1. Who controls your information
Ultra Protection Ltd, trading as MercuryLink, is the controller of personal data described in this notice. We are registered in England and Wales under company number 17020291. Our registered office is Office 17322, 182–184 High Street North, East Ham, London, E6 2JA, United Kingdom.
Privacy questions and rights requests may be sent to accounts@mercurylink.co.
2. Scope
This policy applies to visitors, account holders, business contacts and supplier representatives whose information is processed through the MercuryLink website, sourcing requests, support messages or Managed Negotiation service. It does not govern an independent supplier’s own website or privacy practices.
3. Information we collect
- Account and identity data: name, business email, account role, email-verification status and securely hashed password and session records.
- Sourcing data: product images, filenames, product descriptions, quantities, units, delivery addresses, target prices, origin preferences, customisation and certification requirements.
- Service records: supplier research, evidence, scores, messages, admin decisions, negotiation emails, quotations, offers and request history.
- Payment and transaction data: service selected, amount, currency, payment status, Stripe checkout identifiers and timestamps. MercuryLink does not receive or store your full payment-card number.
- Technical and security data: IP address and related request information, login and rate-limit events, CAPTCHA results, browser/device information made available in network requests, and security or audit records.
- Communications: messages sent to support, administrators, suppliers or through the service, including attachments and contact details.
Please do not upload identity documents, payment-card details, sensitive personal data or information about another person unless it is necessary, lawful and you have authority to provide it.
4. Where information comes from
Most personal data comes directly from you. We may also receive payment status from Stripe, supplier contact and response data from public websites or suppliers, security signals from Google reCAPTCHA and hosting providers, and delivery or complaint information from our communications providers.
5. Why we use information and our lawful bases
- Contract: to create and secure your account, save requests, analyse uploaded products, take payment, research suppliers, provide reports, support negotiations and communicate about the service.
- Legitimate interests: to prevent fraud and abuse, enforce our terms, protect users and suppliers, improve reliability, troubleshoot failures, maintain business records and defend legal claims. We consider the impact on individuals before relying on this basis.
- Legal obligation: to keep tax and accounting records, respond to lawful authority requests, apply sanctions or other legal controls, and meet corporate and data-protection duties.
- Consent: where we specifically ask for optional consent, such as future direct marketing. You may withdraw consent at any time without affecting earlier lawful use.
We do not currently sell personal data or use it for third-party behavioural advertising.
6. AI-assisted processing and compliance decisions
Product images and Client-approved briefs may be sent to an AI service to identify visible product characteristics, develop research queries, organise public supplier evidence and support negotiation drafts. Human administrators can review sourcing results and negotiation outputs before they are published or relied upon.
After payment, automated and human-assisted safety checks may classify a request as prohibited. A prohibited classification can stop research, produce no supplier results and temporarily suspend an account. We use the image, title, description, requested transaction and safety response to make this assessment. You may request human review by emailing us with the request ID. We do not intend to make solely automated decisions that produce legal or similarly significant effects without the safeguards required by applicable law.
8. International transfers
MercuryLink serves international sourcing activity, so information may be processed outside the United Kingdom, including where a supplier or technology provider is located. Where UK data-protection law requires safeguards, we rely on an adequacy regulation, approved contractual protections such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. Contact us if you would like further information about safeguards relevant to your data.
9. How long we keep information
We keep personal data only for as long as reasonably necessary for the purposes above. Account and sourcing records are generally retained while the account is active and afterwards where needed to provide history, resolve disputes, prevent prohibited re-registration and protect legal rights. Contract, invoice and payment records may be kept for up to six years after the relevant transaction, or longer where tax, legal or dispute requirements apply.
Retention periods may also depend on the sensitivity of the data, security risk, contractual commitments and whether deletion would impair an ongoing investigation or legal claim. We delete or anonymise information when it is no longer required. Backup copies may remain for a limited period until overwritten.
10. Security
We use measures designed to protect information, including access controls, password hashing, private session credentials, encrypted integration secrets, private object storage and restricted administrator functions. No internet service can guarantee absolute security. You are responsible for using a unique password and protecting your account and email access.
12. Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to access, correct or erase personal data; restrict or object to its use; receive portable data; withdraw consent; and ask for review of certain automated decisions. These rights are not absolute—for example, we may retain transaction or abuse-prevention records where law or legitimate claims require it.
Send a request to accounts@mercurylink.co. We may need to verify your identity and authority before responding. You also have the right to complain to the UK Information Commissioner’s Office through ico.org.uk, or to the appropriate regulator where you live.
13. Children
MercuryLink is a business service and is not intended for anyone under 18. We do not knowingly create accounts for children.
14. Changes and contact
We may update this notice when our service, providers or legal obligations change. Material changes will be highlighted through the website or account where appropriate, and the updated date will appear at the top. Questions may be sent to accounts@mercurylink.co.
