Scope and contact
This notice covers the Mercer Atlas Labs public website, business enquiries and invited access to its private workspace. For questions or requests, contact the operator at hello@merceratlaslabs.com and use “Privacy enquiry” as the subject.
Information we handle
If you email us, we receive your email address, message and any information or attachments you choose to include. When you request access, we process your email address, a temporary sign-in challenge, session information and request metadata used to limit abuse. Invited users may enter project notes, assignments, evidence and cost proposals in the private workspace. Web requests also involve technical information such as an IP address and browser headers.
Why we use it
We use this information to respond to enquiries, provide authorised access, coordinate agreed work and protect the service. Where a legal basis is required, relevant bases include steps you request before an agreement, performing an applicable agreement, and legitimate interests in managing correspondence and securing the workspace. Any optional use that requires consent must be explained and agreed separately. We do not sell personal information or use it for advertising on this website.
Cookies and analytics
The public pages do not set analytics or advertising cookies and load no third-party analytics scripts. Sign-in uses essential cookies to associate a code with the requesting browser and maintain an authenticated session. The cookie notice explains their purposes and duration. Blocking these cookies prevents sign-in.
Read the cookie noticeService providers and location
Cloudflare hosts this website and stores private workspace records and authentication information. Resend processes email addresses, message content and delivery information to send and receive business email and sign-in codes. Email providers used by a correspondent may also process messages. Information can be processed outside your country; Resend describes storage in the United States in its published data-protection information. A domain’s sending region is not a promise that all related information stays in that region. Access to private workspace records is restricted to authorised operators.
Resend privacy informationRetention
Sign-in codes expire after 10 minutes. Sessions expire after 30 minutes of inactivity or 12 hours overall and are revoked on sign-out. Temporary authentication and rate-limit records are stored with restricted access. Expired records are removed during subsequent activity or scheduled cleanup, which runs at 15-minute intervals while temporary records remain. Provider backup and email-service retention are separate. Business correspondence and project records are reviewed according to the purpose of the relationship and any applicable legal obligation; the current workspace does not automatically delete those records.
Your choices and rights
You can choose not to send an enquiry and can clear cookies or sign out. Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of your information, object to relevant processing, or withdraw consent where processing relies on it. We may need to verify your identity and explain any information we must retain. You may also raise a concern with the relevant data-protection authority.
Security and future changes
We restrict workspace access and use expiring codes and sessions. No website or email system can promise absolute security. The current website does not send enquiry or workspace content to an AI model for automated decision-making. If new integrations materially change how personal information is used, this notice must be updated before that use begins.