What we collect, why, and what you can do about it.
Last updated: 18th of August 2026
This policy explains what personal data manx.directory collects, why, and what you can do about it.
The data controller is OLXR Limited (“we”, “us”), a company registered in the Isle of Man (company number 133388C, registered office 61 Port-E-Chee Avenue, Douglas, IM2 5EU, Isle of Man), which runs this site under its registered business name manx.directory (number 031885B). We’re registered with the Isle of Man Information Commissioner, registration number R629904.
Questions, or want to exercise your rights? Get in touch.
Every listing is created by the business owner, or by someone authorised to act for them. We don’t seed listings from public databases and we don’t scrape them from anywhere else, so nothing appears on the site unless a person put it there.
If your business appears and you didn’t put it there, that shouldn’t have happened. Use the report link on the listing or contact us to have it corrected or removed. Both are free, we check each request by hand, and we’ll action removals promptly. If you want the listing yourself, we’ll remove it and you can add your own.
We write to Isle of Man businesses to tell them they can list for free. This section explains exactly how that works, because you may be reading it having received one of those emails rather than because you use the site.
This information is held for outreach only. It is never published on the site, and it never becomes a listing - listings only exist because a business owner created one.
Where we got your details. Publicly available business information - your own website, a public listing, or open data such as OpenStreetMap. We record where each detail came from and when, so we can always tell you.
What we hold. Your business name, a business contact address, and where we found it. Nothing more. Where the address a business publishes is a named one - sarah@example.im rather than info@ - that is personal data as well as a business contact, and everything in this policy applies to it.
Why we’re allowed to. Legitimate interests: building a directory that is useful to the Island depends on the businesses on it knowing it exists. It relates to a commercial activity, it’s directly relevant to the business we’re writing to, and every message carries a one-click way to stop.
How to stop it. Use the unsubscribe link in any email. It works immediately, needs no account and asks no questions, and anything already queued to be sent is cancelled with it. Or contact us and we’ll do it for you.
If you’d rather we held nothing at all, tell us and we’ll delete it - keeping only the record that you asked us to stop, so we can’t contact you again by accident. Being on that list doesn’t stop you listing your business later if you change your mind.
We set one cookie of our own, md_session, to keep you signed in after you use a sign-in link. That is the only cookie involved. Your browser also remembers three small things locally - that you’ve already been counted as a view on a listing, that you’ve dismissed our “just getting started” notice, and a token from Cloudflare’s anti-bot check, which loads only on the contact form and after you press a “call” or “email” button.
None of this is used for advertising or cross-site tracking, and we set nothing that builds a profile of you or follows you to other sites. We use Fathom Analytics to count visits: it sets no cookies, stores nothing on your device, records nothing that identifies you, and honours “Do Not Track”. That is why there is still nothing here to ask your consent for. Full detail is in our cookie policy.
We don’t sell your data, and we don’t use it for advertising.
We process your data:
Where we rely on legitimate interests, you have the right to object. For direct marketing that right is absolute - tell us and we stop, with no exceptions and no questions asked. For anything else, tell us and we’ll stop unless we have compelling grounds not to.
Isle of Man data protection law applies: the Data Protection Act 2018 and the GDPR and LED Implementing Regulations 2018, which apply a version of the EU GDPR on the Island.
We share data only with the providers who help us run the service, and where we’re legally required to:
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, database, and sending sign-in and service emails (via SES) | London (eu-west-2) |
| Cloudflare | Anti-bot checks (Turnstile) on our forms and on listing pages where contact details are revealed | Global edge network |
| OpenStreetMap Foundation | Turning an address into map coordinates - only when a business owner asks us to look one up | Global |
| Paddle.com Market Limited | Payment processing and invoicing | UK / EU |
| Conva Ventures Inc. (Fathom Analytics) | Counting visits to the site - no cookies, nothing identifying you | Canada; EU visitors processed on EU infrastructure |
Maps are served from our own systems. We hold our own copy of the map of the Island and deliver it ourselves, so looking at a map doesn’t tell anyone else which business you were looking at.
There is one exception, and it only affects business owners. If you use “Find from postcode” while adding or editing a listing, that address is sent to the OpenStreetMap Foundation to be turned into map coordinates. It happens when you press that button, on the listing form, and never for someone browsing the directory. See the OpenStreetMap Foundation privacy policy.
Your published listing is, of course, visible to the public and to search engines.
Our main systems - the database, your listing and account data, and the sending of sign-in emails - run in Amazon Web Services’ London region (eu-west-2). The Isle of Man, the UK and the EEA are mutually adequate jurisdictions, so no additional safeguards are needed for that.
Cloudflare operates a global network, so a request may be handled outside the UK depending on where you are, and the same is true of the address lookup described above on the occasions a business owner uses it. Where data reaches a country without an adequacy decision, we rely on standard contractual clauses and appropriate safeguards.
Deleting a listing. Hide it whenever you like. If you ask us to delete it, we keep it hidden for 30 days in case you change your mind, then remove it permanently from our systems. You can cancel at any point during those 30 days.
Closing your account. There’s a button at the foot of your dashboard. Your listings are hidden straight away and everything is deleted 30 days later - and you can stop it at any point in between. After that we clear your email address and any name you’ve given us, and keep only a record that the account existed, where it’s referenced by a moderation decision or a do-not-contact request we’re required to honour. At that point nothing in our systems identifies you.
Backups. Our database is backed up automatically and those backups are kept for 7 days. Data you’ve deleted can survive in a backup until it rotates out, so allow up to 7 days after deletion for it to be gone everywhere.
One exception. If you tell us never to contact you again, we keep a record of that instruction indefinitely - and only that. It’s the only way to guarantee we don’t contact you by accident later, so we won’t delete it even if you ask us to delete everything else.
Payment and invoice records sit outside all of this: we’re legally required to keep them for six years and can’t delete them on request.
The site runs over HTTPS throughout. Sign-in links are single-use and expire quickly. Access to production systems is restricted and dependencies are kept current. No system is completely secure, but we take reasonable technical and organisational measures, and we’ll notify the Information Commissioner and anyone affected where the law requires it if something goes wrong.
You can access, correct, export or delete your personal data, object to certain processing - absolutely, in the case of direct marketing - and ask us to restrict it. Most listing data you can edit or remove yourself from your dashboard - for anything else, get in touch. We’ll respond within one month, and may need to verify your identity first.
You also have the right to complain to the Isle of Man Information Commissioner at inforights.im. We’d rather you came to us first so we can put it right.
We may update this policy. The current version always lives on this page with the date it was last updated. If we make a significant change to how we use your data, we’ll tell you by email where reasonable.
See also our terms of use, cookie policy and refund policy.