Privacy Policy

Last updated 1 August 2026

MidnightUX designs and builds websites for small businesses. This policy explains what personal data we handle, why we handle it, who we share it with, how long we keep it, and the rights you have over it. If we contacted you and you never gave us your details, section 04 answers that directly and tells you how to make us stop.

01Who we are and how to reach us

Data controller
MidnightUX is a trading name, not a registered company. The controller is founder one, full legal name and founder two, full legal name, trading as MidnightUX. Until a company is registered, they contract with you personally.
Country of establishment
Bangladesh
Contact for everything
hello@midnightux.com

We run a single mailbox. Privacy questions, rights requests, opt-out requests and general enquiries all go to the same address, and all of them reach a person. Put the topic in the subject line if you can. To opt out of contact from us, “stop” in the subject line is enough.

We aim to acknowledge every privacy request within 5 business days, and to resolve it within the deadlines set out in Your rights below.

Data Protection Officer

We have not appointed one. Our core activities are not large-scale systematic monitoring and we do not process special category data at scale, so we do not believe Article 37 requires it.

02Quick summary

The whole policy is below. This is the short version of the questions people actually ask.

Do you sell my personal data?
No. We have never sold personal data and we do not share it for cross-context behavioural advertising.
Do you contact people who did not ask to hear from you?
Yes, businesses, subject to the regional rules in Marketing and outreach below.
Where does your prospect data come from?
Public business listings, business websites, public directories and map listings. See Where we get prospect data.
Can I make you stop?
Yes. Immediately, permanently, and with no reason required. One email to hello@midnightux.com.
Where is my data processed?
Bangladesh, plus our service providers in the US and the EU. See International transfers.
Do you use tracking cookies?
Only if you consent. Analytics storage is denied by default. See Cookies and analytics.
Do you handle sensitive data?
No. We do not seek health, biometric, financial account, religious, political or sexual orientation data, and we ask that you do not send it.

03What we collect, and why

This policy covers four groups of people, and the answers are not the same for each: visitors to this website, people who book a call, clients, and prospects we contact who did not contact us first.

Website visitors

When you load this website, our hosting provider and our own logs necessarily process:

  • IP address. Delivering the page, security, abuse prevention and rate limiting.
  • Browser, device and operating system. Rendering correctly and diagnosing faults.
  • Pages viewed, time on page, referring URL. Understanding what people find useful.
  • Approximate location, derived from IP at city level. Security and coarse analytics only. We do not collect GPS or precise location.
  • Campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, gbraid, wbraid, fbclid, msclkid) from the link you clicked, so we know which campaign brought you here.

Campaign parameters are stored in your browser under the sessionStorage key ms_campaign. This is first-touch only, it is cleared when you close the tab, and it is not a cookie. We also store your scroll position in sessionStorage so that reloading does not lose your place. Neither is used to build a profile of you.

Analytics storage is denied until you consent. The Google tag loads with storage switched off and runs cookieless, and it is not granted storage unless you accept on the banner. See Cookies and analytics.

People who book a call

Our booking flow has two steps. In the first, on our own site, we ask for:

  • Your name. Required, so we can address you correctly and put a name on the calendar invitation.
  • Your email address. Required, to send the confirmation and meeting link, and to reply to you.
  • A message about your project. Optional, so the call is useful from the first minute.
  • Which button you pressed. Collected automatically, so we know whether you want a consultation, the $399 package, the $699 package or a custom quote.
  • Your stored campaign parameters. Collected automatically, for attribution.

In the second step the booking calendar is provided by Cal.com. When you choose a time, Cal.com processes your name, email address, chosen time slot and timezone under its own privacy policy, as an independent controller for its own platform operations and as our processor for the booking itself.

Once a booking is confirmed, Cal.com sends us a signed webhook and we send two emails over SMTP: a confirmation to you, and a notification to ourselves. Those contain your name, email address, the chosen time, your timezone, the meeting link and any message you wrote.

We do not ask for, and do not want, your phone number, postal address, date of birth, financial account details or any government identifier at this stage.

Clients

If you engage us, we additionally process what the work requires:

  • Billing contact name, billing email, billing address, and tax or VAT registration number where applicable.
  • Payment references. We do not store full card numbers. Payments are handled by a third-party payment provider, which is the controller of your payment instrument data. We will tell you which provider before you pay.
  • Credentials and access you choose to give us: domain registrar, hosting, CMS logins, DNS, repository access, analytics accounts and brand assets.
  • Project correspondence, briefs, feedback, revision notes and approvals.
  • The content you supply for the site, which may itself contain personal data about your staff or customers. Where that happens we act as your processor. See When we act for our clients.

04Where we get prospect data

This section is our notice under Article 14 of the GDPR and Article 14 of the UK GDPR, which apply when personal data is obtained from somewhere other than the person it describes. If we contacted you and you did not give us your details, this is the section that explains it.

What we collect about prospects

We collect business contact information only:

  • Business or organisation name.
  • Business website address.
  • A publicly listed business email address, and where published, a general business phone number.
  • A publicly listed business address.
  • A role or job title, and where it is published alongside the business listing, the name of a contact person.
  • Publicly visible information about the business’s existing website: whether it exists, whether it is mobile-friendly, and how quickly it loads. This is how we decide whether our service is relevant to you at all.

We do not collect personal email addresses, personal mobile numbers, home addresses, or any special category data, and we do not enrich, append, infer or purchase additional data about individuals.

The sources we use

Publicly accessible business websites
Business contact details published by the business itself, on “Contact” and “About” pages.
Public business directories and industry listings
Business contact details.
Public map and local business listings
Business name, category, public phone, public address and website link.
Professional and business networking profiles
Business contact details and role, where the person has published them.
Referrals
Name, business and business contact details, where an existing contact passes them on.

Why we are allowed to do this

We rely on legitimate interests (GDPR Article 6(1)(f)) to identify businesses that may want a website and to make a first, relevant, business-to-business approach. We rely on legitimate interests here and will explain our reasoning on request. The factors that keep the balance in favour of processing are that the data is business data published by the business, the volume per person is minimal, we do not profile individuals, and we make stopping trivially easy.

How to make us stop

Your right to object is absolute where the purpose is direct marketing. Under Article 21(2) there is no balancing test and no grounds are needed. If you tell us to stop, we stop, permanently, without asking why.

Do any one of these:

  • Reply “stop” or “unsubscribe” to any message we send.
  • Click the unsubscribe link in any email.
  • Email hello@midnightux.com.

When you opt out we keep the minimum record needed to honour it, which is your email address or phone number in a suppression list. We keep that indefinitely, because deleting it is how people get contacted a second time. That retention rests on our legitimate interest in not contacting you again, and on compliance with anti-spam law. You can ask us to delete the suppression record instead, and we will explain the consequence before doing so.

How long we keep prospect data

If you do not respond
6 months from first contact, then deleted.
If you tell us you are not interested
Deleted within 30 days, except the suppression record.
If you opt out
Deleted within 30 days, except the suppression record.
If you become a client
Retained under the client rules in How long we keep data.

06Marketing and outreach by region

We contact businesses. The rules differ by where the recipient is, and we apply the stricter rule when in doubt.

European Union and EEA

The GDPR governs whether we may hold the data. The ePrivacy Directive (2002/58/EC), implemented separately by each member state, governs whether we may send the message. These are different questions, and passing one does not pass the other.

  • Email to a named individual at a business is treated as email to a natural person in several member states and requires prior consent.
  • Germany requires prior consent for advertising email, including business-to-business, under UWG §7. We do not send cold email to Germany without consent.
  • Italy and Austria apply similarly strict rules.
  • France, the Netherlandsand several others permit business-to-business email to a role or generic business address, where the offer relates to the recipient’s professional function, with a clear opt-out in every message.
  • Generic role addresses (info@, contact@, hello@) are lower risk than named individual addresses in most member states, and are our default.

Every message we send to the EEA carries our identity, our contact details, the reason you are hearing from us, where we got your details, and a working one-click opt-out.

United Kingdom

Under PECR, unsolicited marketing email to corporate subscribers (limited companies, LLPs, public bodies) is permitted with clear identification and an opt-out. Marketing email to sole traders and unincorporated partnerships is treated as marketing to individuals and requires consent or the soft opt-in. We check corporate status before emailing UK contacts.

United States

  • Email. We do not send unsolicited commercial email to recipients in the United States. The CAN-SPAM Act requires a valid physical postal address in every commercial message, and we do not currently publish one, so we do not run US cold email at all. If that changes, this section changes first.
  • Calls. We do not make marketing calls.
  • Texts. We do not send marketing SMS.

Canada

CASL requires express or implied consent before sending a commercial electronic message. Implied consent may exist where a business address is conspicuously published without a statement refusing unsolicited messages, and the message is relevant to that person’s role. We rely only on that narrow route, and we treat the implied-consent window as expiring on the statutory timetable.

Australia

The Spam Act 2003 requires consent, which may be inferred where a work address is conspicuously published without a statement refusing unsolicited messages and the message is relevant to the role. Every message identifies us and carries a functional unsubscribe.

Everywhere else

We apply the strictest of the recipient’s local law, this policy, and the platform terms of whatever channel we are using.

What we never do

  • Use false or misleading sender names, subject lines or headers.
  • Conceal that a message is a commercial approach.
  • Continue after an opt-out.
  • Contact people at addresses obtained by circumventing a technical restriction, a login wall, or a robots.txt exclusion.
  • Buy or rent marketing lists, or sell ours.
  • Send unsolicited messages to personal email addresses or personal mobile numbers.

07Who we share data with

We do not sell personal data. We share it with the following recipients, each under their standard data processing terms or a written contract.

Cal.com
Name, email, chosen time, timezone and booking notes. Processor for the booking, controller for its own platform. US and EU.
Google (Gmail and Workspace SMTP)
The contents of confirmation and notification emails. Processor. US and global.
Google (Meet)
Meeting link and participants. Processor. US and global.
Google Analytics 4
Pseudonymous usage data, only with consent. Processor. US and global.
Our hosting provider
Request logs and IP addresses. Processor. US and EU.
Our payment provider
Billing name, email and payment instrument. Independent controller.
Our accountant
Invoices and billing records. Processor or independent controller. Bangladesh.
Professional advisers and insurers
Only what a specific matter requires. Independent controllers.
Law enforcement, courts and regulators
Only what is legally compelled. Independent controllers.

We may also disclose data in connection with a merger, acquisition or sale of assets, in which case we will give notice before your data becomes subject to a different policy.

We do not share personal data for cross-context behavioural advertising, and we do not permit our processors to use it for their own marketing.

08International transfers

We are established in Bangladesh. If you are in the EEA, the UK or Switzerland, your personal data will be transferred outside your home territory when you deal with us.

Bangladesh is not the subject of an adequacy decision by the European Commission or the UK Government. Transfers therefore rely on appropriate safeguards.

You to us
Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), plus the UK International Data Transfer Addendum for UK data.
Us to our processors
Standard Contractual Clauses in each processor agreement, or the processor’s own certified transfer mechanism.
Occasional transfers needed to perform your contract
The Article 49(1)(b) derogation, used only where it genuinely applies.

Our supplementary measures include encryption in transit (TLS) for all communications, access limited to the individuals working on your project, and a commitment to challenge any government access request that appears unlawful and to notify you unless legally prohibited.

You may request a copy of our Standard Contractual Clauses, with commercial terms redacted, from hello@midnightux.com.

09How long we keep data

Website server logs
30 days. Security and diagnostics.
Analytics data
14 months. The GA4 default, kept short deliberately.
Campaign parameters in sessionStorage
Until you close the tab. Attribution only.
An enquiry that does not become a project
12 months from last contact, so we recognise you if you return.
Prospect data, no response
6 months.
Prospect data, declined or opted out
30 days, except the suppression record.
Suppression list
Indefinite, so we never contact you again.
Client project files and correspondence
3 years after the project ends. Support, warranty and dispute defence.
Contracts
6 years after the contract ends. Limitation periods.
Invoices, accounting and tax records
6 years. Legal obligation.
Backups
Rolling 30 days. Backups are overwritten, not individually edited.

When a retention period ends we delete the data or irreversibly anonymise it. If deletion from a backup is not technically possible, we isolate the data and delete it on the next backup cycle.

10Your rights

If you are in the EEA or the UK, the GDPR or UK GDPR gives you the rights below. We extend these same rights to everyone we deal with, wherever you live. It is simpler than running two standards, and it is the right way to behave.

Access
Get confirmation of whether we hold data about you, and a copy of it.
Rectification
Have inaccurate data corrected, and incomplete data completed.
Erasure
Have your data deleted, where no legal obligation requires us to keep it.
Restriction
Have us pause processing while a dispute about accuracy or legitimate interests is resolved.
Portability
Receive data you gave us in a structured, machine-readable format, where processing is based on consent or contract and is automated.
Object
Object to processing based on legitimate interests. For direct marketing this right is absolute and we will always comply.
Withdraw consent
At any time, as easily as you gave it.
Not be subject to automated decisions
We do not make decisions with legal or similarly significant effects by automated means.
Complain
Lodge a complaint with a supervisory authority. See Complaints.

How to exercise a right

Email hello@midnightux.com and tell us what you want. You do not need to use a form or particular wording.

We may ask you to confirm your identity, but only proportionately. For a request about an email address, replying from that address is usually enough. We will not demand identity documents where a lesser check will do.

Our deadlines. One month under the GDPR and UK GDPR, extendable by two further months for complex requests, in which case we will tell you within the first month and explain why. 45 days under US state laws, extendable by a further 45 days.

Our fee. None. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain our reasoning and your right to complain if we ever do.

11Rights in California and other US states

We honour the following for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and every other US state with a comprehensive privacy law.

  • Right to know what personal information we collect, the sources, the purposes and the categories of recipient. This policy is that disclosure.
  • Right to delete personal information we hold about you.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We have not sold or shared personal information in the preceding 12 months, including the personal information of minors under 16.
  • Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
  • Right to non-discrimination. We will never charge you more, give you less, or refuse to work with you because you exercised a privacy right.
  • Authorised agents may submit requests on your behalf with written proof of authorisation.

Categories collected in the last 12 months, in CCPA terminology: identifiers (name, email, IP address), commercial information (services enquired about and purchased), internet activity (pages viewed, referral source), and professional or employment information (job title, employer) for business contacts. We collect these for the purposes stated above, and retain them per How long we keep data.

Global Privacy Control. We honour the GPC browser signal as a valid opt-out request where our analytics are in use.

12Cookies, analytics and tracking

What we actually set

ms_campaign
sessionStorage, not a cookie. First-touch campaign attribution, cleared when the tab closes.
Scroll position
sessionStorage. Returns you to your place on reload. Strictly necessary for the interface to work.
ms_consent
localStorage, not a cookie. Holds one word, your answer to the analytics banner, so we do not ask again on every visit. It is the one thing here that survives closing the tab, because a consent decision that expires with the session means being asked over and over, which is its own kind of pressure.
Google Analytics 4
Cookies and local storage, to understand how the site is used. Requires your consent.

Consent

We use Google Consent Mode v2. Denied by default: analytics_storage, ad_storage, ad_user_data and ad_personalization. Analytics runs cookieless, or does not run at all, until you grant consent on the banner. functionality_storage and security_storage are granted, because the site cannot function or stay secure without them.

The three advertising signals stay denied whatever you choose, because we run no advertising tags at all. Accepting the banner grants exactly one thing, analytics_storage, and nothing else.

Third-party embeds, in particular the Cal.com booking calendar, may set their own storage when the booking step loads. That embed only loads after you open the booking dialog and reach step two, which is an action you take deliberately.

Your controls

  • Cookie settings, in the footer of every page, reopens the same two-button banner. Withdrawing is the same click as granting.
  • Browser settings let you block or delete cookies and clear local storage.
  • The Google Analytics opt-out browser add-on is at tools.google.com/dlpage/gaoptout.
  • We honour the Global Privacy Control signal.
  • We do not respond to legacy “Do Not Track” headers, which have no agreed meaning.

13Security

Our measures include:

  • TLS for all traffic to and from the site, and for SMTP.
  • HMAC-SHA256 signature verification on the Cal.com booking webhook, using a constant-time comparison, so that no one can forge a booking event.
  • Secrets held only in environment variables, never in the repository, with server-only modules enforced at build time so credential-reading code can never be bundled into the browser.
  • Least privilege. Access to client systems is limited to the people working on the project, and is handed back or revoked at project end.
  • Multi-factor authentication on our email, hosting, repository and registrar accounts.

No system is perfectly secure and we do not claim otherwise. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify you directly and without undue delay where the risk is high. Where we act as a processor for a client, we will notify that client without undue delay so they can meet their own deadline.

Please do not send us passwords, card numbers, government identifiers or health information by email. If we need credentials from you, we will ask you to share them through a secure channel.

14Children

Our services are for businesses. This site is not directed at children, we do not knowingly collect personal data from anyone under 16, and we have no features intended to appeal to children.

If you believe a child has given us personal data, contact hello@midnightux.com and we will delete it promptly. We do not knowingly sell or share the personal information of anyone under 16, and as stated above we do not sell or share personal information at all.

15Automated decisions and AI

We do not make decisions producing legal or similarly significant effects about you by solely automated means. A person reads every enquiry and decides every engagement.

We use AI tools in two distinct ways, and we keep them separate.

  1. In our own work. We may use AI assistants to help write code, draft copy or summarise notes. Where a tool would process personal data belonging to you or your customers, we use business or enterprise tiers configured so that inputs are not used to train the provider’s models, and we tell you if a specific tool is needed for your project.
  2. In what we build for clients. Where you ask us to integrate AI features into your website, the resulting processing is yours as controller, not ours. We will document the provider, the data flows and the retention in the project handover so that you can describe it accurately in your own privacy policy. See the Terms of Service for the associated disclaimers.

We do not use your personal data, your project content, or prospect data to train any AI model of our own.

16When we act for our clients

When we build or maintain a website, we may process personal data belonging to your customers, staff or site visitors. In that relationship you are the controller and we are the processor. We will:

  • Process that data only on your documented instructions.
  • Impose confidentiality obligations on everyone we let near it.
  • Apply the security measures set out above.
  • Not engage a sub-processor without your prior general or specific authorisation, and give you notice of intended changes so you can object.
  • Assist you with data subject requests, breach notification, DPIAs and prior consultation, so far as we reasonably can.
  • Delete or return the data at the end of the engagement, at your choice.
  • Make available the information you need to demonstrate compliance, and allow audits on reasonable notice.

This policy is a notice, not a contract. Where the personal data concerned relates to individuals in the EEA or the UK, these commitments will be captured in a signed Data Processing Agreement meeting Article 28(3), with Standard Contractual Clauses attached for the transfer to Bangladesh. Ask for one and we will put it in place before the work starts.

17Complaints

Please raise it with us first at hello@midnightux.com. We would rather fix it than have you go elsewhere, and we will respond substantively.

You always have the right to go straight to a regulator.

EEA
The supervisory authority in your country of residence, place of work, or where the issue arose. The list is at edpb.europa.eu.
United Kingdom
The Information Commissioner’s Office, ico.org.uk, helpline 0303 123 1113.
California
The California Privacy Protection Agency, cppa.ca.gov, and the California Attorney General.
Other US states
Your State Attorney General.
Canada
The Office of the Privacy Commissioner, priv.gc.ca.
Australia
The Office of the Australian Information Commissioner, oaic.gov.au.

18Changes to this policy

We will update this policy when our practices change. The “Last updated” date at the top always reflects the current version.

For material changes, meaning changes to what we collect, why we collect it, who we share it with, or your rights, we will give 30 days’ notice by email to clients and to anyone who has given us their address, and by a prominent notice on the site. Where a change requires your consent, we will ask for it rather than assume it.

Previous versions are available on request from hello@midnightux.com.