone or messaging number, company, location, service interest, and answers you provide in a form.
  • Attribution and campaign information: landing surface and page, referring address, UTM source/medium/campaign/content/term values, advertising click identifiers such as fbclid, ttclid, gclid, and ctwa_clid, and related advertising cookies where configured.
  • Visitor and device information: a random first-party visitor identifier, timestamp, browser or device information represented by a pseudonymous hash, and IP address represented by a tenant-specific pseudonymous hash. Hashing reduces direct identifiability but does not necessarily make information anonymous.
  • Usage and conversion information: page views, lead submissions, booking-slot views, booking confirmations, the page or surface involved, and related event timestamps.
  • Booking and outcome information: appointment provider reference, appointment time, duration, timezone, status, attendance or no-show status, and commercial outcome information supplied by a Client. confirm whether any booking form also collects free-text or sensitive data.
  • Account and access information: business email, name, tenant membership, roles, permissions, login session, API-token metadata, and authentication records. Passwords are stored as derived password hashes, not readable passwords.
  • Operational and security information: audit events, actions taken, timestamps, pseudonymous network identifiers, rate-limit keys, error and diagnostic information, and security-event data.
  • Client configuration and content: pages, offers, branding, workflow settings, provider references, and instructions supplied by a Client.
  • Communications metadata: channel, external contact or conversation references, state, timestamps, assignments, and extracted signals where the applicable service enables them. Demand Graph is designed not to store message bodies in its own database; message content remains with the connected communication provider, which applies its own retention and privacy terms.
  • Commercial information: Order Forms, invoices, payment status, support history, and business contacts. identify payment provider and confirm whether Demand Graph ever receives payment instrument data.
  • Information from third parties: information provided by the relevant Client, its authorized users, connected CRM, channel, calendar, booking, analytics, advertising, or other provider.

Please do not provide sensitive or specially regulated information unless the relevant form or Client expressly requests it and the required safeguards and notices are in place.

3. How and why we use information

We use information as needed to:

  • provide websites, landing pages, forms, bookings, notifications, accounts, and contracted managed services;
  • connect a not-yet-identified visit to a later lead or booking and measure campaign and page performance;
  • notify the relevant Client about a lead, booking, or service event;
  • authenticate users, enforce tenant permissions, prevent abuse, secure the service, and diagnose failures;
  • communicate about enquiries, proposals, contracts, support, changes, and service administration;
  • maintain business, tax, contractual, audit, and legal records;
  • comply with law and protect people, Clients, Demand Graph, and the public; and
  • improve reliability and functionality using aggregated or de-identified information and permitted service telemetry.

When we process personal information for a Client, our purposes and authority are limited by that Client's documented instructions and the applicable agreement. We do not use Client prospect data to train a general-purpose model or for our own targeted advertising unless a separate written authorization and legally sufficient notice or consent are in place.

4. Legal bases where applicable

Some laws require us to identify a legal basis for each use. Depending on the activity and jurisdiction, we rely on:

  • contract or steps requested before a contract to answer an enquiry, provide an account, or perform an Order Form;
  • legitimate interests, where permitted, to secure and operate the service, prevent abuse, measure business performance, administer relationships, and improve reliability, after balancing those interests against individual rights;
  • consent for cookies, tracking, marketing, or another activity where consent is required;
  • legal obligations for tax, accounting, regulatory, court, and law-enforcement requirements; and
  • protection of rights and vital interests where necessary and legally permitted.

For Client-controlled processing, the Client determines the applicable legal basis. Contact the Client for details about its purposes, legal basis, and marketing practices.

5. First-party identifiers, cookies, and tracking

Demand Graph currently uses a first-party cookie named dg_vid containing a random UUID. Its maximum lifetime is two years. It lets a first visit, later lead submission, analytics events, and booking be associated with the same browser. It does not itself contain a name, email address, or telephone number, but it becomes personal information when linked to a lead or other identifiers.

We may also read or receive advertising click identifiers, UTM parameters, referrer information, and configured advertising cookies such as Meta's _fbp or _fbc. Server-side measurement is used because browser blocking can otherwise make campaign data incomplete. Product events may be sent to the analytics provider selected for the relevant tenant.

The current implementation issues the visitor identifier on the first applicable page request. Before deployment in a market that requires prior consent for this measurement, Demand Graph or the relevant Client must configure a legally appropriate consent mechanism and prevent collection until the required choice is obtained. final consent platform, cookie categories, consent signals, and withdrawal method.

You can delete or block cookies in your browser. Doing so may create a new visitor identifier on a later visit and may reduce attribution accuracy. Browser controls do not necessarily remove records already lawfully collected or stop tracking performed by a third-party service you visit.

final Global Privacy Control, Do Not Track, California opt-out, and targeted- advertising response.

6. How we disclose information

We may disclose information only as reasonably needed to:

  • the relevant Client and its authorized users;
  • infrastructure, edge-security, database, storage, analytics, email, communication, CRM, booking, calendar, support, professional-adviser, and other providers acting for Demand Graph or a Client;
  • a party involved in a merger, financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and legal requirements;
  • courts, regulators, law enforcement, or others where required by law or reasonably necessary to protect rights, safety, and service integrity; and
  • another party at your direction or with valid consent.

Production provider list: link to current provider/subprocessor list, purposes, locations, and role.

final statement on whether Demand Graph “sells” or “shares” personal information or uses it for targeted advertising under applicable US state privacy laws. Do not publish until the final analytics and advertising configuration is reviewed.

7. International transfers

Demand Graph, Clients, and service providers may process information in countries other than the country where it was collected. Those countries may have different data-protection laws. Before production launch, Demand Graph will document hosting and provider locations and use any transfer mechanism required by applicable law, such as an adequacy decision, approved contractual clauses, or another valid safeguard.

operating countries, hosting regions, transfer mechanisms, and instructions for obtaining a copy of applicable safeguards.

8. Retention

We keep personal information only as long as reasonably necessary for the relevant purpose, including contracted services, security, dispute resolution, and legal, tax, and accounting obligations. The final schedule must be approved before publication:

CategoryDraft approachFinal period
First-party visitor cookieBrowser cookie expires after at most two years unless deleted earlierTwo years
Attribution touches and identity linksRetained for the agreed attribution window, then deleted or de-identified; erased when linked contact erasure requires itattribution retention
Leads, form answers, and contact identifiersRetained for Client instructions and the active relationship, then deleted or de-identifiedlead retention
Bookings and commercial outcomesIdentifiers deleted or de-identified when no longer needed; non-identifying business history may remainbooking/outcome retention
Client-user accounts and sessionsActive relationship plus security and account-close periodaccount and expired-session retention
Audit, security, rate-limit, and diagnostic recordsRetained according to security and legal needlog and audit retention
Contracts, invoices, and legal recordsStatutory and dispute-limitation periodcommercial record retention
BackupsRemoved through ordinary rotation after production deletionbackup rotation period

When a contact is erased, Demand Graph can delete lead records, attributable visitor touches, and identity links and remove identifying values from the contact record. Conversion events, bookings, and revenue history may remain only after the contact reference or other identifying values are removed, where permitted by law. Information required for legal claims, security, or compliance may be restricted and retained for the applicable period.

9. Security

We use administrative, technical, and organizational safeguards intended to protect information, including tenant-scoped access controls, database row-level isolation, least-privilege credentials, secure transport, access auditing, bounded public inputs, rate limiting, and controls designed to keep raw contact details and credentials out of logs. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

Security contact: security reporting email or vulnerability-disclosure URL.

10. Your choices and rights

Depending on applicable law and Demand Graph's role, you may have rights to:

  • receive information about processing;
  • access or obtain a copy of personal information;
  • correct inaccurate or incomplete information;
  • delete information;
  • restrict or object to processing;
  • receive portable data;
  • withdraw consent without affecting earlier lawful processing;
  • opt out of direct marketing, sale, sharing, or targeted advertising where applicable;
  • appeal a refused privacy request where applicable;
  • avoid a decision based solely on automated processing where it has a legal or similarly significant effect; and
  • complain to a competent privacy or data-protection authority.

These rights are not absolute. We may verify identity, ask for details needed to locate records, apply legal exceptions, or route a request to the responsible Client.

If your information came through a Client page or campaign, contact that Client first. Demand Graph will assist it as required by contract and law. For Demand Graph-controlled information, submit a request to privacy request email or portal. We will respond within applicable or committed response period and will not discriminate against you for exercising a legal right.

Authorized agents may submit requests where applicable, subject to proof of authority and identity verification. Appeals may be sent to privacy appeals contact.

11. Marketing communications

Demand Graph may send service communications needed for an enquiry, account, or contract. We send promotional communications only where permitted by law and the recipient may opt out using the message instructions or by contacting marketing preferences email. Opting out of marketing does not stop necessary service or transactional communications.

Clients control marketing sent through their own channels and are responsible for their legal basis, suppression lists, consent, and required disclosures.

12. Automated processing and profiling

As of the “Last updated” date, Demand Graph records attribution and conversion events and may present them to human operators. Prospect signals, readiness scores, and recommendations, when enabled, are intended to support rather than replace human sales and service decisions. Demand Graph does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for an individual.

Before enabling materially significant profiling or automated decision-making, Demand Graph and the relevant Client must assess applicable law, provide required information, and implement any rights to human review, explanation, objection, or contest.

13. Children

The Services are designed for business audiences and are not directed to children under minimum age based on launch markets. Do not submit a child's information. If you believe a child provided information contrary to this policy, contact us so we can investigate and take appropriate action.

14. Changes to this policy

We may update this policy when our services, providers, or legal obligations change. We will update the date above and provide any additional notice or consent required by law. Materially different uses of information will not be applied retroactively without a lawful basis.

15. Contact and complaints

Demand Graph entity type registered address and country Privacy requests: privacy email or portal Privacy officer or representative, if required: grievance officer, DPO, EU representative, or UK representative contact, or “not required” after review General support: support email

You may also complain to the privacy or data-protection authority where you live, work, or believe an infringement occurred. jurisdiction-specific authority links required at launch.

Questions about this document?
[email protected]