Privacy policy
Last updated: 27 September 2026
1. Who we are
JDWA Digital is the trading name of Simon Jackson, a sole trader operating remotely in the United Kingdom (England and Wales jurisdiction). We operate this website (jdwa.co.uk) to describe our services and to capture enquiries from prospective clients. JDWA Digital is registered with the UK Information Commissioner's Office as a data controller. UK ICO fee is paid annually. A copy of the registration confirmation is provided to any client on request. For any privacy question, email [email protected].
2. What we collect
When you visit this site, we may collect:
- Anonymous traffic data via Google Analytics 4 (only if you have approved cookies)
- Advertising identifiers via Facebook, Google, and LinkedIn (only if you have approved cookies)
- Your name, email, phone, and message if you fill out the audit request form
- Server logs (IP, user agent, referrer) for 30 days, used only for security and abuse prevention
When you become a client, additional data is processed to deliver the service (see Section 7 below for the full sub-processor list and data categories).
3. Cookies & consent
We use a consent banner that requires explicit approval before any tracking script runs. If you decline, no analytics or advertising pixels are loaded and the page renders normally but invisibly. Your choice is stored in a cookie (jdwa-cookie-consent) for one year. You can clear it at any time via your browser settings, after which the banner will appear again on your next visit.
4. How we use the data
If you approve cookies, the data we collect is used to:
- Understand which pages and copy drive the most enquiries
- Show you more relevant content on Facebook, Instagram, Google, and LinkedIn based on which pages you've visited
- Reply to your enquiry if you've filled out a form
We do not sell your data. We do not share it with anyone except the advertising platforms named above (and only after consent).
5. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Request correction or deletion of that data
- Object to processing for direct marketing purposes
- Lodge a complaint with the ICO (ico.org.uk)
You can exercise any of these rights from inside the client dashboard (Settings > Account > Delete account) without contacting us directly, except for the ICO complaint route.
6. Contact
For any privacy-related questions, email [email protected] or use the contact form on the contact page.
7. Sub-processors and data flows (client-account data)
When you are a client of JDWA Digital, additional data flows through these named third-party processors. Each one was chosen because it is the lowest-friction, narrowest-data provider for the role. You can revoke our access at any time by removing the OAuth grant in your Google account or contacting us, and we will delete the stored token within 7 days.
7a. Google (Search Console, Analytics 4, Business Profile, Ads)
Provider: Google LLC, USA (data may be stored in EU or US regions depending on your account settings).
Data shared: search queries, page clicks, and average position from your Search Console property; sessions, users, pageviews, and traffic sources from your GA4 property; your business name, address, hours, phone, photos, and posts from your Google Business Profile; campaign + ad-group performance from your Google Ads account if you use PPC management.
Data NOT shared: we do not modify Search Console settings, sitemaps, or verifications. We do not write to GA4 (read-only data API). We do not edit your business profile fields, hours, photos, or reviews. We do not transfer ads data to any other third party.
Use: we surface ranking trends, content-calendar suggestions, traffic and conversion attribution inside your JDWA dashboard, and (if you use our PPC service) we create and manage ad campaigns inside your Google Ads account on your behalf. Live campaign creation requires Google Ads API Standard access which we are in the process of applying for.
Compliance: JDWA's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the platform features visible to you inside your own dashboard. We never transfer Google user data to third parties except as needed to deliver the service you have contracted for.
7b. Meta (Facebook Pages + Instagram)
Provider: Meta Platforms, Inc., USA.
Data shared: your Facebook Page id, your Instagram business account id, the text + media of posts you approve through JDWA, and engagement metrics (likes, comments, reach, clicks) on those posts.
Data NOT shared: we do not access your personal Facebook profile, your friends list, your personal messages, your ad account outside what is strictly needed for organic publishing, or any data of users who interact with your Page.
Use: we publish posts to your Facebook Page and Instagram business account when you have approved them through the JDWA dashboard. We pull engagement metrics for those posts only.
7c. Stripe (payments)
Provider: Stripe Payments Europe Ltd. (UK entity), 1 Shelbourne Buildings, Dublin, Ireland.
Data shared: your email address, billing address, last four digits of the card, card brand, expiry month. We do NOT see or store the full card number, CVC, or any payment-card data on our servers.
Use: monthly subscription billing, one-off Service Add-on invoices, and webhook-triggered status updates (subscription paused/resumed, payment failed).
7d. Resend (transactional email)
Provider: Resend.com, San Francisco, USA. Sub-processor region for outbound delivery: AWS Frankfurt (eu-central-1).
Data shared: your email address, your name, and the body content of any transactional emails we send (invite emails, password resets, plan reminders). Inbound email to a JDWA Digital account (if you've replied to an automated message) is received by our Dovecot mail server on the Netcup VPS in Nuremberg, Germany; that mailbox is for transactional handling only and is not used for general correspondence or marketing.
Data NOT shared: we do not upload your contact list, we do not send marketing email through Resend, and we do not use Resend for tracking-based analytics.
7e. Hosting + storage infrastructure
The JDWA Digital platform runs on the founder's own infrastructure, hosted on a Netcup VPS (Netcup GmbH, Bismarckstraße 5, 90402 Nürnberg, Germany) located in Nuremberg, Germany. Compute, database (PostgreSQL), cache (Redis), and the Next.js + worker containers are all managed by Coolify on that VPS.
Database storage is on Netcup's encrypted storage subsystem within that Nuremberg deployment. Application-level disk-encryption-at-rest is not configured in the JDWA platform itself; we rely on Netcup's underlying infrastructure protection for data-at-rest on this VPS.
Email transactional delivery: Resend (San Francisco, sub-processor region: AWS Frankfurt).
Object storage: Backblaze B2, EU region (specific bucket name is recorded in our internal data-flow documentation; client-facing clients do not need to know the bucket name to verify their data is stored in the EU).
If any of these providers or regions change, we will update this section of the Privacy Policy and notify all active clients by email within 30 days, in line with clause 10.2 of the Terms of Service.
7f. Optional sub-processors (only if you enable the feature)
- DataForSEO (rank tracking, SERP analysis): receives the keywords and the website URL you want to track. Opt-in per client.
- Google PageSpeed Insights: receives the URL of your website to score performance.
- Google Places API (prospecting): receives business name and city searches for lead generation.
None of these optional sub-processors receive client-account OAuth tokens or financial data. They only receive the read-only API request described above. If you are not on a tier that uses them, no data flows to them at all.
8. Data residency and security
All client-account data (your business profile, integrations, time logged, payment history) is stored in our PostgreSQL database on the JDWA Digital Netcup VPS in Nuremberg, Germany. We do not export or back up any client-account data outside the EU/EEA. File attachments and report PDFs are stored on Backblaze B2 in an EU region (client data never lands on Backblaze's US regions). Inbound email received by our Dovecot server stays on the same VPS. Backups of the Postgres database (taken weekly) are encrypted in transit via TLS and stored on the same Netcup infrastructure with the same EU jurisdiction guarantee.
Access to production data is restricted to the founder's account. Two-factor authentication is enforced on all production access (server SSH, Coolify UI, Resend dashboard, Stripe dashboard, Google Cloud Console, Backblaze B2 console, GitHub repo). Audit logs of every admin action are stored for 12 months.
In the event of a personal data breach affecting your data, we will notify the ICO within 72 hours and you by email at the address on file, per UK GDPR Article 33-34.
9. Data retention and deletion
- Active client-account data: retained for the duration of the engagement.
- Terminated client-account data: full export available on request. We delete account-derived data within 30 days of termination, except where retention is required by law (UK tax law requires 6 years of invoice history).
- Marketing-site visitor data (server logs, GA4): 30 days for logs; GA4 cookies expire after consent expires (1 year max).
- OAuth tokens: deleted within 7 days of access revocation OR service termination, whichever is earlier.
10. Compliance framework
JDWA Digital's use of Google APIs (including Search Console, Google Analytics 4, Google Business Profile, and Google Ads) complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as described in Section 7 to deliver the service you have contracted for, and we do not use Google user data to develop or improve services outside the JDWA platform.
Our handling of Meta platform data complies with the Meta Platform Terms and the Meta Developer Policies. We only request the scopes and features strictly needed to publish organic posts on your behalf and read back engagement metrics.
Stripe handling of payment data complies with PCI-DSS via Stripe's Level 1 certified service. We never touch raw card data on our servers.