Privacy
Last updated
Comatter uses limited personal information to run and secure this website, understand basic aggregate use and performance, respond when people contact us and administer the company. This notice covers the activities we control today.
This notice covers this website and the company activities above. It does not cover our products, which run on their own domains under their own privacy information. Lightpass is in a supervised pilot on lightpass.app; its customer and prospect data is stored and processed within the UK or EU unless the customer and Comatter explicitly agree a documented exception, and its own privacy information covers that processing. Moonbound is at the validation stage and processes no personal data.
Who we are
The data controller is Comatter Ltd, registered in England and Wales under company number 17388932, with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF. You can reach us about anything on this page at hello@comatter.co.uk.
What we use and why
Visiting this website
Cloudflare Pages receives IP address, request and header data, device and network information and security or activity events to deliver and protect these static pages. We rely on our legitimate interests in running a reliable and secure public site.
Cloudflare Real User Measurements is currently enabled outside its documented UK and European exclusion. For those other connections, Cloudflare may collect in-memory page, referrer and performance and resource timing information to produce aggregate basic-use and website-performance statistics. We rely on legitimate interests in understanding use, finding faults and improving performance. Cloudflare says this feature does not use cookies or browser storage, does not track people over time and discards the source IP address before storing the performance data. We do not use it for advertising, cross-site tracking, visitor profiles or individual-level action logs, and we do not create a Comatter raw export or secondary analytics store.
If you contact us
We use your name, contact details, organisation or role and the content of the correspondence to reply, take steps you request before a contract and keep a necessary record of the conversation. We rely on legitimate interests in responding and administering the relationship, and on pre-contract steps where you request them.
Company, supplier and account administration
We use necessary business-contact, due-diligence, contract, invoice and payment information, company records and account, author, access and audit metadata to run and secure the company. The basis is contract or requested pre-contract steps where applicable, legal obligation and our legitimate interests in ordinary administration, security, source integrity and legal claims.
We receive this information from you, your organisation, normal account or service activity and official or ordinary business records. We do not ask for special-category or criminal-offence information through this website or an ordinary enquiry. Please do not send it unless we have agreed a lawful and secure route.
We do not sell personal information, share it with data brokers or advertising networks, or make solely automated decisions with legal or similarly significant effects in these activities.
Who receives information
We use the following current services only where the activity needs them:
- Cloudflare Pages and its account-level request/security logging and aggregate performance measurement for this website;
- Microsoft 365 and OneDrive for correspondence and company records;
- GitHub for private source repositories;
- ChatGPT Business for bounded internal business and development work;
- Google Cloud Identity for company browser profiles, credential management and sign-ins; and
- Monzo Bank Limited as the separate UK controller providing company banking.
We may also disclose information where law requires it or where necessary to establish, exercise or defend legal claims. None of these services is approved by this notice for live customer or product data.
International access and transfers
Our cloud providers operate internationally, so information may be processed outside the UK. Their standard public terms describe different routes, including UK adequacy regulations and contractual safeguards such as the UK Addendum to the EU standard contractual clauses. The applicable route depends on the provider, service and recipient. You can contact us for information about the relevant safeguard or how to obtain a copy.
We do not claim that data stays in the UK or EU. Before a service receives live customer/product data or materially higher-risk information, we complete the specific provider, recipient and transfer review for that use.
How long we keep information
- We use Cloudflare's standard service retention for website request, security, activity and performance data while the feature is needed for delivery, security and aggregate site improvement, and review that need annually. We do not create a Comatter raw export, visitor profile or secondary analytics store.
- We review ordinary closed enquiries annually and delete them 24 months after the last substantive contact, unless an active contract, right, complaint, legal duty or legal hold requires longer.
- Formation and share records are permanent. We normally keep signed contracts for their term plus seven years, tax, account, invoice and receipt records for seven years and insurance records for seven years after expiry.
- We keep account, audit and source history while access, security and source integrity require it, then remove access and unnecessary exports. Provider technical periods vary by service.
- We normally keep a closed data-protection rights or complaint case for three years. We extend this to six years only when a recorded material claims or accountability reason requires it.
A documented legal hold may pause deletion for its stated scope and review period. Incidental personal information does not automatically inherit the longest corporate-record period.
Your rights
Depending on the activity and lawful basis, you may have rights to access, correct or erase your personal information, restrict its use, receive portable information or object to processing. Contact us to exercise a right. We may need proportionate information to verify your identity or authority.
Your right to object
You can object to processing based on our legitimate interests. We will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. An objection to direct marketing is absolute, although we do not currently carry out direct-marketing processing.
Complaints
You can make a data-protection complaint to us at hello@comatter.co.uk. We will acknowledge an applicable complaint within 30 days, investigate and respond without undue delay, keep you informed and tell you the outcome.
You can also complain to the Information Commissioner's Office at ico.org.uk. You do not have to complain to us first.
Cookies and similar technologies
The website source sets no cookies or browser storage, embeds no advertising network and serves fonts from this domain. Cloudflare's account-level RUM feature is described above because it can be injected by the hosting layer even though it is absent from the repository. Under the current setting, Cloudflare documents that RUM is excluded for connections handled in the UK and listed European countries. We will not enable it for UK connections without first providing the clear information and simple, free objection mechanism required for that use.
Changes
We review this notice when a purpose, data type, service, provider, location, retention rule or law materially changes. We update the date and provide information at the relevant collection point before a new use begins.