Security and data handling
How we look after your data.
Written for the person who has to sign off a supplier. It covers where data is held, who can reach it, how long it stays and how to get it removed. If your procurement process needs something this does not answer, ask and we will answer it in writing.
Last updated 2026-09-08. Questions to dpo@mpldigital.co.uk.
Where data is held
- Enquiry data is stored in Google Cloud Firestore in the europe-west4 region, in the Netherlands, within the EEA.
- The enquiry is also emailed to us, so a copy travels through Resend and Amazon SES in eu-west-1 (Ireland) and comes to rest in Google Workspace. Both are in the EEA. Where a project starts, correspondence about it may also be held in the tools we run the business on, listed below.
- Client systems are hosted in the region agreed with that client, and we will tell you exactly where yours would sit before any work starts.
- We do not use offshore development or support. The person handling your data is Mike Lewis, in the United Kingdom.
Who can reach it
- Administrative access requires a Google account on an approved company domain and a role record held server-side. A company email address on its own grants nothing.
- The database refuses all direct client access. Every read and write goes through the server, so a leaked public key opens nothing.
- Sessions are held in a signed, HTTP-only, secure cookie. Signing out revokes the underlying credentials, not just the cookie in that browser.
- Access rules are enforced in the database itself rather than in the interface, and covered by an automated test suite.
How long it stays
- Enquiries are reviewed and deleted two years after the last contact. That review is carried out by hand rather than by an automatic process.
- Where an enquiry becomes a project, the associated records are kept for six years to meet accounting and legal obligations.
- Backups are taken daily and retained for seven days, with point-in-time recovery enabled. A deletion cannot purge a backup taken before it, so a record may persist in backup for up to seven days after removal.
Who else processes it
- Google Cloud and Firebase: hosting, database and authentication, in the EEA.
- Resend: delivery of enquiry notification and confirmation emails. Resend delivers through Amazon SES in eu-west-1.
- Cloudflare: DNS, and Turnstile, which checks that a form submission comes from a person. Turnstile receives the visitor IP address and technical signals from the browser, and never the content of the form.
- Sentry, EU region: error reporting. Receives technical diagnostics about faults, not enquiry content.
- Cloudflare Web Analytics: cookieless and non-fingerprinting. It sets nothing on the visitor device and collects nothing that identifies a person.
- Google Workspace: the mailbox enquiry notifications arrive in.
- Xero: accounting, where an enquiry becomes an invoiced project.
- We do not sell or share personal data, and we do not pass it to third parties for marketing or advertising.
Getting data back or removed
- Ask, and we will confirm what is held and remove it. Requests go to the address below and are answered within one month, which is the statutory limit rather than our target.
- We can produce a complete export of everything held about an enquiry, including when consent was given and which version of the privacy policy was agreed to.
- You do not need a reason and there is no form to fill in.
How the sites themselves are built
- Content is rendered on the server, so pages work without JavaScript and remain readable to assistive technology and to crawlers.
- Security headers, including strict transport security and content type protections, are set by the application rather than by a proxy, so they hold wherever the site is served from.
- Every change runs through automated checks before it can reach production: type checking, linting, unit tests, database access-rule tests, and assertions that the served pages contain their content. Performance and accessibility are measured on every change and reviewed rather than used to block a release.
- Accessibility is held to WCAG 2.1 AA. Eleven routes are audited automatically on every change, and keyboard navigation, focus management and the underlying accessibility tree have been checked by hand. A session with a screen reader user is scheduled and has not happened yet: automated tools and a keyboard cannot tell you what a page sounds like, and we would rather say so than imply assurance we do not have.
What we do not do
- We do not use advertising or third-party tracking cookies on our own site.
- We do not add analytics that identify individuals without asking first and updating this page in the same change.
- We do not publish a client name, logo or case study without the client agreeing to it. Our own system refuses to publish a case study unless approval has been recorded against it, along with who recorded it and when. That record shows the decision was taken; the agreement itself lives in the correspondence with that client.
MPL Technologies Limited · Company No. 17085377 · Unit 1 Abbots Quay, Monks Ferry, Birkenhead, CH41 5LH