DNG OPS Digital Negative Book a teardown
Legal · Instrument 01

Privacy Policy

Effective: 1 September 2026Issued by: DNG Ops, New Jersey, United States

This privacy policy describes the categories of personal information collected by DNG Ops in connection with the website located at dngops.com, the purposes for which that information is processed, the parties to whom it is disclosed, and the rights available to data subjects. It is issued in a formal register but is intended to be intelligible, as required by Article 12 of Regulation (EU) 2016/679.

1.Identity of the Controller

1.1DNG Ops, a creative operations firm having its principal place of business in the State of New Jersey, United States of America (the “Company”), is the controller in respect of the personal information described in this Policy.
1.2The Company may be contacted at grigori@dngops.com. The Company is not required to appoint a data protection officer and has not done so.

2.Scope of this Policy

2.1This Policy applies to the Site and to communications addressed to the Company through it. It does not apply to third-party websites accessible by hyperlink from the Site, which are governed by the policies of their respective operators.
2.2The Company collects a deliberately limited quantity of personal information. Where a processing operation is performed by a third party rather than by the Company, that fact is stated and the third party’s policy is cited in preference to a paraphrase thereof.

3.Information Collected via the Site

3.1The Site operates without user accounts, authentication, contact forms, or transactional functionality. It does not set advertising or tracking cookies and does not participate in any cross-site tracking, retargeting, or advertising identifier framework.
3.2Analytics. The Company employs Cloudflare Web Analytics, a measurement service which does not use cookies, does not fingerprint the browser or device, and does not construct a profile of, or track, any individual across websites. The categories of data recorded are:
  • (a)the uniform resource locator of the page requested and the referring address, if any;
  • (b)browser type, device type, and operating system;
  • (c)country of origin, derived from the internet protocol address and not stored in association with it; and
  • (d)page load performance timings.
3.3Such data is available to the Company in aggregate form only and cannot be used by the Company to identify any individual.
3.4Hosting. The Site is hosted upon Cloudflare Pages. In common with any hosting provider, Cloudflare processes internet protocol addresses in transit for the purposes of transmitting the requested content and of protecting the Site against attack and abuse. The Company neither receives nor retains a log of individual visitors.

4.Appointment Scheduling

4.1The scheduling function on the Site directs the user to an appointment page operated by Google LLC. Booking is effected by Google and not by the Site.
4.2In the course of booking, the user supplies to Google a name, an electronic mail address, and a response to the question posed by the Company concerning the user’s brand. Google verifies the electronic mail address for the purpose of preventing fraudulent and automated bookings and thereafter transmits those particulars to the Company.
4.3The Company processes those particulars solely in order to research the user’s advertising activity in advance of the appointment, to conduct the appointment, and to correspond thereafter where the user has requested that it do so. The Company does not enroll any person upon a mailing list and operates no automated marketing sequence.
4.4Google’s processing is governed by the Google Privacy Policy.

5.Correspondence

5.1Where a person addresses electronic mail to the Company, the message and the sender’s address are retained within the Company’s Google Workspace environment for the purposes of responding and of maintaining a record of matters discussed and agreed.

6.Client Advertising Accounts

6.1This Article applies exclusively to clients of the Company and not to visitors to the Site.
6.2Clients grant to the Company read-only partner access to their advertising accounts, ordinarily upon the Meta and TikTok platforms. The Company neither requests nor holds any client credential. Read-only access does not permit the Company to alter campaigns, budgets, or expenditure.
6.3The Company exercises such access for the sole purpose of ascertaining the performance of creative produced by it and of preparing the periodic report contracted for. The Company does not export, aggregate, resell, or benchmark client account data, and does not employ it to inform work undertaken for any other client.
6.4Access terminates upon conclusion of the engagement and may be revoked by the client at any time from the client’s own account settings without recourse to the Company.
6.5Data residing within a client’s advertising account remains the client’s and remains governed by the client’s agreement with the platform operator. The Company’s access constitutes inspection and not collection.

7.Purposes and Legal Bases of Processing

7.1Where Regulation (EU) 2016/679 or the United Kingdom General Data Protection Regulation applies, the Company relies upon the following legal bases:
  • (a)Legitimate interests (Article 6(1)(f)) in respect of aggregate analytics, the security of the Site, and correspondence with prospective clients, the Company’s interest being to understand demand for its services, to maintain the Site, and to respond to enquiries;
  • (b)Steps preparatory to a contract (Article 6(1)(b)) in respect of appointment bookings and of negotiations conducted with prospective clients;
  • (c)Performance of a contract (Article 6(1)(b)) in respect of the delivery of services and of reporting to clients; and
  • (d)Compliance with a legal obligation (Article 6(1)(c)) in respect of the retention of records required by tax and corporate law.
7.2The Company does not process special categories of personal data within the meaning of Article 9, and undertakes no automated decision-making producing legal or similarly significant effects within the meaning of Article 22.

8.Disclosure to Processors

8.1The Company discloses personal information to the following processors only, and this list is complete as at the Effective Date:
  • (a)Cloudflare, Inc. — hosting of the Site and provision of analytics; and
  • (b)Google LLC — electronic mail, appointment scheduling, and telephony.

The company does not sell personal information, has never sold personal information, and does not share personal information for cross-context behavioral advertising. The company does not disclose personal information to any party otherwise than as stated in this article, save where compelled by law or by valid legal process.

9.International Transfers

9.1The Company is established in the United States and processes personal information there. Where personal information is transferred from the European Economic Area or the United Kingdom, such transfer is effected upon the basis of the standard contractual clauses or other appropriate safeguards operated by the processors identified in Article 8.

10.Retention

10.1Personal information is retained for the following periods:
  • (a)Analytics: in aggregate form only, upon the retention schedule operated by Cloudflare. No such data identifies an individual;
  • (b)Booking particulars and correspondence: for the duration of the enquiry and for a period not exceeding two (2) years thereafter, for the purpose of maintaining a record; and
  • (c)Client records: for the duration of the engagement and thereafter for such period as tax, corporate, and limitation law requires.
10.2A data subject may request earlier erasure of an enquiry, which request the Company shall honor save where retention is required by law.

11.Rights of Data Subjects

11.1Subject to the conditions and exemptions provided by applicable law, a data subject has the right to request access to, rectification of, or erasure of personal information concerning them; to request restriction of or to object to processing; to request portability; and, where processing is founded upon consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
11.2The Company acknowledges that by reason of its size and turnover it falls below the statutory thresholds at which several of these obligations would bind it. The Company undertakes to honor such requests notwithstanding.
11.3Requests should be addressed to grigori@dngops.com and will be answered within thirty (30) days. No fee is charged and no data subject will be subjected to discriminatory treatment by reason of having made a request.
11.4A data subject in the European Economic Area or the United Kingdom has the further right to lodge a complaint with their national supervisory authority.

12.Notice to California Residents

12.1Under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, a California resident has the rights to know, to delete, to correct, to opt out of sale or sharing, and to limit the use of sensitive personal information.
12.2The categories of personal information collected are identifiers (name and electronic mail address, supplied voluntarily) and internet activity information (aggregate analytics). The Company collects no sensitive personal information within the meaning of the statute.
12.3The Company does not sell or share personal information, and accordingly no “Do Not Sell or Share My Personal Information” mechanism is required. Requests may be made by the means stated in Clause 11.3.

13.Children

13.1The Site is directed to businesses and is not directed to children. The Company does not knowingly collect personal information from any person under the age of sixteen (16). Where the Company becomes aware that it has done so, it shall erase that information without undue delay.

14.Security

14.1The Company maintains technical and organizational measures appropriate to the limited nature of its processing, including transport layer encryption across the Site, multi-factor authentication upon its Google Workspace tenancy, and the principle of least privilege in respect of access to client advertising accounts.
14.2No method of transmission or storage is wholly secure, and the Company does not warrant absolute security.

15.Amendment of this Policy

15.1The Company may amend this Policy from time to time. Any amendment shall take effect upon publication upon the Site and the Effective Date shall be updated accordingly. Material amendments shall be summarized upon this page rather than incorporated without notice.

16.Contact

16.1Enquiries concerning this Policy, and requests in respect of personal information, should be addressed to DNG Ops at grigori@dngops.com or by telephone to (609) 200-1769 during the hours of 11:00 to 13:00 and 16:00 to 18:00 Eastern Time on business days.

This instrument is published by DNG Ops and takes effect on the Effective Date stated above. It supersedes all previous versions. © 2026 DNG Ops. All rights reserved.