Skip to content
Privacy policy

Your data, plainly.

We build systems that handle data for a living, so we hold ourselves to the standard we build to. This policy says what we collect, why, and what you can do about it, in plain English, because that’s how we write everything.

Last updated 30/07/2026
01

Who we are

Vybzz is the trading name of MZ Corp Limited, a company registered in England and Wales (company number 17351738) with its registered office at 128 City Road, London, EC1V 2NX. For UK GDPR purposes, MZ Corp Limited is the data controller for the personal data described in this policy.

You can reach us about anything in this policy at hello@vybzz.co.uk.

02

What we collect

When you enquire through the form on our contact page, your name, business name, email address, industry and anything you choose to tell us about your business. That form is submitted to our hosting provider (Netlify), which stores it and notifies us, under its own data-processing agreement.

When you book a call through our calendar (cal.eu), meaning the details you enter there, your name, email and the notes you add.

When you browse the site, aggregate information such as pages visited, referring site and device type, measured by Plausible Analytics. Plausible sets no cookies, stores no personal data and does not track you across sites. We do not run advertising trackers.

If you give us information about other people, such as colleagues or customers, you confirm you are entitled to share it with us.

03

Why we collect it

To answer your enquiry, run your audit and prepare your report. That is the whole business, so it is most of the processing we do.

To keep simple records of who we have spoken to and what was agreed, the same records any professional firm keeps.

We do not sell personal data, rent lists, or send marketing you have not asked for.

04

Our lawful bases

Performing a contract, or taking steps you ask us to take before one, when handling your enquiry, audit and engagement.

Legitimate interests, meaning keeping business records and replying to people who contact us.

Consent, for anything optional such as a newsletter, which you can withdraw at any time by replying “stop” or emailing us.

Legal obligation, where we must keep records for tax or respond to a lawful request from an authority.

05

Who we share it with

The tools that run the firm: our hosting and form provider (Netlify), our scheduling provider (cal.eu), our email provider and our document storage, each under its own data-processing agreement. A current list of processors is available on request.

Professional advisers such as accountants or insurers where necessary, and authorities where the law requires it. No one else.

06

International transfers

We prefer UK and EU hosted providers. Where a provider processes data outside the UK, we rely on UK adequacy regulations or on the safeguards UK GDPR provides, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

07

Client project data and AI

When we build and manage a Superagent for a client, the client’s customer data stays in the client’s own systems. We act as a processor under the client’s instructions, governed by a written agreement, and every action the agent takes is logged and visible to the client.

The AI models we use are configured so that client and customer data is not used to train public models. Model providers process data under contract as processors or sub-processors, and conversations are encrypted in transit.

08

Special category and children’s data

We do not seek special category data, such as health information, through this website, and we ask you not to send it in an enquiry. Where a client engagement involves such data, for example at a clinic, the client remains the controller, a data-processing agreement governs the work, and safeguards are agreed before anything is built.

This website and our services are aimed at businesses, not children, and we do not knowingly collect children’s data.

09

Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. The agents we build for clients operate under human oversight, with consequential actions held in an approval queue for a person to sign off.

10

How we protect it

This website has no database of its own, no user accounts and no payment forms. Form enquiries are held by our hosting provider and emailed to us, bookings run through our scheduling provider, and everything travels over an encrypted connection. There is very little here to attack, by design.

The data we do hold is encrypted in transit, stored with reputable UK/EU-hosted providers, protected by two-factor authentication, and accessible only to authorised Vybzz staff. If we ever suffered a breach involving your data, we would tell you and the ICO as UK GDPR requires, without undue delay and within 72 hours of becoming aware where the law requires it.

Your Superagent runs on enterprise-grade infrastructure. The platforms underneath it, meaning the AI model providers, cloud hosting, database and payment processing, are SOC 2 and ISO 27001 certified. Those certifications belong to the platforms, not to Vybzz, and we will name which provider holds which on request.

11

How long we keep it

Enquiries that go nowhere are deleted within 12 months.

Client records, reports and contracts are kept for six years after the engagement ends, in line with standard UK commercial and tax practice, then deleted.

12

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct it, delete it, restrict its use, or object to our processing, and take your data elsewhere. Email hello@vybzz.co.uk and we will respond within one calendar month, free of charge.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you told us first.

13

Cookies

This site uses only the cookies it needs to function. Our analytics tool is Plausible Analytics, which is cookie free and privacy first: it records aggregate page views without cookies, without a device fingerprint and without any data that identifies you, so no consent banner is required under UK law. There are no advertising cookies and no cross-site tracking. If that ever changes, this section will name the tool first.

14

Other websites

This site links to third-party sites, such as our scheduling provider. Their privacy practices are their own, and we encourage you to read their policies.

15

Changes to this policy

If we change how we handle personal data, this page changes first, with the date above updated. Material changes will be flagged to existing clients directly.

Questions about any of this, or a request under your rights, go to hello@vybzz.co.uk. A founder will answer within one working day.