Privacy Policy

Privacy Policy

Effective Date: 1 June 2025  |  Last Updated: 1 June 2025

This Privacy Policy explains how mohatu (trading as mohatu, hereinafter referred to as “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you visit or interact with our website at mohatu.info (the “Website”). We are committed to handling your personal information responsibly and in full compliance with the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018.

Please read this policy carefully. By using our Website, you acknowledge that you have read and understood the practices described herein. If you do not agree with any part of this policy, please discontinue use of the Website.


1. Who We Are and How to Contact Us

mohatu is the data controller responsible for your personal data collected through this Website. Our contact details are as follows:

  • Trading Name: mohatu
  • Legal Name: mohatu
  • Website: mohatu.info
  • Email: [email protected]
  • Phone: +44 7400 987401
  • Address: London

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us using the details above. We aim to respond to all privacy-related enquiries within 30 days.

As a UK-based data controller, we are subject to regulation by the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection.


2. Data We Collect

We collect a limited and proportionate amount of personal data necessary to operate this Website and respond to your enquiries. The categories of data we collect are set out below.

2.1 Information You Provide Directly

When you complete and submit a contact form on our Website, we collect the following information:

  • Full Name — so that we can address you appropriately in our response.
  • Email Address — to enable us to reply to your enquiry electronically.
  • Phone Number — if provided, to allow us to contact you by telephone if necessary or preferred.
  • Message Content — the details of your enquiry, question, or request as you have written them.

You are not obliged to provide all of the above fields; however, failure to provide certain information (such as your email address) may prevent us from responding to your enquiry effectively.

2.2 Information Collected Automatically

When you visit our Website, certain technical information may be collected automatically by our web server and any analytics tools we employ, including:

  • IP Address — used for security monitoring, fraud prevention, and aggregate traffic analysis.
  • Browser Type and Version — to help us understand how users access our Website and to ensure compatibility.
  • Operating System — collected as part of standard server logs.
  • Pages Visited and Time Spent — to understand which content is most useful to visitors.
  • Referring URLs — to understand how you arrived at our Website.
  • Date and Time of Access — for security and performance monitoring.

2.3 Information Collected via Cookies

We use cookies and similar tracking technologies on our Website. Full details of our cookie use are set out in Section 6 of this policy.

2.4 Data We Do Not Collect

We do not intentionally collect any special categories of personal data (also known as sensitive personal data) as defined under Article 9 of the UK GDPR, including data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data. We also do not knowingly collect personal data from children under the age of 13 (see Section 12 for further details).


3. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

  • To respond to your enquiry — When you submit a contact form, we use your name, email address, phone number, and message to understand and respond to your request.
  • To manage our business relationship with you — We may retain your contact details to follow up on a previous enquiry or to provide ongoing services you have requested.
  • To improve the Website — Aggregated and anonymised analytics data helps us understand how visitors use our Website, enabling us to improve content and user experience.
  • To maintain Website security — Technical data such as IP addresses is used to detect and prevent malicious activity, fraud, and unauthorised access.
  • To comply with legal obligations — We may process and retain your data to comply with applicable UK law or to respond to lawful requests from regulatory or law enforcement authorities.

4. Lawful Basis for Processing

Under the UK GDPR, we are required to identify a lawful basis for each purpose for which we process your personal data. Our lawful bases are as follows:

  • Legitimate Interests (Article 6(1)(f) UK GDPR) — Processing your contact form submission data to respond to your enquiry and to maintain the security of our Website. We have conducted a legitimate interests assessment and are satisfied that our interests are not overridden by your rights and interests.
  • Consent (Article 6(1)(a) UK GDPR) — Where we use optional analytics cookies or collect data beyond what is strictly necessary, we will rely on your freely given, specific, informed, and unambiguous consent, which you may withdraw at any time.
  • Legal Obligation (Article 6(1)(c) UK GDPR) — Where we are required to retain or process your data to comply with UK law, tax or accounting obligations, or a court order.
  • Contract (Article 6(1)(b) UK GDPR) — Where processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract.

5. How Contact Form Submissions Are Processed

When you submit a contact form on our Website, the following process occurs:

  1. Your submission data (name, email address, phone number, and message) is transmitted securely over an encrypted HTTPS connection to our web server.
  2. The data is processed by our server-side application (PHP) and typically delivered to our designated business email address via a secure mail transfer protocol.
  3. Your submission may be temporarily stored in server logs or a database for operational purposes, for a limited duration as described in Section 8 of this policy.
  4. We do not use your contact form data for automated decision-making or profiling as defined under Article 22 of the UK GDPR.
  5. Your data will not be sold, rented, or shared with any third party for their own marketing purposes.

We handle all contact form submissions with care and use the information solely to respond to and manage your enquiry.


6. Cookies and Tracking Technologies

Cookies are small text files placed on your device when you visit a website. Our Website uses cookies to ensure it functions correctly and, where you have given your consent, to analyse how visitors use the site.

6.1 Strictly Necessary (Functional) Cookies

These cookies are essential for the operation of our Website. They enable core functionality such as security, page navigation, and access to secure areas. The Website cannot function properly without these cookies, and they cannot be switched off. They do not store any personally identifiable information. No consent is required for these cookies under the Privacy and Electronic Communications Regulations 2003 (PECR).

6.2 Analytics Cookies (Optional)

With your consent, we may use optional analytics cookies to collect information about how visitors interact with our Website. This helps us to improve our Website and understand which content is most popular. Analytics data is collected in aggregate and anonymised where possible. You may opt out of analytics cookies at any time by adjusting your cookie preferences via our cookie consent banner or by following the browser-based opt-out instructions provided by the relevant analytics provider.

6.3 How to Manage Cookies

You can control and/or delete cookies as you wish. You can delete all cookies already on your device and configure most browsers to prevent them from being placed. However, if you do so, you may need to manually adjust your preferences every time you visit our Website and some features may not work as intended. For further information on managing cookies, please visit www.allaboutcookies.org or the ICO’s guidance on cookies.


7. Third-Party Services

Our Website may use certain third-party services that may collect data about you. These are described below.

7.1 Google Fonts

Our Website may load fonts from Google Fonts, a service provided by Google LLC (and/or Google Ireland Limited for UK/EEA users). When your browser requests a font from Google’s servers, Google may collect your IP address and browser information as part of this request. Google’s collection and use of data is governed by its own Privacy Policy. We have implemented Google Fonts in a manner that minimises data transfer where technically feasible, including self-hosting fonts where possible. Where Google Fonts are loaded externally, a transfer of your IP address to Google’s servers (which may be located outside the UK) may occur.

7.2 Tailwind CSS CDN

Our Website may load the Tailwind CSS framework from a content delivery network (CDN). Loading resources from a CDN may result in your IP address being transmitted to the CDN provider’s servers. The CDN provider may collect limited technical data (including IP address and browser type) for the purposes of delivering content and maintaining network security. We select CDN providers that operate under appropriate data protection safeguards.

7.3 Web Hosting Provider

Our Website is hosted by a third-party web hosting provider. Server logs maintained by our hosting provider may include your IP address, the date and time of your visit, and other technical information. We have a data processing agreement in place with our hosting provider, as required by UK GDPR.

7.4 No Sale of Data to Third Parties

We do not sell, trade, or otherwise transfer your personal data to third parties for their own commercial purposes. Any third parties with whom we share data are limited to those acting as data processors on our behalf and are bound by appropriate contractual obligations.


8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our specific retention periods are as follows:

  • Contact Form Submissions: We retain the personal data submitted via contact forms (name, email address, phone number, and message) for a period of up to 2 years from the date of submission. This period allows us to manage ongoing correspondence and any follow-up enquiries, and to maintain adequate records of business communications.
  • Server and Access Logs: Technical logs (including IP addresses and access timestamps) are retained for a period of up to 90 days for security and troubleshooting purposes, after which they are automatically deleted or anonymised.
  • Analytics Data: Where analytics data is collected with your consent, it is retained for a period consistent with the retention policies of the relevant analytics platform, or for a maximum of 26 months, after which it is deleted or anonymised.
  • Legal and Compliance Records: Where we are required by law (for example, for tax or accounting purposes) to retain certain records, we will retain those records for the period required by applicable legislation (typically 6 years in the UK for financial records under the Companies Act 2006 and HMRC guidance).

Once the applicable retention period has expired, your personal data will be securely deleted or irreversibly anonymised. If you request deletion of your data before the end of the retention period (see Section 9), we will comply with your request unless we have a lawful reason to retain the data.


9. Your Rights Under UK GDPR

As a data subject located in the United Kingdom, you have the following rights under the UK GDPR and the Data Protection Act 2018:

  • Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you, together with information about how it is processed. We will provide this information in the form of a Subject Access Request (SAR) response, free of charge, within one calendar month of receipt of your request.
  • Right to Rectification (Article 16): You have the right to request that we correct any inaccurate or incomplete personal data we hold about you, without undue delay.
  • Right to Erasure / ‘Right to be Forgotten’ (Article 17): You have the right to request that we delete your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, or where you withdraw consent and there is no other lawful basis for processing.
  • Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, for example whilst we verify the accuracy of data you have contested.
  • Right to Data Portability (Article 20): Where we process your data based on consent or to perform a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to request that we transmit it directly to another controller where technically feasible.
  • Right to Object (Article 21): You have the right to object to our processing of your personal data where we rely on legitimate interests as our lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is for the establishment, exercise, or defence of legal claims.
  • Rights in Relation to Automated Decision-Making (Article 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. We do not engage in such processing.

9.1 How to Exercise Your Rights

To exercise any of the above rights, please contact us in writing using the contact details provided in Section 1. We may need to verify your identity before processing your request. We will respond to all legitimate requests within one calendar month. In complex or multiple-request cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the first month.

There is no charge for exercising your rights in most circumstances. However, if a request is manifestly unfounded or excessive (for example, if it is repetitive), we reserve the right to charge a reasonable fee or to refuse to act on the request.

9.2 Right to Lodge a Complaint

If you believe that we have not handled your personal data in accordance with applicable data protection law, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the opportunity to address your concerns before you contact the ICO. We encourage you to contact us in the first instance so that we can attempt to resolve the matter.


10. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • HTTPS Encryption: All data transmitted between your browser and our Website is encrypted using SSL/TLS technology. Our Website uses HTTPS to ensure your data is protected in transit.
  • Access Controls: Access to personal data is restricted to authorised personnel only, on a need-to-know basis, and is protected by strong authentication controls.
  • Secure Email Handling: Contact form submissions are transmitted to our business email account via secure protocols. We use reputable email service providers with appropriate security standards.
  • Server Security: Our web hosting environment is maintained with up-to-date software, security patches, and firewall protection.
  • Data Minimisation: We collect only the personal data that is strictly necessary for the stated purpose, in accordance with the principle of data minimisation under UK GDPR.
  • Regular Reviews: We periodically review our data processing activities and security measures to ensure continued compliance with applicable law and best practice.

No method of electronic transmission or storage is 100% secure. Whilst we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR. Where required, we will also notify affected individuals without undue delay.


11. International Data Transfers

In the ordinary course of operating our Website, some of your personal data may be transferred to, stored in, or processed in countries outside the United Kingdom. This may occur, for example, when third-party service providers (such as Google Fonts or CDN providers) process data on servers located outside the UK.

Where such international transfers occur, we take steps to ensure that your personal data receives an adequate level of protection in accordance with UK data protection law. We rely on one or more of the following transfer mechanisms:

  • UK Adequacy Regulations: Transfers to countries or international organisations that the UK Secretary of State has determined provide an adequate level of protection for personal data.
  • UK International Data Transfer Agreements (IDTAs): Where no adequacy decision exists, we rely on UK IDTAs (the UK equivalent of EU Standard Contractual Clauses) or other appropriate safeguards as permitted under UK GDPR.
  • Binding Corporate Rules or other approved mechanisms where applicable.

If you would like further information about international transfers of your personal data, or to obtain a copy of the relevant transfer mechanisms, please contact us using the details in Section 1.


12. Children’s Privacy

Our Website and services are not directed at children under the age of 13 years. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and you believe that your child has provided us with personal data without your consent, please contact us immediately using the details in Section 1, and we will take steps to delete such information from our records as soon as reasonably practicable.

In accordance with the Age Appropriate Design Code (Children’s Code) issued by the ICO, we are mindful of protecting the privacy of younger users and do not engage in data practices that are detrimental to children’s privacy and wellbeing.

If you are between the ages of 13 and 17, we strongly encourage you to obtain the consent of a parent or guardian before submitting any personal data through our Website.


13. Links to Third-Party Websites

Our Website may contain links to external websites or resources operated by third parties. These links are provided for your convenience and information only. We have no control over the content or privacy practices of those websites and do not accept any responsibility or liability for them. We encourage you to review the privacy policies of any third-party websites you visit.


14. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or for other operational, legal, or regulatory reasons. Any changes we make will be effective immediately upon posting the updated policy to our Website, with the “Last Updated” date revised accordingly.

Where we make material changes to this Privacy Policy that significantly affect your rights or how we process your personal data, we will take reasonable steps to inform you of those changes. This may include:

  • Displaying a prominent notice on our Website homepage or relevant pages;
  • Sending an email notification to individuals who have previously contacted us, where we hold their email address and it is appropriate to do so;
  • Including a summary of key changes at the top of the revised policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website after the effective date of any changes constitutes your acceptance of the updated policy.


15. Data Protection Officer

Depending on the scale and nature of our data processing activities, we may or may not be formally required to appoint a Data Protection Officer (DPO) under Article 37 of the UK GDPR. Regardless of any formal obligation, we are committed to maintaining high standards of data protection governance.

All data protection enquiries, subject access requests, and privacy concerns should be directed to us using the contact details provided in Section 1. We will ensure that all such communications are handled by a responsible individual with appropriate knowledge of data protection law.


16. Legal Basis Summary Table

For transparency, we summarise our data processing activities and corresponding lawful bases below:

Processing ActivityData InvolvedLawful Basis
Responding to contact form enquiriesName, email, phone, messageLegitimate Interests
Website security monitoringIP address, access logsLegitimate Interests
Optional analytics trackingCookies, usage dataConsent
Retaining records for legal complianceBusiness correspondenceLegal Obligation
Loading external resources (fonts, CDN)IP address (transmitted to third party)Legitimate Interests / Consent

17. Complaints and Concerns

We take all privacy-related complaints seriously. If you have a concern about how we have handled your personal data, please contact us in the first instance using the details in Section 1. We will acknowledge your complaint promptly and endeavour to resolve it within 30 days.

If you remain dissatisfied following our response, or if you do not hear from us within a reasonable period, you have the right to escalate your complaint to the Information Commissioner’s Office (ICO) using the contact details provided in Section 9.2. The ICO can investigate your complaint and, where appropriate, take enforcement action against us.


Effective Date: 1 June 2025  |  Last Updated: 1 June 2025

This Privacy Policy is governed by the laws of England and Wales. Any disputes arising in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.

© 2025 mohatu. All rights reserved.  |  mohatu.info