Legal

Privacy Policy

Last updated: 9 September 2026  ·  Applies to: missionctrl.agency and trustos.missionctrl.agency

This Privacy Policy explains how MissionCTRL Ltd ("MissionCTRL", "we", "us" or "our") collects, uses, shares and protects personal data when you visit our websites, use our self-serve tools, contact us, subscribe to our communications, book a meeting, or otherwise engage with us. It applies to missionctrl.agency and to our product site trustos.missionctrl.agency (together, "the sites").

We are committed to handling your personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

1.Who we are

MissionCTRL Ltd is the data controller responsible for your personal data.

2.The personal data we collect

We collect and process the following categories of personal data:

Information you give us

Information we collect automatically

Information we obtain from other sources

We do not knowingly collect special category data (such as data about health, race or religion) and ask that you do not send it to us through the sites.

3.How and why we use your data

We only use your personal data where we have a lawful basis to do so under UK GDPR. The table below sets out our main purposes and the corresponding lawful basis.

PurposeData usedLawful basis
Responding to your enquiries and providing the services or information you requestEnquiry / form data, correspondenceLegitimate interests; steps prior to entering a contract
Generating and delivering personalised reports through our self-serve toolsTool and assessment dataLegitimate interests; steps prior to entering a contract
Sending you our newsletter, marketing updates and insightsName, emailConsent (you can withdraw at any time)
Arranging and managing meetingsBooking and scheduling dataLegitimate interests; steps prior to a contract
Business-to-business outreach to relevant organisationsProfessional contact dataLegitimate interests (with an opt-out in every message)
Producing trust research and analysisPublic research materialLegitimate interests
Understanding how the sites are used and improving themAggregated, cookieless analyticsLegitimate interests
Understanding in detail how pages are readSession analytics (Microsoft Clarity) — heatmaps, session replayConsent (you can withdraw at any time)
Maintaining security and preventing misuseTechnical and usage dataLegitimate interests; legal obligation
Complying with our legal and regulatory obligationsRelevant recordsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to this processing at any time (see Section 9).

3a.AI-assisted analysis

Some of our tools and research use Claude, a commercial AI service provided by Anthropic, to generate analysis and reports. Information submitted through our self-serve tools may be processed by Anthropic for this purpose under our commercial agreement with them. Under Anthropic's commercial terms, data processed this way is not used to train AI models (see Anthropic's Privacy Center: privacy.claude.com). We review AI-generated outputs before they inform any client work.

4.Cookies and similar technologies

Our standard analytics provider, Plausible, is cookieless and does not set tracking cookies or collect personal data, so it requires no consent. We additionally offer Microsoft Clarity session analytics, which does set cookies — so we ask for your consent before it loads, and it stays off if you decline or if your browser sends a Global Privacy Control signal. It is never used on our password-protected client pages.

Some embedded third-party tools — such as forms, calendar booking, or video — may set their own cookies when you interact with them. Where any non-essential cookie that requires consent is used, we will ask for your consent first. For full detail on cookies, see our Cookie Policy.

5.Who we share your data with

We do not sell your personal data. We share it only with trusted service providers ("processors") who help us run our business, and only as needed to deliver the purposes above. These include:

We may also disclose personal data where required to comply with the law, enforce our agreements, or protect our rights, property or safety, and to professional advisers or in connection with a business reorganisation or sale.

6.When we work for a client

Where a client engages us to measure trust across their stakeholders — for example, surveying their employees, customers or partners — we collect and analyse responses on that client's behalf and under their instructions. For that work, the client is the data controller and their privacy notice applies; our responsibilities are set out in a data processing agreement with them. Responses are treated as confidential and reported in aggregate. Raw response data is deleted or returned at the end of the engagement, unless the client instructs otherwise.

7.International transfers

Some of our providers are based outside the UK, including in the United States. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — such as a UK adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.

8.How long we keep your data

We keep personal data only for as long as necessary for the purposes set out in this policy, after which it is securely deleted or anonymised. In general:

9.Your rights

Under UK data protection law you have the right to:

To exercise any of these rights, contact us at hello@missionctrl.agency. We will respond within one month. Exercising your rights is free of charge in most cases.

Right to complain. If you are unhappy with how we have handled your data, you can complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would welcome the chance to address your concerns first.

10.How we protect your data

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration. We restrict access to those who need it, and we work only with providers who maintain robust security standards. No method of transmission over the internet is completely secure, however, and we cannot guarantee absolute security.

11.Children

Our sites and services are intended for businesses and professionals and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18.

12.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The latest version will always be published on this page, with the "Last updated" date revised accordingly. Significant changes will be communicated where appropriate.

13.Contact us

For any questions about this policy or how we handle your personal data, please contact: