Legal

Privacy Policy

This Privacy Policy explains how Reakt Labs Ltd (“Reakt Labs”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit www.reakt-labs.com, contact us through the site, or sign in to one of our services using your Google Account.

We have written it to be read, not to be skimmed past. If anything here is unclear, email us at [email protected] and we will explain it in plain terms.

Effective date:
5 September 2026
Last updated:
5 September 2026

1. Who we are

Reakt Labs Ltd is a technology consulting and software development company registered in England and Wales, trading as “Reakt”. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal data described in this policy — meaning we decide why and how it is processed.

Details
Legal entityReakt Labs Ltd
Registered inEngland and Wales
Registered office5 Brayford Square, London, E1 0SG, United Kingdom
Nigeria office8 Asaba Cl, Garki, Abuja 900103, Federal Capital Territory, Nigeria
Privacy contact[email protected]
Telephone+447832806654

We are not currently required to appoint a Data Protection Officer. Privacy questions are handled by our leadership team at the address above.

2. Scope of this policy

This policy applies to personal data we process when you:

  • browse or interact with our website;
  • submit an enquiry through our contact form, or email or call us;
  • sign in to a Reakt Labs service using Sign in with Google;
  • engage us as a client, or act as a contact at a prospective client, supplier or partner; or
  • apply to work with us, or otherwise correspond with us in a business capacity.

Where we build or operate software on behalf of a client, that client is normally the data controller and we act as their data processor under a separate written agreement. In those cases, the client’s own privacy notice governs how your data is used, not this one.

3. Information we collect

Information you give us

  • Contact and enquiry details — your name, email address, company name, and the content of any message you send us through our contact form or by email.
  • Account information — if you create an account or sign in with Google, the profile details described in section 4.
  • Engagement information — if you become a client, the contact, billing and project information needed to deliver and invoice for our services.

Information we collect automatically

  • Technical data — IP address, browser type and version, operating system, device type, screen size, language and time zone.
  • Usage data — the pages you view, the links you click, referring URLs, and the dates and times of your visits.
  • Cookie data — as described in section 7.

Information we do not want

We do not ask for special category data — such as information about your health, race or ethnicity, religious or political beliefs, sex life or sexual orientation, trade union membership, or genetic or biometric data. Please do not include such information in messages you send us. We also do not collect payment card details through this website; client payments are handled by bank transfer or by a regulated payment provider under separate terms.

4. Google sign-in and Google user data

Some Reakt Labs services let you sign in with your Google Account instead of creating a separate username and password. This section explains exactly what we receive from Google, what we do with it, and what we will never do with it.

What we request

We request only the minimum scopes needed to authenticate you. We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other restricted or sensitive Google API scope.

ScopeWhat it gives usWhy we need it
OpenID
openid
A unique, stable identifier for your Google Account.Lets us recognise you as the same person each time you sign in, without you creating a separate password.
See your primary Google Account email address
.../auth/userinfo.email
Your email address and whether Google has verified it.Used as the unique identifier for your account and to send you service-related messages such as security notices.
See your personal info, including any personal info you have made publicly available
.../auth/userinfo.profile
Your name, profile picture and locale.Used to personalise the interface — for example, greeting you by name and showing your avatar.

How we use Google user data

  • to create and secure your account and keep you signed in;
  • to identify you as the same user across sessions and devices, using your Google Account identifier and email address;
  • to personalise the interface — for example, displaying your name and profile picture; and
  • to send service messages such as security alerts and important changes to the service.

What we never do with Google user data

  • We do not sell, rent or licence Google user data to anyone, in any circumstances.
  • We do not use Google user data for advertising, retargeting or audience profiling.
  • We do not use Google user data to train, fine-tune or evaluate artificial intelligence or machine learning models — whether our own or a third party’s.
  • We do not allow humans to read Google user data, except with your explicit consent for a specific issue, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised so it can no longer identify you.
  • We do not transfer Google user data to third parties except to the infrastructure providers listed in section 8, who process it on our instructions solely to operate the service.

Limited Use disclosure

Reakt Labs Ltd’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage, retention and revoking access

We store the profile data received from Google for as long as your account remains active. You are in control of this at all times:

  • Revoke our access at any time from your Google Account security settings at myaccount.google.com/permissions. Revoking access stops any further data flowing to us, and you will no longer be able to sign in with Google.
  • Delete your data by emailing [email protected] from the address associated with your account. We will delete the Google user data we hold about you within 30 days, except where we are required by law to retain a limited record.

Revoking access through Google does not by itself delete data we have already received, so please contact us as well if deletion is what you want.

5. How we use your information

We use personal data for the following purposes:

  • Responding to enquiries and providing quotes — replying to messages sent through our contact form or by email, and discussing potential work.
  • Providing our services — delivering consulting, development and innovation services to clients, managing projects, and handling invoicing.
  • Authenticating and securing accounts — verifying who you are, keeping you signed in, and detecting and preventing fraud, abuse and security incidents.
  • Operating and improving the site — keeping the website available, diagnosing faults, and understanding in aggregate which content is useful.
  • Meeting legal obligations — keeping accounting records, responding to lawful requests, and establishing, exercising or defending legal claims.

We do not carry out automated decision-making that produces legal effects concerning you, and we do not engage in behavioural advertising.

7. Cookies and similar technologies

Cookies are small text files placed on your device when you visit a website. We also use similar technologies such as browser local storage. This section serves as our cookie policy.

CategoryWhat it doesConsent needed?
Strictly necessaryRequired for the site to function — for example, routing requests, balancing load, remembering your cookie preferences, and keeping you signed in after authentication.No — these are exempt under the Privacy and Electronic Communications Regulations.
FunctionalRemembers choices you make, such as language or interface preferences, so you do not have to set them again.Yes.
AnalyticsHelps us understand, in aggregate, how visitors find and use the site so we can improve it. We configure analytics to minimise the data collected and do not use it to build advertising profiles.Yes.

We do not use advertising or cross-site tracking cookies on this website, and we do not sell any information gathered through cookies.

Managing cookies

You can accept or reject non-essential cookies when you first visit the site, and change your mind at any time through your browser settings. Every major browser lets you view, block and delete cookies — see the “Help”, “Privacy” or “Settings” menu in your browser. Blocking strictly necessary cookies may stop parts of the site from working properly.

Our site respects the Global Privacy Control (GPC) signal where your browser sends one. We do not currently respond to legacy “Do Not Track” headers, as no common standard for them has been agreed.

8. How we share your information

We do not sell your personal data, and we never have. We do not share it with third parties for their own marketing.

We share personal data only with the following categories of recipient, and only as far as necessary:

RecipientPurposeData involved
Web3FormsDelivers contact-form submissions to our inbox.Name, email address, company and message content.
Hosting and infrastructure providersServe the website and store application data.Technical and usage data; account data where applicable.
Google LLCProvides Sign in with Google authentication.The profile data described in section 4.
Professional advisersLegal, accounting and insurance advice where genuinely needed.Only what is relevant to the matter.
Authorities and legal partiesWhere required by law, court order or regulator, or to establish or defend legal claims.Only what we are legally required to disclose.
A buyer or successorIf we sell, merge or reorganise the business, data may transfer as part of that transaction.Subject to this policy continuing to apply.

Every supplier that processes personal data on our behalf is bound by a written contract requiring them to act only on our instructions, keep the data confidential and secure, and delete or return it when the relationship ends.

9. International data transfers

We operate from the United Kingdom and Nigeria, and some of our suppliers are based outside the UK and the European Economic Area, including in the United States. This means your personal data may be transferred to, stored in, or accessed from a country whose data protection laws differ from your own.

Where we transfer personal data out of the UK or EEA, we rely on one of the following safeguards:

  • an adequacy decision by the UK Government or the European Commission covering the destination country;
  • the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses; or
  • the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment and any additional technical measures needed.

You can request a copy of the safeguards we use by emailing [email protected].

10. How long we keep your information

We keep personal data only for as long as we need it for the purpose we collected it for, and then delete or anonymise it.

Type of dataRetention period
Contact-form and email enquiries that do not lead to workUp to 24 months from the last contact, then deleted.
Account and Google profile dataFor as long as the account is active, and deleted within 30 days of account closure or a deletion request.
Client project records and correspondenceFor the duration of the engagement and 6 years afterwards, to cover the limitation period for contractual claims.
Invoices and accounting records6 years from the end of the relevant financial year, as required by UK tax law.
Website logs and analytics dataUp to 14 months, usually in aggregated form.

Where we are required to keep a record of a deletion request itself, we retain only the minimum needed to demonstrate that we honoured it.

11. How we protect your information

We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include:

  • encryption of data in transit using TLS across the whole site, and encryption at rest for stored application data;
  • access controls on the principle of least privilege, with multi-factor authentication required for administrative accounts;
  • delegating password handling to Google where you sign in with Google, so we never see or store your Google password;
  • supplier due diligence, written data processing terms, and periodic review of the services we rely on; and
  • internal procedures for detecting, investigating and reporting suspected personal data breaches.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and notify you directly where the risk is high.

12. Your data protection rights

If you are in the UK or the EEA, you have the following rights. They are free to exercise, and we will respond within one month.

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where we no longer have a good reason to keep it.
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
  • Portability — receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time, with no need to give a reason.
  • Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.

How to exercise your rights

Email [email protected] with “Data protection request” in the subject line, telling us which right you want to exercise. We may ask for information to verify your identity before we act, so that we do not disclose your data to someone else.

Complaints

We would like the chance to resolve any concern first, but you have the right to complain to a supervisory authority at any time. In the UK this is the Information Commissioner’s Office — ico.org.uk/make-a-complaint or 0303 123 1113. If you are in the EEA, you may complain to the supervisory authority in your country of residence or work.

13. Notice for US residents

If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to request a copy or deletion of it, to correct it, and not to be discriminated against for exercising those rights.

For the avoidance of doubt: we do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding twelve months, including in respect of anyone under 16.

To make a request, email [email protected]. You may use an authorised agent, in which case we will ask for proof of their authority.

14. Children’s privacy

Our website and services are intended for businesses and for adults. They are not directed at children, and we do not knowingly collect personal data from anyone under the age of 16 (or under 13 in the United States). If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.

16. Changes to this policy

We may update this policy to reflect changes in our services, our suppliers, or the law. When we do, we will revise the “Last updated” date at the top of this page. If the changes are significant — for example, a new purpose for using your data — we will give you clear notice by email or a prominent notice on the site before the change takes effect. Please check back periodically.

17. How to contact us

For any question about this policy, or to exercise your rights, please contact us:

You may also want to read our Terms & Conditions, which govern your use of this website.