Mortar ← back to mortarautomation.com

Privacy policy

Last updated: 3 July 2026

Mortar Automation (“Mortar”, “we”, “us”) is a done-for-you automation service operated by Daniel Bennett, based in the Netherlands. This policy explains what personal data we collect, why, and what your rights are. It covers the website mortarautomation.com and, once launched, the Mortar service itself. Contact for anything in this policy: hello@mortarautomation.com.

1. Who is responsible for your data

The data controller is Daniel Bennett, trading as Mortar Automation, Netherlands. Business registration details will be added to this page upon registration with the Dutch Chamber of Commerce (KvK).

2. What we collect today (waitlist)

We use this to contact you about Mortar’s launch, to size interest, and to decide which tools to support next. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by unsubscribing or emailing us. We do not sell or share the waitlist with anyone.

3. What we collect when you become a customer

Legal bases: performance of our contract with you (Art. 6(1)(b) GDPR) for running the service; our legitimate interest (Art. 6(1)(f)) in monitoring, securing and improving it; and legal obligations (Art. 6(1)(c)) for invoicing and tax records.

4. Google user data — Limited Use disclosure

Where you connect a Google service, Mortar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

5. Who helps us run the service (processors)

We use a small number of infrastructure providers under data-processing agreements. Currently: Hetzner Online GmbH (server hosting, Germany/Finland, EU) and a transactional email provider for sending service emails. A current list of sub-processors is available on request. We do not transfer your personal data outside the EU/EEA except where a provider offers appropriate safeguards under GDPR (such as Standard Contractual Clauses), and we prefer EU-hosted providers.

6. How long we keep data

7. Security

Credentials are stored encrypted at rest with per-customer isolation; all traffic is encrypted in transit (TLS); access to production systems is limited and logged; sensitive values are masked in logs; and databases are backed up on EU infrastructure. No internet service can promise perfection — if we ever discover a breach affecting your data, we will notify you and the Dutch supervisory authority as GDPR requires.

8. Your rights

Under the GDPR you can ask us at any time to: access the personal data we hold about you; correct it; delete it; restrict or object to processing; receive it in a portable format; or withdraw consent. Email hello@mortarautomation.com and we will respond within one month. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

9. Cookies

This website does not use advertising or cross-site tracking cookies. If we add analytics, we will use a privacy-respecting, cookieless option or ask for your consent first, and update this policy.

10. Children

Mortar is a business service and not directed at anyone under 16. We do not knowingly collect data from children.

11. Changes to this policy

If we change this policy in a way that matters, we will note it here with a new “last updated” date and, for significant changes affecting customers, tell you by email before they take effect.