Mrixton & Co
Terms of ServicePrivacy PolicyCookie Policy

Legal

Privacy Policy

This Policy explains what personal data we collect, why we process it, how long we keep it, who we share it with, and the rights available to you under UK data protection law (and, where applicable, similar rights for visitors elsewhere).

Last updated: 10 July 2026 · Governing law: England and Wales

1. Who is responsible for your data

The data controller for personal data collected via this website and our discovery booking tools is Mrixton & Co("Mrixton & Co", "we", "us", or "our").

Contact for privacy matters: contact@mrixton.com.

This Policy is designed for compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where PECR (Privacy and Electronic Communications Regulations) applies to cookies or electronic marketing, those rules also apply — see our Cookie Policy. If you are in the European Economic Area or another jurisdiction with similar data-protection laws, we apply equivalent protections where those laws require us to do so.

2. Scope

This Policy covers personal data we process when you interact with us from the UK or internationally, including when you:

  • visit or interact with https://mrixton.com;
  • submit a discovery, qualification, or contact form;
  • book or attend a discovery call;
  • email or otherwise contact us;
  • access a token-gated platform preview we provide.

If we later provide a production software platform that processes your tenants', landlords', or employees' data on your instructions, that processing will be governed by a separate data processing agreement and product privacy terms. Platform previews currently use mock data and are not intended for live personal data.

3. Personal data we collect

3.1 Information you provide

Depending on the form or interaction, this may include:

  • Identity and contact — first name, last name, email address, phone number (including country code), job title, company name, and company website;
  • Business qualification — approximate portfolio size (units band), team size, current tools, primary operational pain point, service interest (software, AI visibility audit, or both), buying timeline, and operating region (for example whether you are UK-based or international);
  • Booking details — preferred call time, time zone, and related scheduling information;
  • Communications — content of emails, call notes, and follow-up correspondence you send us.

3.2 Information collected automatically

  • Technical and usage data — approximate location derived from IP for security/rate-limiting, browser and device characteristics, pages viewed, and performance metrics via our hosting analytics providers;
  • Session identifiers — a randomly generated lead identifier stored in your browser session storage to correlate multi-step form progress;
  • Marketing attribution — UTM parameters (for example utm_source and utm_campaign) if present in the URL when you submit a form;
  • Cookies and similar technologies — as described in our Cookie Policy.

3.3 Information we do not intentionally collect via the Site

We do not ask website visitors for special category data (such as health or biometric data), payment card details on the Site, or live tenant/landlord records through demo forms. Demo portal forms in preview environments are client-side illustrations and are not designed to transmit real personal data to our servers.

4. How we use personal data and legal bases

We process personal data only where we have a lawful basis under UK GDPR:

PurposeExamplesLegal basis
Respond to enquiries and run discoveryQualify interest, schedule calls, send confirmationsLegitimate interests (B2B sales and service delivery); contract steps where you request a booking
Operate and secure the SiteRate limiting, abuse prevention, diagnosticsLegitimate interests (security and service integrity)
Analytics and performanceUnderstand Site usage and improve experienceLegitimate interests; consent where required for non-essential cookies
Marketing to business contactsFollow-up about our services where permittedLegitimate interests and/or PECR soft-opt-in / consent as applicable
Legal and complianceKeep records, respond to lawful requestsLegal obligation; legitimate interests
Perform a paid engagementDeliver software or audit services under an OrderContract; legitimate interests

Where we rely on legitimate interests, we balance our interests against your rights. You may object to processing based on legitimate interests as described in Section 10.

Partial form captures (for example, an email address saved when you begin a multi-step form) are used to reduce drop-off friction and allow us to follow up on incomplete enquiries. You can ask us to delete that data at any time.

5. Who we share data with

We do not sell personal data. We share data with service providers who process it on our instructions and under appropriate contractual protections, including:

  • Hosting and analytics — Vercel (website hosting, analytics, and speed insights);
  • Productivity and CRM tooling — Google Workspace services such as Google Sheets (lead records) and Google Calendar / Google Meet (scheduling and meetings);
  • Email delivery — Resend (transactional confirmation and notification emails), when configured;
  • Optional booking widgets — Calendly, only if we enable that fallback booking path.

We may also disclose data to professional advisers, or where required by law, regulation, legal process, or to protect rights, safety, and security. In a corporate transaction (merger, acquisition, or asset sale), data may transfer to the successor entity under equivalent protections.

6. International transfers

Some providers may process data in the United Kingdom, European Economic Area, United States, or other countries. Where personal data is transferred outside the UK, we use appropriate safeguards required by UK GDPR, such as the UK International Data Transfer Agreement / Addendum, adequacy regulations, or other lawful transfer mechanisms offered by the provider.

7. How long we keep data

We retain personal data only as long as needed for the purposes above:

  • Enquiry and lead records — typically up to 24 months from last meaningful contact, unless a longer period is needed for an active opportunity or legal claim;
  • Booked call and calendar records — for the period needed to run the meeting and related follow-up, then in line with our ordinary business records practices;
  • Contract and billing records — for the life of the engagement plus up to 6 years (or longer if required for tax or legal reasons);
  • Security and rate-limit logs — short periods necessary for abuse prevention.

When retention ends, we delete or irreversibly anonymise data where practicable.

8. Security

We implement appropriate technical and organisational measures, including access controls, encrypted transport (HTTPS), least-privilege credentials for integrations, and rate limiting on booking APIs. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

9. Marketing and B2B outreach

If you enquire about our services, we may contact you about similar products or services using the details you provided, in line with PECR and UK GDPR (and equivalent rules where they apply to international contacts). You can opt out of marketing emails at any time by replying "unsubscribe" or emailing contact@mrixton.com.

Separately, we may conduct B2B prospecting using publicly available business information (for example, company registries and company websites) for legitimate sales outreach in the UK and other markets we serve. That activity is not based on data you submit through this Site. Recipients can ask us to stop contacting them and we will honour suppression requests.

10. Your rights

Under UK GDPR, you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data in certain circumstances;
  • restrict or object to certain processing (including direct marketing);
  • data portability, where applicable;
  • withdraw consent where processing is consent-based, without affecting prior lawful processing;
  • lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EEA, you may also complain to your local supervisory authority.

To exercise these rights, email contact@mrixton.com. We may need to verify your identity before responding. We aim to respond within one month, subject to extensions permitted by law for complex requests.

11. Children

Our services are directed at businesses and are not intended for children under 18. We do not knowingly collect personal data from children.

12. Automated decision-making

Our qualification flow may compute an internal fit score to help prioritise enquiries. This assists our team; it does not produce solely automated decisions with legal or similarly significant effects about you. You may contact us to discuss how an enquiry was handled.

13. Changes to this Policy

We may update this Policy periodically. The "Last updated" date will change when we do. Material changes will be posted on this page. Continued use of the Site after an update constitutes awareness of the revised Policy.

14. Contact

Privacy questions or requests: contact@mrixton.com.

Registered office and company number will be added to this Policy when a registered legal entity is confirmed.

Questions

For questions about these terms or your personal data, contact us at contact@mrixton.com.

Mrixton & Co

Bespoke software and AI visibility audits for property management companies worldwide.

ServicesHow It WorksFAQContact
Terms of ServicePrivacy PolicyCookie Policy

© 2026 Mrixton & Co · contact@mrixton.com · Platform preview available on request