Privacy Policy

Last updated: 22 August 2026

Millerweb Limited (“Millerweb”, “we”, “us” or “our”) is a specialist technology, data and AI consultancy providing senior technology leadership, data strategy and architecture, responsible AI and agentic systems, and bespoke digital product engineering.

Millerweb Limited is registered in England and Wales under company number 05773346.

Registered office:
Union House
111 New Union Street
Coventry
England
CV1 2NT

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act (incorporating provisions under the Data (Use and Access) Act), Millerweb Limited is the data controller where we determine how and why personal information is processed.

You can contact us through the contact form at www.millerweb.biz, by email at info@millerweb.biz, or by writing to our registered office.

1. Who we are

Millerweb Limited combines senior technology and data leadership with hands-on engineering to turn complex data, AI, and digital ideas into practical, secure, and trustworthy systems. We operate across four main service areas:

  • Data Systems & Strategy: Designing data platform architectures, governance frameworks, data warehouses, and integration pipelines.
  • Artificial Intelligence & Agentic Systems: Building pragmatic machine learning systems, natural language processing, retrieval-augmented generation (RAG), and secure, tool-using agentic workflows with human oversight.
  • Technology Leadership: Providing Fractional / Virtual CTO advisory, technology roadmaps, cloud architecture, cybersecurity oversight, and technical due diligence.
  • Digital Products & Platforms: Engineering bespoke software, SaaS platforms, Data-as-a-Service solutions, APIs, and mobile-friendly applications.

2. Information we collect

Depending on how you interact with us, we may collect:

  • Contact details: Your name, business email address, organisation name, job title, and telephone number.
  • Enquiry information: Details, project goals, service interests, and messages submitted via our website contact form.
  • Correspondence: Records of communications, emails, and scoping discussions.
  • Contract & billing information: Information required to manage commercial agreements, deliver contracted services, issue invoices, and maintain accounting records.
  • Technical and usage telemetry: Device type, approximate browser configuration, and non-personal navigation telemetry collected via Google Analytics 4 (only when you have consented to analytics).

Our website does not collect sensitive personal data or special category data through public forms.

3. How we use personal information

We process personal information for the following purposes:

  • To evaluate, respond to, and process enquiries submitted through our website.
  • To discuss, prepare, and deliver technology consultancy proposals and commercial contracts.
  • To deliver our contracted services, manage projects, and provide technical leadership.
  • To maintain client, partner, and supplier relationships.
  • To issue invoices, process payments, and comply with UK statutory financial and tax accounting requirements.
  • To operate, protect, and harden our website and infrastructure against security threats, misuse, and spam.
  • To measure website engagement and user interaction on an aggregated, non-personal basis (subject to your consent).
  • To establish, exercise, or defend legal claims where necessary.

4. Our lawful bases for processing

Under the UK GDPR, we process personal information on the following lawful bases:

  • Contractual necessity (Article 6(1)(b)): Processing necessary to take steps at your request prior to entering into a contract, or to perform a contract with you.
  • Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate commercial interests (such as responding to professional inquiries, securing our systems, and managing client relationships), where those interests are not overridden by your privacy rights.
  • Legal obligation (Article 6(1)(c)): Processing necessary to comply with statutory legal, accounting, tax, or regulatory duties in England and Wales.
  • Consent (Article 6(1)(a)): Where you have provided specific, informed consent, such as opting into website analytics cookies via our Cookie Notice Banner. You can withdraw your consent at any time.

5. Responsible AI and automated processing

Responsible AI is integral to Millerweb's practice. When designing, developing, and deploying AI and intelligent systems, we operate under clear ethical and technical principles:

  • Privacy by Design: Personal data inputs to AI systems are minimized, pseudonymized where appropriate, and protected by strict architectural boundaries.
  • Human-in-the-Loop Oversight: We do not conduct solely automated decision-making that produces legal or similarly significant effects regarding individuals. Critical decisions retain human oversight.
  • Zero Unauthorized Training: Client confidential information and personal data are never used to train public or commercial foundation models without express written authorisation.
  • Data Provenance & Auditability: AI-assisted workflows and agentic pipelines maintain deterministic logs and auditable data lineages.

6. Third-party processors & data sharing

We work with carefully vetted, reputable third-party technology providers to operate our business infrastructure:

  • FormSubmit.co: Secure form routing processor used to transmit website contact form inquiries to our administrative email. Form data is transmitted securely over TLS.
  • Google Analytics 4 (Google Ireland Limited / Google LLC): Used to measure aggregated website interaction metrics under strict Consent Mode v2 (active only upon explicit consent, with zero PII transmission).
  • Hosting & Cloud Infrastructure (e.g. Fly.io): Used to run our containerised web services in secure UK/European data centres.
  • Productivity & Email Providers: Secure enterprise email and document storage providers.
  • Professional Advisors: Accountants, legal advisors, and insurers where necessary for professional compliance.

We do not sell, rent, or trade personal information to any third parties for advertising or commercial exploitation.

7. International data transfers

Where third-party service providers process data outside the United Kingdom, we ensure that appropriate safeguards are in place in accordance with the UK GDPR, such as UK International Data Transfer Agreements (IDTAs), European Commission Standard Contractual Clauses (SCCs) with the UK Addendum, or relevant adequacy regulations.

8. Data retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:

  • General enquiries: Retained for up to 24 months following the last meaningful communication, after which they are securely deleted.
  • Client contracts & project records: Retained for the duration of the engagement and up to 7 years thereafter to comply with statutory legal, accounting, and tax requirements.
  • Web security logs: Retained for up to 90 days for operational threat monitoring before automatic rotation.

9. Security measures

We implement proportionate technical and organizational safeguards to protect personal data, including:

  • Enforced HTTPS/TLS encryption across all web traffic.
  • Hardened web server security headers (Content Security Policy, anti-clickjacking headers, and strict MIME protections).
  • Honeypot mechanisms and anti-bot verification on contact forms.
  • Least-privilege access controls, multi-factor authentication, and encrypted data storage.

10. Your individual rights

Under UK data protection law, you have the following rights regarding your personal information:

  • Right of access: Request a copy of the personal information we hold about you.
  • Right to rectification: Request correction of any inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data where retention is no longer necessary.
  • Right to restriction: Request that we restrict the processing of your data in certain circumstances.
  • Right to data portability: Request a transfer of your personal information to you or a third party in a structured, commonly used format.
  • Right to object: Object to processing based on our legitimate interests.
  • Right to withdraw consent: Withdraw any previously given consent at any time without affecting the lawfulness of prior processing.

11. Inquiries and complaints

To exercise any of your rights or raise a data protection concern, please contact us at:

Email: info@millerweb.biz
Post: Millerweb Limited, Union House, 111 New Union Street, Coventry, CV1 2NT, UK

In accordance with the Data (Use and Access) Act provisions, we acknowledge complaints within 30 days and conduct investigations without undue delay.

You also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

12. Changes to this Privacy Policy

We review and update this Privacy Policy periodically. The latest version will always be published on our website at www.millerweb.biz/privacy-policy.html.