Privacy & cookies
Last updated 2 September 2026
Who we are
Mutual is a trading name of We Make Stuff Ltd, a company registered in England & Wales (No. 10364574, VAT No. 249706085). For anything on this page we are the data controller — responsible for how your data is used, and answerable for it.
- Post
- 23 St Leonards Road, Bexhill-On-Sea, East Sussex, United Kingdom, TN40 1HH
- hello@mutual.agency
- Phone
- 01424 559 858
- Data protection officer
- Emma Browne — emma.browne@mutual.agency
- ICO registration
- ZA411596
Anything about your data — a question, a request, a complaint — goes to Emma Browne, our data protection officer, at emma.browne@mutual.agency. General enquiries are better off at hello@mutual.agency.
What we collect
When you fill in a form
The enquiry forms on this site — the contact form, the enquiry form on a service page, and the email gate on our tour video — ask for your name and email address, along with whatever you tell us in the message. Some of them also offer optional fields: your timescale, your budget, anything else you want us to know, and where you heard about us.
Those submissions are emailed straight to us and are not written to a database, a CRM or anything else. The only record of your enquiry is that email in our inbox. You also get a short confirmation email so you know it arrived.
When you opt in to hear from us
The forms have an unticked box for marketing email. Tick it and your name and email go to Mailchimp, who run our mailing list. Leave it alone and they don't — we'll only reply about the thing you contacted us about.
When you just read the site
We use Plausible to count visits. It sets no cookies, reads nothing from your device and builds no profile of you — it produces aggregate numbers (pages, referrers, countries, rough device type) and nothing that identifies a person. There is no cross-site tracking on this website.
When you book a call
Our "book a call" panel embeds Google's appointment scheduling. If you use it, the booking is made with Google Calendar and what you type goes to Google as well as to us. Nothing from Google is requested until you've accepted marketing cookies and opened the panel — if you'd rather not use it, email or ring us and we'll book a time directly.
When you watch a video
Our videos are hosted by Vimeo and play in their player, loaded with Vimeo's do-not-track setting on. It waits for your consent: until you accept marketing cookies nothing is requested from Vimeo at all, so they don't see your visit.
Behind the scenes
Our hosting keeps standard server logs — IP address, browser, what was requested, when — for a short period, so outages and abuse can be investigated. We don't analyse them for anything else.
What we don't collect
No accounts, no advertising pixels, no fingerprinting, no session recording, no heatmaps, and no special category data. We don't buy data about you from anyone else, and we don't make decisions about you automatically.
Lawful basis
UK GDPR requires a lawful basis for each use of your data. Ours:
- Answering your enquiry — steps towards a contract, and our legitimate interest in running an agency people can contact. You asked us a question; we need your details to answer it.
- Marketing email — your consent, given by ticking the box, withdrawable from the unsubscribe link in every email or by telling us.
- Client work — performance of our contract with you, plus our legal obligations to keep accounting records.
- Cookieless analytics and server logs — our legitimate interest in knowing whether the site works and keeping it secure. Because our analytics store nothing on your device, this doesn't need consent under PECR.
- Spam protection on our forms — our legitimate interest in not being buried in automated submissions.
- Cookies that aren't strictly necessary, and the third-party embeds — your consent, through the cookie banner.
How long we keep it
- Enquiries that didn't go anywhere — the email stays in our inbox while we're talking, then gets cleared out after two years.
- Client records — for the length of the relationship, then seven years for the parts HMRC requires us to keep.
- Mailing list — until you unsubscribe, and we remove inactive subscribers periodically anyway.
- Consent records — twelve months, then you're asked again.
- Server logs — a short rolling window set by our host.
- Analytics — aggregate counts with no personal data in them, kept indefinitely.
Data outside the UK
Some of the suppliers above are based in the United States. Where personal data reaches them, the transfer relies on the UK's approved safeguards — the UK extension to the EU–US Data Privacy Framework where the supplier is certified under it, and the International Data Transfer Addendum to the EU standard contractual clauses where it isn't.
If you'd like to know which safeguard applies to a particular supplier, ask us and we'll tell you.
Your rights
Under UK GDPR you can ask us to:
- Show you what personal data we hold about you, and a copy of it.
- Correct anything that's wrong or incomplete.
- Delete it, where we've no continuing reason to keep it.
- Restrict what we do with it while a dispute is sorted out.
- Stop using it for a purpose you object to — including marketing, which we'll always honour.
- Move it, in a portable format, to you or someone else.
You can also withdraw consent at any time, for the things we rely on consent for. Withdrawing it doesn't undo what was done while it was in force.
Email emma.browne@mutual.agency and we'll respond within a month. It's free, and we won't ask you to justify the request.
If we get it wrong, you're entitled to complain to the Information Commissioner's Office — ico.org.uk/make-a-complaint, or 0303 123 1113. We'd rather you gave us the chance to fix it first, but that's your call.
Changes
When we change how we handle personal data, this page changes with it and the date at the top moves. If a change is significant and we hold your email address, we'll email you about it.
This page was last updated on 2 September 2026.