Legal
Privacy Policy
The short version: we ask for a name, an email address and a few details about your project, we use them to reply to you, and we do not sell them or hand them to advertisers. This site sets no advertising or analytics cookies at all.
- Effective
- September 1, 2026
- Last updated
- September 1, 2026
- Issued by
- Mage Digital LLC
01 Summary
This page explains, in plain terms, what MAGE does with personal information. The detail follows, but the substance is this:
- What we collect: what you type into our waitlist form, what you send us by email, and the standard technical log our web server writes for every request.
- Why: to answer your enquiry, to deliver work you have engaged us for, to keep records the law requires, and to keep the site secure.
- Who else sees it: only the small number of service providers that host our website and carry our email, and only to the extent needed to run those services.
- What we never do: sell or rent your information, share it with advertisers or data brokers, use it to train machine-learning models, or run behavioural advertising or third-party analytics on this website.
- How long: 24 months for enquiries that do not become projects, longer only where accounting or tax law requires it.
- Your call: ask us to show, correct or delete your record at privacy@magedigitalagency.com and we will act within 30 days, free of charge.
02 Who is responsible for your information
The data controller is Mage Digital LLC, a New Mexico Limited Liability Company trading as MAGE.
- Registered office: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States
- Privacy contact: privacy@magedigitalagency.com
- General contact: hello@magedigitalagency.com
This policy covers magedigitalagency.com and the professional services we provide from it. It does not cover any third-party website you reach from a link here; those have their own policies.
Where we design or build a website or product for a client, that client is the controller of data collected through their own systems, and we act on their instructions. This policy is about our own site and our own client relationships.
03 What we collect, and why
Information you give us on the waitlist form
- Required: full name, work email address, the type of work you need, and a budget range. Without these we cannot reply usefully.
- Optional: company name, current website, and a short description of your project.
- Consent record: the fact that you checked the consent box, and the date and time of submission.
We use this to reply to you, to prepare for an introduction call, and to keep an accurate record of your enquiry.
Information you send us directly
Email, documents, briefs, credentials and anything else you choose to send while we discuss or carry out work. We use it only to do the job you asked for.
Client and billing records
If you become a client, we hold the signed statement of work, invoices, the billing contact details on them, and the correspondence relating to the engagement. Card and bank details are handled by our payment provider or your bank; we never see or store full payment card numbers, and this website takes no payments.
Technical logs
Our web server records the usual request information: IP address, timestamp, requested URL, HTTP status, referring page and browser user-agent string. This is standard for every web server and we use it only for security, abuse prevention and diagnosing faults. Where we store an identifier alongside a waitlist entry, we store a one-way hash of the IP address rather than the address itself.
What we deliberately do not collect
We do not ask for, and you should not send us, Social Security or national identification numbers, driver's licence numbers, full financial account or card numbers, precise geolocation, biometric data, health information, or information about racial or ethnic origin, religion, political opinions, trade-union membership, sexual orientation or criminal history. We do not knowingly collect anything from children (see section 12), and we do not buy personal information from data brokers or scrape it from third-party platforms.
04 Cookies and tracking
This website uses one cookie, and only when you interact with the waitlist form:
mage_session— a strictly necessary session cookie that holds an anonymous session identifier so we can protect the form against cross-site request forgery and rate-limit abuse. It contains no personal information, is not readable by JavaScript, and expires when you close your browser.
There is no advertising cookie, no remarketing pixel, no social media tracker, no session-recording script, no heatmap tool and no third-party analytics on this site. We do not build advertising profiles and we do not participate in cross-context behavioural advertising, so there is nothing here to opt out of.
Two third-party services are requested by the page for rendering: a web font stylesheet and a CSS framework file, each loaded from its provider's content delivery network. Your browser necessarily discloses its IP address to those providers in order to fetch the file, exactly as it would for any image on any website. We do not send them any personal information and they set no cookies on our behalf.
We honour the Global Privacy Control signal and browser Do-Not-Track headers by
default, in the sense that there is no tracking to disable.
05 Our lawful bases for processing
Where the EU or UK General Data Protection Regulation applies, we rely on:
- Consent — for the waitlist form. You give it by checking the box, and you can withdraw it at any time by emailing us, which does not affect processing already carried out.
- Contract — to negotiate, perform and administer an engagement you have entered into with us.
- Legal obligation — to keep accounting, tax and contractual records.
- Legitimate interests — to secure our website, prevent abuse and fraud, and defend legal claims. We have weighed these against your rights and use the least intrusive method available, which is why our logs are minimal and our identifiers are hashed.
We do not carry out automated decision-making or profiling that produces legal effects for you.
06 Who we share information with
We do not sell, rent, trade or otherwise disclose personal information for money or for anything else of value, and we never have. We do not share it for advertising purposes.
We use a deliberately small set of service providers, each bound by a written agreement to process data only on our instructions and to keep it confidential:
- Web hosting — stores the site and the file containing waitlist submissions.
- Business email — carries our correspondence with you.
- Accounting and payment processing — for client invoices, where a client relationship exists. These providers receive billing details only, never project content.
Beyond that, we disclose information only where we must: to comply with a valid legal obligation or lawful request, to enforce our Terms of Service, to protect the rights, property or safety of any person, or to a successor entity if our business is transferred, in which case this policy continues to apply to information already collected.
We do not use your personal information, your project files or your content to train machine-learning or artificial-intelligence models, and we do not licence it to anyone who does.
07 How we protect information
Our safeguards are proportionate to what we hold, which is deliberately little:
- the entire site is served over HTTPS with strict transport security;
- waitlist submissions are written to a location outside the public web root's reach and are blocked from direct download at the web-server level;
- the form is protected by an anti-forgery token, rate limiting and automated-submission checks;
- access to stored enquiries is limited to the people who need it, on devices with full-disk encryption and multi-factor authentication on every account;
- credentials clients give us are held in an encrypted password manager and removed at the end of the engagement.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information, we will notify you and any regulator required, without undue delay and in any event within 72 hours of becoming aware where the law sets that deadline, and we will tell you what happened and what to do about it.
08 How long we keep it
- Waitlist entries that do not become projects: 24 months from your last contact with us, then deleted.
- Correspondence: 24 months, unless it relates to a signed engagement.
- Client contracts, invoices and accounting records: seven years, as United States federal and New Mexico tax and record-keeping rules require.
- Project files and deliverables: up to three years after completion so we can support the work, then archived or deleted at your instruction.
- Server access logs: up to 90 days.
You can ask us to delete your information sooner, and we will, except for records we are legally required to keep. In that case we tell you exactly what we are retaining and why.
09 Your rights and how to use them
Wherever you live, we will honour the following requests:
- Access — a copy of the personal information we hold about you.
- Correction — fix anything inaccurate or incomplete.
- Deletion — erase your record, subject to legal retention duties.
- Portability — receive your data in a structured, machine-readable format.
- Restriction and objection — ask us to pause or stop a particular use.
- Withdraw consent — at any time, for anything based on consent.
- Non-retaliation — we will never degrade our service or change our prices because you exercised a privacy right.
Email privacy@magedigitalagency.com from the address you gave us, or tell us enough for us to locate your record. We respond within 30 days and may extend once by a further 45 days for a complex request, telling you before we do. There is no charge. We verify identity using the email address on file, and we ask for no extra personal information to do it. An authorised agent may act for you with written permission we can verify.
If you are unhappy with our answer, you may complain to your supervisory authority: in the EU or UK your national data protection authority, or in the United States your state Attorney General. We would rather you came to us first.
10 Notice for California residents
This section is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
Categories of personal information we collect: identifiers (name, email address, company name, website address, hashed IP address); commercial information (the type of work and budget range you indicate, and, for clients, transaction records); internet or network activity (standard server log entries); and professional or employment-related information you choose to give us about your role.
Sources: directly from you, and automatically from your browser when you load a page.
Business purposes: responding to your enquiry, performing a contract, security and fraud prevention, and legal compliance.
Sensitive personal information: we do not collect it.
Sale or sharing: in the twelve months before the date of this policy we have not sold personal information and have not shared it for cross-context behavioural advertising. We do not do either, so no opt-out mechanism is required.
Financial incentives: we offer none in exchange for personal information.
Your California rights: to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and to be free from retaliation. Use the contact route in section 9. We do not need to charge you and we will not treat you differently.
11 International visitors and transfers
We operate from the United States and our service providers store data in the United States. If you contact us from outside the United States, your information is transferred to and processed there, where privacy law differs from your own.
Where the GDPR applies to a transfer, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with the technical measures in section 7. By submitting the form you understand that this transfer is necessary for us to reply to you.
We do not currently have an EU or UK establishment or representative. If that changes, this section will be updated with the representative's details.
12 Children's privacy
Our services are sold to businesses and this website is not directed to children. We do not knowingly collect personal information from anyone under 16, and we do not create content or products aimed at children.
If you believe a child has submitted information to us, email privacy@magedigitalagency.com and we will delete the record promptly and confirm that we have done so.
13 Changes to this policy
If our practices change, we update this page and change the effective date at the top. This version is effective September 1, 2026.
For a material change, such as a new category of data or a new purpose, we will give notice at least 14 days in advance by email to anyone whose information we currently hold, and where the law requires consent we will ask for it again rather than assume it.
14 Contact us about privacy
- Email: privacy@magedigitalagency.com
- Post: Mage Digital LLC, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States
Write in English if you can, tell us which right you want to use, and we will confirm receipt and give you a timeline. A person reads that inbox.
Related documents
Questions about this document? Write to legal@magedigitalagency.com. Postal notices go to Mage Digital LLC, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States.