MNessaMNessa
ServicesCare plansAboutLegal CentreStart a project
Home/Legal Centre/Privacy Notice

Privacy Notice

How MNessa uses personal information.

This notice explains how MNessa Limited handles personal information when you visit our website, contact us, request an appointment, discuss a project or become a client.

Version
1.0.0
Effective
28 July 2026
Last updated
28 July 2026

On this page

  1. Scope and who we are
  2. Information we collect
  3. Where information comes from
  4. Purposes and lawful bases
  5. Required and optional information
  6. Who we share information with
  7. International transfers
  8. How long we keep information
  9. Security
  10. Your rights
  11. Data-protection complaints
  12. Children
  13. Changes to this notice

1. Scope and who we are

MNessa Limited is a company registered in England and Wales under company number 12020692. Its registered office is 127 Roman Road, London, England, E2 0QN. For the personal information described in this notice, MNessa Limited is normally the controller, meaning that it decides why and how the information is used.

You can contact us at contact@mnessa.co.uk. This notice applies to the MNessa website, enquiries, appointment requests, proposals, client administration and related business communications. A client contract or data-processing agreement may provide additional information for a particular service.

2. Information we collect

Depending on how you interact with MNessa, we may collect:

  • Identity and contact information, such as your name, work email address, telephone number, job title and organisation.
  • Enquiry and appointment information, including the service requested, organisation type, team size, preferred timeline, appointment details and the content of your message.
  • Project and client information, such as requirements, meeting notes, proposals, contracts, instructions, support requests, deliverables and communications.
  • Commercial and transaction information, including quotations, invoices, payment status and accounting records. Card or bank details may be handled directly by a payment provider or bank rather than stored by MNessa.
  • Technical and security information, such as IP address, browser or device type, request time, referring page and security or diagnostic logs generated by the website, hosting platform or email service.
  • Website preference information, including light or dark theme and whether the loading animation has already been shown during the browser session.
  • Marketing preferences, if you separately choose to receive updates from MNessa.

Please do not include passwords, payment-card details, health information or other sensitive personal information in a general enquiry unless it is genuinely necessary and MNessa has agreed an appropriate way to receive it.

3. Where information comes from

We usually receive information directly from you, including through forms, email, telephone, video calls and meetings. We may also receive information:

  • from a colleague, professional adviser or other person who introduces you or includes you in a project;
  • from a client where your information is needed for MNessa to provide an agreed service;
  • from publicly available business sources, such as an organisation's website or Companies House; and
  • automatically from the website and its infrastructure when you visit or submit a request.

Where the law requires us to give you privacy information after obtaining it from someone else, we will do so within the applicable period unless an exception applies.

4. Why we use information and our lawful bases

PurposeTypical informationLawful basis
Responding to enquiries, arranging appointments and deciding whether MNessa can help Contact, organisation and enquiry details Steps requested before entering a contract; and legitimate interests in managing genuine business enquiries
Preparing proposals, entering and performing contracts, delivering services and providing support Contact, project, communications and commercial information Contract; and legitimate interests where the contract is with your organisation rather than with you personally
Billing, accounting, tax, company administration and record keeping Contact, transaction and client records Legal obligation; contract; and legitimate interests in responsible financial administration
Operating, securing, diagnosing and improving the website and services Technical, security and usage information Legitimate interests in maintaining secure and reliable systems; and legal obligation where applicable
Managing disputes, complaints, legal claims and regulatory requests Relevant correspondence, project and transaction records Legal obligation; and legitimate interests in protecting legal rights and resolving concerns
Sending optional news or promotional communications Contact details and marketing preferences Consent where required, or legitimate interests where electronic-marketing and data-protection rules permit it

Where we rely on legitimate interests, we consider whether the use is necessary, proportionate and balanced against your rights. You may object to processing based on legitimate interests. You may object to direct marketing at any time.

MNessa does not currently use website enquiry information to make decisions about people solely by automated means that produce legal or similarly significant effects.

5. Required and optional information

Fields marked as required are needed to understand and respond to your request. Other fields, such as a telephone number or preferred timeline, are optional. If necessary information is not provided, MNessa may be unable to respond fully, arrange an appointment or provide a requested service.

Submitting an enquiry does not add you to a marketing list. Any optional marketing choice will be presented separately and can be withdrawn at any time.

6. Who we share information with

We may share relevant information with:

  • MNessa directors, personnel and authorised contractors who need it for their work;
  • website hosting, deployment, domain, security, backup and infrastructure providers;
  • email, appointment scheduling, collaboration, customer-management and productivity providers;
  • payment, banking, accounting and invoicing providers;
  • professional advisers, such as accountants, insurers, solicitors or auditors;
  • regulators, courts, law-enforcement bodies and public authorities where disclosure is required or permitted by law; and
  • a purchaser, investor or successor if MNessa is reorganised, sold or transfers part of its business, subject to appropriate confidentiality and legal safeguards.

The website's enquiry route is designed to transmit submissions to MNessa by email rather than deliberately create a separate public-facing enquiry database. Hosting and email providers may nevertheless process or retain messages, logs and backups under their service terms. MNessa does not sell personal information.

7. International transfers

Some technology suppliers may process information outside the United Kingdom. Where this amounts to a restricted transfer, MNessa will use an available legal mechanism, such as UK adequacy regulations, appropriate contractual safeguards including the UK International Data Transfer Agreement or UK Addendum, or another lawful exception. Where required, MNessa will also assess whether additional safeguards are appropriate.

You may contact us for further information about the safeguards relevant to your information.

8. How long we keep information

We use the following starting points, subject to legal, contractual and operational needs:

  • General enquiries that do not become client work: normally up to 24 months after the last meaningful contact.
  • Appointment records that do not become client work: normally up to 24 months after the appointment or last contact.
  • Client, project, contract, invoice and accounting records: normally six years after the end of the relevant relationship, transaction or financial period, and longer where required for tax, legal claims, an investigation or another legal duty.
  • Technical and security logs: for the period reasonably needed for security, diagnostics and incident investigation, which varies by system and provider.
  • Marketing records: until you opt out or the information is no longer needed. A minimal suppression record may be retained to respect an opt-out.
  • Browser preferences: until the browser session ends, you clear the storage, or the preference is replaced, as explained in the Cookie Notice.

We may delete or anonymise information sooner when it is no longer needed. We periodically review retention and avoid keeping identifiable information indefinitely merely in case it may become useful.

9. Security

MNessa uses proportionate technical and organisational measures intended to protect information against accidental loss, unauthorised access, alteration or disclosure. Measures are selected according to the nature of the service and risk and may include access controls, multi-factor authentication, encrypted connections, managed hosting, backups, updates, logging and supplier controls.

No internet service can be guaranteed completely secure. Please use an appropriate secure channel rather than a general website form for highly confidential material. Further information is available in our Information Security Statement.

10. Your rights

Depending on the circumstances and lawful basis, you may have the right to:

  • be informed about how your personal information is used;
  • request access to your personal information;
  • ask for inaccurate or incomplete information to be corrected;
  • ask for information to be erased;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format; and
  • withdraw consent at any time where consent is the lawful basis.

These rights are not absolute and exemptions may apply. We may need information to verify identity and authority before responding. We will not normally charge a fee, but the law permits a reasonable fee or refusal in limited circumstances.

11. Data-protection complaints

You can make a data-protection complaint by emailing contact@mnessa.co.uk with the subject Data protection complaint. Please describe what happened, the outcome you seek and any relevant dates or correspondence.

MNessa will facilitate complaints, acknowledge receipt within 30 days, take appropriate steps to investigate, keep you informed where needed and communicate the outcome without undue delay.

You may also complain to the Information Commissioner's Office, the UK's data-protection regulator. Details are available at ico.org.uk. We would appreciate the opportunity to address the concern first, but contacting MNessa is not intended to remove any right to approach the ICO.

12. Children

This business website and its services are not directed at children. We do not knowingly seek personal information from children through the general enquiry form. If you believe a child has submitted information inappropriately, contact us so that we can assess and, where appropriate, remove it.

13. Changes to this notice

We may update this notice when our services, suppliers or legal obligations change. The version and date at the top identify the published notice. Material changes may also be highlighted on the website or brought to the attention of affected people where appropriate.

Questions or concerns

Talk to MNessa.

Email contact@mnessa.co.uk. For a data-protection complaint, use the subject line Data protection complaint.

Contact MNessa
MNessa

Engineering-led digital services, software and infrastructure for modern businesses.

Company

HomeServicesCare plansLegal Centre

Legal & trust

Privacy NoticeCookie NoticeWebsite & Booking TermsAccessibility StatementResponsible AI & Technology StatementInformation Security Statement

Contact

contact@mnessa.co.uk+44 (0) 79 5858 5550127 Roman RoadLondon · E2 0QNUnited Kingdom
© MNessa Limited · Registered in England and Wales · Company 12020692 · Registered office: 127 Roman Road, London, E2 0QN