1. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details, including names, roles, organisations, email addresses and telephone numbers.
- Enquiry and relationship details, including how you found us, your requirements, lead stage, notes and communications.
- Client delivery information, including projects, tasks, milestones, meetings, services, documents and progress updates.
- Account and security information, including your sign-in email, encrypted password record, account role and authentication session.
- Commercial and financial information, including proposals, retainers, invoice references, values, payment status and due dates. We do not currently collect payment-card details through this website.
- Technical information made available through hosting and security systems, such as IP address, device/browser information and request or error logs.
Please do not provide special-category information—such as health, biometric, political or religious information—unless it is genuinely necessary and we have agreed an appropriate way to handle it.
2. Where information comes from
We collect information directly from you, from your organisation or an authorised colleague, through correspondence and meetings, and through your use of the secure workspace. Business contact details may also come from referrals, publicly available business sources or lead lists imported into our internal CRM. Where information did not come directly from you, we will provide the required privacy information within the applicable legal timeframe.
3. Why we use information
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries and preparing proposals | Steps before a contract; legitimate interests |
| Delivering and managing agreed services | Contract; legitimate interests |
| Providing and securing workspace accounts | Contract; legitimate interests; legal obligations |
| Invoices, accounting and business records | Contract; legal obligations |
| Managing business leads and relationships | Legitimate interests in running and growing the business |
| Optional marketing communications | Consent or legitimate interests, subject to electronic-marketing rules |
| Preventing misuse and resolving disputes | Legitimate interests; legal obligations; legal claims |
Where we rely on legitimate interests, we consider whether the use is necessary, proportionate and within your reasonable expectations. You can object to that use in certain circumstances.
4. Who we share information with
We do not sell personal information. We may share only what is necessary with:
- hosting, database, email, file-storage and technical-support providers acting under our instructions;
- professional advisers such as accountants, insurers or legal advisers;
- your organisation and authorised project participants;
- public authorities, regulators or courts where disclosure is legally required; or
- a buyer or successor if the business is reorganised, sold or transferred, subject to appropriate safeguards.
Some providers may process information outside the UK. Where this happens, we use a lawful transfer mechanism and appropriate contractual or organisational safeguards.
5. How long we keep information
We keep information only for as long as needed for the purpose collected, including legal, tax, accounting and dispute requirements. Our usual targets are:
- unconverted lead and enquiry records: up to 24 months after the last meaningful interaction;
- client, project, contract and key correspondence records: up to six years after the relationship ends;
- invoice and accounting records: for the legally required accounting retention period, usually six years;
- account access: while the account is required, followed by removal or de-identification within a reasonable closure period; and
- security and technical logs: for the shorter period set by the relevant service provider, unless required to investigate an incident.
We may keep information longer where a dispute, legal hold or regulatory requirement applies, and may retain anonymised information that can no longer identify an individual.
6. Security
We use proportionate technical and organisational measures, including access controls, role-based client separation, encrypted password hashing, signed browser-only authentication cookies and secure transport when deployed over HTTPS. No online system can be guaranteed completely secure, so please contact us promptly if you believe an account or record has been compromised.
7. Your rights
Under UK data protection law, depending on the circumstances, you may have the right to:
- be informed about how your information is used;
- request access to, correction of, or deletion of your information;
- restrict or object to particular uses;
- receive certain information in a portable format;
- withdraw consent at any time where consent is the basis; and
- complain to the Information Commissioner’s Office.
To exercise a right, email hello@agentlabs.co.uk. We may need to verify your identity. You can also contact the Information Commissioner’s Office; we would appreciate the opportunity to address your concern first.
8. Children
Our website and client workspace are intended for business users aged 18 or over. We do not knowingly collect children’s information through these services.
9. Changes and contact
We may update this policy when our services, suppliers or legal obligations change. The current version and revision date will remain on this page. Privacy questions can be sent to hello@agentlabs.co.uk.
