Dragons Forge Solutions
Websites, software and digital systems built differently.
Return to website
Privacy Policy
This policy explains how Dragons Forge Solutions collects, uses, shares, stores and protects personal information when you visit our website, contact us, become a customer or use one of our digital products and services.
Who we are
Dragons Forge Solutions provides website design and development, web application development, hosting, technical support and digital products including systems such as Ticket Forge, Stream Forge, Club Forge Pro, Mail Forge, Contact Forge, Web Forge, Commerce Forge and Dragons Forge Core.
For personal information we collect for our own business purposes, Dragons Forge Solutions is the data controller. This means we decide why and how that information is used.
Trading name: Dragons Forge Solutions
Legal owner or registered business name: [ADD LEGAL NAME]
Business structure: [ADD SOLE TRADER / LIMITED COMPANY / OTHER]
Postal address: [ADD BUSINESS POSTAL ADDRESS]
Privacy email: [ADD PRIVACY EMAIL ADDRESS]
ICO registration number, where applicable: [ADD ICO NUMBER OR REMOVE THIS LINE]
Scope of this policy
This policy applies when you:
- visit dragonsforgesolutions.co.uk or another website operated directly by us;
- submit an enquiry, request a quotation or contact our support team;
- purchase or subscribe to a Dragons Forge Solutions service;
- create an account within a product we operate directly;
- receive marketing communications from us; or
- work with us as a customer, prospective customer, supplier, contractor or business contact.
This policy is designed to reflect the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations where they apply.
Some Dragons Forge Solutions products are supplied to other organisations for use on their own websites or services. In those circumstances, the customer organisation will usually be the data controller and Dragons Forge Solutions will usually act as its data processor. Section 7 explains this distinction.
Information we collect
The personal information we collect depends on how you interact with us and which services you use.
Identity and contact details
Name, organisation, job title, postal address, email address, telephone number and account username.
Business and project details
Project requirements, website content, technical specifications, correspondence, quotations, contracts and support history.
Account and service data
Login records, product settings, subscriptions, permissions, service usage, support requests and audit information.
Payment and transaction data
Billing address, purchase details, payment status, invoices, refunds and limited payment references supplied by our payment provider.
Technical information
IP address, browser, device, operating system, referral source, approximate location, timestamps, diagnostic logs and security events.
Marketing preferences
Your communication choices, consent records and interactions with emails or campaigns where tracking is enabled lawfully.
Special category information
We do not normally need sensitive personal information such as health, biometric, religious, racial or ethnic information. Please do not send this information unless it is genuinely necessary. Where a service requires it, we will identify an additional lawful condition and apply appropriate safeguards.
Payment card information
We do not normally receive or store your complete debit or credit card number. Card payments are handled by an authorised payment provider through its secure systems.
How we collect information
We may collect personal information:
- directly from you, including through forms, email, telephone, meetings, account registration, checkout and support requests;
- automatically, through server logs, necessary cookies and other permitted technologies;
- from a customer organisation, where they provide information needed for us to deliver or support a contracted service;
- from service providers, including payment, hosting, security and email providers; and
- from public sources, such as a business website or Companies House, when relevant to a genuine business enquiry or relationship.
How we use personal information
We may use personal information to:
- respond to enquiries and prepare quotations or proposals;
- create, manage and secure customer accounts;
- design, build, host, maintain and support websites, software and digital services;
- process orders, subscriptions, invoices, payments and refunds;
- provide technical notices, service updates and customer support;
- monitor service performance, diagnose faults and improve reliability;
- prevent fraud, misuse, unauthorised access and security incidents;
- maintain business, tax and accounting records;
- manage suppliers, contractors and commercial relationships;
- send relevant marketing where permitted and honour opt-out requests;
- establish, exercise or defend legal claims; and
- comply with legal, regulatory and law-enforcement requirements.
We will not use personal information for a new purpose that is incompatible with the original purpose unless the law permits it or we provide appropriate information and, where required, obtain consent.
Our lawful bases
UK data protection law requires us to have a valid lawful basis for each use of personal information.
| Purpose | Typical lawful basis | What this means |
|---|---|---|
| Responding to enquiries and preparing proposals | Legitimate interests or steps before entering a contract | We use the information needed to understand and respond to your request. |
| Providing purchased services, subscriptions and support | Contract | The processing is necessary to deliver what you or your organisation has asked us to provide. |
| Billing, tax, accounting and legal records | Legal obligation and legitimate interests | We keep records required by law and necessary to manage our business. |
| Security, fraud prevention and service monitoring | Legitimate interests and, where applicable, legal obligation | We protect our systems, customers, users and business from misuse or harm. |
| Optional analytics, advertising or non-essential cookies | Consent, where required | You can choose whether these technologies are used and can change your choice. |
| Email marketing | Consent or legitimate interests where electronic marketing rules permit | We send relevant communications and provide a clear way to unsubscribe. |
| Legal claims and dispute management | Legitimate interests or legal obligation | We may retain and use relevant information to protect legal rights. |
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against your rights, interests and reasonable expectations.
Information processed through customer platforms
A business, sports club, venue, event organiser or other customer may use a Dragons Forge Solutions product on its own website. Examples may include ticketing, streaming, membership, league management, email, ecommerce or customer communication systems.
The customer should provide its own privacy notice explaining its use of your information. Questions about an order, ticket, membership, account, marketing message or other activity managed by one of our customers should normally be directed to that customer first.
We may still act as an independent controller for limited information relating to our own security, billing, service administration, legal obligations and direct relationship with the customer.
Who we share information with
We may share personal information only where necessary with:
- hosting, cloud infrastructure, backup and content-delivery providers;
- domain, email, communication and support service providers;
- payment processors, banks and fraud-prevention providers;
- accounting, legal, insurance and professional advisers;
- analytics and website technology providers, subject to your choices where consent is required;
- contractors or development partners working under confidentiality and data-protection obligations;
- a buyer, investor or successor if our business or relevant assets are sold or reorganised; and
- courts, regulators, law-enforcement bodies or public authorities where disclosure is required or permitted by law.
We require service providers handling personal information on our behalf to use appropriate security and confidentiality measures and to process the information only for authorised purposes.
Current key providers
Complete this list before publishing so it reflects the systems actually in use:
- [ADD HOSTING / CLOUD PROVIDERS]
- [ADD PAYMENT PROVIDER, FOR EXAMPLE STRIPE]
- [ADD EMAIL DELIVERY / CRM PROVIDERS]
- [ADD ANALYTICS, CAPTCHA OR SECURITY PROVIDERS]
We do not sell personal information to third parties.
Payments and financial information
Payments may be processed by a third-party payment provider. The provider collects and processes payment information under its own privacy terms and security standards. We normally receive transaction references, payment status, the amount paid and limited customer or card details needed for reconciliation, fraud prevention, support and refunds.
We may retain invoices, transaction records and related correspondence for tax, accounting, contractual and legal purposes.
Cookies and similar technologies
Our website may use cookies, local storage, pixels, scripts or similar technologies. These can support core website functions, remember preferences, protect accounts, measure performance or help us understand how the website is used.
Types of technology we may use
- Strictly necessary: required for security, network management, account login, checkout, consent choices or another service you request.
- Functional: remember choices and provide enhanced features.
- Analytics: help us understand visits, performance and user journeys.
- Marketing: measure campaigns or support relevant advertising.
Where the law requires consent, non-essential technologies will not be activated until you make a choice. You can reject them without losing access to the main website and can change your choice through our cookie settings.
A separate cookie notice should identify each cookie or technology, its provider, purpose and duration. [ADD LINK TO COOKIE POLICY OR COOKIE SETTINGS]
Marketing communications
We may send information about relevant services, product updates, offers or business news where we have a valid lawful basis and electronic marketing rules allow it.
You can stop direct marketing at any time by:
- using the unsubscribe link in a marketing email;
- changing your communication preferences where available; or
- contacting us using the details in section 19.
Opting out of marketing will not prevent us from sending essential service, security, billing or contractual communications.
International data transfers
Some technology providers may store or access personal information outside the United Kingdom. Where this occurs, we will use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by UK law.
Additional technical, contractual or organisational safeguards may be used where appropriate to the risk.
How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose it was collected, including contractual, security, tax, accounting, support and legal requirements. We then securely delete, anonymise or restrict it unless a longer period is required or permitted by law.
| Record type | Typical retention approach |
|---|---|
| Enquiries that do not become customers | [ADD PERIOD, FOR EXAMPLE 12–24 MONTHS] |
| Customer contracts and project records | For the relationship and then [ADD PERIOD], subject to legal or dispute requirements. |
| Invoices, payment and tax records | [CONFIRM REQUIRED ACCOUNTING RETENTION PERIOD] |
| Support tickets and service correspondence | [ADD PERIOD], depending on the service and relevance to ongoing support. |
| Account and platform data | For the active service and a defined period after closure, subject to backup cycles and the customer’s instructions. |
| Security and technical logs | [ADD PERIOD], unless needed for investigation, fraud prevention or legal claims. |
| Marketing records | Until you opt out, plus a minimal suppression record so we can respect your choice. |
How we protect information
We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, destruction or unauthorised access. Depending on the service, these may include:
- encrypted connections and secure hosting configurations;
- access controls, authentication and least-privilege permissions;
- software updates, vulnerability management and security monitoring;
- backups and recovery procedures;
- logging, fraud prevention and incident response processes;
- confidentiality obligations and controlled contractor access; and
- data minimisation and retention controls.
No website, transmission or storage system can be guaranteed completely secure. You are responsible for keeping your passwords and account credentials confidential and should contact us promptly if you believe an account or service has been compromised.
Your data protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- be informed about how your personal information is used;
- request access to personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion where there is no valid reason for continued processing;
- request restriction of processing in certain circumstances;
- object to processing based on legitimate interests or for direct marketing;
- request portability of certain information you provided to us;
- withdraw consent at any time where processing relies on consent; and
- challenge certain solely automated decisions that produce legal or similarly significant effects.
These rights are not absolute and exemptions may apply. We may need to verify your identity before acting on a request. We will normally respond without undue delay and within the period required by law.
Where Dragons Forge Solutions processes information only on behalf of a customer, we may refer your request to that customer or assist the customer in responding.
Children’s information
Our main business website and services are intended for organisations and adults and are not designed to collect personal information directly from children without an appropriate reason and safeguard.
Some customer-operated platforms, such as sports club, event or membership systems, may involve information about children. In those cases, the customer is normally responsible for identifying the correct lawful basis, providing suitable information to children and parents or guardians, and obtaining consent where it is legally required. We provide processor support and security measures under our agreement with that customer.
Links to other websites and services
Our website may link to websites, applications or services operated by other organisations. Their privacy practices are outside our control. You should review the privacy information provided by the relevant organisation before submitting personal information.
Changes to this privacy policy
We may update this policy to reflect changes to our services, technology, suppliers, business operations or legal obligations. The latest version will be published on this page with a revised “last updated” date. Where a change materially affects how we use personal information, we may provide an additional notice where appropriate.
Contact us and make a complaint
Contact us if you have a privacy question, want to exercise a data protection right or believe we have handled your personal information incorrectly.
Dragons Forge Solutions
Email: [ADD PRIVACY EMAIL ADDRESS]
Postal address: [ADD BUSINESS POSTAL ADDRESS]
Online contact: dragonsforgesolutions.co.uk/contact/
We will acknowledge a data protection complaint within 30 days of receiving it. We will then investigate it appropriately, keep you informed where necessary and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator. We would appreciate the opportunity to address your concerns first, but you can contact the ICO at any time through ico.org.uk/make-a-complaint/ or by telephone on 0303 123 1113.
