Home Interviews Regular GuestsTechDigitalisationConsultingBusiness & GeneralHealthcareBusiness & EntrepreneurshipSustainabilityEducationFinancial ServicesB2BManufacturingSupply ChainReal EstateMarketingRetail Services Video InterviewsPress Releases & ArticlesSEO ServicesAEO PackagesSocial PackagesBook Publishing Awards Blog News About Us Apply to be featured Contact Log in
Spotify ↗ Amazon Music ↗
Legal

Privacy Policy

What DGL Media Solutions Ltd collects, why, who else sees it, and how long we keep it.

No analytics. No advertising pixels. No tracking cookies.
We set two cookies, both strictly necessary to keep you logged in, and nothing else. There is no cookie banner because there is nothing to consent to.
DGL Media Solutions Ltd — trading as Xraised
Data controller, registered in England and Wales, company number 16463544
Suite E Ground Floor Profile West, 950 Great West Road, Brentford, United Kingdom, TW8 9ES
Questions, or to exercise your rights: gianmarco@xraised.com
Version 1.1 Effective 7 August 2026 Last updated 8 August 2026 Legal review 7 August 2026 Terms & Conditions →

01Who is responsible for your data

DGL Media Solutions Ltd (“we”, “us”, “our”), trading as Xraised, is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 16463544, at Suite E Ground Floor Profile West, 950 Great West Road, Brentford, United Kingdom, TW8 9ES.

We are based in and operate from the United Kingdom, and we process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

For anything in this notice, including to exercise your rights, write to gianmarco@xraised.com.

This notice explains what we collect and why. The terms on which we supply our services are separate, and are in our Terms & Conditions.

02We do not track you

Our website carries no analytics, no advertising pixels and no third-party tracking of any kind. There is no Google Analytics, no tag manager, no Meta pixel, no session recording and no cross-site advertising technology.

We therefore do not build a profile of you, do not track you across other websites, and have no cookie consent banner because there is nothing non-essential to consent to.

The two cookies we do set

  • Session cookie — set when you log in to the client portal or the team dashboard. It holds a signed reference to your session, nothing else. Marked HttpOnly, SameSite=Lax and Secure.
  • xr_member — set when a site member logs in, so the site remembers you for up to 30 days. It holds a signed member id and nothing else. Marked HttpOnly, SameSite=Lax and Secure.

Both are strictly necessary to provide a service you asked for, so they do not require consent. Clearing them, or logging out, removes them.

Your browser also stores your currency preference (pounds or dollars) locally so the prices you see stay as you left them. That value never leaves your device and is not personal data.

03What we collect, and when

We collect only what a specific purpose requires. What that is depends on how you deal with us.

If you are a client

  • Your account — email address, display name, and a password stored only as a bcrypt hash. We never hold your password itself and cannot recover it.
  • Your order — name, company, role, the link you give us, the pitch or brief you write, the product bought, the amount and currency, and the reference numbers Stripe returns.
  • Material you supply for a piece — the text, context, keywords, links and any file you upload for us to write from, together with the filename, size and type of that file.
  • The work itself — drafts, the published article, your feedback and change requests, edits you propose, approvals you give, and the notifications we send you.
  • Internal notes — notes our team writes on your account to run the work (with the name of the colleague who wrote them). You are entitled to see these on request.
  • Your plan, where you subscribe — its status, renewal date and the Stripe references for it.

If you register as a site member

  • Your email address, a bcrypt hash of your password, whether the email has been confirmed, and the dates you registered, confirmed and last logged in.
  • Your watchlist — the interviews you saved.
  • Any comment you post: the name and email you enter, the comment, and its moderation status.

If you book a video interview

Booking and payment happen on Calendly, which collects your name, email, chosen slot and payment. We receive the booking details from Calendly and record the resulting service on your account. The card itself is handled by Calendly's payment provider and never reaches us.

If you simply visit the website

Nothing is recorded about you. We do not log visits for analytics.

Two narrow exceptions, both about abuse rather than about you: when you post a comment or like an interview, we store a salted, irreversible hash of your IP address so the same source cannot flood the site. We never store an IP address in readable form, and the hash cannot be turned back into one.

04Payments

Card payments are processed by Stripe. Card numbers, expiry dates and security codes are entered on Stripe's own pages and never reach our servers — we neither receive nor store them.

What we keep is the record of the transaction: the amount, the currency, the product, the date, and the identifiers Stripe returns so a payment can be matched to an order (a session id, a payment intent id, an invoice id and a customer id). None of these reveal your card.

Updating a card or viewing your invoices opens Stripe's own secure billing page. We see that the plan changed; we do not see the card.

05Saving your payment method

When you buy from us you are asked to accept these policies, and in doing so you agree that your payment method may be saved for future use. This section explains exactly what that means.

Stripe holds it, we do not

The payment method is stored by Stripe, on Stripe's systems, under their PCI-DSS certification. It is never stored on our servers and we never see your card number, expiry date or security code. What we hold is an opaque reference that lets us ask Stripe to charge you — it is useless to anyone who obtained it, and it cannot be turned back into a card number.

What we use it for

  • taking the recurring payment on a monthly plan;
  • charging a fee you have already agreed to in the Terms — for example the rescheduling fee for a video interview missed at short notice;
  • issuing an invoice for further work you ask us for, so you do not have to enter your card again.

We do not charge you for anything you have not ordered or agreed to. A saved payment method is a convenience for work you have asked for; it is not permission to bill you at will.

Our legal basis

Performance of our contract with you, for payments due under it, and our legitimate interest in being paid for work you have ordered. Where a payment is not covered by either, we ask you first.

Removing it

You can remove or replace a saved payment method at any time from Update payment method in your Portal, which opens Stripe's own secure page — or by writing to us. Removing it does not cancel a plan, and it does not affect anything already delivered; if a plan is still running you will need to give us another way to pay it.

Questions about a saved method, or about a charge you do not recognise: gianmarco@xraised.com.

06Why we use it, and our legal basis

To perform our contract with you

  • creating and running your account and the client portal;
  • producing, reviewing and publishing the work you have ordered;
  • taking payment, issuing receipts and managing your plan;
  • sending you service messages — confirmations, “ready for your review”, publication notices, payment problems and login credentials.

Service messages are not marketing. They are how the contract is performed, so they are sent for as long as you have an account with work in it, and cannot be unsubscribed from separately.

To meet a legal obligation

Keeping accounting and tax records, and responding to lawful requests from a court or regulator.

For our legitimate interests

  • keeping the service secure and preventing abuse — the hashed-IP rate limiting described above, and comment moderation;
  • keeping internal notes so the team can run your work consistently;
  • establishing, exercising or defending legal claims;
  • showing work we have produced in our portfolio, with your permission, which you may withdraw at any time.

Where we rely on legitimate interests we have considered whether it is fair to you, and you may object at any time — see “Your rights”.

With your consent

Marketing emails, and anything else we ask you about specifically. Consent can be withdrawn at any time without affecting what was done before.

07Marketing

We send commercial email only to people who have explicitly asked for it. Buying from us does not sign you up to anything, and we do not add clients to a marketing list because they became clients.

Every marketing email carries a one-click unsubscribe, and unsubscribing takes effect immediately. It does not stop the service messages about work you have ordered, which are part of the contract.

We do not sell, rent or share your details with anyone for their own marketing. Ever.

08Who else sees your data

We share personal data only with the suppliers that make the service work, and only as far as each one needs. They act on our instructions under a contract, and may not use your data for their own purposes.

  • Stripe — payments, subscriptions and the billing portal.
  • Resend — sending our transactional email.
  • Microsoft Azure — storage of video, images and files connected to your work.
  • Railway — hosting of the application and its database.
  • Calendly — booking and payment for video interviews.
  • Asana — our internal work management. Data flows from Asana to us: our system reads tasks and never writes back.
  • Anthropic — see the next section.

We do not sell personal data, and we share it with no one else — no data brokers, no advertising networks, no partners.

We may also disclose data where the law requires it, or to establish or defend a legal claim. If our business is transferred, your data would move with the contract it belongs to.

The publications we submit your work to

This is the disclosure that matters most, so we state it plainly. To publish your article we send the outlet the finished piece and the details that identify you as its subject — typically your name, role, company, quotes attributed to you, your links and any photograph you supplied.

Once published, that material is public, and the outlet becomes responsible for it as its own controller. It may be indexed by search engines, syndicated to other outlets, cached or archived, and can remain accessible even if the original page is later removed. See “Removing a published article” in our Terms & Conditions.

09Use of AI in producing your work

We use Anthropic's Claude API to draft articles. This means the material you give us for a piece — your name, your company, the context and brief you write, keywords, links and any photo reference — is sent to Anthropic so a draft can be produced.

Anthropic processes it on our instructions as our processor. Under its commercial API terms, submissions are not used to train its models.

No draft is published as it comes out. Every piece is reviewed by our editorial team and approved by you in the portal before it goes anywhere.

If you would prefer that your material is not processed this way, tell us at gianmarco@xraised.com before you send it and we will handle the piece manually.

10Where your data goes

We are based in the United Kingdom and our database is hosted for us by Railway. Some of our suppliers — including Stripe, Resend, Anthropic, Calendly and Asana — are established outside the UK, or process data outside it, mainly in the United States and the European Economic Area.

Where personal data leaves the UK we rely on the safeguards UK law recognises: an adequacy decision where one covers the country concerned, or the International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with the supplier's own technical and organisational measures.

You may ask us for details of the safeguard that applies to a particular supplier by writing to gianmarco@xraised.com.

11How long we keep it

We keep personal data only as long as the purpose it was collected for requires, and then delete it or make it anonymous. The periods below say what we keep and why.

WhatHow longWhy
Billing, invoices and accounting records6 years after the end of the accounting periodRequired by UK tax law
Client account and service historyFor the relationship, then 6 yearsThe limitation period for a contract claim in England and Wales
Material you supplied for a pieceFor the relationship, then 6 yearsKept with the work it belongs to, in case the piece is questioned
Internal team notes on an accountDeleted with the client recordThey have no purpose once the account is gone
Applications and orders that never completed12 monthsLong enough to answer a returning enquiry, no longer
Site member accountUntil you delete itIt is yours to keep or remove — deleting it takes one click in your account page, and takes effect immediately
Comments and their hashed IP12 months after the comment is removed or rejectedAbuse prevention only
Published articles and interviewsIndefinitely, while publicPublication is the service; see the note below

Site member accounts have no automatic expiry. Your account stays until you delete it, which you can do yourself at any time. We may remove accounts that have been inactive for a long time, but only after writing to you first and giving you the chance to keep it.

Published work is different. The point of what we do is that a piece appears publicly and stays there, so published articles, interviews and the credits on them remain online. Removing something already published is dealt with in our Terms & Conditions, and does not depend on this retention table.

Where we must keep a record for tax or legal reasons after you ask us to erase your data, we restrict it to that purpose alone and stop using it for anything else.

12Your rights

Under the UK GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you, including the internal notes on your account.
  • Rectification — have inaccurate data corrected, or incomplete data completed.
  • Erasure — have your data deleted where we no longer need it, subject to records we must keep by law.
  • Restriction — have us pause processing while a question about it is resolved.
  • Portability — receive the data you gave us in a common, machine-readable format, or have it sent to someone else.
  • Objection — object to processing we base on legitimate interests, and to direct marketing at any time, with no reason needed.
  • Withdraw consent — where we rely on it, at any time.

To exercise any of these, write to gianmarco@xraised.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity first — that is to protect your data, not to delay you.

Deleting a site member account yourself

If you registered as a site member you can delete your account immediately from your account page: it removes your registration and your saved watchlist straight away, with no request and no waiting.

Client accounts are tied to paid work and to records we must keep, so they are closed by writing to us; we will tell you exactly what is deleted and what has to be retained, and why.

Complaining

We would rather hear from you first, but you can complain to the UK's supervisory authority at any time: the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk, 0303 123 1113.

13How we protect it

  • The site and portal are served over HTTPS, and session cookies are signed, HttpOnly and Secure.
  • Passwords are stored only as bcrypt hashes; nobody at Xraised can read your password.
  • Card data never reaches our systems.
  • IP addresses are stored only as a salted, irreversible hash.
  • Access to client data is limited to the team members who need it, and the portal shows each client only their own work.
  • Files are held in private storage and served through short-lived, expiring links rather than public URLs.

No system is perfectly secure. If a breach were ever likely to put your rights at risk, we would tell the ICO within 72 hours and tell you without undue delay.

14Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, tell us and we will delete it.

15Data about other people

If you give us personal data about someone else — a colleague, an executive quoted in your article, a person in a photograph — you confirm that you may lawfully do so and that you have told them how it will be used, including that it will be published.

Tell them about this notice. If they contact us directly we will deal with them fairly and, where appropriate, refer them to you.

16Changes to this notice

We update this notice when what we do changes. The version shown here is always the current one, with its version number and date at the top of the page.

If a change materially affects how we use data we already hold, we will tell you by email before it takes effect.

↑ Back to top