Privacy & cookies

Last updated 3 September 2026

Who we are

Mutual is a trading name of We Make Stuff Ltd, a company registered in England & Wales (No. 10364574, VAT No. 249706085). For anything on this page we are the data controller — responsible for how your data is used, and answerable for it.

Post
23 St Leonards Road, Bexhill-On-Sea, East Sussex, United Kingdom, TN40 1HH
Email
hello@mutual.agency
Phone
01424 559 858
Data protection officer
Emma Browne — emma.browne@mutual.agency
ICO registration
ZA411596

Anything about your data — a question, a request, a complaint — goes to Emma Browne, our data protection officer, at emma.browne@mutual.agency. General enquiries are better off at hello@mutual.agency.

What we collect

When you fill in a form

The enquiry forms on this site — the contact form, the enquiry form on a service page, and the email gate on our tour video — ask for your name and email address, along with whatever you tell us in the message. Some of them also offer optional fields: your timescale, your budget, anything else you want us to know, and where you heard about us.

Those submissions are emailed straight to us and are not written to a database, a CRM or anything else. The only record of your enquiry is that email in our inbox. You also get a short confirmation email so you know it arrived.

When you opt in to hear from us

The forms have an unticked box for marketing email. Tick it and your name and email go to Mailchimp, who run our mailing list. Leave it alone and they don't — we'll only reply about the thing you contacted us about.

When you just read the site

We use Plausible to count visits. It sets no cookies, reads nothing from your device and builds no profile of you — it produces aggregate numbers (pages, referrers, countries, rough device type) and nothing that identifies a person. It builds no profile of you and follows you nowhere else.

When you visit from a company network

If you accept marketing cookies, we also run Leadfeeder, made by Dealfront. It takes the network address your visit arrives from and looks it up in a database of business networks, which tells us that someone at a company read a particular page. The lookup names an organisation, not a person, and it isn't precise: home broadband and mobile connections come back as the internet provider rather than a business, and those are discarded.

We use it to see which businesses are interested in us — and then, often, to start a conversation. That means we may approach whoever at that company looks like the right person to talk to, usually by finding them on LinkedIn — a marketing lead, say — and messaging them there. That part is just us doing the research anyone can do: your visit tells us the company and nothing whatsoever about who was reading it.

If we do get in touch, we'll say plainly that it's because the company turned up on our site. Tell us you'd rather not hear from us and that's the end of it, for good — you don't have to give a reason. We approach people at work, about work, and never at a personal address.

Leadfeeder sets its own cookies so that repeat visits from the same browser join up. None of this runs until you accept marketing cookies on the banner: decline, and nothing is requested from Dealfront at all.

When you book a call

Our "book a call" panel embeds Google's appointment scheduling. If you use it, the booking is made with Google Calendar and what you type goes to Google as well as to us. Nothing from Google is requested until you've accepted marketing cookies and opened the panel — if you'd rather not use it, email or ring us and we'll book a time directly.

When you watch a video

Our videos are hosted by Vimeo and play in their player, loaded with Vimeo's do-not-track setting on. It waits for your consent: until you accept marketing cookies nothing is requested from Vimeo at all, so they don't see your visit.

Behind the scenes

Our hosting keeps standard server logs — IP address, browser, what was requested, when — for a short period, so outages and abuse can be investigated. We don't analyse them for anything else.

What we don't collect

No accounts, no advertising pixels, no fingerprinting, no session recording, no heatmaps, and no special category data. We don't buy data about you from anyone else — the company lookup above draws on Dealfront's database of business networks, not on anything about you — and we don't make decisions about you automatically.

Lawful basis

UK GDPR requires a lawful basis for each use of your data. Ours:

  • Answering your enquiry — steps towards a contract, and our legitimate interest in running an agency people can contact. You asked us a question; we need your details to answer it.
  • Marketing email — your consent, given by ticking the box, withdrawable from the unsubscribe link in every email or by telling us.
  • Client work — performance of our contract with you, plus our legal obligations to keep accounting records.
  • Cookieless analytics and server logs — our legitimate interest in knowing whether the site works and keeping it secure. Because our analytics store nothing on your device, this doesn't need consent under PECR.
  • Identifying the businesses that visit, and getting in touch with them — your consent for the cookies Leadfeeder sets, and our legitimate interest in business-to-business marketing for what follows: working out which companies are interested, and approaching someone there about work. We've weighed that against what a work contact would reasonably expect, which is why the approach is always to a business role rather than a private address, always says where it came from, and stops permanently the first time you ask. Say no on the banner and none of it starts; object at any point and it ends.
  • Spam protection on our forms — our legitimate interest in not being buried in automated submissions.
  • Cookies that aren't strictly necessary, and the third-party embeds — your consent, through the cookie banner.

Cookies

The site needs a couple of strictly necessary cookies to work — a session cookie and a CSRF token that stops someone forging a form submission on your behalf — plus one from Cookiebot recording what you chose on the banner, so you're not asked again on every page.

Anything beyond that waits for you. Our consent manager blocks non-essential scripts until you accept them, and everything Google-related starts from denied and stays there unless you say otherwise.

Three things do wait on your consent, because they involve someone else's server: the tour video (hosted by Vimeo), the booking form (Google Calendar) and the company lookup described above (Leadfeeder). Until you accept, none of them is requested at all — the video and the booking form show a short note in their place instead, and you can accept from there. Nothing else on the site is held back, and you can still reach us by email or phone without accepting anything.

The table below comes from a live scan of this site, so it lists whatever is currently set.

Reopens the banner. You can change your mind as often as you like.

Who else sees it

We don't sell, rent or trade personal data. The only third parties involved are the suppliers who run parts of this site for us, each under a contract that limits them to doing what we've asked:

  • Servd Hosting for this website, including server logs
  • Postmark Delivers the enquiry notification and your confirmation email
  • Plausible Cookieless, aggregate visitor analytics
  • Dealfront Leadfeeder, the company lookup — only runs once you consent
  • Cookiebot The cookie banner, and the record of what you consented to
  • Cloudflare Turnstile, the spam check that runs when you submit a form
  • Vimeo Hosts our videos — only loaded once you consent
  • Mailchimp Our mailing list — only if you opted in
  • Google Appointment scheduling, if you book a call with us

Beyond that, we'd only hand over personal data if the law required it — a court order, or a regulator with the power to ask.

How long we keep it

  • Enquiries that didn't go anywhere — the email stays in our inbox while we're talking, then gets cleared out after two years.
  • Client records — for the length of the relationship, then seven years for the parts HMRC requires us to keep.
  • Mailing list — until you unsubscribe, and we remove inactive subscribers periodically anyway.
  • Cookie consent — the choice you make on the banner is stored for twelve months, then you're asked again. Cookiebot also keeps a record of it, as our evidence that you were asked.
  • Company visits — the record Leadfeeder builds of which businesses came to the site stays in our account while we use it, and goes when we close it. If we approached someone off the back of it and nothing came of it, we clear that the way we clear any other enquiry that went nowhere.
  • Server logs — a short rolling window set by our host.
  • Analytics — aggregate counts with no personal data in them, kept indefinitely.

Data outside the UK

Some of the suppliers above are based in the United States. Where personal data reaches them, the transfer relies on the UK's approved safeguards — the UK extension to the EU–US Data Privacy Framework where the supplier is certified under it, and the International Data Transfer Addendum to the EU standard contractual clauses where it isn't.

Dealfront is the exception in the other direction: it's an EU company, based in Germany and Finland, and the UK recognises the EU as offering adequate protection, so no extra safeguard is needed for it.

If you'd like to know which safeguard applies to a particular supplier, ask us and we'll tell you.

Your rights

Under UK GDPR you can ask us to:

  • Show you what personal data we hold about you, and a copy of it.
  • Correct anything that's wrong or incomplete.
  • Delete it, where we've no continuing reason to keep it.
  • Restrict what we do with it while a dispute is sorted out.
  • Stop using it for a purpose you object to — including marketing, which we'll always honour.
  • Move it, in a portable format, to you or someone else.

You can also withdraw consent at any time, for the things we rely on consent for. Withdrawing it doesn't undo what was done while it was in force.

Email emma.browne@mutual.agency and we'll respond within a month. It's free, and we won't ask you to justify the request.

If we get it wrong, you're entitled to complain to the Information Commissioner's Officeico.org.uk/make-a-complaint, or 0303 123 1113. We'd rather you gave us the chance to fix it first, but that's your call.

Changes

When we change how we handle personal data, this page changes with it and the date at the top moves. If a change is significant and we hold your email address, we'll email you about it.

This page was last updated on 3 September 2026.