1. Who we are
Reakt Labs Ltd is a technology consulting and software development company registered in England and Wales, trading as “Reakt”. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal data described in this policy — meaning we decide why and how it is processed.
| Details | |
|---|---|
| Legal entity | Reakt Labs Ltd |
| Registered in | England and Wales |
| Registered office | 5 Brayford Square, London, E1 0SG, United Kingdom |
| Nigeria office | 8 Asaba Cl, Garki, Abuja 900103, Federal Capital Territory, Nigeria |
| Privacy contact | [email protected] |
| Telephone | +447832806654 |
We are not currently required to appoint a Data Protection Officer. Privacy questions are handled by our leadership team at the address above.
2. Scope of this policy
This policy applies to personal data we process when you:
- browse or interact with our website;
- submit an enquiry through our contact form, or email or call us;
- sign in to a Reakt Labs service using Sign in with Google;
- engage us as a client, or act as a contact at a prospective client, supplier or partner; or
- apply to work with us, or otherwise correspond with us in a business capacity.
Where we build or operate software on behalf of a client, that client is normally the data controller and we act as their data processor under a separate written agreement. In those cases, the client’s own privacy notice governs how your data is used, not this one.
3. Information we collect
Information you give us
- Contact and enquiry details — your name, email address, company name, and the content of any message you send us through our contact form or by email.
- Account information — if you create an account or sign in with Google, the profile details described in section 4.
- Engagement information — if you become a client, the contact, billing and project information needed to deliver and invoice for our services.
Information we collect automatically
- Technical data — IP address, browser type and version, operating system, device type, screen size, language and time zone.
- Usage data — the pages you view, the links you click, referring URLs, and the dates and times of your visits.
- Cookie data — as described in section 7.
Information we do not want
We do not ask for special category data — such as information about your health, race or ethnicity, religious or political beliefs, sex life or sexual orientation, trade union membership, or genetic or biometric data. Please do not include such information in messages you send us. We also do not collect payment card details through this website; client payments are handled by bank transfer or by a regulated payment provider under separate terms.
4. Google sign-in and Google user data
Some Reakt Labs services let you sign in with your Google Account instead of creating a separate username and password. This section explains exactly what we receive from Google, what we do with it, and what we will never do with it.
What we request
We request only the minimum scopes needed to authenticate you. We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other restricted or sensitive Google API scope.
| Scope | What it gives us | Why we need it |
|---|---|---|
OpenIDopenid | A unique, stable identifier for your Google Account. | Lets us recognise you as the same person each time you sign in, without you creating a separate password. |
See your primary Google Account email address.../auth/userinfo.email | Your email address and whether Google has verified it. | Used as the unique identifier for your account and to send you service-related messages such as security notices. |
See your personal info, including any personal info you have made publicly available.../auth/userinfo.profile | Your name, profile picture and locale. | Used to personalise the interface — for example, greeting you by name and showing your avatar. |
How we use Google user data
- to create and secure your account and keep you signed in;
- to identify you as the same user across sessions and devices, using your Google Account identifier and email address;
- to personalise the interface — for example, displaying your name and profile picture; and
- to send service messages such as security alerts and important changes to the service.
What we never do with Google user data
- We do not sell, rent or licence Google user data to anyone, in any circumstances.
- We do not use Google user data for advertising, retargeting or audience profiling.
- We do not use Google user data to train, fine-tune or evaluate artificial intelligence or machine learning models — whether our own or a third party’s.
- We do not allow humans to read Google user data, except with your explicit consent for a specific issue, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised so it can no longer identify you.
- We do not transfer Google user data to third parties except to the infrastructure providers listed in section 8, who process it on our instructions solely to operate the service.
Limited Use disclosure
Reakt Labs Ltd’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage, retention and revoking access
We store the profile data received from Google for as long as your account remains active. You are in control of this at all times:
- Revoke our access at any time from your Google Account security settings at myaccount.google.com/permissions. Revoking access stops any further data flowing to us, and you will no longer be able to sign in with Google.
- Delete your data by emailing [email protected] from the address associated with your account. We will delete the Google user data we hold about you within 30 days, except where we are required by law to retain a limited record.
Revoking access through Google does not by itself delete data we have already received, so please contact us as well if deletion is what you want.
5. How we use your information
We use personal data for the following purposes:
- Responding to enquiries and providing quotes — replying to messages sent through our contact form or by email, and discussing potential work.
- Providing our services — delivering consulting, development and innovation services to clients, managing projects, and handling invoicing.
- Authenticating and securing accounts — verifying who you are, keeping you signed in, and detecting and preventing fraud, abuse and security incidents.
- Operating and improving the site — keeping the website available, diagnosing faults, and understanding in aggregate which content is useful.
- Meeting legal obligations — keeping accounting records, responding to lawful requests, and establishing, exercising or defending legal claims.
We do not carry out automated decision-making that produces legal effects concerning you, and we do not engage in behavioural advertising.
6. Legal bases for processing
If you are in the United Kingdom or the European Economic Area, we must have a lawful basis under Article 6 of the UK GDPR or EU GDPR for each processing activity. Ours are:
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry and discuss potential work | Steps taken at your request prior to entering a contract, and our legitimate interests in responding to people who contact us. |
| Deliver services and manage a client engagement | Performance of a contract with you, or our legitimate interests where the contract is with your employer. |
| Authenticate you via Sign in with Google | Performance of a contract (providing you with the service you asked for), and your consent given on the Google consent screen. |
| Keep the site secure and prevent abuse | Our legitimate interests in protecting our systems, our users and our business. |
| Set non-essential cookies | Your consent, which you can withdraw at any time. |
| Keep financial and legal records | Compliance with our legal obligations. |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and concluded that they are not. You can ask us for details of that assessment, and you have the right to object — see section 12.
9. International data transfers
We operate from the United Kingdom and Nigeria, and some of our suppliers are based outside the UK and the European Economic Area, including in the United States. This means your personal data may be transferred to, stored in, or accessed from a country whose data protection laws differ from your own.
Where we transfer personal data out of the UK or EEA, we rely on one of the following safeguards:
- an adequacy decision by the UK Government or the European Commission covering the destination country;
- the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses; or
- the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment and any additional technical measures needed.
You can request a copy of the safeguards we use by emailing [email protected].
10. How long we keep your information
We keep personal data only for as long as we need it for the purpose we collected it for, and then delete or anonymise it.
| Type of data | Retention period |
|---|---|
| Contact-form and email enquiries that do not lead to work | Up to 24 months from the last contact, then deleted. |
| Account and Google profile data | For as long as the account is active, and deleted within 30 days of account closure or a deletion request. |
| Client project records and correspondence | For the duration of the engagement and 6 years afterwards, to cover the limitation period for contractual claims. |
| Invoices and accounting records | 6 years from the end of the relevant financial year, as required by UK tax law. |
| Website logs and analytics data | Up to 14 months, usually in aggregated form. |
Where we are required to keep a record of a deletion request itself, we retain only the minimum needed to demonstrate that we honoured it.
11. How we protect your information
We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include:
- encryption of data in transit using TLS across the whole site, and encryption at rest for stored application data;
- access controls on the principle of least privilege, with multi-factor authentication required for administrative accounts;
- delegating password handling to Google where you sign in with Google, so we never see or store your Google password;
- supplier due diligence, written data processing terms, and periodic review of the services we rely on; and
- internal procedures for detecting, investigating and reporting suspected personal data breaches.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and notify you directly where the risk is high.
12. Your data protection rights
If you are in the UK or the EEA, you have the following rights. They are free to exercise, and we will respond within one month.
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have a good reason to keep it.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time, with no need to give a reason.
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
How to exercise your rights
Email [email protected] with “Data protection request” in the subject line, telling us which right you want to exercise. We may ask for information to verify your identity before we act, so that we do not disclose your data to someone else.
Complaints
We would like the chance to resolve any concern first, but you have the right to complain to a supervisory authority at any time. In the UK this is the Information Commissioner’s Office — ico.org.uk/make-a-complaint or 0303 123 1113. If you are in the EEA, you may complain to the supervisory authority in your country of residence or work.
13. Notice for US residents
If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to request a copy or deletion of it, to correct it, and not to be discriminated against for exercising those rights.
For the avoidance of doubt: we do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding twelve months, including in respect of anyone under 16.
To make a request, email [email protected]. You may use an authorised agent, in which case we will ask for proof of their authority.
14. Children’s privacy
Our website and services are intended for businesses and for adults. They are not directed at children, and we do not knowingly collect personal data from anyone under the age of 16 (or under 13 in the United States). If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.
15. Third-party links and services
Our website links to third-party sites, including our profiles on social platforms. We do not control those sites and are not responsible for their content or their privacy practices. Following a link means that site’s own privacy policy applies, and we encourage you to read it before providing any personal data.
16. Changes to this policy
We may update this policy to reflect changes in our services, our suppliers, or the law. When we do, we will revise the “Last updated” date at the top of this page. If the changes are significant — for example, a new purpose for using your data — we will give you clear notice by email or a prominent notice on the site before the change takes effect. Please check back periodically.
17. How to contact us
For any question about this policy, or to exercise your rights, please contact us:
- Email: [email protected]
- Telephone: +447832806654
- Post: Reakt Labs Ltd, 5 Brayford Square, London, E1 0SG, United Kingdom
You may also want to read our Terms & Conditions, which govern your use of this website.