Privacy Policy

Last updated: 10 March 2025

1. Introduction

MASH Virtual Ltd ("we", "us", "our"), registered in England and Wales, is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share and protect your personal data when you use our website, applications, SaaS platforms, games, AR/VR/XR solutions and related services (collectively, "Services").

We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR). Our registered address is: Venture X, Building 7, Chiswick Park, 566 Chiswick High Road, London W4 5YG, United Kingdom.

2. Information We Collect

2.1 Information you provide to us

  • Name, email address, phone number and company details when you contact us, subscribe or register
  • Account credentials when creating user accounts on our platforms
  • Payment and billing information processed via secure third-party payment providers
  • Content you submit such as assessment responses, uploaded files, video interview recordings and learning data
  • Communications you send us including support requests and feedback

2.2 Information collected automatically

  • Device information (browser type, OS, screen resolution, device identifiers)
  • IP address and approximate geolocation
  • Cookies, pixels and similar tracking technologies (see our Cookie Policy)
  • Usage data including pages visited, features used, session duration and interaction patterns
  • Analytics data via Google Analytics, Microsoft Clarity or similar services

2.3 Information from third parties

  • Social media profile data if you connect via LinkedIn, Facebook, Google, X (Twitter), Instagram or similar platforms
  • Data from partner organisations, assessment bodies and educational institutions where relevant to service delivery
  • Publicly available business information

3. Lawful Basis for Processing

We rely on the following legal bases under UK GDPR Article 6:

  • Contract: Processing necessary to perform our contractual obligations to you
  • Legitimate interests: Improving our services, marketing, fraud prevention and network security
  • Consent: Where you have given explicit consent (e.g. marketing emails, non-essential cookies)
  • Legal obligation: Complying with applicable UK laws and regulations

4. How We Use Your Data

  • Providing, maintaining and improving our Services including SaaS platforms, assessment technology, LMS, games and XR solutions
  • Processing transactions and managing your accounts
  • Communicating with you about services, updates, security alerts and support
  • Personalising user experiences using AI and machine learning (e.g. learner analytics, career mapping, adaptive assessments)
  • Sending marketing communications where we have your consent or a legitimate interest
  • Analysing usage patterns to improve functionality and user experience
  • Ensuring security and preventing fraud
  • Complying with legal and regulatory requirements

5. Data Sharing and Disclosure

We may share your personal data with:

  • Service providers: Cloud hosting (AWS, Azure, GCP), payment processors, email services, analytics tools and customer support platforms that process data on our behalf under data processing agreements
  • Business partners: Assessment bodies, educational institutions, employers and recruitment partners — only to the extent necessary for service delivery
  • Government and public bodies: Where required under a G2G partnership model or by law
  • Social media platforms: If you choose to interact with our content or connect your social accounts (LinkedIn, Facebook, Instagram, X/Twitter, YouTube)
  • Professional advisors: Lawyers, accountants and auditors as necessary
  • Law enforcement: Where required by law, court order or to protect our legal rights

We do not sell your personal data to third parties.

6. International Data Transfers

Your data may be transferred outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place in accordance with UK GDPR, including:

  • UK adequacy regulations for approved countries
  • International Data Transfer Agreements (IDTAs) or the UK Addendum to EU Standard Contractual Clauses
  • Binding Corporate Rules where applicable

7. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this policy, unless a longer retention period is required or permitted by law. Typical retention periods:

  • Account data: duration of the account plus 2 years
  • Assessment and certification data: as required by awarding body or regulatory requirements (typically 5–7 years)
  • Marketing data: until you withdraw consent
  • Financial records: 6 years as required by UK tax law
  • Website analytics: 26 months

8. Your Rights

Under UK GDPR, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Restrict processing in certain circumstances
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests or direct marketing
  • Automated decisions: Not be subject to solely automated decision-making, including profiling, that produces legal or significant effects

To exercise any of these rights, contact us at hello@mashvirtual.com. We will respond within one month as required by law.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, regular security audits, and secure development practices. However, no method of transmission over the Internet is 100% secure.

10. Children's Privacy

Our Services are not directed at children under 13. Where our platforms are used in educational settings involving minors, data processing is conducted under the authority and consent of the educational institution. We comply with the ICO's Children's Code (Age Appropriate Design Code) where applicable.

11. Social Media and Third-Party Links

Our website and services may contain links to third-party websites and social media platforms including LinkedIn, Facebook, Instagram, X (Twitter), YouTube and others. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

If you interact with social media plugins or share buttons on our site, those platforms may collect data about your visit in accordance with their own policies.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "Last updated" date. Continued use of our Services after changes constitutes acceptance of the updated policy.

13. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

14. Contact Us

For any questions about this Privacy Policy or your personal data: