Privacy Policy
Last updated August 7, 2026
Privacy Policy
Last updated: [current date]
1. Introduction
Medraf Digital ("we," "us," or "our") operates the website https://medrafdigital.co.uk and provides AI automation services to businesses in the hospitality industry. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what personal data we collect, how we use it, how we share it, and your rights regarding your information. By using our website or services, you agree to the collection and use of information in accordance with this policy. If you have questions or concerns, please contact us at hello@medrafdigital.co.uk.
2. Information We Collect
We collect personal information that you provide to us directly and information that is collected automatically when you use our website or services.
Information You Provide Directly:
- Identity and contact data: name, email address, phone number, company name, and job title when you fill out forms, request information, sign up for our services, or communicate with us.
- Payment information: billing name, billing address, and payment card details when you purchase our services. Payment card information is collected and processed directly by our third-party payment processor and is not stored on our servers.
- Communications and content: any messages, questions, feedback, testimonials, or other content you submit to us through contact forms, email, SMS, or other channels.
- Account information: username, password, and preferences if you create an account on our platform.
Information Collected Automatically:
- Device and usage data: IP address, browser type and version, operating system, device type, unique device identifiers, pages visited, time and date of visits, time spent on pages, referring website, and other usage statistics.
- Approximate location data: derived from your IP address to understand general geographic regions of our visitors.
- Cookies and similar tracking technologies: we use cookies, web beacons, and similar technologies to collect information about your browsing behavior. For details, see Section 7 and our Cookie Policy.
Information from Third Parties:
We may receive information about you from third-party service providers, analytics partners, advertising networks, and publicly available sources to supplement the information we collect directly.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- Service delivery: to provide, maintain, and improve our AI automation services, fulfill contracts, and deliver the products or services you request.
- Payment processing: to process transactions, verify payment information, and manage billing through our third-party payment processor.
- Communications: to send transactional emails and SMS messages related to your account, purchases, or service updates; to respond to your inquiries and provide customer support; and to send marketing communications about our services, promotions, and industry insights where you have consented or we have a legitimate interest.
- Analytics and improvement: to analyze how visitors use our website, understand user preferences, improve our services, develop new features, and optimize user experience.
- Security and fraud prevention: to detect, prevent, and address technical issues, fraudulent activity, security threats, and violations of our terms.
- Legal compliance: to comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
- Business operations: to manage our business relationships, maintain records, and conduct internal administration.
4. Legal Bases for Processing
For visitors in the European Union and United Kingdom, we process your personal data under the following legal bases as required by the General Data Protection Regulation (GDPR) and UK GDPR:
- Consent: when you have given clear consent for us to process your personal data for a specific purpose, such as subscribing to marketing communications or accepting cookies.
- Performance of a contract: when processing is necessary to fulfill a contract we have with you or to take steps at your request before entering into a contract, such as delivering services you have purchased.
- Legitimate interests: when processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Legitimate interests include improving our services, conducting analytics, preventing fraud, and direct marketing to existing customers.
- Legal obligation: when we must process your data to comply with legal or regulatory requirements.
5. How We Share Your Information
We do not sell your personal information to third parties. We share your information only in the following circumstances:
Service Providers and Processors:
We share personal data with trusted third-party service providers who perform services on our behalf, including:
- Payment processors to handle transactions securely.
- Email service providers to send transactional and marketing emails.
- SMS service providers to send text messages where you have provided prior express consent.
- Website hosting and cloud storage providers to store data and maintain our infrastructure.
- Analytics providers to understand website usage and improve our services.
- Customer relationship management (CRM) and marketing automation platforms.
These service providers are contractually obligated to use your information only for the purposes we specify and to implement appropriate security measures.
Legal and Safety Disclosures:
We may disclose your information if required to do so by law or in response to valid requests by public authorities, such as to comply with a subpoena, court order, or legal process; to protect our rights, property, or safety or that of our users or the public; to enforce our terms and conditions; or to investigate fraud or security issues.
Business Transfers:
If Medraf Digital is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your personal information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any change in ownership or use of your personal information.
California Opt-Out of Sale or Sharing:
We do not sell personal information as defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not share personal information for cross-context behavioral advertising. California residents have the right to opt out of any future sale or sharing, and we will honor such requests.
6. Marketing Communications and Your Choices
Email Marketing:
We may send you marketing emails about our services, promotions, and industry news if you have consented to receive them or if we have a legitimate interest and you have not opted out. Every marketing email includes an unsubscribe link. You may opt out at any time by clicking the unsubscribe link or by contacting us at hello@medrafdigital.co.uk. We comply with the CAN-SPAM Act, including honoring opt-out requests promptly, identifying ourselves as the sender, and including our physical mailing address in commercial emails.
SMS Marketing:
If you provide your mobile phone number and opt in to receive SMS messages, we may send you text messages about our services, promotions, and updates. By opting in, you provide your prior express written consent as required by the Telephone Consumer Protection Act (TCPA). You may opt out at any time by replying STOP to any message. Reply HELP for assistance. Message and data rates may apply. We will honor opt-out requests immediately and will not send further marketing messages to that number.
Transactional Communications:
Even if you opt out of marketing communications, we may still send you transactional or service-related messages necessary to provide our services, such as order confirmations, account notifications, and customer support responses.
7. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing activity, remember your preferences, and analyze website usage. Cookies are small text files stored on your device. Some cookies are essential for the website to function, while others are used for analytics, advertising, and personalization.
You can control cookies through your browser settings and opt out of certain tracking technologies. For detailed information about the cookies we use, the purposes for which we use them, and how to manage your cookie preferences, please see our separate Cookie Policy.
8. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Retention periods vary depending on the type of data and the purpose for which it was collected:
- Account and service data is retained for the duration of your relationship with us and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
- Marketing data is retained until you opt out or request deletion, or until we determine the data is no longer relevant for marketing purposes.
- Payment and transaction records are retained as required by tax, accounting, and financial regulations, typically for at least seven years.
- Analytics and usage data may be retained in aggregated or anonymized form indefinitely for statistical and business intelligence purposes.
When personal data is no longer needed, we will securely delete or anonymize it in accordance with our data retention and deletion policies.
9. Data Security
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, secure server infrastructure, access controls, regular security assessments, and employee training on data protection.
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information.
EU and UK Residents (GDPR and UK GDPR):
If you are located in the European Union or United Kingdom, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete personal data.
- Right to erasure (right to be forgotten): request deletion of your personal data in certain circumstances.
- Right to restriction of processing: request that we limit how we use your personal data in certain situations.
- Right to data portability: request a copy of your personal data in a structured, commonly used, and machine-readable format.
- Right to object: object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
You also have the right to lodge a complaint with a supervisory authority if you believe we have violated your privacy rights.
California Residents (CCPA and CPRA):
If you are a California resident, you have the following rights:
- Right to know: request disclosure of the categories and specific pieces of personal information we have collected, the sources from which it was collected, the purposes for collection, and the categories of third parties with whom we share it.
- Right to delete: request deletion of your personal information, subject to certain exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: opt out of the sale of your personal information or sharing for cross-context behavioral advertising. We do not sell or share personal information as defined by the CCPA/CPRA.
- Right to limit use of sensitive personal information: request limitation on the use and disclosure of sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA/CPRA.
- Right to non-discrimination: you have the right not to receive discriminatory treatment for exercising your privacy rights.
Submitting a Request:
To exercise any of these rights, please contact us at hello@medrafdigital.co.uk or call +447933286995. Please provide sufficient information to allow us to verify your identity and locate your data. We will respond to verified requests within the timeframes required by applicable law (typically 30 days for GDPR requests and 45 days for CCPA requests, with possible extensions). We do not charge a fee for processing requests unless they are manifestly unfounded, excessive, or repetitive.
11. International Data Transfers
Medraf Digital is based in the United Kingdom. If you are accessing our services from outside the UK, please be aware that your personal information may be transferred to, stored, and processed in the UK or other countries where our service providers operate. These countries may have data protection laws that differ from those in your country of residence.
When we transfer personal data from the European Economic Area (EEA) or UK to countries that do not provide an adequate level of data protection, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or UK authorities, or rely on other lawful transfer mechanisms. By using our services, you consent to the transfer of your information to countries outside your country of residence.
12. Children's Privacy
Our services are not directed to children under the age of 13 (or under 16 in the European Economic Area and United Kingdom). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at hello@medrafdigital.co.uk. If we become aware that we have collected personal information from a child under the applicable age without verification of parental consent, we will take steps to delete that information promptly.
13. Third-Party Links and Services
Our website may contain links to third-party websites, applications, or services that are not operated or controlled by Medraf Digital. This Privacy Policy does not apply to those third-party sites or services. We are not responsible for the privacy practices or content of third parties. We encourage you to review the privacy policies of any third-party sites or services before providing them with your personal information.
We may use third-party analytics, advertising, and social media services that collect information about your online activities over time and across different websites. These third parties may use cookies and similar technologies to track your behavior and serve targeted advertising. You can opt out of certain third-party tracking and advertising through industry opt-out tools and browser settings.
If we publish testimonials, reviews, or endorsements on our website or marketing materials, we will obtain your consent before using your name or likeness. In accordance with the Federal Trade Commission's 16 CFR Part 255 guidelines, any material connections between us and endorsers (such as compensation or free products) will be clearly disclosed. If you wish to update or remove a testimonial, please contact us.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this policy. If we make material changes that significantly affect your rights or how we use your personal information, we will notify you by email (if you have provided an email address) or by posting a prominent notice on our website prior to the changes taking effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our services after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Medraf Digital Llinos Haf Owen Email: hello@medrafdigital.co.uk Phone: +447933286995
For privacy-related inquiries or to exercise your data protection rights, you may also contact our compliance team at the email address above. We will respond to your inquiry as promptly as possible and within the timeframes required by applicable law.