Privacy policy
Last updated 18 September 2026
Who we are
MonaLisaa is the trading name of Craig Malloy, sole trader. In this notice, “we”, “us” and “MonaLisaa” mean that trader.
Geographic business address: [BUSINESS-ADDRESS].
For privacy questions, requests or complaints, email [email protected].
[ICO]
This notice covers monalisaa.co, our website-building service, accounts, payments and support. We decide how personal information is used for running that business and are its “controller”. When we handle information on a customer’s behalf to build their site or handle their visitors’ enquiries, the customer is normally the controller and we are their “processor”. Our Data processing terms cover that work. A customer’s website needs its own privacy notice; this notice does not replace it.
What we collect and why
We receive information from you, from someone acting for your business, from your use of the service and from our payment and service providers. A customer may supply information about staff, reviewers or other people for their website.
| Information | What we use it for | Our lawful basis when we act as controller |
|---|---|---|
| Account email, sign-in requests and session records | Sign you in, connect your purchases and protect access | Performing our contract with you, or taking steps you request before a contract. If you act for another business, our legitimate interest in providing that business’s service |
| Business details, quiz answers, website choices, uploaded logos/photos, generated drafts, edit requests and change records | Build, display, edit and supply the website you request | Contract or requested pre-contract steps for your own information; legitimate interests in serving business representatives. Personal information supplied for your website is also subject to our processor terms where we act on your instructions |
| Order, plan, payment reference, billing status and acceptance records | Take payment, fulfil orders, record agreed terms and deal with disputes | Contract; legal obligations for required accounting records; legitimate interests in keeping evidence and resolving disputes |
| Messages and information you send for support or complaints | Answer you, investigate problems and meet legal duties | Contract where relevant; legitimate interests in providing support; legal obligations where applicable |
| Technical information, such as IP address, browser/request details, timestamps and error or security records | Operate and protect the service, investigate faults and misuse | Legitimate interests in a reliable, secure service and protecting users; legal obligations where applicable |
These legitimate interests do not give us permission to disregard your rights. You can ask us about our assessment or object as explained below.
You choose whether to use the service. Without the details needed for an account, a payment or the requested website, we may be unable to provide it. Optional photographs and extra business details are your choice. Do not upload passwords, payment-card details, private customer files, health information or other sensitive personal information into website content or AI edit requests.
Website content, uploads and AI
We use OpenAI to help generate copy and images and interpret requests to change a site. This involves sending relevant generation inputs, image prompts, edit requests and site summaries to OpenAI. Do not assume a draft or an AI conversation is a suitable place for confidential information.
Uploads and generated assets are stored by the service. Uploaded images can be served through direct URLs without a sign-in check. Preview links can also be shared. A hard-to-guess link is not a promise of confidentiality. Content you approve for publication is available to visitors and may be copied, cached or indexed by others. Removing our copy cannot remove every copy held by someone else.
The AI assists with producing content; you decide what to approve. The service also makes automated checks, including sign-in, validation and anti-abuse checks, which can refuse a request. Contact us if a check prevents you using the service. We do not use the website-writing AI to make decisions about people with legal or similarly significant effects.
Enquiries sent through customer websites
An enquiry is for the business shown on that website. That business decides why it needs the information and how it follows up. We handle it on the business’s behalf from collection, not just after an email arrives.
The enquiry service collects the visitor’s name, email, phone number and message, together with the site identifier, submission time and verification/delivery information. Some submissions that fail a bot check are still stored. Where verification is unavailable or not configured, a submission may be stored as unverified.
We attempt to send the full enquiry through Resend to the business email entered in that website’s business details, with the visitor’s email as the reply-to address. This is not a separate verified recipient setting. A successful submission response does not prove that an alert was delivered or read. Customers should check their enquiry records as well as their inbox.
Enquiry database rows become eligible for automatic deletion once they are more than 30 days old. The application’s cleanup process runs at startup and then at approximately hourly intervals while running. Interruptions or failures can delay deletion. This process does not delete delivered emails, customers’ inbox copies, backups or provider logs. Those copies have separate retention arrangements.
For a request about an enquiry, contact the business whose site you used. You can also contact us and we will help direct it appropriately. We do not treat sending an enquiry as permission for our own marketing.
Who receives information
We use these services for the purposes described:
- OpenAI: AI generation and editing inputs and outputs.
- Resend: transactional email, including sign-in links and customer enquiry alerts.
- Stripe: hosted payment collection, billing and payment records. You enter payment details with Stripe; our checkout receives references and payment/order information rather than collecting your full card details itself.
- Cloudflare: published-site delivery through Workers and Workers Static Assets over HTTPS, domain-availability DNS lookups, registrar services for the endings listed below, and Turnstile checks where configured. Web Analytics is off unless an analytics token is configured, as explained in our Cookie policy. This does not promise that a customer’s custom-domain DNS or TLS provisioning has completed.
- Google Fonts: the app requests fonts from Google, which receives the browser connection information needed to serve them.
- Google Gmail: correspondence sent to our support/privacy address.
- Railway: application hosting and PostgreSQL database hosting. Jobs, previews and uploaded files use the application’s filesystem; the repository records the Railway persistent volume at
/data. This is primary storage, not an independent backup. - Porkbun and Cloudflare Registrar: registration details when we arrange a domain, together with the relevant registry. The current routing uses Porkbun for
.co.uk,.ukand.org.uk, and Cloudflare Registrar for.com,.net,.organd.co. Registration, renewal and transfer arrangements must be agreed for the selected domain.
A provider may act on our instructions for some work and be a separate controller for other work, such as payment fraud prevention or legal duties. Our processor terms identify the providers authorised to handle customer-controlled information on our behalf. We may also disclose relevant information to professional advisers, authorities where required by law, or people involved in a genuine transfer of the business, with appropriate protections.
Information outside the UK
Some providers may handle information outside the UK, including through support access. We do not promise UK-only storage.
The provider-specific processing and support countries, contracting entities and UK transfer safeguards have not yet been verified for this draft. The transfer disclosure is incomplete and must be completed before this notice is published; a provider’s brand or API address does not establish the applicable contract or safeguard.
Email [email protected] for information about these arrangements or a copy of the relevant safeguards, with confidential details removed where necessary.
How long we keep information
We keep information for the purpose for which it is needed, including necessary legal records and genuine disputes. The following schedule distinguishes current behaviour from selected policies whose operation is not yet verified; the enquiry-row rule does not apply to everything in your account.
| Record | Retention period or decision rule |
|---|---|
| Enquiry database rows, including failed/unverified submissions | Eligible for deletion after 30 days, with the cleanup limits explained above |
| Sign-in links and sessions | Links expire after 15 minutes and sessions after 30 days. Expiry stops their use. There is currently no automatic expiry-based deletion of login-token or session records. Consuming a login link or revoking a session changes its status; it does not delete the row |
| Unpurchased quiz answers, jobs, previews and abandoned uploads | There is currently no automatic age-based deletion of these files; a 90-day deletion limit is not implemented |
| Account details, purchased sites, content, assets and edit history | Held for the service; automatic account closure and deletion 90 days after closure are not implemented. There is currently no enforced post-closure deletion deadline for these records |
| Required transaction and accounting records | Our selected business-record schedule is 6 years from the end of the relevant tax year. The application does not automatically delete these records at that date; the accounting retention procedure must be established before this schedule is represented as operating |
| Contract, content and approval evidence outside required accounting records | Follows the account/site schedule above, subject to a specific legal obligation or dispute; it is not all assigned a 6-year accounting period |
| Support mail and privacy/complaint records | Our selected support schedule is 2 years from the last correspondence on the matter, subject to a specific legal obligation or dispute. This is a manual mailbox policy; its operation has not yet been verified |
| Security, application and provider logs | There is currently no application-wide 90-day log-deletion control. Provider log retention depends on each service and account configuration and has not yet been verified |
| Backups and copies held by our providers | We do not currently operate an independent backup, and there is no tested restore. Provider-held copies may persist for a period set by the provider. Deletion from our database does not guarantee removal from provider copies. We cannot state a verified retention or deletion period for those copies |
If a particular record is needed for a legal obligation or dispute beyond its normal period, we limit what we retain and its use to that reason. The customer sets the retention of enquiry copies in their own systems.
Cookies and marketing
Our Cookie policy explains cookies, browser storage and third-party requests. Accepting service terms or approving a website is not marketing consent. Sign-in links, receipts and necessary service messages are not an invitation to unrelated advertising.
[MARKETING-PRACTICE]
Your rights
Depending on the circumstances, you can ask to see your personal information, correct it, have it erased, restrict its use or receive a portable copy. These rights have legal limits; for example, we may need to keep required accounting records.
You can object to use based on legitimate interests. You can object to direct marketing at any time, and we must stop using your personal information for that purpose.
Where we rely on consent, you can withdraw it at any time by emailing us, without affecting lawful use before withdrawal. Cookie choices, where applicable, are explained separately in the Cookie policy.
Email [email protected]. We may need proportionate information to confirm your identity. We normally respond within one month; if the law permits more time, we will explain why and tell you the applicable deadline. Requests are normally free.
Complaints and changes
To complain about our handling of personal information, email [email protected] with what happened and what you would like us to put right. We will acknowledge a data protection complaint within 30 days, investigate it and keep you informed of progress and the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator. You do not have to waive that right to use our complaints process.
We will date changes to this notice and bring material changes to affected people’s attention where required. If the business operator changes, we will update the identity and contact details and explain relevant changes in how information is handled.