Legal

Privacy notice

How MPH MEDIA & TECH LTD handles personal data under the UK General Data Protection Regulation and the Data Protection Act 2018.

Last updated: 27 August 2026 · Data controller: MPH MEDIA & TECH LTD, company number 17172873, 8 Mildmays, Danbury, Chelmsford, Essex, CM3 4DP, United Kingdom · Contact: support@mphmedia.pro

1. Summary

This website collects nothing. It sets no cookies, runs no analytics, embeds no tracking pixels and contains no forms. If you never contact us, we hold no personal data about you at all.

We do hold personal data about people who write to us, and about the staff and representatives of our clients and suppliers. This notice explains what we hold, why, for how long, and what you can require us to do about it.

2. Who we are

MPH MEDIA & TECH LTD ("MPH Media & Tech", "we", "us") is a private company limited by shares, incorporated in England and Wales on 21 April 2026 with company number 17172873. Our registered office is 8 Mildmays, Danbury, Chelmsford, Essex, CM3 4DP, United Kingdom.

We are the data controller for the personal data described in this notice. For questions, requests or complaints, write to support@mphmedia.pro.

3. What we collect and why

CategoryWhat it includesWhy we hold itLawful basis
Enquiry correspondence Your name, email address, employer, and whatever you choose to put in your message To answer you and to decide whether we can help Legitimate interests — responding to a request you initiated
Client records Contact details of the people we deal with, project correspondence, agreed scopes and notes To carry out the engagement we have agreed Contract, and legitimate interests where the individual is a client's employee rather than our counterparty
Accounting records Invoices, purchase records, payment references To run the company's accounts and meet HMRC and Companies Act obligations Legal obligation
Technical access data Credentials and access we are granted to a client's systems; incidental exposure to data held in those systems To deliver development, consultancy and managed operations work Contract — normally as a processor acting on the client's instructions
Supplier records Contact and billing details of our own suppliers and associates To buy the services we need to operate Contract and legitimate interests

4. Data in our clients' systems

When we develop, review or operate a system for a client, that system may contain personal data about the client's own customers, members, staff or audience. In relation to that data:

  • The client is the data controller and we act as a processor.
  • We act only on the client's documented instructions.
  • We access production data only where the work genuinely requires it, and prefer anonymised or synthetic data where it will do.
  • Where UK GDPR requires it, a written processing agreement is put in place before work begins.
  • We do not use client data for our own purposes, including for training, marketing or benchmarking.

If you are an individual whose data sits in a system we operate for one of our clients, your rights are exercised against that client. Write to them; if you write to us we will pass the request on and tell you that we have done so.

5. What this website does

The site is static HTML, CSS and a small amount of JavaScript served from a web host. It does not:

  • set cookies of any kind, including analytics or advertising cookies;
  • run analytics, heatmapping, session recording or A/B testing;
  • embed social media widgets, comment systems or third-party video players;
  • contain forms, logins or any other mechanism that submits data to us.

The one external request the site makes is to Google Fonts, to load the two typefaces used in the design. That request means your IP address is visible to Google as the font provider. If you would prefer to avoid it, most browsers and content blockers can block font requests without affecting the site's usability. See our cookie notice for the detail.

Our hosting provider keeps standard server logs (IP address, timestamp, page requested, user agent) for security and diagnostics, as any web host does. We do not use those logs to build a picture of individual visitors.

6. How long we keep things

RecordRetention
Enquiries that do not become workUp to 12 months, then deleted
Client project records and correspondence6 years after the end of the engagement, to cover the limitation period for contractual claims
Accounting and tax records6 years from the end of the relevant accounting period, as required by law
Access credentials to client systemsRevoked and deleted at the end of the engagement, or sooner on request
Server logsAs set by the hosting provider, typically weeks rather than months

7. Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. We share it only with:

  • service providers we use to run the business — email and file storage, hosting, accounting software — each under a contract that restricts what they may do with it;
  • named associates brought into a project, and only where we have told the client who they are beforehand;
  • our accountant and, if ever needed, our professional advisers;
  • public authorities where we are legally required to disclose.

Some of these providers operate outside the United Kingdom. Where personal data is transferred abroad, it is protected by UK adequacy regulations or by the International Data Transfer Agreement or Addendum, as applicable.

8. How we protect it

  • Access to client systems is granted per person and revoked when no longer needed.
  • Multi-factor authentication is used on every account that supports it.
  • Devices are encrypted at rest and kept patched.
  • Credentials are held in a password manager, never in email, documents or code.
  • Production data is not copied to local machines except where a task requires it and the client has agreed.

No arrangement is perfect. If a breach occurs that is likely to risk your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and tell affected individuals where the law requires.

9. Your rights

Under UK GDPR you have the right to:

  • be told what personal data we hold about you and obtain a copy of it;
  • have inaccurate data corrected;
  • have data erased where we no longer have a good reason to hold it;
  • restrict how we use it while a dispute is resolved;
  • receive data you gave us in a portable format;
  • object to processing carried out on the basis of legitimate interests;
  • withdraw consent at any time, where consent was the basis for processing.

Write to support@mphmedia.pro. We respond within one month and there is no charge for a reasonable request. We may ask you to confirm your identity before acting.

10. Complaints

If you are unhappy with how we have handled your data, tell us first — most issues are resolved quickly. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · ico.org.uk

11. Changes to this notice

We update this notice when what we do changes. The date at the top of the page shows when it was last revised. Material changes affecting existing clients are notified by email rather than only posted here.