Privacy Policy
Version 5.0 | Last updated 18 May 2026
This Policy explains how Mocono Technologies Ltd collects and uses personal data when you visit our website, enquire about or use our platform, or otherwise deal with us. It also explains the more limited role we play when we handle data on behalf of a publisher customer. Please read section 3 carefully — it determines which parts of this Policy apply to you.
1. Who We Are
1.1 Controller: Mocono Technologies Ltd ("Mocono", "we", "our", "us") is a company registered in England and Wales under company number 12613304, with its registered office at 47 Butt Road, Colchester, Essex, England, CO3 3BZ. Where we act as a controller, Mocono Technologies Ltd is the controller of your personal data.
1.2 Registration: We are registered with the Information Commissioner's Office under registration number ICO:00011779727.
1.3 Contact: Data protection enquiries should be sent to privacy@mocono.co.uk or by post to our registered office marked for the attention of the Data Protection Lead. We are not required to appoint a Data Protection Officer and have not done so; the Data Protection Lead is our designated point of contact.
2. The Law We Follow
2.1 We comply with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 ("PECR"). Where we process the personal data of individuals in the European Economic Area in circumstances to which Regulation (EU) 2016/679 ("EU GDPR") applies, we comply with that Regulation in respect of that processing. References in this Policy to "applicable data protection law" mean the above as amended or replaced from time to time.
3. Our Two Roles — Please Read This First
3.1 As a controller: We are the controller of personal data relating to our own business: our website visitors, prospective and actual publisher customers, the individual contacts at those publishers, billing contacts, support contacts, job applicants and suppliers. Sections 4 to 15 of this Policy apply to that data.
3.2 As a processor: Our platform provides paywalling and subscriber management services to publishers. When a publisher uses our platform, we process personal data relating to that publisher's subscribers, registrants and website visitors strictly on the publisher's documented instructions. In that context the publisher is the controller and Mocono is the processor. We do not decide why or how that data is used.
3.3 If you are a subscriber to a publication: This Policy does not describe how your personal data is used. That is determined by the publisher whose publication you subscribe to or register with, and is described in that publisher's own privacy notice. If you contact us directly about such data, we will, wherever we can identify the relevant publisher, forward your request to them and confirm to you that we have done so. We are not able to grant, refuse or otherwise action such a request ourselves without the publisher's instruction.
3.4 Cookies on publisher websites: Cookies, local storage and similar technologies set by our paywall and entitlement scripts on a publisher's website are deployed on that publisher's behalf and under its control. It is the publisher's responsibility to provide the required notice and, where applicable, to obtain consent under PECR. Section 10 of this Policy covers only cookies set on Mocono's own website.
4. Personal Data We Collect as a Controller
4.1 Data you give us: Name, job title, employer, business email address, business telephone number, postal address, publication and title details, account credentials, billing and bank or card details, correspondence and support tickets, event and webinar registrations, marketing preferences, and any other information you choose to provide.
4.2 Data we generate: Account activity, configuration choices, support history, service usage statistics, invoices and payment history, and internal notes relating to our relationship with you.
4.3 Data collected automatically: IP address, approximate location derived from IP address, device and browser type, operating system, referring page, pages viewed, session duration, and interactions with our emails such as opens and link clicks. This is collected through cookies and similar technologies as described in section 10.
4.4 Data from third parties: We obtain business contact data and firmographic information from publicly available sources such as company websites, Companies House, trade directories and professional networking sites, and from reputable business data providers and enrichment services. We use this only in a business-to-business context, to identify and contact organisations that may have a professional interest in our services. Where we obtain data in this way we will, where required, tell you within one month of obtaining it or at the point of first contact, whichever is earlier.
4.5 Special category data: We do not seek to collect special category personal data or criminal offence data in the ordinary course of business, and ask that you do not provide it to us unsolicited.
5. Why We Use Your Data and Our Lawful Bases
The table below sets out our purposes and the lawful basis on which we rely for each. Where we rely on legitimate interests, the interest concerned is identified.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the platform and the services under our Terms and Conditions | Account, contact, configuration, usage and support data | Performance of a contract; legitimate interests where the contract is with your employer rather than with you personally (interest: delivering the services we are engaged to deliver) |
| Onboarding, support, service messages and administration | Account, contact, support and correspondence data | Performance of a contract; legitimate interests (interest: administering the customer relationship) |
| Invoicing, payment collection and credit control | Billing, bank or card, transaction and correspondence data | Performance of a contract; legal obligation (tax and accounting); legitimate interests (interest: recovering sums due) |
| Securing, monitoring and troubleshooting the platform, and preventing fraud and abuse | Technical, log, usage and account data | Legitimate interests (interest: protecting the security and integrity of our systems and our customers' data); legal obligation |
| Improving, developing and testing our products, including analytics and benchmarking | Usage, technical and aggregated data | Legitimate interests (interest: understanding how our products are used so we can improve them) |
| Training and evaluating machine learning and AI models | Aggregated and anonymised usage data only. We do not use subscriber personal data held on behalf of publishers to train general-purpose models. | Legitimate interests (interest: developing our products). Where data has been effectively anonymised it is no longer personal data and data protection law does not apply to it. |
| Business-to-business marketing, including email, telephone and postal outreach and remarketing | Business contact data, marketing preference data, engagement data | Legitimate interests (interest: promoting our services to relevant businesses), subject to your right to object at any time. Where PECR requires consent, we rely on consent. |
| Producing anonymised industry insight, benchmarks and case studies | Aggregated and anonymised usage data | Legitimate interests (interest: publishing sector research and demonstrating our services) |
| Complying with legal, regulatory, tax and accounting obligations, and responding to lawful requests | Any relevant data | Legal obligation |
| Establishing, exercising or defending legal claims, and in connection with a sale, merger or reorganisation of our business | Any relevant data | Legitimate interests (interest: protecting our legal position and conducting corporate transactions) |
| Recruitment | Application, CV, interview and right to work data | Legitimate interests and steps prior to entering a contract; legal obligation for right to work checks |
5.1 Legitimate interests: Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interests against your rights and freedoms, and we have concluded that our processing is proportionate and would be within your reasonable expectations. You may request a summary of the relevant assessment using the contact details in section 1.3.
5.2 Consent: Where we rely on consent, you may withdraw it at any time using the contact details in section 1.3 or the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.3 Change of purpose: If we need to use your personal data for a purpose other than that for which we collected it, we will assess whether the new purpose is compatible with the original one, and where it is not, we will notify you and identify the lawful basis on which we rely.
6. Marketing
6.1 Business-to-business marketing: We market our services to businesses. Where permitted by PECR, we may send marketing emails to corporate subscribers and to individuals at corporate bodies without prior consent, and to existing and prospective customers under the soft opt-in where we obtained your details in the course of a sale or negotiations. Every marketing message includes a means of opting out.
6.2 Opting out: You may opt out of marketing at any time, free of charge, by using the unsubscribe link in any message or by contacting us. We will action opt-outs promptly and will maintain a suppression record so that we do not contact you again; that suppression record is itself retained indefinitely for the purpose of honouring your objection.
6.3 Service messages: Opting out of marketing does not stop service, billing, security and contractual messages, which we are required or entitled to send while you hold an account.
7. Who We Share Data With
7.1 Service providers: We share personal data with providers who support our business, including cloud hosting and infrastructure, payment processing, email delivery, customer relationship management, support ticketing, analytics, accounting and professional advisers. Each is bound by written terms restricting their use of the data to the provision of services to us.
7.2 Sub-processors: Where we act as a processor for a publisher, we appoint sub-processors under the general written authorisation given in our Data Processing Addendum. A current list of sub-processors is maintained on our platform.
7.3 Publishers: Where you are a contact at a publisher customer, we may share your details with colleagues at that publisher who administer the account.
7.4 Legal and corporate: We may disclose personal data where required by law, regulation, court order or a competent authority, to enforce or apply our terms, to protect the rights, property or safety of Mocono, our customers or others, and to a prospective or actual buyer, investor or successor in connection with a sale, merger, financing or reorganisation of our business, subject in each case to appropriate confidentiality protections.
7.5 No sale of data: We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
8. International Transfers
8.1 Our primary infrastructure is located in the United Kingdom. Some of our service providers process personal data outside the UK. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, which will be one of: (a) a determination of adequacy by the UK Government; (b) the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or (c) another mechanism permitted by applicable data protection law. You may request details of the safeguards applying to a particular transfer using the contact details in section 1.3.
9. How Long We Keep Data
9.1 Principle: We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax and reporting requirements and to establish, exercise or defend legal claims.
9.2 Indicative periods: Unless a longer period is required by law or is necessary for a live or anticipated claim, we apply the following as a guide:
- Customer account and contract records: for the duration of the relationship and for six years after it ends, reflecting the limitation period under the Limitation Act 1980.
- Invoicing, payment and accounting records: six years from the end of the relevant accounting period.
- Marketing and prospect data: for so long as the contact remains commercially relevant, and reviewed at least every twenty-four months.
- Suppression and opt-out records: indefinitely, in order to honour your objection.
- Website analytics and log data: up to twenty-six months.
- Unsuccessful job applications: twelve months.
9.3 Publisher data: Personal data we process on behalf of a publisher is retained in accordance with that publisher's instructions and our Terms and Conditions and Data Processing Addendum. Following termination we make the data available for export for thirty days and may then delete it from our live systems.
9.4 Anonymised data: We may retain and use indefinitely data which has been aggregated or anonymised so that it can no longer be used to identify an individual. Such data is not personal data and this Policy does not restrict our use of it.
9.5 Backups: Data deleted from our live systems may persist in encrypted backups for a limited period before being overwritten in the ordinary course of our backup cycle.
10. Cookies and Similar Technologies
10.1 Our website: We use strictly necessary cookies to operate our website and secure your session. We also use analytics, functional and marketing cookies, which are set only where you have given consent through our cookie banner.
10.2 Managing cookies: You may withdraw or change your cookie consent at any time through the cookie settings link on our website, or by adjusting your browser settings. Disabling strictly necessary cookies may prevent parts of our website from working.
10.3 Details: A current list of the cookies we set, their purpose and their duration is available at [cookie policy URL].
10.4 Publisher websites: As explained in section 3.4, cookies set by our scripts on a publisher's website are the responsibility of that publisher.
11. Automated Decision-Making
11.1 We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. We do use automated tools to score and prioritise sales leads and to detect fraudulent or abusive activity; these are subject to human review before any decision materially affecting an individual is taken.
12. Security
12.1 We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls on a least-privilege basis, network segregation, logging and monitoring, staff confidentiality obligations and training, and supplier due diligence. No system can be guaranteed to be completely secure, and transmission of data over the internet is at your own risk.
12.2 Incidents: We maintain a personal data breach response procedure and will notify the ICO and affected individuals where required by applicable data protection law. Where we act as a processor, we will notify the relevant publisher without undue delay.
13. Your Rights
13.1 Your rights: Subject to the conditions and exemptions in applicable data protection law, you have the right to:
- Access — obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — have inaccurate personal data corrected and incomplete data completed.
- Erasure — have personal data deleted where there is no good reason for us to continue processing it.
- Restriction — ask us to suspend processing in certain circumstances.
- Portability — receive certain data in a structured, commonly used, machine-readable format.
- Object — object to processing based on legitimate interests, and to object at any time and absolutely to processing for direct marketing.
- Withdraw consent — where we rely on consent.
- Automated decisions — not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects.
13.2 How to exercise them: Contact us using the details in section 1.3. Please tell us clearly which right you wish to exercise and provide enough detail for us to locate the relevant data.
13.3 Verification: We may ask you for information to verify your identity before responding. This is a security measure to ensure personal data is not disclosed to the wrong person. The response period does not begin until we have received the information we reasonably require.
13.4 Timescales and fees: We respond without undue delay and in any event within one month. We may extend that period by up to two further months where a request is complex or where a number of requests have been received, and will tell you within one month if we do so. Requests are free of charge, but we may charge a reasonable fee based on administrative cost, or refuse to act, where a request is manifestly unfounded or excessive, in particular where it is repetitive. We will explain our reasons if we do so.
13.5 Exemptions: Some rights are qualified and do not apply in all circumstances. Where we are unable to comply with a request in whole or in part, we will explain why, and we will inform you of your right to complain to the ICO and to seek a judicial remedy.
13.6 If we are the processor: If your request relates to data we hold on behalf of a publisher, please see section 3.3.
14. Complaints
14.1 If you are unhappy with how we have handled your personal data, please contact us first using the details in section 1.3 so that we have the opportunity to resolve the matter. You also have the right at any time to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. If you are in the EEA you may complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
15. Changes, Links and Contact
15.1 Changes: We may update this Policy from time to time. The date at the top of this Policy shows when it was last revised. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention, by email or a notice on our website, before it takes effect.
15.2 Third party links: Our website and platform may contain links to third party websites. We are not responsible for the privacy practices of those websites and encourage you to read their privacy notices.
15.3 Children: Our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under the age of 18 in a controller capacity.
15.4 Contact: Questions about this Policy should be directed to privacy@mocono.co.uk.
This Policy should be read together with our Publisher Terms and Conditions, our Data Processing Addendum and our Cookie Policy.

