1. Who we are
Mercurium Analytics Ltd. ("Mercurium", "we", "us") is the data controller of the personal data we process through our marketing site and the Mercurium platform. We're registered in England & Wales. Our contact address is on the contact page.
2. What data we collect
On the marketing site
- Contact-form submissions — name, email, company, the message you send us.
- Technical telemetry — IP address, browser, pages visited (only with your consent via our cookie banner).
On the Mercurium platform
- Account data — name, work email, role, organisation.
- Content you upload — documents, data rooms and workflow outputs are the property of your organisation; we process them under instruction.
- Usage logs — authentication events, actions inside the product, aggregated performance metrics.
3. Why we process it (legal basis)
- Legitimate interest — replying to your enquiry, protecting the site from abuse.
- Contract performance — operating the Mercurium platform for your organisation.
- Consent — optional analytics cookies, marketing emails you explicitly sign up for.
- Legal obligation — KYC/AML checks where we ourselves act as a regulated counterparty.
4. Who we share data with
We don't sell data. We share it only with sub-processors who power the product under a written Data Processing Agreement — hosting (Railway, Cloudflare), authentication (Auth0), email (SendGrid), and product analytics (PostHog, EU region only). A full up-to-date list is available on request.
5. Where data lives
Our production infrastructure is EU-resident by default. Where we deploy on customer tenancy (private GPU, on-premise), data never leaves the customer environment. We make documented exceptions for regulated sub-processors where GDPR-equivalent safeguards (Standard Contractual Clauses, UK IDTAs) are in place.
6. How long we keep data
- Contact enquiries — 24 months from last interaction, then deleted.
- Account data — for the duration of the subscription + 12 months for statutory backup retention.
- Customer content — retained as long as the customer's workspace is active, or as contracted in the DPA.
7. Your rights
Under UK GDPR / EU GDPR you can ask us to access, rectify, erase or port your personal data, and you can object to or restrict certain processing. Email contact@mercurium-analytics.com — we'll reply within 30 days.
8. Cookies
See our cookie preferences page. Strictly necessary cookies only by default; analytics cookies only with explicit consent.
9. Changes to this policy
We'll post material changes here with a new effective date. Substantial changes to paying customers' data handling trigger written notice under the DPA.