Privacy Notice
Last updated: 18 September 2026
This Privacy Notice explains how Why Go Digital Ltd collects, uses, stores and protects personal information when you visit the InsYte website, create an InsYte business account, use the InsYte web application, purchase Credits, connect third-party platforms, use Ask InsYte, receive InsYte Directions, audits, scores and reports, use InsYte's learning and measurement functionality, or contact us for support or other purposes.
Please read this Privacy Notice carefully.
1. Who we are
InsYte is a trading name of Why Go Digital Ltd.
InsYte is operated by:
- Why Go Digital Ltd
- 1 Brookside
- Orwell
- Royston
- SG8 5TQ
- United Kingdom
Company number: 09085173
Email: admin@insyte.info
Website: https://insyte.info
Web application: https://app.insyte.info
For the purposes of UK data protection law, Why Go Digital Ltd may act as:
- a DATA CONTROLLER for personal information we determine how and why to use; and
- a DATA PROCESSOR where we process personal information on behalf of an InsYte business customer under that customer's instructions.
The exact role depends upon the processing activity.
2. About InsYte
InsYte is an AI-assisted business intelligence and digital performance platform.
InsYte is designed to help businesses improve areas including:
- SEO performance;
- search visibility;
- AI search visibility;
- website performance;
- site health;
- digital performance;
- advertising performance;
- e-commerce performance;
- local visibility;
- content performance;
- competitor understanding;
- email and social performance.
InsYte may bring together information from different sources in order to LEARN, ASSIMILATE and DIRECT, and, where appropriate, MEASURE RESULTS and LEARN FROM WHAT HAPPENS NEXT.
3. Personal information we may collect
Depending on how you use InsYte, we may collect the following categories of personal information.
A. ACCOUNT INFORMATION. This may include:
- first name;
- last name;
- business name;
- business sector;
- business address;
- address line 1;
- address line 2;
- town/city;
- county;
- country;
- postcode;
- business email address;
- username;
- account number;
- activation status;
- account role;
- login and authentication information.
We do not need to know or view your password. Passwords are stored using appropriate secure password hashing and authentication controls.
B. BUSINESS PROFILE INFORMATION. This may include:
- business type;
- industry;
- website address;
- products;
- services;
- locations;
- brands;
- categories;
- primary business objectives;
- conversion types;
- competitor information;
- business settings;
- account preferences.
Some business information may not itself be personal data. However, it may become personal data where it identifies or relates to an individual, sole trader, employee, customer or other identifiable person.
C. CONTACT AND COMMUNICATION INFORMATION. This may include:
- email correspondence;
- support requests;
- customer-service messages;
- feedback;
- account enquiries;
- marketing preferences;
- communications relating to billing or service operation.
D. PAYMENT AND BILLING INFORMATION. This may include:
- billing name;
- billing address;
- transaction amount;
- Credits purchased;
- payment status;
- payment reference;
- invoice information;
- refund information;
- transaction history.
Payment card details are handled by the payment provider and are not stored by InsYte.
E. CREDIT INFORMATION. This may include:
- Credit balance;
- Credits purchased;
- Credits used;
- date/time of Credit transactions;
- InsYte function for which Credits were used;
- Credit adjustments;
- refunds;
- administrative Credit changes.
F. TECHNICAL INFORMATION. We may collect information such as:
- IP address;
- browser type;
- device information;
- operating system;
- login activity;
- security events;
- session information;
- application errors;
- diagnostic information;
- access logs;
- audit logs.
G. WEBSITE AND APP USAGE INFORMATION. This may include information about:
- pages viewed;
- features used;
- actions performed;
- Directions viewed;
- audits run;
- Ask InsYte usage;
- integration status;
- Weekly Brief usage;
- account activity;
- Credit usage;
- interactions with InsYte.
H. CONNECTED PLATFORM INFORMATION. If you connect authorised third-party services to InsYte, we may process information obtained through those services. Depending on the integration this may include information from:
- Google Analytics;
- Google Search Console;
- Google Ads;
- Google Business Profile;
- Google Merchant services;
- email platforms;
- social platforms;
- website systems;
- e-commerce platforms;
- advertising platforms;
- other supported services.
The exact information depends upon the service connected, the permissions you grant, the information available through that service and your InsYte settings.
I. WEBSITE AND SEO INFORMATION. InsYte may analyse information such as:
- website URLs;
- page titles;
- meta descriptions;
- headings;
- website structure;
- internal links;
- broken links;
- technical SEO findings;
- indexability;
- crawlability;
- content structure;
- structured information;
- page-performance information;
- product/service information.
Much of this information may be publicly available and may not be personal data. However, personal information contained on websites may be processed where relevant to the service.
J. ANALYTICS AND PERFORMANCE INFORMATION. Depending on your integrations, this may include:
- traffic;
- search impressions;
- search clicks;
- click-through rates;
- landing-page performance;
- conversions;
- enquiries;
- calls;
- purchases;
- revenue;
- website behaviour;
- campaign performance;
- product/category performance;
- location performance.
Where these relate to identifiable individuals, they may constitute personal data.
K. COMPETITOR INFORMATION. InsYte may process legitimate publicly available or licensed information about businesses selected or identified for competitor analysis. This may include:
- business names;
- domains;
- public pages;
- services;
- products;
- categories;
- public content;
- public search visibility;
- public business information;
- public changes to websites.
We do not seek to obtain a competitor's private analytics, internal sales data or confidential information without lawful authority.
L. DIRECTIONS AND FINDINGS. We may store:
- InsYte findings;
- recommendations;
- Directions;
- priority;
- impact estimates;
- confidence;
- supporting evidence;
- action status;
- dates;
- related business areas.
M. CUSTOMER ACTION INFORMATION. Where you act upon an InsYte Direction, we may record:
- the Direction;
- whether it was accepted;
- whether action was taken;
- the action date;
- information you provide about the action;
- the relevant page/product/service;
- measurement status.
N. LEARNING AND OUTCOME INFORMATION. Where InsYte measures the result of a customer action, we may process:
- baseline performance;
- subsequent performance;
- measured outcomes;
- associated signals;
- confidence;
- confounding factors;
- learning records;
- historical recommendations;
- customer-specific patterns.
This information is used to improve the relevance of future InsYte analysis for the customer where the service supports this.
O. APPROVED ACTION INFORMATION. Where InsYte supports customer-approved execution, we may process:
- proposed changes;
- approved changes;
- approval date/time;
- approving user;
- execution status;
- platform affected;
- verification result;
- rollback information;
- action history.
4. Information we do not intend to collect
InsYte is a business service.
We do not intentionally require customers to provide special category personal data such as:
- health information;
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic information;
- biometric information used for identification;
- information concerning sex life or sexual orientation.
Customers should avoid uploading or connecting unnecessary special category data to InsYte.
If a particular integration or use case requires processing of sensitive information, this must be assessed separately before use.
5. How we collect information
We may obtain information:
- DIRECTLY FROM YOU, for example when you register, purchase Credits, contact us, configure your business, ask InsYte questions or mark actions as completed;
- FROM CONNECTED SERVICES, where you authorise InsYte to access an external platform;
- FROM YOUR BUSINESS WEBSITE, through permitted website analysis or crawling;
- FROM PUBLIC SOURCES, where competitor or market information is lawfully publicly available;
- AUTOMATICALLY, through technical logs, security monitoring and permitted cookies or similar technologies.
6. Why we use personal information
We may use personal information for the following purposes.
A. PROVIDING THE INSYTE SERVICE, including:
- creating Accounts;
- authenticating users;
- activating Accounts;
- operating dashboards;
- providing Directions;
- providing scores;
- running audits;
- providing Ask InsYte;
- providing Weekly Briefs;
- managing integrations;
- storing customer settings.
B. LEARNING ABOUT THE CUSTOMER'S BUSINESS. Where supported, InsYte may use relevant history to:
- establish baselines;
- identify patterns;
- understand business performance;
- compare periods;
- understand customer objectives;
- improve future Directions.
C. ASSIMILATING CONNECTED INFORMATION. InsYte may bring relevant information together to identify:
- relationships;
- issues;
- opportunities;
- performance changes;
- potential causes;
- areas requiring attention.
D. PROVIDING DIRECTIONS. We use information to generate:
- findings;
- recommendations;
- priorities;
- potential impact;
- effort;
- confidence;
- suggested next actions.
E. MEASURING RESULTS. Where applicable, we may compare performance before and after a customer action. This helps InsYte identify whether the available evidence suggests a positive change, a negative change, a mixed result, no material change, or an inconclusive result.
F. IMPROVING CUSTOMER-SPECIFIC DIRECTION. Where the service supports outcome-based learning, we may use previous Directions, actions and measured results as context for future analysis.
G. BILLING AND CREDITS, including:
- processing purchases;
- allocating Credits;
- deducting Credits;
- maintaining Credit ledgers;
- issuing invoices;
- handling refunds;
- preventing duplicate charges.
H. SECURITY AND FRAUD PREVENTION, including:
- protecting Accounts;
- detecting suspicious activity;
- protecting integrations;
- maintaining audit logs;
- investigating abuse;
- preventing fraud.
I. SUPPORT, including responding to support requests, diagnosing technical issues, assisting customers and resolving billing queries.
J. SERVICE IMPROVEMENT. We may use appropriate service and technical information to understand how InsYte is used, identify errors, improve reliability, improve user experience and develop new functionality.
K. LEGAL AND REGULATORY COMPLIANCE, including accounting, tax, regulatory obligations, responding to lawful requests and protecting legal rights.
L. MARKETING. Where permitted, we may use contact information to communicate with customers and prospective customers about InsYte, service updates, relevant products, events, offers and business information. Marketing communications will comply with applicable data protection and electronic marketing requirements.
7. Our lawful bases
We must have a lawful basis under UK data protection law when we process personal data. Depending on the processing activity, we may rely on:
CONTRACT, where processing is necessary to:
- create and administer your Account;
- provide InsYte;
- process Credit purchases;
- deliver requested services;
- provide customer support;
- perform agreed customer actions.
LEGITIMATE INTERESTS, where necessary for legitimate business purposes such as:
- operating and improving InsYte;
- maintaining security;
- preventing fraud;
- understanding service usage;
- protecting our rights;
- appropriate B2B communications;
- improving service reliability.
Where we rely on legitimate interests, we consider whether our interests are overridden by the rights and interests of the individual.
LEGAL OBLIGATION, where information must be processed to comply with legal obligations, for example accounting, taxation, regulatory requirements and lawful requests.
CONSENT, where consent is the appropriate lawful basis, including certain optional marketing activities, non-essential cookies, optional tracking technologies and other processing where consent is specifically requested.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing lawfully carried out before the withdrawal.
8. Business customer data — controller and processor roles
For some information, Why Go Digital Ltd determines how and why the information is used. In those circumstances, Why Go Digital Ltd acts as CONTROLLER.
For some information connected by a business customer, the customer may determine the purpose of processing and Why Go Digital Ltd may process the information only to provide the InsYte service. In those circumstances, the CUSTOMER may be the CONTROLLER and Why Go Digital Ltd may be the PROCESSOR.
Where legally required, a separate Data Processing Agreement may apply.
9. AI processing
InsYte uses AI-assisted systems to analyse relevant business information and generate findings, explanations and Directions.
Information sent to an AI service is limited to information reasonably necessary for the relevant InsYte function.
We will take reasonable steps to:
- minimise unnecessary personal information;
- protect customer information;
- use appropriate service providers;
- configure services appropriately;
- apply contractual safeguards where required.
The exact AI providers used may change over time. Where required, current subprocessors and providers will be identified in a subprocessor list or similar transparency page.
10. Automated decision-making
InsYte provides automated analysis and recommendations. However, InsYte is designed primarily as a decision-support system for business users.
InsYte Directions do not normally make legal or similarly significant decisions about individuals.
Customers remain responsible for reviewing business Directions before acting upon them.
Where InsYte supports customer-approved execution, external actions require customer approval before execution.
If InsYte introduces processing involving solely automated decisions that produce legal or similarly significant effects on individuals, we will assess the applicable legal requirements and update this Privacy Notice where required.
11. Who we may share information with
We may share personal information with categories of recipients where necessary to operate InsYte. These may include:
- CLOUD HOSTING PROVIDERS, for hosting the application, database and infrastructure;
- AUTHENTICATION PROVIDERS, where used to manage secure login and account access;
- PAYMENT PROVIDERS, to process Credit purchases, refunds and billing;
- AI SERVICE PROVIDERS, where necessary to provide AI-assisted InsYte functionality;
- ANALYTICS AND MONITORING PROVIDERS, where used to operate, secure and improve the service;
- EMAIL AND COMMUNICATION PROVIDERS, for transactional messages, account notifications and authorised communications;
- INTEGRATION PROVIDERS, where required to connect services authorised by the customer;
- PROFESSIONAL ADVISERS, including accountants, auditors, lawyers or insurers where reasonably necessary;
- REGULATORS, AUTHORITIES OR COURTS, where disclosure is legally required;
- BUSINESS SUCCESSORS, where Why Go Digital Ltd or InsYte is involved in a legitimate merger, sale, restructuring or transfer of business or assets, subject to appropriate safeguards.
12. Subprocessors
Where Why Go Digital Ltd acts as processor, we may use subprocessors to help provide InsYte.
Where required, customers will be provided with information about relevant subprocessors.
A current InsYte subprocessor list identifying material service providers involved in processing customer-controlled personal data is available on request using the contact details in this Privacy Notice.
13. International transfers
Some service providers may process personal information outside the United Kingdom.
Where personal information is transferred internationally, we will take appropriate steps required by UK data protection law. Depending on the destination and provider, this may include reliance upon:
- UK adequacy regulations; or
- appropriate safeguards such as an approved International Data Transfer Agreement or Addendum; or
- another lawful transfer mechanism.
Where appropriate, additional transfer-risk assessments or equivalent data-protection assessments will be carried out.
Information on applicable transfer safeguards may be requested using the contact details in this Privacy Notice.
14. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, contractual and security requirements.
Different categories may have different retention periods.
ACCOUNT INFORMATION is normally retained while the Account is active and for an appropriate period after closure where required for legal, security, accounting or contractual purposes.
PAYMENT AND ACCOUNTING RECORDS are retained as required for applicable accounting, taxation and legal obligations.
DIRECTIONS, SCORES, AUDITS AND LEARNING HISTORY may be retained while the Account remains active so that InsYte can provide historical comparison and customer-specific learning.
TECHNICAL AND SECURITY LOGS are retained for an appropriate period based on security, operational and legal requirements.
SUPPORT INFORMATION is retained for an appropriate period to resolve enquiries and maintain a service history.
MARKETING INFORMATION is retained until consent is withdrawn, an objection is made, or the information is otherwise no longer required, subject to maintaining appropriate suppression records where necessary.
An internal data retention schedule records the actual retention periods used by InsYte and is available on request.
15. Account closure
Customers may request closure of an InsYte Account.
Account closure does not necessarily mean that every item of information can be deleted immediately. We may retain information where necessary for:
- legal obligations;
- accounting;
- fraud prevention;
- security;
- resolving disputes;
- establishing or defending legal claims;
- appropriate data suppression.
Information no longer required will be deleted, anonymised or otherwise handled in accordance with applicable retention requirements.
16. Customer-specific learning
Where InsYte stores customer-specific learning, that information is used primarily to improve the service for the relevant customer. This may include:
- previous Directions;
- actions;
- outcomes;
- historical patterns;
- data maturity;
- customer-specific findings.
We will not intentionally expose one customer's confidential learning or performance information to another customer.
17. Cross-customer learning
InsYte may in future use appropriately aggregated or de-identified information to improve methodologies or service performance.
Any such use must be designed to prevent another customer from accessing identifiable confidential business information.
We will not use one customer's identifiable confidential business information as another customer's data source.
Where any future model-training activity materially changes how customer data is used, this Privacy Notice and associated contractual documentation will be reviewed before implementation.
18. Security
We use appropriate technical and organisational measures designed to protect personal information. These may include:
- access controls;
- secure authentication;
- password hashing;
- encryption where appropriate;
- tenant/account isolation;
- secure infrastructure;
- audit logging;
- restricted administrative access;
- secure API handling;
- monitoring;
- backup and recovery controls;
- software maintenance.
No system connected to the internet can be guaranteed completely secure.
19. Customer passwords
Passwords are stored using secure password hashing.
Why Go Digital Ltd staff cannot retrieve a customer's plain-text password.
Customers must protect their login credentials and notify us if they believe an Account has been compromised.
20. Third-party connection tokens
Where InsYte requires tokens or credentials to connect authorised third-party services, those credentials are stored and handled securely.
Sensitive integration credentials are not exposed through the customer interface or normal application logs.
21. Administrative access
Authorised InsYte administrators may access customer Account information where reasonably necessary for:
- support;
- billing;
- security;
- account administration;
- troubleshooting;
- compliance.
Administrative access is permission-controlled, limited to authorised personnel and logged where appropriate.
InsYte administrators do not need access to a customer's password.
22. Cookies and similar technologies
The InsYte website and web application may use cookies and similar technologies.
STRICTLY NECESSARY COOKIES may be required for login, security, sessions, account functionality and application operation.
InsYte currently uses strictly necessary cookies only. We do not currently use advertising, profiling or third-party marketing cookies.
ANALYTICS OR OTHER NON-ESSENTIAL COOKIES will not be placed before the user has provided the required consent, where consent is required by law.
If non-essential cookies are introduced, users will be provided with appropriate controls to ACCEPT, REJECT or MANAGE them, together with a separate cookie policy.
23. Marketing communications
We may send service-related communications necessary to operate an Account. These are different from marketing communications.
Where required, marketing messages will only be sent where there is an appropriate lawful basis and applicable electronic-marketing rules are satisfied.
Marketing communications include an appropriate method to unsubscribe or object.
Opting out of marketing will not prevent necessary service messages such as:
- account notifications;
- security notices;
- Credit/payment information;
- service changes;
- Weekly Brief availability where treated as part of the requested service.
24. Your data protection rights
Depending upon the circumstances and lawful basis, individuals may have rights including:
- RIGHT TO BE INFORMED — to receive information about how personal data is used;
- RIGHT OF ACCESS — to request a copy of personal information held about you;
- RIGHT TO RECTIFICATION — to request correction of inaccurate or incomplete personal information;
- RIGHT TO ERASURE — to request deletion of personal information in certain circumstances;
- RIGHT TO RESTRICT PROCESSING — to request restriction of processing in certain circumstances;
- RIGHT TO DATA PORTABILITY — to receive certain personal information in a portable form where the right applies;
- RIGHT TO OBJECT — to object to certain processing, including certain processing based on legitimate interests;
- RIGHT TO OBJECT TO DIRECT MARKETING — you may object to the use of your personal data for direct marketing;
- RIGHT TO WITHDRAW CONSENT — where processing relies upon consent, you may withdraw that consent at any time;
- RIGHTS RELATING TO AUTOMATED DECISION-MAKING — you may have rights in relation to certain solely automated decisions that produce legal or similarly significant effects.
These rights are not absolute and may depend upon the circumstances and the lawful basis being used.
25. Your right to object
You have the right to object to the processing of your personal data in certain circumstances.
In particular, you have the right to object at any time to the use of your personal data for direct marketing.
To exercise this right contact: admin@insyte.info
26. Making a data protection request
To exercise a data protection right, contact admin@insyte.info or write to:
- Why Go Digital Ltd
- 1 Brookside
- Orwell
- Royston
- SG8 5TQ
- United Kingdom
We may need to verify your identity before responding.
We will respond within the timescale required by applicable data protection law.
27. Business customer requests involving their data
Where Why Go Digital Ltd acts as a processor on behalf of a business customer, requests concerning personal data controlled by that customer may need to be handled by the customer as controller.
Where appropriate, we will provide reasonable assistance to the customer in responding to data protection requests in accordance with applicable contractual and legal obligations.
28. Complaints
If you have concerns about how we use personal information, please contact us first so that we can investigate.
You also have the right to complain to the UK data protection regulator:
- Information Commissioner's Office (ICO)
- Website: https://ico.org.uk
Nothing in this Privacy Notice affects your right to make a complaint to the ICO.
29. Children
InsYte is a business service and is not intended for children.
Customers must not knowingly create InsYte user Accounts for children unless such use has been expressly approved and assessed as lawful and appropriate.
If we become aware that personal information relating to a child has been provided inappropriately, we will take appropriate steps.
30. Links to third-party websites
The InsYte website or application may contain links to third-party websites or services.
Those third parties have their own privacy practices.
Why Go Digital Ltd is not responsible for the privacy practices of a third-party service solely because InsYte links to it.
31. Changes to this Privacy Notice
We may update this Privacy Notice when:
- InsYte changes;
- new integrations are introduced;
- processing activities change;
- service providers change;
- legal requirements change.
The latest version will be published on the InsYte website and web application.
Where a material change affects existing customers, we will provide appropriate notice where required.
32. Contact us
For privacy questions, requests or concerns contact:
- Why Go Digital Ltd
- 1 Brookside
- Orwell
- Royston
- SG8 5TQ
- United Kingdom
Email: admin@insyte.info
