Privacy

What we dowith your data

We build products that ask people to trust them with data, so it would be strange to write a privacy notice nobody can read. This one is in plain language and still carries everything Articles 13 and 14 of the UK and EU GDPR require — every category of person we hold data about, each purpose and its lawful basis, who receives it, where it travels, how long we keep it, and what you can make us do about it.

It is long because being specific takes more words than being vague. Use the contents list to jump to the part that concerns you — or read the short versionand email us with anything it leaves open.

Last updated August 2026Applies to digitalcompositionlab.com and our correspondenceUK GDPR · EU GDPR · CPRA · Jordan PDPL

The short version

We collect very little

A booking, an email, a job application, and standard server logs. No advertising trackers, no profiling, nothing sold or shared for anyone else's marketing.

You gave it to us

Almost everything we hold, you typed into a booking form, an email, or an application. We don't buy contact lists or scrape profiles.

It crosses borders

We work from Jordan and the US with partners in the UK. Every restricted transfer runs on Standard Contractual Clauses, the UK Addendum, and a transfer risk assessment.

One address for everything

Access, correction, deletion, or anything you'd send a data protection officer: privacy@digitalcompositionlab.com. A person reads it, and it's free.

Who we are, and who is responsible

Digital Composition Lab (DCL) is an R&D software product development lab. For the personal data described in this notice, DCL is the data controller — the party that decides why and how it is used — within the meaning of Article 4(7) UK GDPR and EU GDPR.

This notice covers digitalcompositionlab.com and our own correspondence, recruitment, and commercial relationships. When we build or operate software for a client, that client is normally the controller and DCL acts as their processor under a written agreement meeting Article 28 — section 10 explains what that means for you.

Controller

Digital Composition Lab — company National ID Number 200211688

Registered address

King Abdullah II St, KHBP VBC BLD 0 FLR 1 STE 39A, Amman, 11855, Jordan

Operating locations

Jordan and the United States, with partners in the United Kingdom

Privacy contact

privacy@digitalcompositionlab.com

Data protection officer and representatives

DCL has assessed the criteria in Article 37 UK GDPR and EU GDPR — public-authority status, large-scale regular and systematic monitoring, and large-scale processing of special-category or criminal-offence data — and none currently applies to our own processing. We are therefore not obliged to appoint a statutory Data Protection Officer, and we would rather say that plainly than imply an office we do not have.

Responsibility is not left unowned. A named privacy lead inside DCL is accountable for this notice, for our Article 30 record of processing activities, for our transfer risk assessments, and for answering your requests. Reach that person at privacy@digitalcompositionlab.com; writing "DPO request" in the subject line routes it directly and starts the statutory clock.

If our processing changes such that a DPO becomes mandatory — or a client contract requires one — we will appoint a qualified person, publish their contact details in this section, and notify the relevant supervisory authority.

Privacy lead

Essa Haddad — privacy@digitalcompositionlab.com; every question, request, or complaint about personal data

Statutory DPO

Not appointed; Article 37 criteria assessed and not met. Reviewed annually and on any material change to our processing.

UK representative

Not appointed. We have no UK establishment, do not currently offer services to or monitor people in the UK, and do not sell or share personal data — it is processed for our own operations only. If Article 27 UK GDPR comes to apply, we will appoint a representative and publish their details here.

EU representative

Not appointed, on the same assessment for the EEA. If Article 27 EU GDPR comes to apply, we will appoint a representative and publish their details here.

With no representative currently required or appointed, the privacy lead above is the single contact for any matter relating to our processing.

Who this notice is for

Different people give us different data for different reasons, so the sections that follow are organised by who you are. Find yourself here and read that section — the rest may not apply to you at all.

Website visitors

Anyone who loads a page on digitalcompositionlab.com. See section 04.

Prospective clients

You booked a call, emailed an enquiry, or met us and swapped details. See section 05.

Clients and their people

Your organisation has engaged DCL, and you are a contact, sponsor, or user on the project. See section 06.

Partners and suppliers

You work with us on a venture or supply us a service. See section 07.

Job applicants

You applied to DCL, or we approached you about a role. See section 08.

People in our clients' systems

Your data sits in a product DCL builds or runs for someone else. See section 10 — your rights run through them, and we will help.

Website visitors

The site is deliberately thin. It sets no cookies of its own, runs no advertising or cross-site analytics, and does not fingerprint your device.

What

Server access logs held by our hosting provider: IP address, user-agent string, pages requested, referring URL, timestamps, and response codes.

Why

Keeping the site available, diagnosing faults, and detecting abuse such as scraping or denial-of-service attempts.

Lawful basis

Article 6(1)(f) legitimate interests — operating our own website securely. The data is transient, not linked to a person by us, and never used to build a profile.

Retention

Rotated by our host, typically within 90 days.

Third-party content

The Calendly scheduler on our contact page loads from Calendly's servers and sets its own cookies. See section 11.

Prospective clients and business contacts

This is the most common reason we hold anything about you: you got in touch about working together.

What

Your name, email address, organisation, role where you tell us, the description you write when booking a call, and the correspondence that follows. Meeting notes we take about the problem you described — not about you personally.

Source

You, directly. We do not buy contact lists, scrape LinkedIn, or enrich your record from data brokers.

Why

Holding the meeting you booked, replying to your enquiry, preparing a proposal, and keeping a record of what was discussed so a later conversation can resume where it left off.

Lawful basis

Article 6(1)(b) — steps taken at your request before a contract; or 6(1)(f) legitimate interests in responding to someone who approached us, where no contract is in prospect.

Retention

Three years from our last exchange, then deleted. Ask sooner and we delete sooner.

Clients, and the people who work for them

Once an engagement starts, we hold the ordinary business-contact data needed to run it — as a controller, separately from any personal data inside the systems we build for you, which section 10 covers.

What

Names, work contact details, job titles, correspondence, meeting and workshop notes, project documentation, invoices, and payment records.

Research participants

Where you invite us to interview your staff or customers, we agree the scope in writing first, take only the notes the research needs, and pseudonymise findings unless a participant agrees otherwise.

Why

Delivering the engagement, managing the relationship, invoicing, and meeting our accounting and tax obligations.

Lawful basis

Article 6(1)(b) performance of a contract; 6(1)(c) legal obligation for financial records; 6(1)(f) legitimate interests in managing and defending the relationship.

Retention

For the life of the engagement, then six years for contract and financial records — the limitation and tax retention period — after which they are deleted.

Partners and suppliers

We build some ventures with partners, and we buy services like any other business. Both involve holding contact data about the people on the other side.

What

Names, work contact details, roles, contract terms, correspondence, and payment details of our suppliers and partner organisations' staff.

Why

Running the collaboration or the supply relationship, due diligence, and paying invoices.

Lawful basis

Article 6(1)(b) performance of a contract; 6(1)(f) legitimate interests in due diligence and relationship management; 6(1)(c) where a law requires the record.

Retention

Duration of the relationship plus six years for the contractual and financial record.

Job applicants

Recruitment data is handled by a small number of people and never used for anything other than the hiring decision it belongs to.

What

Your CV, application, portfolio or code samples, interview notes, assessment results, references where you authorise them, and your right-to-work status where the role requires it.

Why

Assessing your application, arranging interviews, and — with your consent — keeping you in mind for a future role.

Lawful basis

Article 6(1)(b) steps prior to an employment contract; 6(1)(f) legitimate interests in running a fair, documented hiring process; 6(1)(a) consent to hold your details for future roles.

Special-category data

We do not ask for it. Where diversity monitoring is offered it is voluntary, anonymised, separated from your application, and never seen by the people deciding.

Retention

Twelve months after the decision, so we can answer questions about the process and evidence non-discrimination — or up to two years if you consent to future consideration. Withdraw that consent at any time and we delete immediately.

Updates and events

DCL does not run a marketing machine. We send nothing you did not ask for, and there is no newsletter you were quietly subscribed to by booking a call.

If we ever publish updates about the lab's work, subscribing will be an explicit, unticked opt-in under Article 6(1)(a), with an unsubscribe link in every message and a preference you can change at any time. Withdrawing it will not affect anything else in our relationship.

Data we handle on our clients' behalf

When we design, build, test, or operate software for a client, the personal data inside that system belongs to their relationship with you, not ours. The client is the controller; DCL is their processor.

In that role we act only on the client's documented instructions, under an Article 28 agreement that binds us to confidentiality, appropriate security, prior authorisation for any sub-processor, assistance with your rights requests and breach notifications, and deletion or return of the data when the engagement ends. We do not use client data to train models, build our own products, or for any purpose of our own.

If your data sits in a product we built for someone else, exercise your rights with that organisation — they hold the relationship and the record. Write to us at privacy@digitalcompositionlab.com anyway if you cannot identify them, and we will point you to the right controller.

Where an engagement requires access to live personal data, we prefer pseudonymised or synthetic datasets in development and testing, and take production access only where there is no workable alternative — logged, time-limited, and least-privilege.

Cookies and similar technologies

We set no cookies of our own — no third-party analytics, no advertising, no cross-site tracking, and nothing that requires a consent banner for our own purposes. One embedded third-party tool sets its own.

We count anonymous, aggregate page-engagement events — which pages are viewed, read and scrolled — using no cookies and nothing that identifies you; browsers signalling Global Privacy Control are not counted at all.

DCL's own cookies

None. The site works without storing anything on your device.

Calendly (contact page)

The embedded scheduler sets cookies necessary for booking to function, and Calendly acts as an independent controller for what it collects through its widget — see calendly.com/legal. The embed loads only on our contact page.

Avoiding it

Email privacy@digitalcompositionlab.com or book through Calendly's own page instead; the embed is never the only route to us. You can also block or delete cookies in your browser at any time.

Do Not Track / GPC

We run no tracking to disable, so these signals have nothing to switch off here. Where the CPRA treats a Global Privacy Control signal as an opt-out request, we honour it.

Who else touches it

The list of third parties is deliberately short. Each acts as our processor under an Article 28 agreement, may act only on our documented instructions, and may not use your data for its own purposes. We do not sell personal data, and we do not share it for anyone else's marketing.

Calendly

Scheduling. Receives your name, email, and meeting description when you book.

Email and calendar provider

Delivery and storage of correspondence and meeting records.

Postmark (ActiveCampaign, Inc.)

Transactional email. Sends our confirmations and replies; sees the name, email address, and message content needed to deliver them.

Hosting provider

Serving this website and retaining the access logs in section 04.

Google Cloud (Google Ireland Ltd)

Application processing and storage. Runs the service that receives job applications and stores application data and CV files.

Accounting and payments

Invoicing and financial records for client and supplier relationships.

Professional advisers

Lawyers, accountants, and auditors — only on a specific matter, and only to the extent it requires.

Acquirers or successors

If DCL is ever reorganised or acquired, data may transfer to the successor under the same protections. You would be told before it happened.

Legal disclosure

Where a valid court order, regulator, or law compels it. We satisfy ourselves the demand is lawful, disclose the minimum required, and tell you unless legally forbidden.

A current list of sub-processors is available on request. Client contracts carry a change-notification commitment, giving you time to object before a new sub-processor starts.

International transfers

DCL works from Jordan and the United States and collaborates with partners in the United Kingdom, so personal data you send us will be accessed from those countries, and our providers may store it in their own regions. Neither Jordan nor the United States benefits from a general UK or EU adequacy decision.

Every restricted transfer out of the UK or EEA is therefore made under Article 46 safeguards: the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the IDTA where it is the appropriate instrument. Each is supported by a documented transfer risk assessment covering the destination's legal regime and, where the assessment calls for it, supplementary measures — encryption in transit and at rest, access controls, pseudonymisation, and a policy of challenging unlawful government access demands.

You have the right to see the safeguards that apply to a specific transfer. Ask at privacy@digitalcompositionlab.com and we will send you a copy of the relevant clauses with commercial terms redacted.

How long we keep it

Nothing is kept indefinitely. Each category has a period and a reason for that period, and deletion at the end is a scheduled task rather than an intention.

Enquiries and meeting records

3 years from the last exchange — so a conversation can resume — then deleted.

Server logs

Typically 90 days, rotated by our host.

Client contracts, project records, invoices

6 years after the engagement ends — the limitation and tax retention period.

Supplier and partner records

Duration of the relationship plus 6 years.

Unsuccessful applications

12 months after the decision, or up to 2 years with your consent.

Consent and preference records

As long as we rely on the consent, plus the period needed to evidence it was validly given.

Client data we process

Deleted or returned at the end of the engagement, on the client's instruction, per the Article 28 agreement.

How we protect it

Our Article 32 measures are the ones we would want from a supplier of ours: access limited to the people who need it and reviewed when roles change; multi-factor authentication on every account; encryption in transit and at rest; separated development, test, and production environments; pseudonymised or synthetic data in non-production wherever it will do; logged and time-limited access to anything live; and confidentiality obligations in every employment and supplier contract.

They are real measures, not a guarantee. No system is perfect, and we would rather say so than claim otherwise.

If a personal data breach occurs, we investigate immediately, contain it, and record it. Where Article 33 requires it we notify the relevant supervisory authority within 72 hours of becoming aware, and where the risk to you is high we tell you directly without undue delay, in plain language, with what happened and what to do about it. Where we are a processor, we notify the client controller without undue delay so they can meet their own obligations.

Automated decision-making, profiling, and AI

We make no decisions about you by automated means and we do not profile you. Nothing on this site or in our correspondence produces a legal or similarly significant effect within the meaning of Article 22.

We do not use your personal data to train machine-learning models — not ours, and not a third party's. Where an engagement involves AI systems, the terms are set in the client contract, the client remains the controller, and any use of personal data for training requires their documented instruction and its own lawful basis.

If that ever changes for our own processing, we will describe the logic involved, the significance, and the consequences for you in this section before it starts — along with your right to human review.

Your rights under the UK and EU GDPR

These rights are yours by law, they are free to use, and using one never counts against you.

Access — Art. 15

Confirmation of whether we process your data, a copy of it, and the supporting detail in this notice as it applies to you.

Rectification — Art. 16

Correction of anything inaccurate, and completion of anything partial.

Erasure — Art. 17

Deletion where we no longer need the data, you withdraw the consent it rested on, or you successfully object — unless a legal obligation requires us to keep it, in which case we say which one.

Restriction — Art. 18

A pause on processing while accuracy or legitimacy is disputed.

Portability — Art. 20

The data you gave us, in a structured, commonly used, machine-readable format, sent to you or directly to another controller where technically feasible.

Objection — Art. 21

An objection to processing based on legitimate interests, which we stop unless we can show compelling grounds that override your rights. For direct marketing there is no balancing test — we simply stop.

Withdraw consent — Art. 7(3)

As easily as you gave it. Withdrawal does not affect the lawfulness of what happened before.

Human review — Art. 22

Not applicable today: we take no automated decisions with legal or similar effect. The right stands if that ever changes.

Complain — Art. 77

To a supervisory authority, whether or not you come to us first.

How to exercise them

Email privacy@digitalcompositionlab.com and say what you want. There is no form to complete and no account to create, and you never have to explain why.

We may ask one or two questions to confirm you are who you say you are — usually replying from the address we already hold is enough. We ask for identity documents only where the request is high-risk and nothing lighter will do, and we delete anything you send for that purpose as soon as the check is complete.

We respond within one month. For genuinely complex or numerous requests we may extend by up to two further months, and if we do, we tell you why within the first month. Requests are free; the law lets us charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and if we ever rely on that we will explain our reasoning and how to challenge it.

If you are unhappy with our answer, reply and say so — a second person reviews it. That route is optional and never a precondition for going to a regulator.

United Kingdom

Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk · 0303 123 1113

EEA

The supervisory authority where you live, work, or where the issue occurred. The European Data Protection Board lists them at edpb.europa.eu.

Jordan

The Personal Data Protection Council established under the Personal Data Protection Law No. 24 of 2023, via the Ministry of Digital Economy and Entrepreneurship.

If you are in California

The California Consumer Privacy Act, as amended by the CPRA, gives you these rights. We honour them for California residents regardless of whether the statutory thresholds apply to us in a given year.

Categories we collect

Identifiers (name, email, IP address), professional information (employer, job title), commercial information (services enquired about), internet activity (server logs), and — for applicants — the professional and education data in your application. No biometric, geolocation-precise, or inferred-profile data.

Sale or sharing

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined. We have not done so in the preceding twelve months, including for anyone under 16.

Sensitive personal information

We do not collect it for the purpose of inferring characteristics, so the right to limit its use has nothing to operate on here.

Your rights

Know, access in a portable form, correct, and delete — plus the right not to be discriminated against for exercising any of them. We offer no financial incentives for data.

How

Email privacy@digitalcompositionlab.com. We verify by matching the details we already hold and respond within 45 days, extendable once by a further 45 with notice. An authorised agent may act for you with written permission.

If you are in Jordan

DCL operates from Jordan, and Jordan's Personal Data Protection Law No. 24 of 2023 applies to that processing alongside the obligations above.

Under it you may ask us to confirm what we hold, obtain a copy, correct or update it, request its erasure or the cessation of processing, withdraw a consent you previously gave, and object where processing is unlawful or no longer necessary. Where the law requires consent for a particular purpose, we ask for it specifically rather than bundling it into a general acceptance.

Requests go to privacy@digitalcompositionlab.com on the same terms as every other request in this notice — free, and answered within one month. If our answer does not satisfy you, you may complain to the Personal Data Protection Council established under that law, via the Ministry of Digital Economy and Entrepreneurship.

Children

Our site and services are intended for people acting in a professional capacity. We do not knowingly collect personal data from anyone under 16, and we do not offer information-society services directly to children. If you believe a child has given us data, tell us and we will delete it without delay.

Changes to this notice

When something material changes — a new processor, a new purpose, a new transfer route, a change of legal basis — we update the date at the top and describe what changed in this section. We do not quietly widen what we do with data you have already given us; where a change requires your consent, we ask before it takes effect.

Version history: August 2026 — first published.

Contact

Every question, request, and complaint about personal data goes to privacy@digitalcompositionlab.com. It is the same address for access, correction, deletion, transfer safeguards, and anything you would ordinarily send to a data protection officer. A person reads it.

Postal correspondence can be sent to our registered address in section 01. If you write to us on paper, include an email address or we will be slow.

Want your data, or want it gone?

Email us and say what you'd like. We answer within one month, usually the same week, and we never charge for it.

privacy@digitalcompositionlab.com →