1. Introduction and Scope

MDR ASSOCIATES LIMITED provides control system design, real-time software, safety instrumented systems, data acquisition platforms, commissioning support and technical documentation to industrial and professional clients. In the course of doing that work, and in the course of running this website, we handle personal information about visitors, prospective clients, client staff, suppliers and partners. This policy describes that handling in plain language.

The policy covers the website at mdrassociates.buzz, any email that you send to our team, telephone conversations with our engineers and the records we keep while delivering a project. It does not cover third party websites that we might link to, because those sites have their own privacy practices and their own controllers. We encourage you to read the privacy notice of any external site you visit.

We have written this document so that it can be read by a busy plant manager as easily as by a legal specialist. Where the law uses a technical term, we explain it in ordinary words. Our goal is that you finish reading this page knowing exactly what happens to your information and why.

2. Who We Are as Controller

The data controller is MDR ASSOCIATES LIMITED, a company established in the United Kingdom. Our registered place of business is 6 Queens Court, Queens Court North, Third Avenue, Team Valley Trading Estate, Gateshead - NE11 0BU, United Kingdom (GB). As controller, we decide why personal information is collected and how it is used, and we remain accountable for the way it is protected.

Our team is deliberately small and technically focused. The person who answers your enquiry is often the same engineer who would deliver your project, which means personal information circulates within a limited group of people who need it to do their work. This is a deliberate design choice that reduces risk and improves the quality of every response.

If you have any question about this policy or about the way we handle your information, you can reach us by email at systems@mdrassociates.buzz or by telephone on +12705963500 during our normal business hours.

3. Information We Collect

We collect several categories of personal information, and the category depends on how you interact with us. The main categories are contact details, enquiry content, technical data, usage data and project correspondence.

Contact details include your name, your email address, your telephone number and, where you provide them, your job title, your employer and a postal address. We collect these details when you write to us, call us or complete a form on our website.

Enquiry content

When you contact us about a project, you may describe a machine, a process, a fault or a timescale. That description can contain personal information, for example the name of a colleague or the location of a site. We treat such content with the same care as any other personal information.

Technical and usage data

Like most websites, ours may record limited technical information such as the type of browser you use, the pages you visit and the approximate region from which you connect. This information helps us keep the site reliable and understand which pages are useful. We describe the tools involved in the sections on cookies and analytics below.

Correspondence records

We keep a record of emails, proposals, meeting notes and project documents because good engineering depends on an accurate history. These records may include personal information such as the names of the people involved in a decision.

4. How We Obtain Information

Most of the personal information we hold comes directly from you. You give it to us when you send an email, place a call, submit the contact form, request a quotation or sign an engagement letter. We value that direct relationship because it keeps our records accurate and our understanding of your needs clear.

Some information arrives indirectly. A colleague at your organisation may introduce you, a partner may forward your details with your knowledge, or a public source such as a company website may provide a business contact. Where we rely on a public source, we limit ourselves to information that is genuinely relevant to a professional enquiry.

We do not buy personal data in bulk, and we do not build profiles of individuals from unrelated sources. If we ever receive information about you that we did not expect, we will tell you where it came from as soon as it is practical to do so.

5. Purposes of Processing

We process personal information for a limited set of purposes, each of which serves a clear professional need. Those purposes are to respond to enquiries, to prepare proposals and quotations, to deliver and support the services described on our website, to manage our commercial and legal obligations and to improve our own operations.

Responding to enquiries means reading your message, understanding the technical problem and replying with a considered answer. Preparing proposals means drafting a scope, an estimate and a schedule that reflect what we have learned about your situation. Delivering services means doing the engineering, whether that involves control system design, real-time software, safety instrumented systems, data acquisition platforms, commissioning support or technical documentation.

Managing obligations means keeping accounting records, meeting tax and regulatory duties and maintaining the evidence we need to stand behind our work. Improving operations means reviewing how we communicate and how our website performs, so that future clients receive a better experience.

6. Lawful Bases for Processing

Every use of personal information must rest on a lawful basis. For most of our processing we rely on legitimate interests, on the performance of a contract or on your consent, and we are careful to match the basis to the activity.

We rely on legitimate interests when we respond to a business enquiry, when we keep records of professional correspondence and when we take reasonable steps to protect our systems. We have considered the balance between our interests and your rights, and we limit the information we use to what is necessary for the purpose in question.

We rely on the performance of a contract, or on steps taken at your request before a contract, when we prepare a quotation or deliver an engagement that you have commissioned. We rely on consent when you ask to receive occasional updates, and you may withdraw that consent at any time without affecting the service we provide to you.

Where the law requires us to process information for a legal obligation, such as a tax or accounting duty, we rely on compliance with that obligation as our basis.

7. Cookies and Similar Technologies

A cookie is a small file that a website may place on your device to remember something about your visit. Cookies can be useful, for example by keeping a page working correctly, or they can be used to track activity across many sites. Our site is built to work without advertising cookies, and we do not use cookies to follow you around the internet.

Where we use a cookie or a similar technology, it is for a functional or an analytical purpose. Functional use keeps the website reliable, and analytical use helps us understand which pages visitors find helpful. You can control cookies through your browser settings, and you can delete cookies already stored on your device at any time.

If you disable cookies, the website should continue to work, although a small number of conveniences may be unavailable. We will always be transparent about any cookie that is not strictly necessary, and we will seek consent where the law requires it.

8. Website Analytics

We measure how our website is used so that we can improve its structure and content. The measurements we take are aggregated, which means they describe patterns rather than individuals. We look at which pages are visited, how visitors arrive and whether people find the information they need.

Aggregated analytics help us decide which services to explain in more depth and where to place essential contact details. We do not use analytics to make automated decisions about you, and we do not sell analytics information to anyone.

Where an analytics service is provided by a third party, that provider acts under a contract that limits its use of the information to the service it provides to us. We choose providers with a strong record on privacy and we review those arrangements from time to time.

9. Sharing and Disclosure

We do not sell personal information, and we do not trade it for marketing purposes. We share information only when it is necessary to deliver a service, to meet a legal duty or to protect legitimate interests.

A necessary delivery might involve a subcontractor who helps us on a project, for example a specialist test house. In that case we share only the details that the subcontractor needs, and we require the subcontractor to protect those details to the same standard we apply ourselves.

A legal duty might involve a court order, a regulatory request or a tax obligation. Where we are permitted to do so, we will tell you that a request has been made, so that you can respond if you wish. We scrutinise every request to be sure it is valid before we act on it.

We may also disclose information when it is necessary to investigate a suspected fraud, to protect the safety of a person or to defend our legal rights. Any such disclosure is limited to what the situation genuinely requires.

10. Service Providers and Processors

We rely on a small number of service providers to run our business, including providers of email, website hosting and document storage. These providers act as processors, which means they handle information on our instructions and not for their own purposes.

Before we engage a processor we consider the sensitivity of the information involved and the security measures the provider offers. Our written agreements require each processor to keep information confidential, to apply appropriate technical safeguards and to assist us in meeting our own legal duties.

We review our processors periodically, and we replace any provider whose practices fall short of the standard we expect. Our clients and website visitors should never have to accept a lower level of protection because of a choice we made about suppliers.

11. International Transfers

Some service providers operate globally, which means information may be stored or processed outside the United Kingdom. Where a transfer leaves the United Kingdom, we take steps to ensure the information continues to receive a comparable level of protection.

Those steps may include relying on an adequacy finding, using approved contractual safeguards or applying additional measures where the circumstances require them. We assess each transfer on its merits rather than assuming that a standard clause is always sufficient.

If you would like to know more about the safeguards that apply to a particular transfer, you can contact us and we will explain the arrangement in plain terms.

12. Retention of Information

We keep personal information only for as long as we need it. The appropriate period depends on the purpose, the legal requirements that apply and the value of the record to the relationship.

Enquiries that do not lead to an engagement are usually kept for a limited period so that we can pick up a conversation if you return, and then removed. Project records are kept for longer because engineering work often needs to be referenced years later, and because accounting and legal rules require it.

When a retention period ends, we delete the information or, where deletion is not immediately possible, we isolate it so that it is no longer used for any active purpose. We review our retention practices regularly to be sure that we are not holding on to information without a reason.

13. Security of Your Information

We protect personal information with a combination of technical and organisational measures. These include access controls that limit who can reach our records, encrypted connections for data in transit, secure storage for documents and a practice of keeping the number of copies of any record as small as it can be.

Our engineers understand that information handling is part of professional conduct, not an administrative afterthought. We train our team to recognise common threats such as fraudulent email and to report anything suspicious immediately. Where a system stores client information, we design it with the same care we bring to a control system, including clear ownership and tested recovery.

No method of storage or transmission is completely secure, and we cannot promise that a breach will never occur. What we can promise is that we will act quickly if one does, that we will investigate thoroughly and that we will notify you and any relevant regulator when the law requires it.

14. Your Rights

The law gives you a set of rights over the personal information we hold about you. These rights are not absolute, and each is subject to conditions, but we will always take a request seriously and explain any limit that applies.

You have the right to be informed about how we use your information, which is the purpose of this policy. You have the right of access, which means you can ask for a copy of the personal information we hold about you and an explanation of how it is used.

You have the right to rectification, so that inaccurate information can be corrected. You have the right to erasure in certain circumstances, often described as the right to be forgotten. You have the right to restrict processing, which pauses certain uses while a concern is examined.

You have the right to data portability, which allows you to receive certain information in a structured and commonly used format. You have the right to object to processing that rests on legitimate interests, and you have rights relating to automated decision making, although we do not use your information for that purpose.

To exercise any of these rights, contact us using the details below. We will respond within the time the law allows and, where a request is complex, we will keep you informed of our progress.

15. Privacy for Children

Our services are professional engineering services intended for businesses and other organisations. This website is not directed at children, and we do not knowingly collect personal information from children in the course of our normal work.

If you believe that a child has provided personal information to us, please contact us so that we can investigate and, where appropriate, remove the information promptly. We would rather act on a concern raised in good faith than leave a record in place that should not exist.

Where a project involves a site that is visited by the public, we still do not collect information about children as part of our engineering role. Our work concerns machines and processes, not the personal profiles of the people who pass nearby.

16. Marketing and Communications

We send occasional updates about our services only where we have a lawful basis to do so. If you have asked to hear from us, you can change your mind at any time, and every message will tell you how to stop receiving further communications.

We keep our communications relevant and infrequent. Our focus is on useful information about control, real-time software and safety engineering rather than on volume. If a message is not helpful to you, we would rather you told us than quietly ignored us.

Even if you opt out of updates, we may still contact you about an active project, an outstanding quotation or a matter connected to a contract we hold with you. Those messages are part of delivering the service you asked for rather than marketing.

17. Client Project Data

When we deliver a project, we sometimes handle technical data that belongs to our client, and that data may contain personal information. In those situations we usually act on the instructions of the client, who remains responsible for the data it has collected.

We treat client project data with the same care as our own records. Access is limited to the engineers working on the engagement, and we return or delete the data at the end of the project in line with the agreement. Where a client asks us to retain a copy for future maintenance, we record that instruction and the period for which it applies.

Because our work often concerns machines rather than people, the personal information involved is usually limited to names and roles. Even so, we apply the full discipline of this policy to every record we hold on behalf of a client.

18. Changes to This Policy

We review this Privacy Policy regularly and update it when our practices or the law change. When we make a material change, we will make the new version available on this page and adjust the date shown at the foot of the document.

We encourage you to revisit this page from time to time, particularly before you begin a new piece of work with us. If a change is significant, we will take reasonable steps to bring it to your attention rather than relying on you to notice it.

Continued use of our website or services after an update means that you accept the revised policy. If you do not agree with a change, you are welcome to contact us to discuss your concerns before deciding how to proceed.

19. How to Contact Us

If you have a question about this policy, a request relating to your rights or a concern about the way your information has been handled, please contact us. We would rather hear from you early than have a small uncertainty grow into a dispute.

You can write to MDR ASSOCIATES LIMITED at 6 Queens Court, Queens Court North, Third Avenue, Team Valley Trading Estate, Gateshead - NE11 0BU, United Kingdom (GB). You can email us at systems@mdrassociates.buzz or telephone us on +12705963500 during our business hours.

When you make a request, it helps if you tell us what it concerns and, where relevant, provide enough detail for us to identify the information involved. We will confirm receipt, explain what happens next and keep you informed until the matter is resolved.

20. Complaints and Regulators

We hope that any concern can be resolved directly with us, and we will always try to do so promptly and fairly. If you are not satisfied with our response, you have the right to raise the matter with the relevant supervisory authority for data protection in the United Kingdom.

Before you escalate a complaint, we would welcome the chance to put things right ourselves. A short conversation often clears up a misunderstanding, and we are willing to explain our reasoning and to change our practice where that is the right thing to do.

We record complaints and the actions we take in response, because learning from a concern is the most reliable way to prevent it from recurring. Your feedback helps us keep the standard of our information handling as high as the standard of our engineering.