Privacy NoticeDraft v1.0 — pending solicitor review
Last updated: 2026-05-19
Contents (15 sections)
Introduction
This privacy notice explains how Mens Network Ltd ("we", "us" or "our") collects and uses your personal data when you visit mensnetwork.global or use the Nexus platform.
By using our site, you confirm that you are 18 years of age or older. Our platform is not intended for and is not directed at children. See our Age Statement for further detail.
We process your personal data lawfully, fairly and transparently in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Full name of legal entity: Mens Network Ltd
Company number: 16262214 (registered in England and Wales)
Registered office: 20 Wenlock Road, London, England, N1 7GU
ICO registration number: ZB892927
Contact email: privacy@mensnetwork.global
We are the data controller responsible for your personal data.
It is important that the information we hold about you is accurate and up to date. Please let us know if your personal information changes by emailing privacy@mensnetwork.global.
2. What data we collect, for what purpose, and on what legal basis
Personal data means any information capable of identifying an individual. It does not include anonymised data.
We process the following categories of personal data:
2.1 Communication Data
Data: Any communication you send us — through contact forms, email, support tickets, social media.
Purpose: Communicating with you, record keeping, and the establishment, pursuance or defence of legal claims.
Legal basis: Our legitimate interests — to respond to communications, keep records, and protect our legal position.
2.2 Organisation Account Data (Nexus platform)
Data: Organisation name, contact person's name, email, phone, address, organisation description, category, social media links.
Purpose: Operating the Nexus directory listing platform — onboarding your organisation, displaying your listing, and providing platform services.
Legal basis: Performance of a contract — processing necessary to deliver the directory service you have signed up for.
2.3 Website Analytics Data
Data: IP address (anonymised), browser type, device, pages visited, session duration, referral source, UTM parameters.
Purpose: Understanding how visitors use the site so we can improve it.
Legal basis: Consent — captured via our cookie banner before any analytics cookies are set.
Processors: Google Analytics 4 (G-TNHH71TQY7), Microsoft Clarity (vtnquskmjq).
2.4 Marketing Data
Data: Email address, name (where provided), marketing preferences, engagement with our communications.
Purpose: Sending pre-launch updates, newsletters, and platform announcements.
Legal basis: Consent (for individual subscribers) or legitimate interests for business contacts under the soft opt-in / B2B exemptions in the Privacy and Electronic Communications Regulations (PECR). A Legitimate Interests Assessment for cold business email was completed on 2026-03-10.
Processors: Beehiiv (newsletter platform), Substack (newsletter platform during transition), Smartlead (campaign delivery).
2.5 Customer Relationship Data
Data: Name, organisation, email, role, communication history, account stage.
Purpose: Managing relationships with prospective and current organisation customers and partners.
Legal basis: Legitimate interests — to operate our sales and partnership pipeline.
Processor: HubSpot.
2.6 Advertising Pixel Data
Data: IP address, browser fingerprint, page views, events; matched against your Meta account if you are logged into Facebook or Instagram (Pixel ID: 891057430423672).
Purpose: Measuring advertising effectiveness and serving relevant content.
Legal basis: Consent — only fired after you accept marketing cookies in our cookie banner.
Critical exclusion: Advertising pixels do not fire on SUPPORT category pages. Visitors to crisis support listings are never tracked. See section 11.
2.7 Sensitive Data
We do not routinely collect sensitive (special category) data about you. Sensitive data refers to data revealing racial or ethnic origin, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health, or genetic and biometric data.
Where you choose to disclose sensitive information to us — for example, in a free-text message to our support team — we will process it only for the purpose for which you provided it. We do not store sensitive data in profile fields, and we do not collect information about criminal convictions and offences.
2.8 Automated decision-making
We do not carry out automated decision-making that produces legal effects or similarly significantly affects you.
We do use AI-assisted classification tools (our internal system Sherlock) to help us categorise organisations submitted to the directory. A human reviews any classification that affects whether an organisation appears on the platform. See our AI / Algorithmic Transparency Statement for full detail.
3. How we collect your personal data
We collect personal data:
- Directly from you — when you fill in forms on our site, sign up to our newsletter, register an organisation account, or contact us.
- Automatically — when you use our website, via cookies and similar technologies. See our Cookie Policy.
- From third parties — analytics providers (Google, Microsoft), advertising networks (Meta), business contact data providers (Brightdata) for B2B outreach, and publicly available sources such as Companies House.
4. Marketing communications
Our legal basis for sending you marketing communications is either your consent or our legitimate interests (B2B, under the PECR soft opt-in or limited-company exemption).
Under PECR, we may send marketing emails to you if (i) you made an enquiry, signed up, or otherwise opted in, or (ii) you are a business contact at a limited company, and (iii) you have not opted out. We obtained or are obtaining consent at the point of data collection where consent is the basis.
Before we share your personal data with any third party for their own marketing purposes, we will obtain your express consent.
You can opt out of marketing communications at any time by:
- Using the unsubscribe link in any marketing email we send you;
- Emailing privacy@mensnetwork.global;
- Adjusting your account preferences if you have one.
Opting out of marketing does not affect personal data we process under other legal bases (for example, organisation account data processed to deliver the service).
5. Who we share your personal data with
We may share your personal data with:
- Service providers who provide IT, hosting, database, email, analytics, and CRM services — see the processor table in section 6.
- Professional advisers — lawyers, accountants, bankers, insurers — where necessary to operate our business or defend legal claims.
- Government bodies and regulators — where required by law, court order, or the legitimate request of a regulator (for example, the ICO).
- Successor entities — third parties to whom we sell, transfer, or merge parts of our business.
We require every third party to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow them to process your personal data for specified purposes and in accordance with our instructions.
We do not sell your personal data to anyone.
6. Processors and international transfers
The processors below act on our instructions to process your personal data. Some are based outside the United Kingdom. Where personal data is transferred outside the UK, we rely on one of: a UK adequacy decision; UK-US Data Bridge certification; or the ICO International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses, supported by a Transfer Risk Assessment.
| Processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Platform database (Nexus) | EU / US | DPA + IDTA where relevant |
| Railway | Application hosting | US | DPA + UK-US Data Bridge |
| HubSpot | CRM | US | UK-US Data Bridge |
| Beehiiv | Newsletter delivery | US | DPA + SCCs |
| Substack | Newsletter delivery (transitional) | US | DPA + SCCs |
| Smartlead | B2B email campaigns | US | DPA |
| Google Analytics 4 | Website analytics | US | UK-US Data Bridge |
| Microsoft Clarity | Session analytics | US | UK-US Data Bridge |
| Meta | Advertising pixel | EU (Meta Ireland) for UK/EEA users; US infrastructure | UK-US Data Bridge |
| Brightdata | B2B contact data sourcing | Israel | UK adequacy decision |
| Zoho | Business systems (Mail, Cliq, CRM) | India / EU | DPA — adequacy not yet decided; risk register entry under review |
| Anthropic / OpenAI / OpenRouter | AI processing (Sherlock platform classification) | US | DPA + SCCs; data tiered per LLM Data Tiering Policy |
| Cloudflare | CDN / DDoS protection | Global edge network | DPA + SCCs |
This list reflects our processors as at the date above. Our full Record of Processing Activities (Article 30 ROPA) is maintained internally and is available to the ICO on request.
7. Data security
We have implemented appropriate technical and organisational measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. Access to personal data is limited to staff and processors who have a business need to know.
We have procedures in place to investigate any suspected personal data breach. Where required by law, we will notify you and the ICO within the required timeframes.
8. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which we collected it, including any legal, accounting, or reporting obligations.
| Data category | Retention period |
|---|---|
| Newsletter subscribers | Until you unsubscribe |
| Organisation account data | Duration of contract + 6 years (UK Limitation Act) |
| Customer communications | 6 years from last contact |
| Marketing prospect data | 12 months from last engagement; suppression list retained indefinitely |
| Analytics data | GA4: 14 months; Microsoft Clarity: 13 months |
| Cold email outreach data | Duration of campaign + 12 months for suppression list |
| Payment data (future, when Stripe is live) | 6 years (HMRC) |
| AI processing logs (Sherlock) | Per LLM Data Tiering Policy — typically 30 days |
In some circumstances we may anonymise your personal data for research or statistical purposes. Anonymised data is no longer personal data and may be retained without further notice to you.
9. Your legal rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you ("right of access" / DSAR).
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten") in defined circumstances.
- Restriction — request restriction of processing in defined circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Object to processing based on legitimate interests or direct marketing.
- Withdraw consent — where consent is the legal basis. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Rights related to automated decision-making (where applicable — see section 2.8).
To exercise any of these rights, email privacy@mensnetwork.global. We will respond within one month. If your request is particularly complex we may extend this by a further two months, in which case we will notify you within the first month.
You will not normally be charged a fee. We may charge a reasonable fee, or refuse to act, if your request is clearly unfounded, repetitive, or excessive.
We may need to verify your identity before responding — this is a security measure.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to address your concerns directly first.
10. Third-party links
Our website may contain links to third-party websites, plug-ins, or applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party sites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.
11. Special protection for SUPPORT category pages
The SUPPORT category of our directory contains crisis and mental health support listings. Because of the sensitive nature of these pages, we apply additional protections:
- No advertising pixels fire on SUPPORT pages. Meta Pixel and similar are excluded.
- No personal data forms invite users to describe their personal circumstances on SUPPORT pages.
- No tracking of which specific support listings a visitor views beyond the minimum technical logs necessary to operate the site.
- Samaritans 116 123 is prominently displayed on every SUPPORT page.
This is part of our Safeguarding Policy and our commitment that finding help should not come with a tracking cost.
12. Cookies
Our website uses cookies and similar technologies. You can set your browser to refuse cookies, or to alert you when websites set cookies. If you disable cookies, some parts of our website may not function correctly.
For full detail on the cookies we use and how to manage them, see our Cookie Policy.
13. Changes to this notice
We may update this privacy notice from time to time. The current version will always be at this URL with the date it was last updated.
If we make material changes, we will notify you — by email if we hold your email address, or by a prominent notice on the site.
How to contact us
For any privacy-related question, complaint, or request:
Email: privacy@mensnetwork.global
Post: Mens Network Ltd, 20 Wenlock Road, London, England, N1 7GU
ICO: ico.org.uk — 0303 123 1113