- Home
- Privacy Policy
Your information, handled properly
What we collect, why we need it, who we share it with, how long we keep it, and the rights you have over it under the UK GDPR.
1. Who we are
Pocket Maze LTD ("Pocket Maze", "we", "us", "our") is a private limited company registered in England and Wales. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal information described in this policy — that is, we decide why and how it is used.
| Detail | Information |
|---|---|
| Legal name | Pocket Maze LTD |
| Company number | 15198808 |
| Jurisdiction | England & Wales, United Kingdom |
| Registered office | Suite 9165, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom |
| Data controller | Pocket Maze LTD |
| Privacy contact | info@pocketmaze.site |
| Telephone / WhatsApp | +44 7418 355739 |
| This version | Version 1.0 — last updated 6 October 2026 |
2. Scope of this policy
This policy explains how we collect, use, share, store, transfer and protect personal information when you:
- visit or interact with pocketmaze.site or any other website we operate;
- contact us by WhatsApp, email, telephone, social media or a website form;
- ask for a quote, place an order, or use any of our services — web hosting, VPS, cloud and dedicated servers, domain registration and DNS, business email, SSL certificates, backups, security and maintenance plans, or software development;
- host a website, application, shop, database or mailbox on our infrastructure (we then also process data about your own customers and visitors — see section 7);
- deal with us as a supplier, contractor, partner or job applicant.
It does not apply to third-party websites or services that we link to or resell. Those organisations have their own privacy notices, and you should read them. Where we resell a third-party service (for example a domain registry, a payment provider or an SSL certificate authority), your information may be shared with that provider as described in section 7.
If you give us information about someone else — for example an employee whose mailbox you are ordering, or an authorised contact on your account — you must have their permission to do so and should point them to this policy.
This policy is written in accordance with the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and, where relevant, the EU GDPR for individuals in the European Economic Area.
3. Information we collect
We collect the following categories of personal information. In each case we have shown typical examples — we only collect what a given service actually needs.
| Category | What it typically includes |
|---|---|
| Identity data | Your name, company name, company or VAT number, job title, and (for domain registrations) the registrant name and legal entity type. |
| Contact data | Email address, telephone and WhatsApp number, billing address, postal address, and any alternative contact you nominate. |
| Account data | Account and user identifiers, login details and PINs, service configuration, domain names, DNS records, mailboxes, hosting plans and support preferences. |
| Order and billing data | Services ordered, quotes, invoices, credit notes, payment status, VAT status, renewal dates and billing history. |
| Payment data | Card type and last four digits, tokenised payment reference, direct-debit mandate, or bank details for payments to you. We never store full card numbers — card payments are processed by our payment provider. |
| Technical data | IP address, device and browser type, operating system, screen size, referring page and access timestamps. |
| Usage and log data | Server, access and authentication logs, bandwidth and resource usage, error and crash reports, and records of support sessions. |
| Communication data | Emails, WhatsApp and chat messages, support tickets, call notes and the content of enquiries you send us. |
| Customer content | Files, websites, databases, emails and backups that you store with us. Where you host with us we handle this as your processor, not as controller. |
| Marketing data | Your marketing preferences, the date and wording of any consent you gave, and interactions with our emails or campaigns. |
| Recruitment data | A CV, covering letter, references and right-to-work information if you apply for a role with us. |
We do not collect special category data (such as health, racial or ethnic origin, political opinions, religious beliefs, biometric or genetic data) and we ask you not to send it to us. If you do send it, we will delete it unless we are legally required to keep it. We do not knowingly collect information about children — see section 13.
4. How we collect your information
| Source | How it works |
|---|---|
| Directly from you | When you complete a form on our website, message us on WhatsApp, email or call us, open an account, place an order, pay an invoice, open a support ticket or respond to a survey. |
| Automatically | When your browser or device connects to our website or servers, we receive technical and usage data such as your IP address and request logs. See section 6 on cookies. |
| From third parties | Payment providers (payment confirmations and fraud signals), fraud and credit-check services, domain registries and registrars, partners and resellers who refer business to us, and publicly available sources such as Companies House. |
| From your own users | Where you host a website, application or mailbox with us, we process information about your customers, visitors and email correspondents strictly on your instructions and as your processor (see section 7). |
5. Why we use your information and our lawful bases
We use your personal information only where we have a lawful basis to do so under the UK GDPR. This table sets out each purpose and the basis we rely on.
| Purpose | Lawful basis |
|---|---|
| Setting up and providing the services you have ordered, including hosting, servers, domains, DNS, mailboxes and software delivery | Contract — processing is necessary to perform our agreement with you |
| Taking and collecting payment, issuing invoices and credit notes, managing renewals | Contract, and legal obligation for tax and company records |
| Answering enquiries, giving quotes and providing technical support | Contract (if you are a customer) or legitimate interests (responding to a business enquiry) |
| Operating, securing and monitoring our network and servers; detecting spam, malware, fraud and abuse; capacity planning | Legitimate interests — keeping our services secure, available and lawful for all customers |
| Improving our website, services and documentation; measuring what works | Legitimate interests — developing and improving our business |
| Marketing our similar services to existing customers by email | Soft opt-in under PECR, with an unsubscribe option in every message |
| Marketing to people who are not existing customers; newsletters and campaigns | Consent, which you can withdraw at any time |
| Complying with legal, regulatory and accounting duties and responding to lawful requests | Legal obligation |
| Establishing, exercising or defending legal claims; recovering debts | Legitimate interests |
| Assessing a job application and keeping recruitment records | Legitimate interests, and consent where we keep details for future roles |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests do not override your rights and freedoms. You can ask us for a summary of that assessment at any time. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of what we did before you withdrew.
We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.
8. International transfers
Our own systems and data are hosted within the United Kingdom and the European Economic Area wherever possible. However, some of the providers we rely on — for example payment processors, Google (web fonts), Meta (WhatsApp) and some certificate or software suppliers — may process data in other countries, including the United States.
Where personal information leaves the UK or EEA we make sure a lawful transfer mechanism is in place, such as:
- a UK adequacy regulation, or an adequacy decision of the European Commission for EEA transfers;
- the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses;
- a transfer risk assessment for the specific transfer, plus, where needed, additional technical and organisational safeguards such as encryption in transit and at rest.
You can ask us for details of the safeguards used for a particular transfer by emailing info@pocketmaze.site.
9. How long we keep information
We keep personal information only for as long as we need it. The periods below are the standard retention periods we apply; we may keep information longer where the law requires it, or where it is necessary for a specific legal claim.
| What | How long we keep it |
|---|---|
| Enquiries and quotes that do not become an order | Up to 24 months, then deleted. |
| Customer account, order and billing records | 6 years after the end of the accounting period in which the relationship ended — required by tax and company law. |
| Invoices and VAT records | 6 years (plus the current year). |
| Server, access and authentication logs | Typically 90 days, on a rolling basis, unless retained for a security investigation. |
| Security incident records | Up to 12 months, or longer if needed for a legal claim. |
| Support and WhatsApp/email correspondence | Up to 24 months from the last message on the thread. |
| Customer content hosted with us (sites, files, mailboxes, backups) | For the duration of the service, plus 30 days after termination to allow export or restoration, after which it is deleted from live systems and overwritten in backups within the normal rotation cycle. |
| Marketing consent records | Kept while consent is valid, plus a suppression record so we do not contact you again by mistake. |
| Recruitment records | 12 months after the decision, unless you ask us to keep them longer. |
| Payment tokens and mandates | For as long as the billing relationship lasts, plus the chargeback window. |
10. How we protect your information
We apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for data in transit, and encryption at rest for backups and sensitive stores;
- least-privilege access control, individual named accounts, and multi-factor authentication for administrative access;
- firewalls, intrusion detection, malware scanning and regular patching of operating systems and applications;
- daily backups held off-site, with restores tested as part of our routine operations;
- logging and 24/7 monitoring of our infrastructure, with alerting to our engineers;
- confidentiality obligations for everyone who works with us, and secure handling of removable media;
- a documented incident response process, so that a breach is contained, assessed and reported.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will tell you without undue delay where the breach is likely to result in a high risk to you. Where we act as your processor, we notify you and you remain responsible for your own regulatory notifications.
No system is completely secure. Please use a strong, unique password for your account, enable two-factor authentication where we offer it, and tell us immediately at info@pocketmaze.site if you suspect unauthorised access.
11. Your rights
Under the UK GDPR you have the following rights. They are not absolute — for example we may need to keep information to comply with tax law, or to defend a legal claim — but we will always explain our reasoning if we cannot act on a request.
| Right | What it means in practice |
|---|---|
| Access | You can ask for a copy of the personal information we hold about you, together with information about how and why we use it. |
| Rectification | You can ask us to correct information that is inaccurate or incomplete. |
| Erasure | You can ask us to delete information where we no longer need it, where you have withdrawn consent, or where our use is unlawful. |
| Restriction | You can ask us to pause our use of your information while a dispute about it is resolved. |
| Portability | Where we process information by automated means on the basis of your consent or a contract, you can ask for it in a structured, commonly used, machine-readable format, or to have it sent to another provider. |
| Objection | You can object to processing based on our legitimate interests, and you have an absolute right to object to direct marketing. |
| Withdraw consent | Where we rely on consent, you can withdraw it at any time. |
| Automated decisions | You have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. We do not carry out such processing. |
| Complain | You can complain to us, and to the Information Commissioner’s Office — see section 15. |
To make a request, email info@pocketmaze.site with the subject “Data request”, or write to us at Suite 9165, 182-184 High Street North, East Ham, London E6 2JA, UK. We will respond within one month, and we do not charge for handling a request unless it is clearly unfounded or excessive (for example repeated requests). We may ask you to confirm your identity, and if you are asking on behalf of someone else we may ask for written authority. If your request concerns data you host with us (for example a mailbox on your domain), we may need to refer you to the organisation that controls that data, or to act on their instruction.
12. Marketing and communications
- If you are an existing customer we may email you about similar services, relying on the soft opt-in. Every message includes a one-click unsubscribe link.
- For anyone else we ask for consent before sending marketing, and you can withdraw it at any time.
- Reply STOP to any WhatsApp message, or email us, to opt out of marketing. We will still contact you about a service you have ordered, a payment, a renewal or a security issue — these are service messages and are not marketing.
- We keep a short suppression list so that we do not contact you after you have opted out.
13. Children
Our services are designed for businesses and professional users and are not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it promptly unless we are legally required to keep it.
14. External links and third-party services
Our website may link to third-party websites and we may resell or integrate third-party services. We are not responsible for how those organisations handle your information. Where a third party processes your information as a controller — for example a payment provider, a domain registry or a social network — its own privacy notice applies in addition to this one.
15. Complaints and the Information Commissioner’s Office
If you are unhappy with how we have handled your information, please tell us first. Email info@pocketmaze.site with the subject “Privacy complaint”. We will acknowledge it within 5 working days, investigate, and give you a substantive response within 30 days. Many issues can be resolved quickly once we know about them.
If you are not satisfied with our response, you have the right to complain to the UK supervisory authority:
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
If you live outside the United Kingdom, you may also complain to the supervisory authority in your country of residence or place of work.
16. Changes to this policy
We review this policy regularly and may update it to reflect changes in our services, our suppliers or the law. The version number and date at the top of the page always show the current version.
If we make a material change — for example a new category of data, a new purpose or a new category of recipient — we will tell you by email or by a prominent notice on the website at least 30 days before it takes effect, unless the change is required sooner by law or to respond to a security risk.
| Version | Date | Summary of change |
|---|---|---|
| 1.0 | 6 October 2026 | First publication of this policy. |
17. How to contact us
Questions about this policy, or about how we handle your information, can be sent to:
Suite 9165, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom
Email: info@pocketmaze.site
WhatsApp and telephone: +44 7418 355739
Support hours: Monday to Friday, 09:00–18:00 GMT
Registered in England & Wales, company number 15198808
This policy is provided in English. It is governed by the laws of England and ' 'Wales. If we translate it into another language for convenience, the English version prevails.' '
Ready to start? Talk to us today.
Tell us what you need — a website, a server, a domain or a piece of software. You will get a clear answer and a fixed quote, usually the same working day.