Privacy Policy
What we collect, why we collect it, how long we keep it, and the rights you have over it. Written to be read rather than to be survived.
Levarlux Studio (“Levarlux”, “we”, “us”) is the controller of personal data described in this policy. We are a software engineering studio operating remotely across GMT ±4. Questions about this policy, or any request exercising your rights, go to [email protected] and are answered within 30 days — usually within two.
1. Who this policy covers
This policy applies to three groups of people, and to the levarlux.com website itself:
- Website visitors — anyone reading this site.
- Business contacts — people who contact us, evaluate us, or work with us at a client, partner, or supplier organisation.
- Applicants — people who apply to work with the studio.
It does not cover data we process on behalf of clients inside their own products. For that data the client is the controller and we act as a processor under the relevant services agreement; our processing obligations are set out there.
2. What we collect
We collect the minimum needed to answer you properly and run an engagement.
| Category | Examples | Source |
|---|---|---|
| Contact details | Name, work email, company, role | You, directly |
| Brief content | Project description, budget range, timing, technical constraints | You, directly |
| Correspondence | Emails, call notes, proposals, contracts | You and us |
| Technical logs | IP address, user agent, requested URL, timestamp | Generated automatically by the web server |
| Application data | CV, portfolio, work history, references | You, directly |
No advertising trackers, no third-party analytics cookies, no fingerprinting, no data brokers, and no “enriched” profiles. The contact form on this site runs entirely in your browser and does not transmit data until you choose to send it.
3. How we use it
We use personal data only for the purpose it was given, and only on one of these legal bases:
- Legitimate interests — responding to your enquiry, discussing a potential engagement, securing the website, and understanding which pages are useful. We balance these against your rights and you may object at any time.
- Contract — taking steps before entering a contract, and performing it once signed: scoping, delivery, invoicing, and support.
- Legal obligation — tax, accounting, and regulatory record-keeping.
- Consent — only where we explicitly ask for it, and revocable at any time (for example, being added to a mailing list). We do not use consent as a default basis.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects about you.
4. Who we share it with
We do not sell personal data, and we do not share it for advertising. It is shared only where an engagement genuinely requires it:
- Infrastructure and tooling providers — email, hosting, document storage, and project tooling, each bound by their own data-processing terms.
- Professional advisers — accountants, lawyers, and insurers, strictly on a need-to-know basis.
- Client organisations — where your details are needed for delivery, for example a named contact on a shared channel.
- Authorities — where the law requires it, and only where we are legally compelled.
Every processor we use is assessed before engagement and is contractually limited to processing on our instructions.
5. International transfers
We work remotely across time zones, so some data may be accessed from outside the UK and European Economic Area. Where a transfer happens we rely on adequacy decisions or the Standard Contractual Clauses, together with organisational safeguards — access control, device encryption, and least-privilege permissions.
6. How long we keep it
| Data | Retention |
|---|---|
| Unsuccessful enquiries | 24 months from last contact |
| Client contracts, invoices, and delivery records | 7 years (statutory accounting requirement) |
| Server and security logs | 90 days, unless needed for an open incident |
| Job applications not taken forward | 12 months, unless you ask us to keep your profile longer |
| Internal notes on active opportunities | 24 months after the last meaningful contact |
At the end of the period the data is deleted or irreversibly anonymised.
7. Security
We apply the same standards to our own data as to client systems: encryption in transit and at rest, hardware-encrypted devices, multi-factor authentication on every account, least-privilege access reviewed quarterly, and no personal data on shared drives with public links. Access is limited to the small number of people who need it to do their job.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay where the risk is high.
8. Your rights
Depending on where you live, you have rights over your personal data. We honour all of them, for everyone, regardless of location:
- Access — ask for a copy of what we hold about you.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — ask us to delete it, where we have no continuing basis to keep it.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, including direct marketing (which we will stop immediately).
- Withdraw consent — at any time, where consent was the basis.
- Complain — to your local supervisory authority. In the UK that is the Information Commissioner’s Office.
To exercise any of these, email [email protected]. We do not charge, and we do not require you to explain why.
9. Third-party services on this site
This website loads its typefaces from Google Fonts, which may receive your IP address when the page loads. We self-host nothing else from third parties: there are no embedded players, social pixels, or tag managers on this site. If that changes, this section changes with it.
Links to external sites are provided for reference. Their privacy practices are their own, and we encourage you to read them.
10. Cookies
We set no cookies — not analytics cookies, not preference cookies, not marketing cookies. Nothing on this site requires consent banners because there is nothing to consent to. Server-side logs used for security are not cookies and are not used to track you across sites.
11. Changes to this policy
When we change this policy we update the effective date at the top of the page and, for material changes, contact anyone with an active engagement before the change takes effect. The current version is always the one published here.
12. Contact
Data protection questions, requests, and complaints:
- Email: [email protected]
- Subject line: “Privacy request” — it reaches the right person faster.
- Response time: within 30 days, usually much sooner.
If you are unhappy with our response you may complain to your data protection authority — in the UK, the Information Commissioner’s Office.
Related: Terms of Service · Contact