1. Who we are
Mozomay Ltd, referred to as "we" or "us", company number 17318563, registered office 128 City Road, London, EC1V 2NX, United Kingdom, is the data controller for the personal data described in this policy, except where we act as a processor as described in section 7.
Our ICO registration number will be published here once our registration is confirmed.
Contact for any privacy matter: lawand@mozomay.com.
2. Two roles. Please read this
- As a controller: we decide how we handle the personal data of the people who run the garages that subscribe to Mozomay, including account holders, contacts and prospects. Sections 3 to 6 cover this.
- As a processor: when a subscribing garage enters data about its own customers, including names, contact details, vehicle registrations, damage photos and job notes, the garage is the controller and we process that data only on its instructions, to provide the service. Section 7 covers this.
3. What we collect as controller
- Account and contact data: name, business name, email, phone and role.
- Billing data: handled by our payment provider Stripe. We receive confirmation and limited details, such as the last 4 digits and billing name, not full card numbers.
- Usage data: how you use the platform, log data, and device or browser information.
- Marketing and enquiry data: information you give when booking a demo, filling in a form, or contacting us.
- Cookies and analytics: see our Cookie Policy.
4. How we use it and our lawful bases
- To provide the service and manage your account: performance of a contract.
- To take payment and prevent fraud: contract or legitimate interests.
- To support you and respond to enquiries: legitimate interests or contract.
- To send service emails, including onboarding and account notices: contract.
- To send marketing, including our product emails and ads: legitimate interests or consent where required. You can opt out at any time.
- To improve and secure the platform and meet legal obligations: legitimate interests or legal obligation.
6. International transfers
Where a provider processes data outside the UK, we rely on appropriate safeguards, such as UK adequacy regulations or the International Data Transfer Agreement or Addendum, to protect it.
7. Garage customers' data, where we are a processor
When a garage uses Mozomay to manage its own customers, it controls that data and we process it under our Terms and the Data Processing Agreement below. We process it only to provide the service and on the garage's instructions, apply appropriate security, do not use it for our own marketing, and return or delete it after the account ends. If you are a customer of a garage that uses Mozomay and have a request about your data, please contact that garage. We will assist them as their processor.
8. How long we keep data
- Account and service data: for as long as you are a customer, then deleted within 30 days of cancellation. You can request an export first.
- Billing records: kept as long as required for legal or tax purposes.
- Marketing and enquiry data: until you opt out or it is no longer needed.
9. How we protect data
We use appropriate technical and organisational measures, including encryption in transit using SSL and access controls. No system is perfectly secure, but we work to keep your data safe and will notify you and the ICO of a reportable breach as required.
10. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to processing, and to data portability, and to withdraw consent where we rely on it. To exercise any right, email lawand@mozomay.com. You can also complain to the Information Commissioner's Office, though we would appreciate the chance to help first.
11. Changes
We may update this policy and will post the current version here with a new "last updated" date.
Annex
Data Processing Agreement
When a garage enters its customers' personal data, including names, contact details, vehicle registrations and damage photos, into Mozomay, the garage is the controller and Mozomay is the processor. UK GDPR Article 28 requires a written processing contract. This DPA forms part of, and is governed by, the Terms of Service.
1. Parties and roles
This DPA is between Mozomay Ltd, the "Processor", and the subscribing business, the "Controller" or garage. It applies whenever Mozomay processes personal data on the Controller's behalf in providing the service.
2. Definitions
"UK GDPR", "personal data", "processing", "data subject", "personal data breach", "sub-processor" and "supervisory authority" have the meanings given in UK data protection law, including UK GDPR and the Data Protection Act 2018.
3. Subject matter, duration, nature and purpose
- Subject matter and duration: processing for the term of the Controller's subscription and the 30-day post-termination retention window.
- Nature and purpose: to provide, operate, support and secure the Mozomay platform.
- Types of personal data: the Controller's customers' names, contact details, vehicle details, damage descriptions and photographs, job and communication records, and the Controller's own staff or user account data.
- Categories of data subjects: the Controller's customers and staff.
4. Processor obligations under UK GDPR Article 28(3)
Mozomay shall: process the personal data only on the Controller's documented instructions, including the Terms and use of the service, unless required by law; ensure persons authorised to process it are under a duty of confidentiality; implement appropriate technical and organisational security measures; engage sub-processors only under clause 5; assist the Controller, so far as possible, in responding to data-subject requests; assist the Controller with security, breach notification and data protection impact assessments; at the Controller's choice, delete or return the personal data at the end of the service; and make available information necessary to demonstrate compliance and allow for audits.
5. Sub-processors
- The Controller gives general authorisation for Mozomay to engage sub-processors to provide the service. Current sub-processors include Stripe for payments, Hostinger for website hosting, Google including Firebase and Google Analytics, Calendly for demo bookings, and Meta for advertising measurement.
- Mozomay will impose data-protection terms on each sub-processor no less protective than this DPA, and remains liable for their performance.
- Mozomay will give the Controller prior notice of any new or replacement sub-processor and allow a reasonable period to object on reasonable data-protection grounds.
6. International transfers
Where personal data is transferred outside the UK, Mozomay will ensure an appropriate safeguard is in place, such as UK adequacy regulations or the International Data Transfer Agreement or Addendum.
7. Security
Mozomay maintains appropriate technical and organisational measures, including encryption of data in transit using SSL or TLS, access controls and authentication, logical separation of customer data, regular backups, and staff access on a least-privilege basis.
8. Return or deletion
On termination, Mozomay will, at the Controller's choice, return or delete the personal data within 30 days, consistent with the cancellation policy in the Terms, except where retention is required by law.
9. Audit
Mozomay will make available information reasonably necessary to demonstrate compliance with Article 28 and contribute to audits, subject to reasonable confidentiality, security, frequency and notice conditions.
10. Breach
Mozomay will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with the information the Controller needs to meet its own obligations.
11. Liability and precedence
This DPA forms part of the Terms. In the event of conflict on data-protection matters, this DPA prevails. Liability is subject to the limitations in the Terms.
