Privacy notice
What this website does with information about you, in plain words.
Who we are
DigiFort (الحصن الرقمي) runs digifort.iq and decides how the information described here is used. Our office is at 4 Streets (Arba’a Shawari), Al Yarmouk, Baghdad, Iraq.
This notice covers the website: its forms, its incident page and the services that run them. Work we do for a client is governed by our contract with that client.
Forms
Each form asks only for what we need to answer it.
- Consultation, briefing, demo and offer requests: your name, organisation and role, how you want us to reply (phone or email) and the details for it, and the language of the reply. Optional: the topic, your sector, who referred you and, for a Secure Brand demo, the brands you want to see.
- Readiness assessment: your organisation, name and phone, the type of entity and its licence status. Optional: your role, a target date and your current systems.
- Tenders, pre-qualification and due-diligence packs: your organisation, name, work email and phone, the deadline, your notes, and the files or a link to them, or a request to sign an NDA first.
- Software scoping: what you are building, the timeline, a budget band and your phone. Optional: your name and email.
- Company profile link: your email and the language edition you want.
With each request we also record the page you sent it from, any campaign tags in the link you followed and the referring page your browser reports. We do not record your IP address with it.
We use it to answer you, to pass your request to the right person and to decide the order in which requests are read, for example when a deadline is close. We do not sell it, and we do not use it for advertising.
Every form is read and answered by a named person.
Who reads it
Each request is saved once, as a private record in our own store on Cloudflare R2, under its EU jurisdiction setting and encrypted by the provider. Only the two people named for that kind of request can read it, plus one logged emergency account held by our IT administrator, used only if both are unavailable. The agency that built this website cannot read it.
Files you upload here are stored encrypted in our own private store (Cloudflare R2, EU jurisdiction), readable only by the two people named on your acknowledgement (plus one logged emergency account held by our IT administrator, used only if both are unavailable), never forwarded to our CRM, and deleted 90 days after the tender is decided. Files are never attached to an email.
Unless you tick the box below, the contact details you give (name, work email, phone, organisation and role) and four labels we add (the type of organisation, a priority band, the service area and your language) are copied to our customer relationship system, HubSpot, a US-based provider. Nothing else goes there: no topics, notes, referrer names, tender details or files, and nothing from the incident page.
Keep my details off your CRM — reply by email only. Ticked, we create no CRM record; your request is read by the named owner and answered from our own mailbox. The option is on the consultation and tender forms.
We send two plain-text emails through Cloudflare Email Service, operated by Cloudflare, Inc., a US-based provider, with no open or click tracking: a notice to the person handling your request and, if you gave an email address, an acknowledgement to you. The notice carries the reference number, your name, organisation and contact details, and a link for our staff. Neither email carries the other details of your request. Our reply comes from our own company mailbox.
The incident page
On our incident page, 'This is an emergency' and the three questions do not use AI. Any line you type is used only to decide the route and is not stored. We keep a record of each use of the incident page, or of the emergency form shown on our other pages, without your text or IP address, for 30 days: the time, the language, the route, the decision and a reference number. None of it enters our CRM or our marketing statistics.
Our providers
These companies process information for us, only to run the parts of the site named here.
- Cloudflare: hosts the site and runs our forms and incident page on its global network; stores form records and files in R2, EU jurisdiction; holds the incident page record and the rate counters.
- Cloudflare, Inc., US-based: Cloudflare Email Service sends the notice and the acknowledgement.
- HubSpot, US-based: our customer relationship system, for the contact details listed above, unless you opt out.
- Microsoft Corporation, US-based: Microsoft Clarity, our website analytics. It records how pages are used (the pages you open, clicks, scrolling and taps, your browser, device and country) as session recordings and heatmaps, under a random identifier for this site. On its own domains, Microsoft also links the visit to its own browser identifier, the MUID cookie, which Microsoft uses for advertising, site analytics and other operational purposes; we do not use it for advertising. The content of forms, everything you type, the incident assistant and the incident number are masked in your browser and never sent to it.
Our website runs on Cloudflare. To protect it from attacks, Cloudflare processes the technical details of each connection, including your IP address, and keeps its security records under its own terms. Our own record of the incident page holds no IP address. To limit abuse of the incident page, a scrambled form of your IP address is held in our rate counters for at most 48 hours and then discarded. Our forms use the same rate counters, with the same limit of 48 hours.
How long we keep it
- Form records: 90 days.
- Tender files: 90 days after the tender is decided, or sooner if you ask.
- Contacts in our CRM: 24 months after our last contact, then deleted.
- The incident page record: 30 days.
- The scrambled IP addresses in our rate counters: 48 hours at most.
- Microsoft Clarity: session recordings 30 days; heatmaps, the click data behind them and any recording we label or save, 9 months (Microsoft’s published retention).
How we protect it
Forms reach our own functions over an encrypted connection; no outside form service sees them. Records and files are stored encrypted. Uploaded files are checked by type and by content before they are stored. Our functions keep no request logs of their own, and we never store your IP address with a request.
Your rights
You can ask us what we hold about you, ask us to correct it or delete it, or ask us to take your details out of our CRM. You can also ask us to stop contacting you.
Write to [email protected], from the address you used if you can, and quote your reference number if you have one. We may ask you to confirm who you are before we act.
To stop Microsoft Clarity in your browser, use the switch on our Cookies page. If your browser sends Global Privacy Control, Clarity does not load at all.
Changes
When the site changes how it handles information, we update this notice. The version on this page is the current one.