Privacy policy
This policy explains what personal data M&R Tech Company Ltd collects through this website, why, and what rights you have. It is written to satisfy the UK GDPR, the Data Protection Act 2018 and Regulation (EU) 2016/679.
1. Controller
M&R Tech Company Ltd, company number 16622857, registered office at Suite 3h,
The Old Courthouse, Chapel Street, Dukinfield, England, SK16 4DT.
Contact for any data protection question: contact@mr-tech.io.
2. What this website collects
Browsing this website does not require you to give us any personal data. The site contains no contact form, no account, no analytics and no advertising trackers. Fonts and scripts are served from our own servers, so loading a page sends no data to any third party.
Two categories of data are nevertheless processed:
- Server logs. Our web server records the IP address, the date and time, the page requested, the HTTP status and the browser user agent. This is necessary to operate the service and to detect abuse or attacks.
- Data you send us. If you write to us at the address published on the site, we process the content of your message and the details you choose to include — typically your name, your email address, your company and your request.
3. Why we process it, and on what basis
- Server logs — legitimate interest (Article 6(1)(f) GDPR): keeping the site available and secure.
- Messages you send — steps taken at your request prior to entering into a contract (Article 6(1)(b)) or legitimate interest in replying to a business enquiry (Article 6(1)(f)).
We do not use your data for automated decision-making or profiling, and we do not sell it.
4. How long we keep it
- Server logs: 12 months maximum, then deleted.
- Business correspondence: for the duration of the exchange and up to 3 years after the last contact, unless a contract or a legal obligation requires longer.
- Accounting records relating to a contract: as required by applicable law.
5. Who can access it
Access is limited to the M&R staff who need it to answer you or to operate the infrastructure. Personal data is hosted on servers located inside the European Union and is not transferred outside the European Economic Area. Where an exchange with the United Kingdom is necessary, it relies on the European Commission's adequacy decision for the UK.
We use no advertising network, no third-party analytics provider and no external font or script CDN on this website.
6. Security
The site is served over HTTPS with a strict Content-Security-Policy and modern security headers. Access to our systems is restricted, logged and protected by strong authentication.
7. Your rights
You have the right to request access to your personal data, its rectification or erasure, the restriction of its processing, and its portability, and to object to processing based on legitimate interest.
To exercise those rights, write to contact@mr-tech.io. We answer within one month.
If you are not satisfied with our answer, you may complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the European Union, to the supervisory authority of your country of residence.
8. Clients of our services
When we operate software or infrastructure for a client, we act as a processor on that client's instructions. That relationship is governed by a written data processing agreement concluded under Article 28 GDPR, which is separate from this policy.
9. Changes
This policy may be updated. The date below indicates the current version.
Last updated: 4 September 2026.