Identity of the controller
IN General Digital Solutions, trading as IN GENERAL ("the Company", "we", "us"), is a digital and creative studio registered in the State of New Mexico, United States. The Company operates the website in-general.net and provides brand identity, web and mobile development, marketing, video production, and photography services to clients internationally.
This Policy sets out the Company's practices with respect to personal information in two contexts: the browsing of its website by visitors, and the processing of project and payment data belonging to clients. It applies to in-general.net and to all subdomains operated by the Company.
- Controller
- IN General Digital Solutions is the controller of the personal information described in this Policy.
- Jurisdiction of establishment
- State of New Mexico, United States.
- Contact for data protection matters
- [email protected]. Correspondence sent to this address is reviewed and answered by a member of the team.
Categories of information collected
The Company collects three categories of information, each limited to what is necessary for the purpose for which it is collected.
- Information provided by you
- Name, email address, telephone or messaging number, company name, and the contents of any message or project brief you submit. Where an engagement is entered into, this extends to the materials supplied for the performance of the work, including brand assets, copy, data, and access credentials.
- Information collected automatically
- IP address, browser and device type, operating system, referring page, pages viewed, duration of each visit, and an approximate location inferred from the IP address. This constitutes standard web server and analytics data.
- Information received from service providers
- Upon settlement of an invoice, the Company's payment processor transmits the amount, currency, date, and outcome of the transaction, the card scheme and the final four digits of the card, and the billing name and country. The Company neither receives nor stores the full card number.
The Company does not acquire personal data from data brokers and does not collect special categories of data, including data concerning health, religious belief, political opinion, or biometric identifiers. Any such data submitted to us unsolicited is deleted.
Purposes of processing
Personal information is processed for the following purposes only:
- Responding to enquiries and preparing proposals and quotations.
- Delivering, administering, and supporting the services contracted for.
- Issuing invoices, collecting payment, and maintaining the accounting and tax records required by law.
- Evaluating the use of the website for the purpose of its improvement.
- Protecting the website, our clients, and the Company against fraud, misuse, and security incidents.
- Sending service communications relating to an engagement to which you are a party. Contacting the Company does not result in your addition to any marketing list.
The Company does not employ personal information in automated decision-making producing legal or similarly significant effects, and does not sell or lease it to any party.
Legal bases for processing
In respect of data subjects located in the European Economic Area or the United Kingdom, the Company relies upon the following legal bases under the General Data Protection Regulation:
- Performance of a contract
- Processing necessary to provide a quotation, perform the contracted work, and collect payment in respect of it.
- Legitimate interests
- Operating and securing the website, evaluating its use, maintaining records of dealings, and establishing or defending legal claims, in each case balanced against the rights and freedoms of the data subject.
- Compliance with a legal obligation
- Retention of invoices, tax records, and financial documentation for the periods prescribed by law.
- Consent
- Optional analytics and any marketing communication to which you have expressly subscribed. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
Payment information
Card payments are processed by a third-party payment institution certified to PCI DSS Level 1. Card details are submitted directly into that provider's certified environment. Such details do not traverse the Company's servers, and the Company has no facility to view, store, or retrieve a full card number, expiry date, or security code.
The information returned to the Company is confined to that required for reconciliation of an invoice: the amount, currency, date, and outcome of the payment, the card scheme and its final four digits, and the billing name and country. The payment provider processes transaction data as an independent controller, subject to its own privacy policy.
Where an entry on your statement is unclear, please contact us at [email protected] prior to raising a dispute with your card issuer. Such entries can ordinarily be identified and resolved within the same business day.
Disclosure to service providers
The Company discloses personal information solely to service providers engaged to perform defined functions on its behalf, and only to the extent each function requires. Every such provider is bound by a written agreement restricting its use of the information to the purposes specified by the Company. The categories of provider engaged are as follows:
- Payment processing
- A payment institution certified to PCI DSS Level 1 processes card transactions, issues receipts, and performs fraud screening.
- Infrastructure, hosting and content delivery
- Cloud hosting, domain name, content delivery, and media storage providers operate the systems upon which the website and its application run, and protect them against attack.
- Website analytics
- An analytics provider processes aggregated usage metrics and anonymised session recordings, as described in the preceding section.
- Business communications
- Electronic mail and messaging providers transmit correspondence between the Company and you.
The identities of individual providers are not published on this page. A current list of the Company's service providers, together with the categories of data each processes, is available upon written request to [email protected].
Beyond the foregoing, disclosure is made only where required by law, pursuant to a valid court order, subpoena, or regulatory demand, or where necessary to establish or defend a legal claim. In the event of a sale or merger of the business, information may transfer as part of that transaction, and affected clients would be notified in advance.
The Company does not disclose client work or client-identifying data to any third party for marketing purposes.
International transfers
The Company is established in the United States, its delivery team operates from the Arab Republic of Egypt, and its service providers maintain infrastructure across several regions. Personal information will accordingly be processed outside your country of residence, including in jurisdictions which may not afford an equivalent standard of data protection.
Where personal data is transferred out of the European Economic Area or the United Kingdom, the Company relies upon the Standard Contractual Clauses adopted by the European Commission, which its providers incorporate into their data processing agreements with the Company.
Retention periods
- Enquiries not resulting in an engagement
- Deleted within 24 months of the date of last contact.
- Client project files and correspondence
- Retained for the duration of the engagement and for a further 3 years, in order to support work delivered.
- Invoices and financial records
- Retained for 7 years, as required by United States taxation and accounting rules.
- Website analytics
- Retained by the analytics provider in accordance with its own retention schedule, presently up to 13 months.
Upon expiry of the applicable retention period, information is deleted or irreversibly anonymised.
Security measures
- All traffic to and from the website is encrypted in transit by means of Transport Layer Security.
- Payment data does not reach the Company's infrastructure, being transmitted directly to the payment provider.
- Access to client files and systems is restricted to those personnel engaged upon the relevant matter.
- Administrative accounts employ strong, unique credentials together with multi-factor authentication wherever supported by the provider.
- Servers and dependencies are maintained at current patch levels, and network access is restricted by firewall to those services which must be reachable.
No system affords absolute security. In the event of a breach affecting your personal information and giving rise to a risk to you, the Company will notify you and the competent supervisory authority without undue delay and within the periods prescribed by law.
Rights of the data subject
Irrespective of your location, you may request that the Company give effect to the following rights in respect of your personal information:
- Access — to obtain a copy of the information held about you.
- Rectification — to correct information that is inaccurate or incomplete.
- Erasure — to have information deleted, save where an overriding obligation to retain it subsists.
- Restriction — to suspend processing pending resolution of a dispute.
- Portability — to receive the information in a structured, machine-readable format, or to have it transmitted to another provider.
- Objection — to object to processing carried out on the basis of legitimate interests.
- Withdrawal of consent — at any time, in respect of processing conducted upon that basis.
Residents of the State of California are further afforded, under the California Consumer Privacy Act as amended by the California Privacy Rights Act, the right to know what personal information is collected and the purposes of its collection, the right to deletion, the right to correction, and the right to opt out of its sale or sharing. The Company neither sells nor shares personal information within the meaning of those statutes, and accordingly no opt-out arises. No discriminatory treatment will be applied by reason of the exercise of any right.
Requests may be submitted to [email protected]. The Company responds within 30 days and levies no charge. Should you be dissatisfied with the response, you may lodge a complaint with the data protection authority of your jurisdiction.
Children's privacy
The Company's services are directed to businesses and are not directed to children. The Company does not knowingly collect personal information from any person under the age of 16. Should you have reason to believe that a child has provided information to the Company, please write to [email protected] and it will be deleted.
Amendment of this Policy
This Policy may be amended to reflect changes in the Company's services, its service providers, or its legal obligations. The date stated at the head of this page reflects the version presently in force. Where an amendment materially affects the treatment of your information, active clients will be notified by electronic mail prior to its taking effect.
Contact
Any question, request, or complaint concerning this Policy or the Company's treatment of personal information should be addressed to [email protected]. All correspondence is reviewed and answered by a member of the team.
