Privacy Policy
This Privacy Policy explains how Webmatx Ltd ("Webmatx", "we", "us", "our") collects, uses, and protects personal data when you use our website at webmatx.com, our AI website builder platform at app.webmatx.com, or engage us for professional services.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
The data controller is Webmatx Ltd, a company registered in England and Wales. You can contact us about data matters at [email protected].
2. What Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (hashed by Clerk) | You provide this when signing up |
| Business data | Business name, type, description, phone, contact email, logo | You provide this in the website builder wizard |
| Payment data | Subscription plan, billing history (card details held by Stripe only) | Stripe processes payments; we store subscription metadata |
| Generated content | AI-generated website pages, domain choices, service areas | Created during your use of our platform |
| Communications | Messages sent via our contact form or email | You provide this when contacting us |
| Usage data | Pages visited, features used, browser type, IP address | Collected automatically via server logs |
We do not sell your personal data to any third party.
3. How We Use Your Data
- To provide and operate the Webmatx platform and services
- To process payments and manage your subscription
- To send transactional emails (receipts, account notifications)
- To respond to enquiries and provide customer support
- To improve our platform and services
- To comply with legal obligations
4. Legal Basis for Processing
- Contract performance — processing necessary to deliver the services you have signed up for
- Legitimate interests — operating and improving our business, fraud prevention, security
- Legal obligation — where we are required to process data by law
- Consent — where you have given consent (e.g. marketing emails, if applicable)
5. Third-Party Services
We use the following third-party processors. Each operates under its own privacy policy and data processing agreements.
- Clerk — authentication and user account management (US/EU)
- Stripe — payment processing and subscription management (US/EU)
- Resend — transactional email delivery (US)
- Supabase — database and file storage (EU region)
- Vercel — platform hosting and edge delivery (global CDN)
- Anthropic (Claude API) — AI content generation for website copy
- Cloudflare — DNS, CDN, and security for webmatx.com
Where data is transferred outside the UK, we rely on UK adequacy decisions, Standard Contractual Clauses, or other appropriate safeguards.
6. Cookies
Our marketing website (webmatx.com) uses only essential cookies required for site functionality. Our platform (app.webmatx.com) uses session cookies necessary for authentication. We do not use advertising or tracking cookies. You can find more detail in our cookie banner.
7. Data Retention
- Account data: retained for the duration of your account, plus 90 days after deletion
- Payment records: retained for 7 years as required by UK tax law
- Generated website content: retained while your subscription is active; deleted 30 days after cancellation
- Contact form messages: retained for up to 2 years
8. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data ("right to be forgotten")
- Restrict or object to processing
- Data portability (receive your data in a structured format)
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include encrypted connections (HTTPS/TLS), hashed passwords, access controls, and regular security reviews.
10. Children
Our services are not directed at children under 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes by email. The current version is always available at webmatx.com/privacy.
12. Contact
For any privacy-related queries: [email protected]
Webmatx Ltd, London, United Kingdom