Privacy Policy
Effective date: 19 March 2026ICO registration: C1930046
Contact: team@masser.uk
This privacy policy explains how Penovex Limited ("Masser", "we", "us") collects, uses, and protects personal data when you visit masser.uk or interact with our marketing website.
This policy covers the Masser marketing site only. If you are a Masser client, see the Client Privacy Policy. If you are visiting a website hosted by Masser, see the privacy policy on that website.
1. Who We Are
Penovex Limited trades as Masser. We provide a subscription web design and hosting service. We are the data controller for the personal data described in this policy.
2. What Data We Collect
2.1 Data You Provide
- Onboarding wizard submissions — name, email address, phone number, business name, industry, website preferences, design choices, uploaded images/logos, and any notes or descriptions you provide
- Enquiry forms — name, email, message content
- Audit requests — your existing website URL and contact details
2.2 Data Collected Automatically
- Technical data — IP address, browser type, operating system, device type, screen resolution
- Usage data — pages visited, time on site, referring source, click interactions
- Cookies — see Section 7
2.3 Data from Your Existing Website
If you provide your current website URL (for audit or build purposes), we may crawl publicly available pages to extract business information such as services offered, contact details, testimonials, and opening hours. We only access content that is already public.
3. How We Use Your Data
| Purpose | Legal basis |
|---|---|
| Processing your onboarding submission and building your website preview | Steps necessary to enter into a contract |
| Contacting you about your preview, revisions, and next steps | Legitimate interest |
| Sending follow-up emails if you don't complete the process | Legitimate interest (with opt-out) |
| Improving our website, service, and AI build quality | Legitimate interest |
| Analysing website traffic and conversion rates | Legitimate interest |
| Complying with legal obligations | Legal obligation |
4. Marketing Communications
After you submit the onboarding wizard, we may send you:
- Preview delivery emails and revision updates (transactional — part of the service)
- Follow-up emails if you haven't responded (e.g. preview nudge, abandoned preview offer)
- Promotional emails about our services
You can opt out of marketing emails at any time by clicking the unsubscribe link in any email or emailing team@masser.uk. Transactional emails related to an active submission cannot be opted out of.
5. Who We Share Your Data With
| Recipient | Purpose |
|---|---|
| Supabase | Database storage |
| Resend | Email delivery |
| Anthropic (Claude AI) | Website generation (business info and preferences only) |
| Stripe | Payment processing (only if you subscribe) |
| Crisp | Live chat support (only if you initiate a chat) |
| fal.ai | Image and video generation for website builds |
| Netlify | Website hosting and deployment |
| Sentry | Error monitoring and service reliability |
We do not sell your personal data to any third party.
6. Data Retention
| Data type | Retention period |
|---|---|
| Onboarding submissions (no payment) | 6 months after last activity |
| Website previews (no payment) | 90 days after creation |
| Enquiry form submissions | 12 months |
| Converted clients | See Client Privacy Policy |
If you submit the onboarding wizard but do not subscribe, your data (including the website preview) is deleted after the periods above. You can request earlier deletion at any time.
7. Cookies
Essential Cookies
We use essential cookies for basic website functionality (session management, security).
Analytics Cookies
We may use Google Analytics to understand how visitors use masser.uk. This collects anonymised usage data including pages visited, session duration, traffic source, and device type.
You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.
We do not use advertising cookies or tracking pixels on masser.uk.
8. Your Rights
Under the UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Object to processing based on legitimate interest
- Data portability — receive your data in a machine-readable format
To exercise any right, contact team@masser.uk. We will respond within 30 days.
9. Data Security
We implement appropriate security measures including HTTPS encryption, secure database access controls, and encrypted email transmission. Payment data is handled entirely by Stripe (PCI DSS compliant) and never stored on our servers.
10. International Transfers
Some service providers process data in the United States. Where data is transferred outside the UK, we ensure appropriate safeguards (Standard Contractual Clauses or equivalent) are in place.
11. Children's Data
Our services are designed for businesses and are not directed at individuals under 18. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated effective date.
13. Complaints
You have the right to complain to the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
14. Contact
- Email: team@masser.uk
- Company: Penovex Limited