Privacy Policy
Last updated: 21 June 2026
Mafhom ("Mafhom", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website (mafhomhub.com), use our client portal, or engage our marketing services. Please read it carefully.
1. Who We Are
Mafhom is a digital marketing agency registered in England and Wales (Company No. 15891234). Our registered office is at 20 Farringdon Street, London EC4A 4AB, United Kingdom.
Data Controller: Mafhom Data Protection contact: privacy@mafhomhub.com ICO Registration Number: ZB712345
If you are located in the UAE or wider MENA region, Mafhom acts as the data controller in accordance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection.
2. What Data We Collect
We collect personal data in the following categories:
Identity Data — first name, last name, username or similar identifier, title. Contact Data — business email address, telephone number, business address. Technical Data — IP address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website. Usage Data — information about how you use our website, products and services. Marketing Data — your preferences in receiving marketing communications from us. Enquiry Data — information you provide when you submit our contact form, including company name, budget range, service interest, and any message content. Client Data — data you provide or we generate in the course of delivering our services, including campaign briefs, advertising account access credentials (handled via platform OAuth — we never store your passwords), performance reports, and creative assets.
3. How We Collect Your Data
Direct interactions — you provide data when completing our enquiry form, signing up to our newsletter, requesting a strategy session, or communicating with us by email, phone, or post.
Automated technologies — as you interact with our website, we automatically collect Technical Data using cookies, server logs, and similar technologies. See our Cookie Policy for full details.
Third parties — we may receive data about you from analytics providers (Google Analytics, Meta Pixel), advertising networks, and our CRM platform.
4. How We Use Your Data
We process your data on the following lawful bases:
Contract — to onboard you as a client, deliver advertising services, issue invoices, and fulfil contractual obligations. Legitimate Interests — to respond to enquiries, improve our website and services, prevent fraud, and manage our business relationships. We balance these interests against your rights before relying on this basis. Legal Obligation — to comply with accounting, tax, anti-money-laundering, and other legal requirements. Consent — to send marketing emails and deploy non-essential cookies (where your consent has been given).
We use your data specifically to: • Respond to your enquiry and send you requested information • Onboard you as a client and deliver agreed services • Manage campaigns across Meta, Google, TikTok, LinkedIn, and other platforms on your behalf • Issue invoices and collect payment • Send performance reports and portal notifications • Improve our website through aggregated analytics • Send marketing communications (where you have opted in or where our legitimate interests apply and you have not opted out)
5. Data Sharing and Disclosure
We do not sell your personal data. We share data only in the following circumstances:
Service providers — We use trusted sub-processors to operate our business, including: • Vercel (website hosting — US, EU transfers covered by SCCs) • PlanetScale / Turso (database — EU region) • Google Workspace (email and documents — EU region) • Stripe (payment processing — ISO 27001 certified) • Notion (project management — EU data residency)
Advertising platforms — To run campaigns on your behalf, we share data with Meta, Google, TikTok, Snapchat, and LinkedIn. Each platform has its own data processing terms, which we will provide on request.
Legal requirements — We may disclose data where required by law, regulation, court order, or to protect the rights, property, or safety of Mafhom, our clients, or others.
6. International Transfers
Some of our service providers are based outside the UK and EEA. Whenever we transfer data internationally, we ensure an equivalent level of protection by using one or more of the following safeguards: • Countries deemed adequate by the UK ICO or European Commission • Standard Contractual Clauses (SCCs) approved by the ICO or European Commission • Binding Corporate Rules where applicable
You can request a copy of the relevant transfer mechanism by contacting privacy@mafhomhub.com.
7. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected. Our standard retention periods are:
Enquiry data (unconverted prospects) — 24 months from submission Client contract and financial records — 7 years (legal requirement under the Companies Act 2006) Campaign performance data — 3 years from campaign end Website analytics — 26 months (rolling, in line with ICO guidance) Marketing consent records — retained until consent is withdrawn
After the relevant retention period, data is securely deleted or anonymised.
8. Your Rights
Under UK GDPR and applicable data protection law, you have the right to:
• Access — request a copy of the personal data we hold about you • Rectification — ask us to correct inaccurate or incomplete data • Erasure — ask us to delete your data in certain circumstances • Restriction — ask us to restrict processing of your data • Data Portability — receive your data in a machine-readable format • Object — object to processing based on legitimate interests or for direct marketing • Withdraw Consent — where processing is based on consent, withdraw it at any time (without affecting prior processing)
To exercise any of these rights, email privacy@mafhomhub.com. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, destruction, or damage. These measures include TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and regular security reviews. However, no system is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email. We encourage you to review this page periodically.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact:
Mafhom Data Protection Team 20 Farringdon Street London EC4A 4AB United Kingdom
Email: privacy@mafhomhub.com Tel: +44 (0)20 7946 0123
Questions about this policy?
privacy@mafhomhub.com