Microface Limited
Privacy policy
This policy explains how Microface Limited handles personal information connected with this website and enquiries about our business.
Last updated:
1. Who is responsible
Microface Limited is registered in England and Wales under company number 01576383. Our registered office is Woodcock Hall, Cobbs Brow Lane, Newburgh, Wigan, England, WN8 7NB. Microface Limited is the controller of personal information covered by this policy. Contact us at sales@microface.com, telephone +44 (0)1257 463225, or write to our registered office. Please mark privacy enquiries for the attention of the Managing Director.
2. Information we receive
When you contact us, we receive the information you choose to provide, such as your name, business contact details, organisation, project requirements, correspondence and attachments. We may also receive business contact details from colleagues acting on your organisation's behalf. Website delivery and security services may record technical information such as IP addresses, requested pages, browser details, timestamps and errors.
3. How the enquiry form works
The form sends your details securely to our website server for validation and onward email delivery to sales@microface.com. Enquiry content is not saved in a website database, but is handled by our hosting and email providers and retained in our correspondence. To prevent abuse, the server keeps submission timestamps and a keyed, hashed identifier derived from your IP address. Rate limits use 15-minute and one-hour windows; expired entries are removed when a subsequent valid request is processed. Providing enquiry details is voluntary, but without sufficient contact and project information we may be unable to respond or prepare a proposal.
4. Purposes and lawful bases
We use personal information under the UK GDPR and Data Protection Act 2018, as amended. The basis depends on the purpose:
- Legitimate interests: responding to business enquiries, preparing proposals for organisations, managing business relationships and protecting our website and communications. Our interests are operating our engineering business, communicating with customers and preventing misuse, balanced against your rights.
- Contract: taking steps at your request before entering into a contract with you personally, or performing that contract.
- Legal obligation: retaining records or making disclosures required by applicable law.
- Consent: where we specifically ask for it for a particular purpose. You can withdraw it at any time without affecting processing already carried out lawfully.
5. Service providers and disclosures
Information may be handled by providers of website hosting, email, IT support and security, and by professional advisers where necessary for the purposes above. We may disclose information where legally required or necessary to establish, exercise or defend legal claims. Preparing an enquiry is not consent to unrelated marketing. If you separately accept advertising measurement, we load Google's advertising tag to measure advert effectiveness and successful enquiries. Google may receive your IP address, browser and device information, cookie or advertising identifiers and page information. Our conversion event does not include your name, email, organisation or enquiry content. We do not enable enhanced conversions or personalised advertising. This optional processing relies on consent; use Cookie settings to withdraw it. Withdrawal does not undo data already sent to Google.
How Google uses information from partner sites6. International processing
Hosting, email and support arrangements may involve processing outside the United Kingdom. Where a restricted international transfer is made, UK data protection law requires an applicable adequacy arrangement, appropriate safeguards or a permitted exception. Contact us for information about the locations and transfer arrangements applicable to your information, including how to obtain details of relevant safeguards.
7. Retention and security
We retain information only for as long as needed for its purpose. Relevant criteria include whether an enquiry remains active, the duration of a customer relationship, ongoing equipment support, record-keeping obligations and applicable periods for legal claims. Technical records are retained according to operational and security needs. Appropriate access and security measures should protect personal information, but no internet or email service can be guaranteed completely secure. Please contact us before sending sensitive or confidential material.
8. Your rights
Depending on the circumstances and applicable exemptions, you may request access to your personal information, correction, erasure, restriction of processing and transfer of information in a portable form. You may withdraw consent where processing relies on consent. Contact us using the details above to exercise these rights. We may need information to verify your identity and will respond within the applicable statutory timeframe.
9. Your right to object
You may object to processing based on legitimate interests on grounds relating to your particular situation. You also have the right to object at any time to use of your personal information for direct marketing, including related profiling. Contact sales@microface.com to raise an objection.
10. Complaints
If you are concerned about our handling of personal information, please contact us so we can investigate. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator.
Contact the ICO or make a complaint11. Cookies, automated decisions and changes
The website does not make solely automated decisions about you with legal or similarly significant effects. Our cookie policy explains website storage and tracking. We may update this privacy policy as the website or our practices change; the date below identifies this version.
Read the cookie policy12. Restricted staff access
Approved staff sign in through Google, which provides a verified email address and account identifier for access checks. Session records and security logs protect restricted administration and record administrative activity. These features are separate from public browsing and do not provide access to staff email messages. Access records and backups are restricted and retained according to operational and security needs.