Privacy Policy
Effective date: 2 August 2026 · Last reviewed: 5 August 2026
1. Who we are
Dusanglobal Ltd (referred to as “Dusanglobal”, “we”, “us” or “our”) is the controller of personal information described in this policy, except where we expressly act as a processor for a customer.
- Legal name
- Dusanglobal Ltd
- Privacy contact
- Secure contact form
2. Scope of this policy
This policy explains how we collect and use personal information when you visit our website, use the AI Solution Builder, submit a secure enquiry, create or use a customer portal account, browse or purchase through the shop, communicate with us, or receive our technology and support services.
Where we process personal information solely on a customer’s documented instructions while delivering managed IT, Microsoft 365, cloud, cyber security, software or support services, that customer will normally be the controller and our processing will also be governed by the applicable contract or data-processing terms.
3. Personal information we collect
| Context | Typical information |
|---|---|
| Website and device use | IP address, browser and device information, requested pages, timestamps, security events, referrer and technical logs. |
| Secure enquiries | Name, company, work email, telephone where provided, enquiry type, message, source page, consent confirmation and submission time. |
| AI Solution Builder | Contact and organisation details, answers about technology, security, cloud, Microsoft 365, AI readiness, resilience and priorities, generated scores, recommendations, assessment reference and consent timestamp. |
| Customer portal and accounts | Identity and sign-in details, account permissions, organisation, tickets, projects, assets, documents, messages, orders and account activity. |
| Shop and commercial activity | Products viewed or ordered, basket and order information, billing and delivery details, payment status, returns, refunds and correspondence. Payment-card data may be handled directly by a payment provider and not stored by us. |
| Sales and service delivery | Contacts, opportunities, quotations, contracts, orders, projects, support tickets, service records, devices, licences, invoices, payments and communications. |
| Cookie and privacy choices | Your essential, analytics, preferences and marketing selections, plus the date and time saved in browser local storage. |
Please do not submit special-category information, criminal-offence information, passwords, payment-card details or confidential third-party data through a general website form unless we specifically request it through an approved secure process.
4. How and why we use personal information
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries, preparing proposals and taking steps requested before a contract | Steps before entering a contract; legitimate interests in developing and administering our business. |
| Providing contracted products, portal access, projects, support and managed services | Performance of a contract; legitimate interests where the customer is an organisation and the individual is its representative. |
| Operating accounts, authentication, security, fraud prevention, backups and audit logs | Legitimate interests in protecting users, customers, systems and services; legal obligation where applicable. |
| Creating CRM leads, opportunities, follow-up tasks and internal notifications from submitted enquiries | Steps before a contract and legitimate interests in responding efficiently and maintaining business records. |
| Producing AI Solution Builder scores and recommendations | Steps requested before a contract and legitimate interests. The results are indicative and are not used to make solely automated legal or similarly significant decisions. |
| Invoicing, accounting, tax, dispute resolution and regulatory compliance | Contract, legal obligation and legitimate interests. |
| Optional analytics, preference or marketing technologies | Consent, where consent is required. Optional technologies remain disabled unless selected. |
| Relevant business-to-business communications about related services | Legitimate interests and, where required, consent. You may object or unsubscribe at any time. |
We assess the appropriate lawful basis for each activity. Where we rely on legitimate interests, we consider our purpose, necessity and the effect on individuals.
5. AI Solution Builder and automated processing
The AI Solution Builder applies explainable rules to the answers you provide to generate indicative maturity scores, priority actions and service recommendations. It is a planning and lead-qualification tool, not a substitute for professional IT, cyber security, legal, regulatory or financial advice.
We do not use the assessment to make a solely automated decision that produces legal or similarly significant effects. A consultant should review recommendations before implementation or contractual commitment.
6. Cookies, local storage and similar technologies
We use strictly necessary technologies for security, sign-in, session continuity, antiforgery protection, basket or portal functions and core application operation. Our consent manager stores your optional-cookie choices in local storage under dgs.cookie-consent.v1 for up to 12 months.
Google Analytics 4 is used only after you consent to analytics technologies. It helps us understand aggregated website usage, page performance and how visitors navigate the site. Google Analytics is configured through Google Consent Mode v2, while advertising storage and advertising-personalisation signals remain denied. Full details are in our Cookie Policy, and you can withdraw consent at any time using Cookie settings in the website footer.
7. Who we share information with
We may share personal information only where necessary with:
- authorised employees, contractors and group personnel;
- hosting, cloud, backup, cyber security, identity, communications, document-storage and support suppliers;
- Microsoft and other technology vendors where their products or services are used;
- Google, where you consent to Google Analytics measurement, subject to Google's applicable service and data-protection terms;
- payment, delivery, finance, accounting, legal and professional advisers;
- customers for whom we act as processor or service provider;
- regulators, courts, law enforcement or public authorities where required; and
- a purchaser, investor or successor in connection with a genuine business transaction, subject to safeguards.
Suppliers are expected to process information under appropriate contractual, confidentiality and security requirements.
8. International transfers
Some technology providers may process information outside the United Kingdom. Where this occurs, we use an available lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard. You may request more information about applicable safeguards.
9. Retention
| Record | Indicative retention |
|---|---|
| Unsuccessful or unconverted website enquiries and AI assessments | Normally up to 24 months after the last meaningful interaction, unless needed longer for a dispute, legal requirement or requested follow-up. |
| Customer, contract, order, project, invoice and payment records | Normally six years after the end of the relevant relationship or accounting period, subject to legal and contractual requirements. |
| Support, service, security and audit records | According to service need, contractual requirements, security risk and the applicable retention schedule; commonly between 12 months and six years. |
| Account and authentication records | For the life of the account and a reasonable period after closure, with selected audit records retained where necessary. |
| Cookie-consent choice in local storage | Up to 12 months unless you clear it or change your preference sooner. |
| Google Analytics data | According to our configured Google Analytics retention settings and Google's applicable deletion controls. Browser cookies have the durations listed in the Cookie Policy. |
Actual periods may be shorter or longer where required by law, a customer contract, litigation hold, security investigation or documented business need. Information is deleted, anonymised or access-restricted when no longer required.
10. Security
We use proportionate technical and organisational measures, which may include access controls, authentication, encryption in transit, secure cookie settings, request-forgery protection, browser security headers, account lockout controls, secure development practices, logging, monitoring, backups, supplier controls, staff confidentiality and incident-management procedures. We describe these controls at a high level and do not publish secrets, internal configuration, infrastructure details or information that would materially weaken security. No internet service is completely risk-free, and users must also protect credentials and devices.
11. Your rights
Depending on the circumstances, you may have rights to be informed, access your information, correct inaccurate information, erase information, restrict processing, receive portable information, object to processing and challenge certain automated decisions. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing.
To exercise a right, use our secure contact form. We may need to verify identity and clarify the request. You also have the right to complain to the UK Information Commissioner’s Office.
12. Children
Our website and business services are intended for organisations and adults. We do not knowingly seek personal information from children through the public website.
13. Changes to this policy
We may update this policy when our services, technologies, suppliers or legal obligations change. The current version and review date will be published here.
