Privacy Policy
Introduction
Messy Works is an automated certification, trust and hosting platform for AI-assisted and legacy software. This policy explains how we use “personal data” (or, in Australia, “personal information”) that you provide to us, or that we collect about you, when you use this website. Personal data is information which relates to an individual and from which they can be identified, directly or indirectly.
For visitors in the UK and the EU/EEA, we are the “data controller” for the personal data described in this policy, which means we decide how and why it is used. For visitors in Australia, we are the organisation (“APP entity”) responsible for handling your personal information under the Privacy Act 1988 (Cth). We process personal data in accordance with the laws set out in “Which laws apply to you” below (together, the “Data Protection Laws”).
- Legal entity: Turn It Off Ltd, a company registered in England and Wales with company number 14784848, trading as Messy Works.
- Registered office: 4th Floor, 399-401 Strand, London, WC2R 0LT.
- ICO registration number: ZB701994.
- Data protection contact: [email protected]
If you have any question about this policy or about your personal data, please contact us using the details above.
Which laws apply to you
This policy is written to work for visitors in the UK, the EU/EEA, and Australia. The practices described in this policy are the same wherever you visit from, but the law and the regulator that apply to you depend on where you are:
| Where you are | Law | Regulator |
|---|---|---|
| United Kingdom | UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) | Information Commissioner’s Office (ICO) |
| EU / EEA | The EU General Data Protection Regulation (GDPR) and the ePrivacy Directive, as implemented into the national law of your member state | The data protection supervisory authority in your EU/EEA country |
| Australia | The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) | Office of the Australian Information Commissioner (OAIC) |
We refer to these collectively as the “Data Protection Laws”. The section “Your privacy rights and how to complain” below sets out your specific rights and complaint route, by region.
The Privacy Act 1988 (Cth) applies to us, and we handle personal information collected from visitors in Australia in accordance with it and the Australian Privacy Principles.
Purpose of this policy
This policy is intended to tell you how we collect and use your personal data, and about your privacy rights and how the law protects you. It applies however you interact with this website, including when you fill in our contact form, use the configurator to request a call back, or otherwise browse the site, and regardless of where you visit from.
This policy covers the personal information we collect through this website. It does not cover the services we deliver to customers under a signed Work Order or contract; information handled as part of a paid engagement is governed by that contract and its own data protection terms (see our customer and builder terms).
This website is not intended for children, and we do not knowingly collect data relating to anyone under 18.
This policy may be supplemented by other privacy notices we give you on specific occasions when we are collecting or processing your personal data, and it does not override them.
Changes to this policy
This policy may be amended in future to reflect changes in Data Protection Laws, our services, or our organisation. The date at the top shows when it was last updated.
Third-party links
Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website that you visit.
The information we collect
We collect the following personal data through this website:
Information you give us directly. When you fill in the contact form or the configurator lead form, we collect:
- your name;
- your email address;
- your phone number;
- your answers to the configurator questions (for example your stack and your goals), where you use it; and
- whether you have opted in to hear from us about our services (marketing).
You do not have to give us this information, but if you do not, we will not be able to respond to your enquiry or arrange a call back.
Information we collect automatically.
- Approximate country. When a page loads, we detect the country your request comes from so that we can show prices in a sensible currency. This is worked out at the moment of the request, is not stored, and does not set a cookie.
- Analytics. This website does not currently use analytics or set any analytics cookies. If we introduce analytics in future (for example to understand which pages are visited), it will run only if you accept it, and we will update this policy and our Cookie Policy first. See our Cookie Policy for the current position.
We do not collect any Special Categories of Personal Data (this includes details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, or health, genetic or biometric data, which is broadly equivalent to “sensitive information” under the Australian Privacy Principles), and we do not collect information about criminal convictions, offences, or criminal record information.
We do not collect payment card or other financial account details through this website.
How your personal data is collected
We collect personal data in two ways:
- Direct interactions. You give us your name, email, phone number and marketing preference by filling in the contact form or the configurator on this website.
- Automated technologies. As you interact with this website, we automatically detect your approximate country (not stored, no cookie). We do not currently use analytics; if we introduce it in future, it would collect information about your browsing actions and patterns on the site only if you consent.
How we use your personal data, and our legal basis
If UK GDPR or the EU GDPR applies to you, we must have a lawful basis for using your personal data. The table below sets out what we do and why.
| What we do | Personal data used | Our lawful basis |
|---|---|---|
| Respond to your enquiry and arrange a call back | Name, email, phone, configurator answers | Necessary to take steps you have asked for, and our legitimate interest in answering enquiries about our services |
| Send you marketing about our services, if you asked us to | Name, email, marketing preference | Your consent, which you can withdraw at any time |
| Keep the website secure and working, and diagnose problems | Technical information such as your request’s country | Our legitimate interest in running a safe, reliable website |
| Understand how the site is used so we can improve it, if we introduce analytics in future | Analytics information | Your consent |
| Meet our legal and accounting obligations | Contact and enquiry records | Compliance with a legal obligation |
“Legitimate interest” means we have a genuine business reason for using your data, and we have weighed that reason against your rights and interests before relying on it. You can ask us about that balancing exercise at any time using the contact details above.
The requirement to obtain your consent before setting any analytics or other non-essential cookie comes from PECR (in the UK) and the ePrivacy Directive (in the EU/EEA). Australia does not have a dedicated cookie-consent law equivalent to PECR or the ePrivacy Directive; to the extent cookies or similar technologies collect personal information from Australian visitors, the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply instead, and we use the same consent-first approach for all visitors regardless of where they are.
For readers in Australia: rather than a “lawful basis” in the GDPR sense, the Privacy Act 1988 (Cth) requires that our collection of personal information be reasonably necessary for our business functions, and that we only use or disclose it for the purpose we collected it for, for a related purpose you would reasonably expect, with your consent, or as otherwise permitted by law. In practice, we use personal information collected from Australia for the same purposes described in the table above.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so. We may process your personal data without your knowledge or consent, in compliance with the above, where this is required or permitted by law.
Marketing and your choices
We will only send you marketing if you have opted in. You can opt out at any time by using the unsubscribe link in any marketing email, or by contacting us using the details above. Opting out of marketing does not stop us contacting you about an enquiry or a service you have asked for.
Who we share your information with
We do not sell your personal data. We share it only with the service providers who help us run this website and respond to you, and only so that they can do that job for us. The providers we currently use are:
- Cloudflare, which hosts this website and helps keep it secure.
- Resend, which delivers the emails generated by our forms. These emails are processed in the European Union (Ireland).
- Apollo, which we may use to enrich the business contact details you give us (for example matching them to publicly available information such as your company and role), so we can respond to your enquiry with the right context.
If we introduce analytics in future, we would also use an analytics provider such as Google Analytics to measure how the site is used, and only if you accept analytics cookies.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and only permit them to process it for the purposes we specify.
We may also share personal data where the law requires it, with professional advisers such as lawyers or accountants where needed, and with a buyer or successor if we sell, transfer or reorganise all or part of our business.
International data transfers
Some of the providers listed above may process personal data outside the country you are visiting from. Depending on where you are, different rules govern these transfers:
- From the UK. Where personal data is transferred outside the UK, we rely on the safeguards UK GDPR requires (for example an adequacy regulation or approved transfer mechanism) to keep your personal data protected to a standard equivalent to that under UK law.
- From the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on the safeguards the GDPR requires (for example an adequacy decision or Standard Contractual Clauses).
- From Australia. Under Australian Privacy Principle 8 (APP 8), before we disclose personal information to a recipient overseas we must take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles in relation to that information, unless an exception applies.
Data security
We have put in place appropriate technical and organisational measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those who have a business need to know it, and they are subject to a duty of confidentiality. We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator where we are legally required to do so.
How long we keep your personal data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements.
In practice, we keep personal data only for as long as it is necessary and required, and no longer than the maximum periods permitted by law.
In some circumstances you can ask us to delete your data sooner: see “Your privacy rights and how to complain” below. We may also anonymise personal data (so it can no longer be associated with you) for research or statistical purposes, in which case we may keep and use that information indefinitely without further notice to you.
Your privacy rights and how to complain
Please contact us first using the details above if you have any concern about how we have handled your personal data, so that we can try to address it directly. Your specific rights, and the regulator you can complain to if you remain unhappy, depend on where you are.
If you are in the UK
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- request access to your personal data (commonly known as a “data subject access request”), so you can receive a copy of what we hold and check we are processing it lawfully;
- request correction of personal data we hold about you that is incomplete or inaccurate;
- request erasure of your personal data in certain circumstances, for example where there is no good reason for us to keep processing it;
- object to processing of your personal data where we rely on legitimate interest, including objecting to direct marketing at any time;
- request restriction of how we use your personal data in certain circumstances;
- request the transfer of your personal data to you or a third party, in a structured, commonly used, machine-readable format, where that right applies; and
- withdraw consent at any time where we rely on your consent, without affecting the lawfulness of processing before you withdrew it.
To exercise any of these rights, contact us using the details above. You will not usually have to pay a fee, and we aim to respond within one month. We may need to confirm your identity first, and if a request is manifestly unfounded, repetitive or excessive, we may charge a reasonable fee or decline to act on it.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) at any time:
Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF
Helpline: 0303 123 1113 Website: https://www.ico.org.uk
If you are in the EU or EEA
Under the GDPR, you have broadly the same rights as those listed above for the UK: access, rectification, erasure, restriction of processing, objection (including to direct marketing), data portability, and the right to withdraw consent at any time. To exercise any of these rights, contact us using the details above.
You also have the right to lodge a complaint with the data protection supervisory authority in your EU/EEA country of habitual residence, place of work, or the place of the alleged infringement.
If you are in Australia
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you have the right to:
- request access to the personal information we hold about you (APP 12); and
- request correction of personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13).
To exercise either of these rights, or to raise any other concern about how we handle your personal information, contact us using the details above. We aim to respond within a reasonable period.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). You can find their contact details and online complaint form at https://www.oaic.gov.au.
Cookies
This website uses only a small number of essential cookies to keep it working and secure. We do not currently set analytics or advertising cookies. If we introduce analytics in future, it will run only if you accept it, following a consent-first approach designed to meet PECR (UK), the ePrivacy Directive (EU/EEA), and to be consistent with the Australian Privacy Principles. Full detail is set out in our Cookie Policy.
Contact us
Turn It Off Ltd, trading as Messy Works 4th Floor, 399-401 Strand, London, WC2R 0LT
Email: [email protected]
Last updated: 24 August 2026