Privacy Policy

Privacy Notice

Last Updated: August 2026
Mind & Matter Global ("Mind & Matter", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Notice explains how we collect, use, store, and process personal data when you visit our website (mindandmatterglobal.com), utilize our SaaS platforms, or engage with our custom AI, software engineering, and consulting services in the United Kingdom (UK) and the European Economic Area (EEA).
This document complies with the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR 2016/679).

1. Important Information and Who We Are

Data Controller

Depending on your location and engagement, (.....NAME…) acts as the Data Controller responsible for your personal data.

Data Protection Officer (DPO) & Contact Details

We have appointed a Data Protection Contact responsible for overseeing questions regarding this Privacy Notice. If you have any questions or wish to exercise your legal rights, please contact us using the details below:
  • Legal Entity Name: Mind & Matter Digital Ltd.
  • Data Protection Contact: 
  • UK Registered Office: Office 1, Hatherton Court, 21 Hatherton Street, Walshall, WS4 2LA
  • General Enquiries: connect@mindandmattertech.co.uk

Complaints & Regulatory Supervisory Authorities

You have the right to lodge a complaint at any time with the relevant data protection authority:
  • UK Residents: The Information Commissioner’s Office (ICO) (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF | Tel: 0303 123 1113 | www.ico.org.uk).
  • EU/EEA Residents: Your local national Data Protection Authority (DPA) within your specific EU Member State.

We would, however, appreciate the opportunity to address your concerns before you approach the regulator, so please contact us in the first instance.

2. The Personal Data We Collect About You

Personal data means any information about an individual from which that person can be identified. We may collect, use, store, and transfer different categories of personal data grouped as follows:
  • Identity Data: First name, last name, job title, company name.
  • Contact Data: Work email address, billing address, business physical address, telephone numbers.
  • Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types, operating system, and platform used to access our website.
  • Usage Data: Information about how you interact with our website, platforms, products, and services.
  • Marketing and Communications Data: Your preferences in receiving marketing from us and our third parties, and your communication preferences.
  • Special Category Data & Minors: We do not collect any "Special Categories of Personal Data" (e.g., health data, political opinions, biometric data) or criminal conviction records, nor do we knowingly collect data relating to children under 16 years of age.

3. How We Collect Your Personal Data

We use different methods to collect data from and about you, including:
  1. Direct Interactions: You voluntarily provide Identity and Contact Data by filling out forms on our website, booking a consultation/demo, downloading whitepapers, or corresponding with us via email or phone.
  2. Automated Technologies or Interactions: As you interact with our website, we automatically collect Technical and Usage Data about your device and browsing actions using cookies, server logs, and similar technologies.
  3. Third Parties or Publicly Available Sources: We may receive technical data from analytics providers (e.g., Google Analytics based outside the UK/EU) and contact data from B2B enrichment platforms (e.g., LinkedIn Sales Navigator).

4. Legal Basis for Processing Your Data

Data protection law requires us to clearly define the specific legal grounds under which we handle different categories of your personal information, and to notify you of these grounds. If a specific legal basis on which we rely to process your information is no longer applicable, we will immediately cease processing your data under that condition. Should our legal basis change, we will, where required by law, promptly notify you of the updated ground under which processing will continue.
Specifically, we process your information relying on one or more of the following legal conditions:
  • Explicit Consent: Where you have given us clear, unambiguous permission to process your data for a specific purpose.
  • Legitimate Interests: Where processing is necessary for our legitimate business operational needs, such as delivering services and technical support effectively to you, provided your rights do not override these interests.
  • Contractual Necessity: To fulfill our obligations under the terms and conditions of a contract agreed upon with you or your organization.
  • Legal and Regulatory Compliance: To satisfy statutory requirements, court orders, or official regulatory obligations to which we are subject.

Purpose / Processing Activity

To register your contact details as a new business enquiry
To deliver our AI software and custom services
To send enterprise marketing communications
To administer, secure, and protect our website
To comply with tax, legal, or regulatory obligations

Category of Data

Identity, Contact
Identity, Contact, Technical, Usage
Identity, Contact, Technical, Usage
Technical, Usage
Identity, Contact, Financial

Lawful Basis for Processing (UK/EU GDPR)

Evaluation of a Contract with you or your company.
Performance of a Contract or Legitimate Interests (to manage business relations).
Consent (where required by law) or Legitimate Interests (B2B direct marketing).
Legitimate Interests (for running our business, network security, and preventing fraud).
Compliance with a Legal Obligation.

5. International Transfers (Cross-Border Data Flows)

Mind & Matter operates globally. Your personal data may be processed outside the UK and the European Economic Area (EEA) (e.g., by our technical team or cloud infrastructure providers in the US or Asia).
Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:
  • Adequacy Decisions: We transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government or European Commission.
  • Standard Contractual Clauses (SCCs) & UK IDTA: Where we use service providers outside the UK/EEA, we implement the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs) with the UK Addendum to guarantee equivalent protection.

6. Data Security and Enterprise Safeguards

We have put in place appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. These measures include:
  • Industry-standard encryption protocols (TLS 1.3 in transit, AES-256 at rest).
  • Strict role-based access control (RBAC) ensuring data is only accessible to employees, contractors, and processors with a business "need-to-know".
  • Procedures to handle any suspected personal data breach, including notifying you and the ICO/EU regulators within 72 hours where legally required

7. Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
  • Client Business Records: Retained for up to 6 years following contract termination to comply with statutory legal and financial audit requirements.
  • Marketing Contacts: Retained until you opt out or withdraw consent.

8. Your Legal Rights Under UK & EU GDPR

Data protection legislation grants you specific statutory rights regarding how your personal information is handled. The applicability of these rights depends directly on the legal basis under which your data is processed:
  • Right of Access (Subject Access Request - SAR): You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data where there is no good reason for us to continue processing it.
  • Right to Restrict Processing: You can ask us to suspend or restrict the processing of your data.
  • Right to Data Portability: You can request the transfer of your personal data to you or a third party in a structured, machine-readable format.
  • Right to Object: You can object to our processing where we rely on Legitimate Interests or direct marketing.
  • Right to Withdraw Consent: You can withdraw your consent at any time where we rely on consent to process your data.

How to Exercise Your Rights

  • No Fee Required: You will not have to pay a fee to access your personal data or exercise any rights.
  • Time Limit: We respond to all legitimate requests within one month.
  • Contact: Email us directly at   dpo@mindandmatterglobal.com

9. Third-Party Links & Cookies

This website may include links to third-party websites, plug-ins, and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
For detailed information on the cookies we use and how you can manage your preferences, please consult our Cookie Policy page.