[ Legal · Data Protection ]

Privacy Policy

What we collect, why we collect it, how long we keep it, and the rights you have over it. Written to be read rather than to be survived.

[ Effective 25 Sep 2026 ][ GDPR / UK GDPR ][ No Data Brokers ]

Levarlux Studio (“Levarlux”, “we”, “us”) is the controller of personal data described in this policy. We are a software engineering studio operating remotely across GMT ±4. Questions about this policy, or any request exercising your rights, go to [email protected] and are answered within 30 days — usually within two.

1. Who this policy covers

This policy applies to three groups of people, and to the levarlux.com website itself:

  • Website visitors — anyone reading this site.
  • Business contacts — people who contact us, evaluate us, or work with us at a client, partner, or supplier organisation.
  • Applicants — people who apply to work with the studio.

It does not cover data we process on behalf of clients inside their own products. For that data the client is the controller and we act as a processor under the relevant services agreement; our processing obligations are set out there.

2. What we collect

We collect the minimum needed to answer you properly and run an engagement.

CategoryExamplesSource
Contact detailsName, work email, company, roleYou, directly
Brief contentProject description, budget range, timing, technical constraintsYou, directly
CorrespondenceEmails, call notes, proposals, contractsYou and us
Technical logsIP address, user agent, requested URL, timestampGenerated automatically by the web server
Application dataCV, portfolio, work history, referencesYou, directly
What we do not collect

No advertising trackers, no third-party analytics cookies, no fingerprinting, no data brokers, and no “enriched” profiles. The contact form on this site runs entirely in your browser and does not transmit data until you choose to send it.

3. How we use it

We use personal data only for the purpose it was given, and only on one of these legal bases:

  • Legitimate interests — responding to your enquiry, discussing a potential engagement, securing the website, and understanding which pages are useful. We balance these against your rights and you may object at any time.
  • Contract — taking steps before entering a contract, and performing it once signed: scoping, delivery, invoicing, and support.
  • Legal obligation — tax, accounting, and regulatory record-keeping.
  • Consent — only where we explicitly ask for it, and revocable at any time (for example, being added to a mailing list). We do not use consent as a default basis.

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects about you.

4. Who we share it with

We do not sell personal data, and we do not share it for advertising. It is shared only where an engagement genuinely requires it:

  • Infrastructure and tooling providers — email, hosting, document storage, and project tooling, each bound by their own data-processing terms.
  • Professional advisers — accountants, lawyers, and insurers, strictly on a need-to-know basis.
  • Client organisations — where your details are needed for delivery, for example a named contact on a shared channel.
  • Authorities — where the law requires it, and only where we are legally compelled.

Every processor we use is assessed before engagement and is contractually limited to processing on our instructions.

5. International transfers

We work remotely across time zones, so some data may be accessed from outside the UK and European Economic Area. Where a transfer happens we rely on adequacy decisions or the Standard Contractual Clauses, together with organisational safeguards — access control, device encryption, and least-privilege permissions.

6. How long we keep it

DataRetention
Unsuccessful enquiries24 months from last contact
Client contracts, invoices, and delivery records7 years (statutory accounting requirement)
Server and security logs90 days, unless needed for an open incident
Job applications not taken forward12 months, unless you ask us to keep your profile longer
Internal notes on active opportunities24 months after the last meaningful contact

At the end of the period the data is deleted or irreversibly anonymised.

7. Security

We apply the same standards to our own data as to client systems: encryption in transit and at rest, hardware-encrypted devices, multi-factor authentication on every account, least-privilege access reviewed quarterly, and no personal data on shared drives with public links. Access is limited to the small number of people who need it to do their job.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay where the risk is high.

8. Your rights

Depending on where you live, you have rights over your personal data. We honour all of them, for everyone, regardless of location:

  • Access — ask for a copy of what we hold about you.
  • Rectification — correct anything inaccurate or incomplete.
  • Erasure — ask us to delete it, where we have no continuing basis to keep it.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, including direct marketing (which we will stop immediately).
  • Withdraw consent — at any time, where consent was the basis.
  • Complain — to your local supervisory authority. In the UK that is the Information Commissioner’s Office.

To exercise any of these, email [email protected]. We do not charge, and we do not require you to explain why.

9. Third-party services on this site

This website loads its typefaces from Google Fonts, which may receive your IP address when the page loads. We self-host nothing else from third parties: there are no embedded players, social pixels, or tag managers on this site. If that changes, this section changes with it.

Links to external sites are provided for reference. Their privacy practices are their own, and we encourage you to read them.

10. Cookies

We set no cookies — not analytics cookies, not preference cookies, not marketing cookies. Nothing on this site requires consent banners because there is nothing to consent to. Server-side logs used for security are not cookies and are not used to track you across sites.

11. Changes to this policy

When we change this policy we update the effective date at the top of the page and, for material changes, contact anyone with an active engagement before the change takes effect. The current version is always the one published here.

12. Contact

Data protection questions, requests, and complaints:

  • Email: [email protected]
  • Subject line: “Privacy request” — it reaches the right person faster.
  • Response time: within 30 days, usually much sooner.

If you are unhappy with our response you may complain to your data protection authority — in the UK, the Information Commissioner’s Office.


Related: Terms of Service · Contact