Privacy policy
What we collect when you use this site, why we are allowed to, who else touches it, and how to make us delete it. Written to be read once rather than skimmed and ignored.
- Last updated
- 22 August 2026
- Version
- 1.1
- Published by
- Milex Systems Ltd (company no. 12168672)
Contents
The short version
We are a web development agency. We do not sell data, we do not run advertising, and we do not build profiles of the people who visit this site. Almost everything we hold is something you typed into a form because you wanted to hear from us.
- If you only read the site, we count the page view and nothing else. No cookie, no profile, nothing stored on your device — and you can switch even that off.
- If you send an enquiry, we keep your name, contact details and what you told us about the project, so we can reply and quote.
- If you run a free audit, we scan the website address you give us and keep the resulting report. We do not need your name or email to do it.
- You can ask us to delete any of it by emailing privacy@zeropixel.io. We have one month to respond, and normally take a day or two.
The rest of this page is the detail the law requires us to give. It is written to be read, not to be impenetrable.
Who is responsible for your data
ZeroPixel is a trading name of Milex Systems Ltd, a company registered in England and Wales under company number 12168672. We are the “controller” of the personal data described on this page, which means we decide why and how it is used, and we are accountable for it.
- Registered office: 9, 50a The Viewpoint, Sheep Street, Northampton, NN1 2LZ, United Kingdom
- Privacy contact: privacy@zeropixel.io
- General contact: sales@zeropixel.io
We are not required to appoint a Data Protection Officer, and have not appointed one. The privacy address above reaches the people who can actually action a request.
What we collect, and why
Nothing here is collected “just in case”. Each item below exists because a specific part of the site would not work without it.
When you browse the site
Our hosting provider processes the technical information every website receives in order to serve a page — your IP address, the page requested, your browser type and the site you came from. This sits in server logs and is used to keep the site up and to investigate faults and attacks.
We also count the page view. That count sets no cookie and stores nothing on your device; visits are grouped using a hash that is discarded and regenerated daily, so the same person is not recognisable the next day or on any other website. We see totals, not people.
Because it writes nothing to your device and produces only aggregate figures, this counting begins on your first page view rather than waiting for you to agree — and you can switch it off at any point from the cookie preferences, at which point it stops immediately. Full detail is in the cookie policy.
When you send an enquiry
The form at /discuss asks for your first and last name, email address, phone number, a project title and description, and optionally your budget and timeline. If you came from the audit tool, the report you were looking at is attached to the enquiry so we know what we are talking about before we reply.
We use this to answer you, scope the work and prepare a quote. Please do not put anything confidential or sensitive in the project description — it is a first contact form, not a secure channel, and a mutual NDA is a better place for the detail.
When you run a free website audit
The tool at /audit takes a website address and produces a report. It needs no name, email or account. To run it we process:
- The website address you enter, and everything the scan then finds on that site — page titles, headings, visible text, images, links, and any contact details published on it.
- A random identifier stored in your browser (the
zp_audit_idcookie) and a one-way hash of your IP address, used purely to count how many free scans have come from you. We store the hash, not the IP, and it cannot be turned back into an address. - Bot-detection signals from your browser, assessed at the moment you submit. Every scan costs us a live browser session, two Google PageSpeed calls and an AI analysis, so the endpoint has to be able to tell a person from a script.
If the site you scan publishes email addresses or phone numbers, the report will list them — that is one of the things it checks. Those may be other people’s details. We only ever read what the site already publishes openly, we never attempt to reach anything behind a login, and we do not use those contacts for marketing. See scanning someone else’s site below.
When you email us
We keep the correspondence, along with your address and anything you chose to put in it, so there is a record of what was agreed.
Our lawful basis for each use
UK GDPR requires a specific legal reason for every use of personal data. Ours are:
- Answering your enquiry and quoting — Article 6(1)(b), steps before a contract. You asked us to get in touch about a possible engagement; we cannot do that without your contact details.
- Delivering work we have been engaged for — Article 6(1)(b), contract.
- Running the free audit tool — Article 6(1)(f), legitimate interests. Our interest is offering a genuinely useful free tool that introduces our work, and running it without it being drained by automated abuse. The impact on you is minimal: no account, no name, no email, and the anti-abuse data is a random identifier and a hash.
- Security, fraud prevention and keeping the site available — Article 6(1)(f), legitimate interests, and, for the storage that involves, the strictly-necessary exemption in regulation 6(4) of PECR.
- Analytics — Article 6(1)(f), legitimate interests, and Article 6(1)(a), consent, for the part that uses a cookie. Our interest is knowing which pages are read so we can stop maintaining the ones that are not. Until you answer the banner, and if you decline, the tool runs in a cookieless mode that writes nothing to your device: the consent rule in regulation 6 of PECR is not engaged, and first-party aggregate statistics of this kind are exempt from it in any case under the Data (Use and Access) Act 2025. The impact on you there is close to nil — no cookie, no profile, no recognition across days or sites. If you accept analytics, a cookie is set so that a returning visitor is recognised across days; that part rests on your consent alone, and withdrawing it deletes the cookie and returns the tool to the cookieless mode. Either way you can object or withdraw by switching it off in the cookie preferences.
- Keeping records and meeting our own legal and tax obligations — Article 6(1)(c).
We do not ask for, and have no use for, special category data — health, ethnicity, political opinions, and so on. Please do not send it to us.
Scanning someone else’s site
The audit tool will scan any publicly reachable website, and the report may contain personal data belonging to people who never visited this site — typically staff email addresses and phone numbers published on a contact page. Where that happens we rely on legitimate interests, and we limit the intrusion in specific ways:
- The scan only reads pages that are publicly published and reachable from the homepage. It does not log in, guess URLs, bypass any restriction, or read anything a search engine could not.
- It follows the same limits as an ordinary visitor and stops after a small number of pages.
- Contact details found during a scan are shown in that report and are never added to a marketing list, sold, or used to contact anyone.
- Anyone whose details appear in a report can have them removed by emailing privacy@zeropixel.io with the domain concerned.
You may only scan a site you own or are authorised to test. That obligation is set out in the audit tool terms.
How we use AI, and what it does not decide
The written part of an audit report is generated by a large language model. We send it the measurements and page content gathered during the scan, and it produces the summary, the list of issues and the suggested priorities.
- The provider processes this on our instructions as our processor. Under our API terms the content is not used to train their models.
- Enquiry form submissions are never sent to an AI provider. Only audit scan data is.
- There is no automated decision-making producing legal or similarly significant effects about you, within the meaning of Article 22. A report is an opinion about a website. No person is scored, ranked, profiled or refused anything on the strength of it.
AI-written text can be wrong. Reports are offered as a starting point for a conversation, not as professional advice — see the audit tool terms.
Where your data goes
We are based in the UK and prefer UK and EU processing regions where a supplier offers them. Some of the suppliers listed above are US companies, so some data is processed outside the UK.
Where that happens, the transfer is covered by one or more of the safeguards UK GDPR allows: the UK extension to the EU-US Data Privacy Framework where the supplier is certified, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with an assessment of the protections in place.
You can ask us for the specific mechanism relied on for any supplier by emailing privacy@zeropixel.io.
How long we keep it
We do not keep things indefinitely by default.
- Enquiries that do not become work — up to 24 months from your last contact with us, then deleted. Projects have long lead times and people come back.
- Enquiries that become work — for the length of the engagement and then 6 years, which is the limitation period for contract claims in England and Wales and the retention HMRC expects for business records.
- Audit reports — up to 12 months. A report can be re-used to answer a repeat scan of the same site for 24 hours, so a fresh scan is not paid for twice.
- Audit abuse counters — the identifier and IP hash are held in a rolling 24-hour window and overwritten, not accumulated. There is no history of who scanned what.
- Email correspondence — up to 6 years, for the same reason as above.
- Server logs — short-term, per our hosting provider’s standard retention.
How it is protected
The site is served over HTTPS only. Secrets and API keys are held in the hosting platform’s encrypted environment, never in the codebase. Data is encrypted in transit and at rest by our suppliers. Access to the enquiry database is limited to the people who need it. The audit endpoint is rate-limited, capped and bot-protected.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to be a risk to your rights, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.
Your rights
Under UK GDPR you can ask us to do any of the following. Email privacy@zeropixel.io — there is no form to fill in and no charge.
- See what we hold about you, and get a copy of it.
- Correct anything that is wrong or incomplete.
- Delete it. We will, unless we are required to keep a record — for example an invoice we must retain for tax.
- Restrict or object to our use of it, particularly where we rely on legitimate interests.
- Receive it in a portable format, where we hold it on the basis of your consent or a contract.
- Withdraw consent at any time, where we relied on it, without affecting anything done before you withdrew it.
- Object to analytics with one click. You do not have to email us or give a reason — switching it off in the cookie preferences is a complete and immediate objection, and we act on it without asking you to justify it.
We will respond within one month. We may ask you to confirm your identity first — only enough to be sure we are not handing your data to someone else.
If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first so we can put it right, but you are not obliged to.
Children
This site sells business services and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, email privacy@zeropixel.io and we will delete it.
Changes to this policy
When this policy changes we update the date and version at the top of the page. If a change materially affects how we use data you have already given us, we will say so on the site rather than rely on you noticing a date. Previous versions are available on request.
ZeroPixel is a trading name of Milex Systems Ltd, a company registered in England and Wales under company number 12168672. Registered office: 9, 50a The Viewpoint, Sheep Street, Northampton, NN1 2LZ, United Kingdom.