// Legal HQ

Privacy Policy

BudgetFitter® Master Privacy Policy. Comprehensive data protection charter detailing UK GDPR compliance, mobile app SDKs, Manifest V3 extension privacy, self-hosted email sovereignty, and global data subject rights.

Last updated: August 22, 2026

MASTER PRIVACY POLICY & DATA PROTECTION CHARTER

We are FozDigital LTD, trading as BudgetFitter (“Company”, “we”, “us”, or “our”), a private limited company incorporated in England and Wales under Company Registration Number 13470802, registered with the UK Information Commissioner’s Office (ICO) under Data Protection Registration Number ZB348787, and owner of registered UK trademark #UK00004088233. Our registered office is located at 124 City Road, London, EC1V 2NX, United Kingdom.

Under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the EU GDPR (Regulation (EU) 2016/679), and applicable international privacy frameworks, FozDigital LTD acts as the Data Controller responsible for determining the purposes and lawful means of processing your personal data across our entire digital infrastructure, which includes:

  • Our website located at https://budgetfitter.uk (the “Website”).
  • Our native mobile applications for Apple iOS and Google Android (the “App”).
  • Our privacy-first browser extension for Chromium-based browsers (the “Extension”).
  • Our self-hosted email newsletter (“The Fitter Newsletter”), dispatched exclusively from our own private server mail infrastructure.
  • Our synchronised member accounts, user dashboards, and personalised Deal Feed.
  • Our Ally Rewards instant digital gift card loyalty and mission verification system.
  • Our interactive comparison utilities, calculators, and quizzes (“FitterTools”).
  • Our conversational search engine and deal intelligence interface (“AI Ally” / “AI Mode”).
  • Our independent editorial publication (“The Savings Review”).
  • Our outbound deal routing, deep-linking, and click attribution services (/go/{id}/).

This Master Privacy Policy provides an exhaustive, transparent breakdown of how we collect, process, store, transfer, and safeguard your personal data, your statutory rights under UK and global data protection laws, and our technical security safeguards.

Our designated Data Protection Officer (DPO) can be contacted directly at [email protected]. For general privacy inquiries, please contact [email protected].

THE BUDGETFITTER PRIVACY MANIFESTO

  • 1. We Do Not Sell or Rent Personal Data: We never monetize, sell, trade, or licence your personal data, search history, or email addresses to third-party data brokers, ad networks, or commercial lead aggregators.
  • 2. 100% Anonymous Public Browsing: You can search verified discount codes, read factsheets, check the BudgetFitter Score (BFS), and copy promo codes without registering an account or disclosing your identity.
  • 3. Self-Hosted Email Sovereignty: The Fitter Newsletter is hosted and dispatched directly from our own private, secure UK/EU server mail infrastructure. We do not export or host subscriber lists on third-party marketing SaaS platforms.
  • 4. Manifest V3 Zero-History Standard: Our browser extension runs passively client-side. It collects zero browsing history, records no keystrokes, and never inspects private browsing tabs.
  • 5. No Intrusive Cross-App Tracking (No IDFA Profiling): Our mobile apps do not track you across third-party apps or websites for targeted advertising and do not use Apple IDFA or Google GAID cross-app profiling.
  • 6. Real-Time Global Privacy Control (GPC) Honouring: We automatically recognize and respect browser-level Global Privacy Control (GPC) and Do-Not-Track (DNT) signals.
  • 7. UK & EEA Data Residency: Your core account data and preference records are housed exclusively in high-security, ISO 27001-certified UK and European Economic Area data facilities.

TABLE OF CONTENTS

  1. 1. WHAT INFORMATION WE COLLECT (CATEGORIES OF DATA)
  2. 2. LAWFUL BASES FOR PROCESSING UNDER UK GDPR (ARTICLE 6)
  3. 3. SELF-HOSTED EMAIL INFRASTRUCTURE & NEWSLETTER PROTOCOL
  4. 4. MOBILE APPLICATION DATA, SDKS & DEVICE PERMISSIONS
  5. 5. APPLE APP STORE & GOOGLE PLAY DATA SAFETY DISCLOSURES
  6. 6. BROWSER EXTENSION PRIVACY ARCHITECTURE (MANIFEST V3)
  7. 7. OUTCLICK ROUTING, SUBIDS & AFFILIATE ATTRIBUTION TELEMETRY
  8. 8. ALLY REWARDS MISSION VERIFICATION & REWARD FULFILMENT
  9. 9. AI ALLY, AI MODE & CONVERSATIONAL PROMPT PRIVACY
  10. 10. AUTOMATED DECISION-MAKING & PROFILING (ARTICLE 22)
  11. 11. THIRD-PARTY DATA PROCESSORS & SERVICE PROVIDERS
  12. 12. INTERNATIONAL DATA TRANSFERS & ADEQUACY SAFEGUARDS
  13. 13. DATA RETENTION SCHEDULE & LIFECYCLE MATRIX
  14. 14. TECHNICAL & ORGANISATIONAL SECURITY SAFEGUARDS
  15. 15. 72-HOUR STATUTORY DATA BREACH NOTIFICATION PROTOCOL
  16. 16. CHILDREN’S PRIVACY (STRICT 18+ STANDARD)
  17. 17. YOUR STATUTORY PRIVACY RIGHTS (UK GDPR & DPA 2018)
  18. 18. DATA SUBJECT ACCESS REQUEST (DSAR) WORKFLOW
  19. 19. GLOBAL PRIVACY CONTROL (GPC) & DO-NOT-TRACK SIGNALS
  20. 20. US STATE PRIVACY RIGHTS (CALIFORNIA CCPA/CPRA, VIRGINIA, COLORADO)
  21. 21. INTERNATIONAL PRIVACY SCHEDULES (EU, UAE & GLOBAL)
  22. 22. COOKIES & LOCAL STORAGE PREFERENCES
  23. 23. POLICY REVISIONS & MATERIAL CHANGE NOTIFICATIONS
  24. 24. CONTACT INFORMATION & ICO COMPLAINTS PROCEDURE

1. WHAT INFORMATION WE COLLECT (CATEGORIES OF DATA)

A. Data You Voluntarily Provide to Us

  • Account Registration Data: Email address, chosen display name, password hash (cryptographically managed via Google Firebase Authentication Identity Platform), account creation timestamp, and unique system user ID.
  • Member Preferences & Deal Feed Selections: Merchant brands you follow, deals you bookmark/save, custom deal drop notification thresholds, and preferred display currency.
  • Newsletter Subscription Data: Email address, opt-in confirmation timestamp, and subscription category selections for The Fitter Newsletter.
  • Ally Rewards Verification Data: When claiming an instant digital gift card reward for completing a merchant mission, you may submit transaction confirmation screenshots, invoice numbers, purchase timestamps, merchant order identifiers, or merchant account emails.
  • Customer Support & Deal Feedback: Content of communications submitted via our contact forms, bug reporting interfaces, “Report Broken Code” buttons, or direct email correspondence with our support team.

B. Data Collected Automatically (Web & Mobile)

  • Device & Telemetry Data: Hardware model, operating system version (iOS, Android, Windows, macOS, Linux), app build version, browser user-agent, screen resolution, and system language preferences.
  • Network & Security Logs: Truncated/pseudonymised IP address (last octet masked for general telemetry), request timestamps, referring URLs, HTTP status codes, and Cloudflare edge security headers used exclusively for DDoS mitigation, rate-limiting, and bot defense.
  • First-Party Aggregated Analytics: Privacy-first pageview and interaction metrics recorded via our independent server-side analytics. We do not use cross-site tracking cookies or export user browsing streams to advertising exchanges.

2. LAWFUL BASES FOR PROCESSING UNDER UK GDPR (ARTICLE 6)

In strict compliance with Article 6 of the UK GDPR and the Data Protection Act 2018, we process your personal data only where an explicit lawful basis applies:

Processing Purpose Categories of Personal Data Lawful Basis (UK GDPR)
User Authentication & Deal Feed Synchronisation Email, user ID, display name, password hash, JWT tokens Contractual Necessity (Art. 6(1)(b)): Essential to deliver your registered account and sync your Deal Feed across devices.
Ally Rewards Mission Verification & Gift Card Fulfilment Email, order receipts, invoice ID, transaction date Contractual Necessity (Art. 6(1)(b)): Essential to validate mission completion and disburse digital gift cards.
The Fitter Newsletter Dispatches Email address, subscription preferences Consent (Art. 6(1)(a)): Explicit double opt-in consent, freely revocable at any time with 1-click unsubscribe.
Mobile App Deal Drop Push Notifications FCM / APNs device push tokens, followed brand IDs Consent (Art. 6(1)(a)): Explicit in-app OS push notification permission granted by the user.
Platform Security, Anti-Scraping & WAF Defense IP address (pseudonymised), user-agent, rate logs Legitimate Interests (Art. 6(1)(f)): Protecting our proprietary database, IT infrastructure, and user security.
Affiliate Outclick Telemetry & Commission Reconciliation Pseudonymous click ID (bf_subid), deal ID, ISO country Legitimate Interests (Art. 6(1)(f)): Reconciling commercial performance attribution with partner merchants.
Tax, Corporate & Statutory Accounting Compliance Gift card disbursement audit records, dispute logs Legal Obligation (Art. 6(1)(c)): Complying with UK Companies Act, HMRC, and ICO record-keeping mandates.

3. SELF-HOSTED EMAIL INFRASTRUCTURE & NEWSLETTER PROTOCOL

Unlike standard web services that export customer subscriber lists to third-party commercial marketing SaaS vendors, The Fitter Newsletter is operated and dispatched directly from our own private, secure server mail infrastructure located within the United Kingdom.

Our Email Commitments:

  • Zero Third-Party List Exporting: Your email address remains securely within our private database and is never shared, synced, or rented to external marketing automation vendors.
  • Double Opt-In Verification: We require explicit confirmation before activating your newsletter subscription to prevent unauthorized or spam sign-ups.
  • One-Click Instant Unsubscribe: Every email dispatch contains a direct, automated one-click unsubscribe link in the footer and supports the standard RFC 8058 List-Unsubscribe header. Unsubscribing immediately suppresses your email from future dispatches without delay.
  • No Invasive Tracking Pixels: We do not embed covert tracking beacons designed to spy on your IP address or physical location upon reading our emails.

4. MOBILE APPLICATION DATA, SDKS & DEVICE PERMISSIONS

Our native iOS and Android Mobile Applications are engineered with data minimization as a core design principle. Below is a complete disclosure of mobile SDKs, device permissions, and data handling:

Mobile Component / SDK Provider & Purpose Data Processed Storage Location
Firebase Authentication Google LLC — User authentication and cross-device session management User ID, email, ID tokens (JWT) Encrypted in iOS Keychain / Android Keystore
Firebase Cloud Messaging (FCM) & Apple APNs Google LLC / Apple Inc. — Dispatching deal drop and mission push alerts Ephemeral Device Push Token Encrypted push token database (EU region)
Firebase Crashlytics & Performance Google LLC — Identifying app crashes and performance bottlenecks Anonymised crash stack traces, OS version, device model Aggregated diagnostics (Zero PII)
Local App Storage (AsyncStorage) BudgetFitter Core — Storing UI preferences, followed brands, dark mode Brand IDs, UI flags, bookmarked deals Locally on device only (Never transmitted to third parties)

Zero Background Location or Sensor Tracking: The BudgetFitter Mobile App does not request, collect, access, or monitor your precise GPS location, background location, contacts, camera, microphone, or photo library.

5. APPLE APP STORE & GOOGLE PLAY DATA SAFETY DISCLOSURES

In accordance with Apple App Store Privacy Nutrition Labels (Guideline 5.1.2) and the Google Play Data Safety Section:

  • Data Used to Track You: NONE. BudgetFitter does not collect or link personal data for cross-app tracking across third-party apps or websites.
  • Data Linked to You: Email address, User ID (for account holders only, used strictly for App Functionality).
  • Data Not Linked to You: Crash logs and performance diagnostics (used strictly for Analytics and App Functionality).
  • Data Security: All data in transit is encrypted using modern TLS 1.3 encryption. You may request account and data deletion at any time via the in-app settings.

6. BROWSER EXTENSION PRIVACY ARCHITECTURE (MANIFEST V3)

The BudgetFitter Chromium Browser Extension adheres strictly to Google Chrome Web Store Developer Program Policies and the Manifest V3 architecture:

  • Passive Client-Side Matching: The Extension checks the hostname of the active tab against our cached public merchant list purely within your browser’s local sandbox to determine if verified promo codes exist for that retailer.
  • Zero Browsing History Collection: The Extension NEVER records, stores, logs, or transmits your web browsing history, search engine queries, visited URLs, page contents, keystrokes, form inputs, passwords, or payment card details.
  • No Script Injection or DOM Scraping: The Extension does not inject invasive scripts into merchant checkout pages, nor does it read form fields containing sensitive billing or shipping information.
  • No Affiliate Hijacking: The Extension operates passively and only activates an affiliate link when you explicitly click a verified coupon button in the extension popup.

7. OUTCLICK ROUTING, SUBIDS & AFFILIATE ATTRIBUTION TELEMETRY

When you click an outbound offer button or deal card on BudgetFitter, our routing service (/go/{id}/) generates a pseudonymous outbound click token (e.g. bf_subid) before redirecting your browser to the merchant’s storefront.

What is Logged: We log the target merchant ID, deal ID, timestamp, general ISO country code, and the pseudonymous click token. This technical telemetry is strictly necessary to reconcile performance-based affiliate commissions and validate qualifying Ally Rewards missions. We do not collect or receive your credit card details, full delivery address, or bank details from partner merchants.

8. ALLY REWARDS MISSION VERIFICATION & REWARD FULFILMENT

To participate in the Ally Rewards programme and receive instant digital gift cards, you may be requested to provide transaction verification data:

  • Proof of Purchase Documents: Order confirmation emails, invoice numbers, receipt screenshots, or merchant account identifiers submitted via our secure portal.
  • Purpose & Scope: This information is processed strictly to verify that a genuine transaction occurred and was not cancelled or refunded during the merchant’s validation window (30–90 days).
  • Reward Disbursement: Once verified, your registered email address is used solely to deliver the secure digital gift card redemption link.
  • Data Purging: Verification attachments and transaction screenshots are securely deleted from our active claim systems within 12 months of gift card disbursement, retaining only anonymised financial audit logs as required by statutory UK accounting rules.

9. AI ALLY, AI MODE & CONVERSATIONAL PROMPT PRIVACY

When you interact with our conversational deal discovery engine (“AI Ally” / “AI Mode”), your natural-language prompts are processed in stateless, real-time memory to retrieve relevant discounts and merchant intelligence from our database.

  • Zero Foundation Model Training: We DO NOT use your personal search prompts, questions, or conversational text to train public AI foundation models.
  • No Commercial Prompt Brokering: We never sell, licence, or share your search inputs with third-party data aggregators.
  • Stateless Execution: Conversational search queries are processed ephemerally and are not linked to your personal identity for commercial ad-targeting.

10. AUTOMATED DECISION-MAKING & PROFILING (ARTICLE 22)

In accordance with Article 22 of the UK GDPR, BudgetFitter does not subject you to decisions based solely on automated processing or profiling that produce legal effects or similarly significant consequences concerning you. All Deal Feed sorting, search rankings, and BudgetFitter Score (BFS) calculations represent objective, platform-wide editorial metrics and non-discriminatory algorithmic ordering.

11. THIRD-PARTY DATA PROCESSORS & SERVICE PROVIDERS

We work exclusively with vetted service providers operating under strict UK GDPR Data Processing Agreements (DPAs) incorporating mandatory confidentiality and technical security obligations:

  • Cloud Infrastructure & Hosting: Enterprise-grade cloud infrastructure and hosting providers operating within the UK and European Economic Area (EEA).
  • Authentication & Push Messaging: Google Ireland Limited (Google Firebase — EU data residency).
  • Edge Security & CDN: Cloudflare, Inc. (providing WAF protection, DDoS mitigation, and SSL/TLS termination).
  • Digital Gift Card Issuance: Regulated corporate gift card distributors (such as Runa, Tango Card, Giftbit) solely for the purpose of generating and emailing unique digital gift card redemption links.
  • Affiliate Networks: Performance affiliate networks (Awin, CJ Affiliate, Impact, Rakuten, Partnerize) solely receiving pseudonymous click tokens (bf_subid) for commission reconciliation.
  • Statutory Authorities: UK law enforcement, HMRC, or regulatory bodies strictly where required under mandatory UK statutory enactments.

12. INTERNATIONAL DATA TRANSFERS & ADEQUACY SAFEGUARDS

Our primary servers and databases are located within the United Kingdom and the European Economic Area (EEA). In instances where service providers (such as Google Firebase or Cloudflare) process data outside the UK or EEA, transfers are conducted strictly pursuant to lawful transfer mechanisms recognized under UK GDPR, including:

  • UK Adequacy Regulations (countries deemed to provide an adequate level of data protection).
  • The UK International Data Transfer Addendum (IDTA) or Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office.
  • The UK-US Data Bridge (Extension to the EU-US Data Privacy Framework) for certified US entities.

13. DATA RETENTION SCHEDULE & LIFECYCLE MATRIX

We retain personal data strictly for the duration necessary to fulfil the specific operational and legal purposes for which it was gathered:

Data Category Retention Period Lifecycle Action & Rationale
Active Member Account Records Lifetime of active account Retained while account remains active; deleted upon user request.
Dormant Accounts 18 consecutive months of zero login activity Automatically archived and permanently pruned following advance electronic notice.
Newsletter Subscription Data Until unsubscribed / deletion request Unsubscribed emails immediately moved to suppression list to prevent future dispatches.
Ally Rewards Verification Proofs 12 months from reward disbursement Receipt screenshots and proof documents securely purged from active servers.
Reward Financial Audit Records 6 years Anonymised transaction records retained for UK statutory tax and Companies Act compliance.
Outclick Routing Telemetry (bf_subid) 90 days Aggregated and anonymised for statistical affiliate reconciliation.
Security & WAF Access Logs 30 to 90 days Purged on rolling basis; retained solely for DDoS and cybersecurity defense.

14. TECHNICAL & ORGANISATIONAL SECURITY SAFEGUARDS

FozDigital LTD implements state-of-the-art technical and organizational measures to safeguard your personal data against unauthorized disclosure, alteration, loss, or destruction:

  • Strict Encryption in Transit: Mandatory HTTPS / TLS 1.3 encryption across all public web endpoints, mobile REST APIs, and extension traffic with HTTP Strict Transport Security (HSTS) enforced.
  • Strong Encryption at Rest: AES-256 cryptographic encryption applied to all persistent databases, storage volumes, and server backups.
  • Identity & Access Controls: Multi-factor authentication (MFA) mandatory for all administrative infrastructure access; strict role-based access control (RBAC) and least-privilege principles.
  • Edge Protection & WAF: Cloudflare Enterprise Web Application Firewall, real-time DDoS mitigation, rate-limiting, and bad-bot traffic suppression.
  • Automated Encrypted Backups: Daily automated snapshots stored in encrypted off-site UK/EU vaults with rolling 30-day lifecycle expiration.

15. 72-HOUR STATUTORY DATA BREACH NOTIFICATION PROTOCOL

In accordance with Articles 33 and 34 of the UK GDPR, FozDigital LTD maintains a formalized Incident Response & Data Breach Protocol. In the unlikely event of a security incident resulting in a personal data breach posing a risk to the rights and freedoms of individuals:

  1. Supervisory Notification: We will formally notify the UK Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
  2. Data Subject Notification: If the breach is likely to result in a high risk to your personal rights and freedoms, we will notify you directly via email or prominent platform notification without undue delay, outlining the nature of the breach, the name of our DPO, the likely consequences, and the mitigation measures taken.

16. CHILDREN’S PRIVACY (STRICT 18+ STANDARD)

The Services are strictly designed and intended for individuals aged 18 and older. We do not knowingly collect, solicit, or maintain personal data from children or individuals under 18 years of age. If we learn that personal data from a minor has been collected without verified parental consent, we will take immediate steps to delete such information from our servers and terminate the associated account. If you become aware of any data collected from a minor, please notify us immediately at [email protected].

17. YOUR STATUTORY PRIVACY RIGHTS (UK GDPR & DPA 2018)

Under Chapter III of the UK GDPR and the Data Protection Act 2018, you possess comprehensive statutory rights regarding your personal data:

  1. Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you (Data Subject Access Request – DSAR).
  2. Right to Rectification (Article 16): You have the right to request the correction of inaccurate or incomplete personal data.
  3. Right to Erasure / “Right to be Forgotten” (Article 17): You have the right to request the permanent deletion of your personal data where there is no compelling legal ground for continued processing.
  4. Right to Restriction of Processing (Article 18): You have the right to request the restriction of processing of your personal data under certain circumstances (e.g. while an accuracy dispute is investigated).
  5. Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON/CSV) to transmit to another controller.
  6. Right to Object (Article 21): You have the right to object at any time to the processing of your personal data based on legitimate interests or for direct marketing purposes.
  7. Right to Withdraw Consent (Article 7(3)): Where processing is based on consent (e.g. newsletter dispatches or push notifications), you have the right to withdraw your consent at any time without affecting the lawfulness of prior processing.

18. DATA SUBJECT ACCESS REQUEST (DSAR) WORKFLOW

We make exercising your privacy rights effortless, transparent, and prompt:

  • Self-Service Account & Data Deletion: You can edit your profile, manage your followed brands, or delete your entire account and all associated data directly within your member dashboard, or by following our Data Management Guide.
  • Formal DSAR Submission: To submit a formal Data Subject Access Request, data portability request, or erasure request, you can complete our verified DSAR Portal or email our Data Protection Officer directly at [email protected].
  • Response Timelines: In full accordance with UK GDPR, we respond to all verified statutory requests within one (1) calendar month of receipt, free of charge. In cases of complex or multiple requests, this period may be extended by up to two additional months with formal notification.

19. GLOBAL PRIVACY CONTROL (GPC) & DO-NOT-TRACK SIGNALS

BudgetFitter natively honours the Global Privacy Control (GPC) browser signal. If your browser or browser extension transmits the GPC signal, our systems automatically suppress optional analytics and non-essential telemetry. We also recognize standard browser-level Do-Not-Track (DNT) header requests.

20. US STATE PRIVACY RIGHTS (CALIFORNIA CCPA/CPRA, VIRGINIA, COLORADO)

For residents of California, Virginia, Colorado, Connecticut, Utah, Texas, and other US states with enacted comprehensive privacy legislation:

  • Notice at Collection & No Sale of Personal Information: We do not sell your personal information, nor do we “share” your personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act (CCPA/CPRA).
  • Your US State Privacy Rights: You have the right to know what personal information we collect, the right to delete your personal information, the right to correct inaccurate data, and the right not to receive discriminatory treatment for exercising your privacy rights.
  • Exercising Your US Rights: US residents may submit requests via our DSAR Portal or by emailing [email protected] with the subject line “US State Privacy Request”.

21. INTERNATIONAL PRIVACY SCHEDULES (EU, UAE & GLOBAL)

For our international readership across the European Union, the Middle East, and Asia:

  • European Union (EU GDPR): All provisions of this Privacy Policy apply equally to individuals located in the EU/EEA pursuant to Regulation (EU) 2016/679. You may lodge a complaint with your local EU Data Protection Authority.
  • United Arab Emirates & Gulf Region (UAE PDPL): Processing of personal data for users in the UAE complies with UAE Federal Decree-Law No. 45/2021 regarding Personal Data Protection.
  • Australia (Privacy Act 1988): We handle personal information in accordance with the Australian Privacy Principles (APPs).

22. COOKIES & LOCAL STORAGE PREFERENCES

BudgetFitter uses essential cookies and local storage tokens strictly necessary to maintain your login session, remember your UI preferences (such as dark mode), and record your consent choices. For a detailed breakdown of all cookies and local storage items, please review our comprehensive Cookie Policy.

23. POLICY REVISIONS & MATERIAL CHANGE NOTIFICATIONS

We may update this Master Privacy Policy periodically to reflect enhancements to our platform, changes in legal regulations, or operational shifts. The “Last updated” date at the top of this policy indicates the effective date of the latest version. For material changes affecting your rights, we will provide prominent notice via website banners, in-app notifications, or direct email communication.

24. CONTACT INFORMATION & ICO COMPLAINTS PROCEDURE

If you have any questions, concerns, or feedback regarding our privacy practices or wish to communicate with our Data Protection Officer, please contact us at:

FozDigital LTD (t/a BudgetFitter)
Data Controller | Company No: 13470802 | ICO Registration: ZB348787 | Trademark: #UK00004088233
Attn: Data Protection Officer (DPO)
124 City Road, London, EC1V 2NX, United Kingdom
DPO Direct Email: [email protected]
General Privacy Email: [email protected]
Web Contact Portal: https://budgetfitter.uk/contact-us/

Right to Lodge a Complaint with the UK Information Commissioner’s Office (ICO):
If you are unsatisfied with how we handle your request or believe our processing violates data protection laws, you have the statutory right to lodge a complaint with the UK supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113 | Website: https://ico.org.uk