Privacy Policy
Last updated: 1 June 2026
1. Who we are
Merlin's Keeper is a web-based exotic animal monitoring platform operated by Dave Carbon (madcarbon@gmail.com), accessible at madcarbon.co.uk.
We are the data controller for the personal data described in this policy.
2. What data we collect and why
Account information
When you register we collect your first name, last name, and email address. We use these to identify your account, send you service emails (email verification, password reset, alert notifications), and allow you to contact us.
Your password is stored as a one-way cryptographic hash. We cannot read your password.
Device and sensor data
Monitoring devices registered to your account upload temperature and humidity readings along with the device's local IP address and firmware version. This data is stored to provide you with live readings, historical graphs, and alert notifications. Sensor readings are not personal data.
Animal records and care events
You may voluntarily add animal names, species, dates and care event logs to your account. You may also upload photos of your animals. This data is stored solely to provide the care tracking features of the platform and is visible only to you unless you explicitly make an image public.
Contact form
If you use the contact form we collect your name, email address, and message in order to respond to your enquiry. This data is also emailed to the site administrator.
Log data
The web server automatically records IP addresses, requested URLs, and HTTP status codes in a standard access log. These logs are retained for operational and security purposes for a short period and are not shared.
An application-level audit log records significant actions (logins, deletions, admin actions) for security monitoring. These entries include IP address and timestamp.
3. Legal basis for processing
We process your personal data on the following grounds:
- Contract performance — processing your account information is necessary to provide the service you registered for.
- Legitimate interests — access logs and audit logs are kept for security and fraud prevention.
- Consent — you voluntarily provide animal data, care event notes, and photos. You can delete these at any time.
4. How we store your data
All data is stored on servers hosted by IONOS (EU data centres). Data is transmitted over HTTPS. Passwords are stored using a one-way cryptographic hash. Sensor data from devices is encrypted in transit between the device and our servers.
We do not transfer your personal data outside the European Economic Area.
5. How long we keep your data
- Account data — retained for as long as your account is active.
- Sensor readings — retained indefinitely for historical graph access.
- Access logs — retained for approximately 30 days on a rolling basis.
- Audit logs — retained for 12 months.
- Contact form messages — retained until manually cleared by an administrator.
6. Third parties
We do not share your personal data with any third parties. We do not use any third-party analytics, advertising, or tracking services. All assets (scripts, fonts, images) are served from our own domain.
7. Cookies
We use only a single strictly necessary session cookie. No tracking or advertising cookies are used. See our Cookie Policy for full details.
8. Your rights
Under UK GDPR and the Data Protection Act 2018 you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data via your account Settings page.
- Erasure — delete your account and all associated personal data at any time via Settings → Delete Account. Your name and email will be permanently anonymised and your animals and devices will be removed.
- Restriction — request that we limit processing of your data.
- Portability — sensor data can be exported as CSV from each device page.
- Object — object to processing based on legitimate interests.
To exercise any of these rights, contact us at madcarbon@gmail.com.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
9. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last revised. Continued use of the platform after changes constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions or requests:
📧 madcarbon@gmail.com
🌍 Contact form