Effective date: 01 May 2025
Last updated: 01 September 2025
Controller: Mehive (“we”, “us”, “our”)
Website: https://mehiveconsulting.com
Contact: info@mehiveconsulting.com
Registered address: Mehive Limited
1) Scope
This Policy explains how we collect, use, share, and protect personal data when you visit our website, contact us, download resources, or engage our services. It applies to visitors and clients globally. For individuals in the UK/EEA, we process personal data in accordance with UK GDPR/EU GDPR.
2) What data we collect
- Contact & identity data: name, email, phone, company, role.
- Professional data: industry, team size, interests, project requirements.
- Usage & technical data: IP address, device/browser, pages viewed, referral source, cookie IDs.
- Communications: emails, form submissions, meeting notes.
- Client service data (if engaged): project artifacts, performance metrics, credentials necessary to deliver services (access controlled).
We do not intentionally collect special category data.
3) How we collect data
- Directly from you (forms, email, meetings, contracts).
- Automatically (cookies/analytics, server logs).
- From third parties (referral partners, LinkedIn, publicly available sources) where permitted.
4) Purposes & lawful bases (UK/EU)
- Provide and improve our services – Contract / Legitimate interests.
- Respond to inquiries and send requested resources – Consent / Legitimate interests.
- Analytics and site performance – Consent (where required) / Legitimate interests.
- Marketing communications – Consent (and you can withdraw anytime).
- Security, fraud prevention, legal compliance – Legal obligation / Legitimate interests.
5) Sharing your data
We may share limited data with:
- Processors/Service Providers: hosting, analytics, CRM, email, scheduling, project tools (e.g., Google, Microsoft, HubSpot, Calendly, Notion, Slack).
- Professional advisors: legal, accounting, insurance.
- Partners (with your consent) for joint offerings or referrals.
We do not sell personal data. Service providers are bound by contract to use data only on our instructions.
6) International transfers
If we transfer personal data outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or UK IDTA, and additional measures as needed.
7) Retention
We keep data only as long as necessary for the purposes described, including to meet legal, accounting, or reporting requirements. Typical periods:
- Website analytics: 14–26 months (configurable).
- Sales enquiries: 24 months from last activity.
- Client records: project duration + up to 7 years (regulatory/accounting).
8) Your rights (UK/EEA)
You may have the right to access, rectify, erase, restrict, object, and data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK).
9) Security
We implement technical and organizational measures appropriate to the risk (access controls, encryption at rest/in transit where supported, least-privilege access, vendor due diligence). No method is 100% secure.
11) Children
Our services are intended for business users. We do not knowingly collect data from children under 16.
12) Third-party links
Our site may link to third-party sites. Their privacy practices are independent of ours; please review their policies.
13) Changes
We may update this Policy and will revise the “Effective date” accordingly. Significant changes may be communicated on the site.
14) Contact
For privacy questions or requests, email hello@mehiveconsulting.com