Privacy Policy
Effective date: 2 August 2026
Next scheduled review: 2 August 2027
1. Who we are
Melosome Group Ltd is the controller of personal information described in this policy.
Company number: 16209712
Registered in: England and Wales
Registered office: Weston-super-Mare, England, BS23 1RS
Email: info@melosome.app
Website: https://www.melosome.com
This policy applies to the Melosome corporate website, corporate enquiries, media and partnership contact, research enquiries, security reports and general career enquiries.
Products and ventures operated by Melosome may publish separate privacy notices where their processing differs from this corporate website.
2. Information we may collect
Information you provide
Depending on how you contact us, this may include:
- your name;
- email address;
- telephone number, if you choose to provide it;
- organisation and role;
- the content of your message;
- files or evidence you deliberately attach;
- communication preferences;
- information needed to respond to a rights request; and
- information included in a security, research, media, partnership or career enquiry.
Please do not send passwords, private keys, full payment-card details, identity documents or unnecessary sensitive personal information through a general enquiry.
Technical and usage information
When you use the website, our systems and hosting providers may process limited technical information such as:
- Internet Protocol address;
- date and time of access;
- requested page or resource;
- browser, device and operating-system information;
- referring page;
- security and diagnostic events;
- form-submission metadata; and
- consent or preference records where applicable.
The website uses Vercel Web Analytics, a cookieless analytics service that reports aggregated visit and page-view counts without setting cookies, storing device identifiers or tracking individuals across websites. Beyond this, the launch version of the website is intended to operate without advertising trackers and without non-essential analytics cookies.
Information from other sources
We may receive business contact information from:
- your organisation;
- a person who introduces you;
- publicly available professional or corporate sources;
- event or research collaborators; or
- service providers involved in legitimate business communication.
Where required, we will provide relevant privacy information within the applicable period.
3. Why we use personal information
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to general, partnership, research, media or career enquiries | Contact details and message content | Legitimate interests in communicating and operating the business; steps at your request before a possible contract where applicable |
| Manage active or prospective business relationships | Professional contact details, correspondence and records of discussions | Legitimate interests; contract or steps before contract where applicable |
| Receive and investigate security reports | Reporter contact, technical evidence and affected-system information | Legitimate interests in protecting systems and users; legal obligations where applicable |
| Operate, secure and diagnose the website | Technical logs, security events and form metadata | Legitimate interests in reliable and secure operation |
| Send company updates where you have deliberately subscribed | Email address, subscription and consent record | Consent |
| Manage privacy and legal requests | Identity and request information, correspondence and evidence | Legal obligation and legitimate interests |
| Establish, exercise or defend legal claims | Relevant correspondence, records and evidence | Legitimate interests and legal obligations |
| Meet company, tax, regulatory and law-enforcement obligations | Information required by law | Legal obligation |
Where we rely on legitimate interests, those interests include operating and protecting Melosome, communicating with relevant people, developing legitimate business and research relationships, maintaining records and defending legal rights. We consider the effect on individuals and do not use legitimate interests where those interests are overridden by individual rights and freedoms.
4. Email updates
The corporate site may offer optional company updates in the future.
We will not add you to a marketing list merely because you send an enquiry. Where updates are offered:
- subscription must be deliberate;
- consent must be recorded;
- each message must provide an unsubscribe method; and
- withdrawal of consent will not affect processing that was lawful before withdrawal.
The launch baseline keeps the public notification form disabled unless these controls and a suitable provider are configured.
5. Cookies and similar technologies
The website is designed to avoid non-essential cookies at launch. Vercel Web Analytics, used to understand aggregate visits, does not set cookies and is not a tracking technology within the meaning of this section.
Strictly necessary storage may be used for security, session integrity or form operation. Any other optional analytics or third-party embeds must not load unless the required notice and consent controls have been implemented.
Read the Cookie Policy for more information.
6. Sharing personal information
We may share information only where necessary with:
- website hosting, content-delivery and infrastructure providers;
- email, communication and form-processing providers;
- security and anti-abuse providers;
- professional advisers such as accountants, insurers, auditors or lawyers;
- contractors working under appropriate confidentiality and data-protection obligations;
- regulators, courts, law-enforcement bodies or public authorities where required or lawfully requested; and
- a buyer, successor or restructuring party where a business or asset transfer is contemplated, subject to appropriate safeguards.
We do not sell personal information.
We do not share corporate website visitor information with advertising data brokers.
7. International transfers
Some service providers may process information outside the United Kingdom.
Where personal information is transferred internationally, we will use a lawful transfer mechanism where required. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another legally recognised safeguard.
Information about a relevant safeguard may be requested using the contact details in this policy, subject to lawful redaction.
8. How long we keep information
We keep information only for as long as reasonably needed for the purpose, legal obligations, security and the establishment or defence of claims.
Typical periods are:
| Record | Typical retention |
|---|---|
| General enquiries that do not become an active relationship | Up to 24 months after the enquiry is closed |
| Active business, research or partnership correspondence | For the relationship and normally up to 6 years afterwards where needed for legal, contractual or record-keeping purposes |
| Unsolicited career enquiries | Up to 12 months unless a different period is agreed or required |
| Mailing-list information | Until you unsubscribe or the list is closed; a minimal suppression record may be retained to respect the unsubscribe request |
| Website operational logs | Normally up to 90 days |
| Security logs or evidence linked to an investigation | Up to 12 months after closure, or longer where needed for legal or security reasons |
| Security vulnerability reports | Normally up to 6 years after closure where needed to preserve remediation and disclosure records |
| Privacy-rights requests | Normally up to 6 years after closure |
| Legal, accounting and company records | For the period required by applicable law |
A record may be kept for a shorter or longer period where the circumstances, law, dispute, investigation or technical constraints justify it. Information no longer required will be deleted, anonymised or securely disposed of.
9. Security
We use technical and organisational measures proportionate to the information and risk.
Measures may include access control, encryption in transit, secure configuration, logging, backups, supplier controls and procedures for handling incidents.
No method of transmission or storage is completely secure. If we identify a personal-data breach, we will assess, contain and report it in accordance with applicable law.
10. Your rights
Depending on the circumstances and lawful basis, you may have the right to:
- be informed about processing;
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain information in a portable format;
- withdraw consent at any time where processing relies on consent; and
- complain to a supervisory authority.
Some rights are qualified and may not apply to every record or purpose.
To make a request, email info@melosome.app with the subject Privacy request — [type of request].
We may ask for information reasonably necessary to confirm identity and locate the relevant records. We will not ask for more identity evidence than the request requires.
11. Automated decisions
The corporate website does not make decisions about people using solely automated processing that produces legal or similarly significant effects.
12. Children's information
The corporate website is not directed at children and is not intended to collect personal information from children through general enquiries.
Melosome products designed for children or young people will require separate, age-appropriate privacy information, consent and safeguarding controls before launch.
If you believe a child has provided information through the corporate website inappropriately, contact us so that we can assess and remove it where appropriate.
13. Links to other websites
The website may link to third-party services. Their privacy practices are controlled by them, not by Melosome. Review the relevant third-party notice before providing information.
14. Complaints
Please contact us first so that we can try to resolve the concern.
You also have the right to complain to the Information Commissioner's Office, the United Kingdom supervisory authority for data protection.
15. Changes to this policy
We may update this policy when the website, law, providers or processing changes.
Material changes will be reflected by a new effective date. Previous versions may be retained for governance and evidence.
16. Contact
Melosome Group Ltd
info@melosome.app
Weston-super-Mare, England, BS23 1RS