Summary
We’re Mecha Site Ltd, a UK company that runs a platform for managing websites. This page explains every kind of data we hold, why we hold it, who we share it with, and the rights you have over it. Read on for detail, or jump to a section using the menu.
- We are the controller of data about you (our account holder) and a processor of data about visitors to the websites we manage on your behalf.
- We rely on five lawful bases: consent, contract, legal obligation, legitimate interest, and recognised legitimate interest under the UK Data (Use and Access) Act 2025.
- We do not sellyour data and we don’t use it for advertising profiling.
- You can access, correct, export, restrict, or erase your data at any time — see Section 10.
- You can complain to us at /legal/complaints (we respond within 30 days, statutory under DUAA §103) — and to the ICO at any time.
1. Who we are
Mecha Site Ltdis a company registered in England & Wales. Our trading name is “Mecha Site”. We act as the data controller for personal data about our account holders, and as a data processor for personal data flowing through the websites we manage.
We are not required to appoint a Data Protection Officer, and we have not appointed one — we have assessed this against the criteria in Article 37 and keep that assessment under review. Privacy questions, requests about your rights, and any concerns go to privacy@mechasite.com, which is monitored by our engineering leadership.
2. Our two roles — controller and processor
Mecha Site has two distinct relationships with personal data. This notice covers both. If you only want to know about one, jump straight to the relevant tab.
Section A · Data about YOU
Controller role
When you create a Mecha Site account or use the platform, we are the controller of your data. We decide what we collect, why, and how long we keep it. Sections 3-14 below cover this role.
Section B · Data about your VISITORS
Processor role
When a visitor uses a website we manage for you (fills a form, browses pages), we process that data on your behalf as a processor. You decide the purposes; we follow your instructions under our Data Processing Agreement. This notice does not describe what your visitors should expect from your website — that is your privacy notice, not ours.
3. Data we collect
We only collect what we need. The full list, kept up to date by our engineering team, lives in a public artefact at docs/pii-manifest.json on our source repository — auditors can read it directly.
Data you give us
- Name and work email address (required to create an account).
- Password hash (we never store the password itself).
- Multi-factor authentication secrets, encrypted at rest.
- Billing details for paid plans (handled by Stripe — we hold only customer ID and last 4 digits).
- Content of support tickets, complaints, and any free-text fields you submit.
Data we collect automatically
- Login events, IP address (truncated to a network range after 30 days), and user-agent for security and audit.
- Anonymous browser stableID for aggregate analytics on public pages (only if you accept the “Statistical” cookie category).
- Error reports from your browser if you accept the “Statistical” cookie category.
- Session-replay recordings only if you explicitly opt in to the “Marketing” cookie category. All text is masked and media is blocked by default.
Data from third parties
- If you sign in via Google, GitHub, or another OAuth provider we receive your name, email address, and a profile identifier from them.
- Stripe sends us subscription status changes via webhook (no card data).
4. Why we use it
- To run the platform you signed up for — keep you logged in, save your work, deliver the service.
- To bill you — process subscriptions and produce VAT-compliant invoices (HMRC requires us to keep these for 7 years).
- To keep the service secure — detect brute-force attempts, fraudulent accounts, and abuse.
- To improve the product — using aggregated, anonymous metrics; we never use your individual content for product analytics.
- To send service emails— password resets, security alerts, billing receipts. We don’t send marketing emails without your explicit consent.
- To respond to legal requests— when we’re legally required to (e.g., HMRC, court order).
5. Lawful bases for processing
We rely on five lawful bases under the UK GDPR + Data (Use and Access) Act 2025. We tell you below which one applies to which activity.
5a. Consent (Art. 6(1)(a))
Used for: marketing emails, session-replay recordings, personalised feature experiments. You can withdraw consent at any time using the cookie preferences link or by emailing privacy@mechasite.com. Withdrawal does not affect processing carried out before you withdrew.
5b. Contract (Art. 6(1)(b))
Used for: account creation, plan delivery, subscription billing, handling support tickets, providing the live editor and dashboard you signed up for. Without this data we cannot perform the contract.
This basis also covers our free website audit. If you ask us to audit your website, running that audit and emailing you the report are steps we take at your request before any contract exists — which is what the second half of this basis is for. We use the website address you give us to run the checks, and your name and email address to send you the result.
5c. Legal obligation (Art. 6(1)(c))
Used for: VAT-compliant invoice retention (HMRC, 7 years), responding to data-subject requests within statutory deadlines, breach notification to the ICO within 72 hours, complaints handling within 30 days under DUAA §103.
5d. Legitimate interest (Art. 6(1)(f))
Used for: protecting the service against fraud and abuse (our interest: keeping the platform and the sites we manage secure for every customer), basic error logging (our interest: finding and fixing faults quickly), network-level rate limiting (our interest: keeping the service available and resistant to automated attack), and aggregate engineering analytics (our interest: understanding how the product is used so we can improve it). Before we rely on this basis we consider what we are trying to achieve, whether the processing is genuinely necessary to achieve it, and how our interest weighs against your rights and freedoms — and we keep that reliance under review. Our interests do not automatically override yours: where the impact on you would outweigh our interest, we don’t use this basis. If you’d like more detail about the legitimate interests behind any of these activities, ask us at privacy@mechasite.com. You can object at any time — see Section 10.
Also used for: keeping your enquiry after we send you a free website audit (our interest: being able to follow up individually with someone who asked us to look at their website — if we told you your domain expires in eleven days, a person should be able to help you with that). This is a separate thing from the audit itself, which we run under Section 5b because you asked for it. We do not add you to a mailing list, and we do not sell or share your details with other marketers. Any contact is individual and from a person. You can object at any time and we will stop.
Also used for: keeping a record that you confirmed you were allowed to request that audit— the date, your IP address and your browser’s user-agent string (our interest: being able to evidence that a named person authorised us to scan a particular website, because scanning a website you have no permission to scan is a criminal matter under the Computer Misuse Act 1990). We never use that record for marketing.
5e. Recognised Legitimate Interest (Art. 6(1)(ea), DUAA Sch. 4)
The Data (Use and Access) Act 2025 creates a new lawful basis for a specific list of public-interest activities. We currently rely on this basis only for safeguarding-related disclosures (e.g., reporting credible threats of harm to relevant authorities). We do not use it for direct marketing, intra-group data sharing, or network security — where we carry out any of those, we rely on standard legitimate interest under Section 5d, including the balancing approach described there, and your right to object applies.
5f. DUAA-exempt categories with opt-out
DUAA exempts certain low-risk storage from prior consent — currently theme/appearance preferences and admin workflow state. We still tell you what these are (see /legal/cookies) and you can opt out at any time using the cookie preferences modal. EU/EEA visitors get the standard opt-in banner instead — we honour the strictest applicable regime.
6. Sub-processors and other third parties
We use a small number of sub-processors to deliver the service — hosting, email, error monitoring, payment processing. The full current list (vendor name, purpose, country) lives at /legal/sub-processors. You can subscribe to email notifications of changes there. We give at least 30 days’ notice before adding a new sub-processor that processes your data.
We have a Data Processing Agreement (or equivalent contractual terms) with every sub-processor that handles data on our instructions. We do not knowingly engage processors that do not meet our security baseline.
One company on that list is not a sub-processor, and we want to be straight about the difference. When you ask for a free website audit, we send the website address you gave us to Google(its PageSpeed Insights and Chrome UX Report tools). Google then visits and measures your website itself. It is not acting on our instructions and we have no data-processing contract with it — these are free public tools under Google's own terms, so in law it is a separate controller and we are simply telling you it receives the address. We send it the website address and nothing else: never your name, never your email, never anything belonging to one of our customers.
Two practical points. Because Google is not a sub-processor of your data here, the 30-day notice above does not apply to it. And because those tools are free and public, anyone at all can point them at any website without asking — so our running them tells the world nothing it could not already have found out in one click.
7. International transfers
Most of your data stays in the United Kingdom or European Economic Area. Where data does leave the UK, we rely on one of the following mechanisms per the destination cluster:
- UK adequacy decision — for transfers to countries the UK Government has assessed as offering adequate protection.
- UK Extension to the EU-US Data Privacy Framework — for transfers to certified US recipients.
- UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs — when the above are not available.
For each sub-processor we maintain a Transfer Risk Assessment documenting the destination country’s legal framework against the “not materially lower” standard introduced by DUAA. We review these annually or sooner if relevant law changes.
8. How long we keep your data
We keep different types of data for different periods:
- Account data — for as long as your account is active, plus 30 days after deletion (recovery window).
- Invoices — 7 years (HMRC). Pseudonymised after account deletion; only legal-name and total are retained.
- Consent records — 6 years (CNIL standard for demonstrability).
- Complaints + DSAR records — 6 years (ICO limitation period).
- Breach incident records — 7 years; affected- individual fields pseudonymised after 2 years.
- Security logs — 1 year (de-identified after that).
- Session replay recordings — 30 days.
- Webhook idempotency records — 1 year.
- Free website audit results — 90 days, then deleted. The report link we email you stops working after 30 days.
- Free website audit enquiries(your name, email and the address you asked us to check) — 2 years, or until you ask us to delete them. Deleting the audit results does not delete your enquiry, and deleting your enquiry does not delete anyone else’s report.
A scheduled job runs daily to purge data past its retention period. Each purge category has independent monitoring; a failed purge raises an internal alert and a tracked remediation ticket.
Backups
Deleting data from our live systems does not delete it from our backups at the same moment, and we think you should know that rather than discover it. Our platform database keeps a short point-in-time recovery history so we can recover from an outage or a mistake. When you delete your account, or we act on an erasure request, the data disappears from the live service immediately and then remains in that recovery history for up to 24 hours before it ages out permanently.
For as long as it persists there it is put beyond use: we do not access it, process it, or use it for any purpose. If we ever had to restore from a backup taken before your erasure, we keep a suppression record — which survives the restore precisely because it is stored separately — and we re-apply your erasure to the restored data before the service goes back into use.
This section describes ourplatform database. Data collected by a website we build and host for a client — that site’s customers, enquiries and orders — lives in that site’s own database, where the client is the data controller and we act on their instructions. That data is covered by that website’s privacy notice, and it has a longer backup window: up to 30 days.
9. Security
Our security details are at /legal/security. In summary: passwords are hashed with Argon2; secrets and CMS credentials are encrypted at rest with AES-256 (Fernet) using rotatable keys; all transport is TLS 1.3; we run multi-factor authentication on all admin accounts; access is least-privilege and audit-logged. We’re working towards SOC 2 Type II certification (target Q2 2027).
10. Your rights
Under UK GDPR and DUAA you have the right to:
- Access a copy of the personal data we hold about you (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erase your data, subject to our legal-obligation and audit retention (Art. 17).
- Restrict processing while we investigate a dispute (Art. 18).
- Port data you provided to us in machine-readable form (Art. 20). This includes your full consent decision history.
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent for any consent-based processing, at any time, without penalty.
- Not be subject to solely automated decisionswith legal or significant effects (Art. 22). We make no such decisions. One favourable-only automated step exists in our partner-storefront order intake: when a partner store’s customer has paid and their onboarding brief meets the configured conditions, our system confirms the order into the fulfilment queue automatically. It can only ever say yes early — declining, holding and all fulfilment work are done by people, and a person can review any automated confirmation.
Request these by emailing privacy@mechasite.com or via the in-app privacy controls (coming Phase 3 — currently by email only). We aim to respond within one calendar month, extending by two further months for complex requests with prior notice to you.
11. Complaints
If you believe we’ve mishandled your data, please tell us first so we can put it right.
To us: use the form at /legal/complaints or email privacy@mechasite.com. We will acknowledge within 30 calendar days as required by DUAA §103, and respond substantively as soon as we can.
To the regulator:you can also lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint at any time, whether or not you contact us first. EEA visitors can contact their national supervisory authority instead.
12. Children
Mecha Site is a B2B service intended for businesses managing their own websites. It is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has signed up, please contact privacy@mechasite.com and we will delete the account.
13. Changes to this notice
When we make a material change — for example a new processing purpose, a new sub-processor handling a new category of data, or a longer retention period — we’ll ask you to re-accept the notice the next time you sign in. We give a clear summary of what changed and why. Non-material changes (typos, reorganisation, clarifications) are recorded in the version history without re-acceptance.
You can always see the current version date at the top of this page. Past versions are kept on file and available on request.
14. Contact
- General privacy questions: privacy@mechasite.com
- Data Protection Officer: privacy@mechasite.com
- Complaints: /legal/complaints