Privacy policy
Last updated: August 2026
This policy explains what personal data we collect through letrixlabs.com and in the course of our work, why we collect it, who we share it with, and what you can do about it. It is written to be read rather than survived. If anything here is unclear, email hello@letrixlabs.com and we will explain it in plain terms.
1. Who we are
Letrix Labs is a trading name of Dime Corporation Ltd, a company registered in England and Wales under company number 13175488, with its registered office at 124 City Road, London, EC1V 2NX, United Kingdom.
For the personal data described in this policy, Dime Corporation Ltd is the data controller. We are registered with the Information Commissioner’s Office under registration number ZC094825.
You can reach us about anything in this policy at hello@letrixlabs.com, or by writing to us at the address above.
2. What this policy covers
This policy covers our website, our enquiry and support channels, and the personal data we hold about clients and prospects.
Two things sit outside it:
- Our own products. The products listed on our products page each have their own privacy policy and terms, which govern the data handled inside those products. This policy does not apply to them. See the Pretty URL privacy policy and the PairVault privacy policy.
- Templates sold through Gumroad. Gumroad is the seller and merchant of record for our templates and operates its own privacy policy covering your purchase. Section 7 explains the limited data we receive from them.
3. When we are a controller, and when we are a processor
This distinction matters, because different rules and different documents apply to each. When you enquire with us, correspond with us, or engage us as a client, we decide how your data is handled, so we are the controller and this policy applies.
When we build, migrate or maintain a system for a client and that system contains personal data belonging to their customers, staff or users, we handle it only on that client’s instructions. There we are a processor, the client is the controller, and the relationship is governed by our Data Processing Agreement rather than by this policy.
4. What we collect
Information you give us
- Enquiry form. Your name, email address, company or project name (optional), the services you are interested in, an indicative budget range, and whatever you write in the project details field.
- Live chat. If you open the chat widget, the messages you send and any contact details you choose to give us in the conversation.
- Email and other correspondence. Anything you send us directly, and our replies.
- Client engagement information. Billing and invoicing details, project materials and content you supply, and, where we have agreed it as part of the work, credentials for systems we need to access on your behalf.
Information collected automatically
- Aggregate analytics. We use a self-hosted, cookieless analytics tool that records page views, referring sites, approximate country, and device or browser type in aggregate. It does not use cookies, does not track you across sites, and does not build a profile of you.
- Optional analytics. Google Analytics, but only if you consent to it. See our Cookie Policy.
- Anti-spam. Our enquiry form is protected by Cloudflare Turnstile, which checks that a submission is not automated. Cloudflare processes your IP address and basic browser signals to do this.
- Error diagnostics. If something breaks in your browser, our self-hosted error monitoring records the technical details of the fault: the error itself, the page, and the browser type. It is configured not to collect IP addresses or other personal identifiers.
We do not collect special category data, and we do not carry out automated decision-making or profiling.
5. Why we use it, and our lawful basis
Under UK GDPR we have to have a specific lawful reason for every use of your personal data. This table sets out ours in full.
| What we do | Why | Lawful basis |
|---|---|---|
| Reply to your enquiry, prepare a quote or proposal | You asked us to, and we cannot answer without it | Legitimate interests: responding to an enquiry you initiated |
| Deliver a project, care plan or other service | To do the work we have been engaged to do | Performance of a contract |
| Answer support requests and live chat messages | To support you | Legitimate interests, or contract if you are a client |
| Issue invoices and keep accounting records | We are legally required to keep them | Legal obligation (Companies Act 2006, HMRC requirements) |
| Protect our forms from spam and abuse | To keep the site usable and secure | Legitimate interests: network and information security |
| Understand aggregate site traffic | To see which pages are useful | Legitimate interests: the data is anonymous and aggregate |
| Run Google Analytics | More detailed traffic analysis | Consent, and only if you give it |
| Establish, exercise or defend legal claims | To protect our position if a dispute arises | Legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded it is not, because the data involved is limited, you would reasonably expect the processing, and it has little or no privacy impact. You can object to any of it. See section 10.
Where we rely on consent, you can withdraw it at any time, and withdrawing it is as easy as giving it. That will not affect anything done before you withdrew.
6. Cookies and similar technologies
We use a small number of cookies and similar browser storage. Non-essential ones are only set if you agree. The full breakdown, including how to change your mind, is in our Cookie Policy.
7. Who we share it with
We do not sell, rent or trade personal data, and we never will. We share it only with providers who help us run the business, each of whom is bound to protect it and to use it only on our instructions.
| Provider | What it handles | Where it is processed |
|---|---|---|
| FreeScout (self-hosted by us) | Enquiries and support conversations | United Kingdom / EU |
| Crisp | Live chat for real-time visitor support | European Union (France) |
| Vercel | Website hosting and serverless application functions (EU region) | European Union / Global |
| Cloudflare | DNS routing, DDoS security and Turnstile anti-spam checks | Global / UK / EU |
| Plausible-compatible analytics (self-hosted by us) | Anonymous, aggregate traffic statistics | United Kingdom / EU |
| GlitchTip (self-hosted by us) | Technical error diagnostics | United Kingdom / EU |
| Google Analytics | Optional analytics: only with your consent | United States |
| Gumroad | Template sales, as seller and merchant of record | United States |
We may also share personal data with:
- our accountants and professional advisers, where they need it to advise us;
- law enforcement, regulators, courts or other authorities, where we are legally required to, or where it is necessary to establish or defend legal claims;
- a buyer or successor, if the business is sold or reorganised, in which case you would be told before your data changed hands.
Most of the systems handling your data are ones we host and run ourselves, rather than third-party platforms. That is a deliberate choice.
8. International transfers
Our core systems (support, analytics and error monitoring) are self-hosted on servers in the United Kingdom and the European Union. Personal data held in those systems stays there.
Two providers process data in the United States: Google Analytics, which only runs if you consent to it, and Gumroad, which handles template purchases as the seller. Where personal data is transferred outside the UK, it is protected by the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses, together with additional safeguards where appropriate. You can ask us for details of the safeguards that apply.
9. How long we keep it
We keep personal data only as long as we actually need it. The periods below are maximums: we often delete sooner, and you can ask us to delete earlier at any time.
| What | How long |
|---|---|
| Enquiries that do not become projects | Up to 24 months from your last contact with us |
| Support conversations from non-clients | Up to 24 months after the conversation is closed |
| Live chat transcripts | Up to 12 months |
| Client project records and correspondence | Up to 6 years after the engagement ends |
| Invoices and accounting records | 6 years after the end of the relevant financial year (HMRC requirement) |
| Technical error diagnostics | Up to 90 days |
| Your cookie preference | 12 months, after which we ask again |
Where we cannot set a fixed period in advance, we decide based on why we hold the data, whether we still need it for that purpose, and whether we are legally required to keep it. Backups are overwritten on their normal cycle, so deleted data may persist briefly in a backup before ageing out.
10. Your rights
Under UK GDPR you have the following rights, all of them free to exercise:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted, where we have no overriding reason to keep it.
- Restriction: have us pause our use of your data while a concern is resolved.
- Portability: receive data you gave us in a machine-readable format, or have it sent elsewhere.
- Object: object to processing based on legitimate interests, including any form of direct marketing.
- Withdraw consent: where we relied on consent, take it back at any time.
- Complain: raise it with the supervisory authority.
To exercise any of these, email hello@letrixlabs.com. We will respond within one month. If a request is particularly complex we may extend that by up to two further months, and we will tell you within the first month if that happens and why.
We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else. If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113.
11. Security
We take appropriate technical and organisational measures to protect personal data. In practice that means:
- all traffic to and from this site is encrypted in transit (TLS);
- our support, analytics and error monitoring systems are self-hosted and access-controlled, rather than spread across vendors;
- where we hold client credentials, they are stored in a dedicated, access-controlled 1Password vault and never in plain text;
- access to personal data is limited to the people who need it to do the work;
- we do not collect personal data we have no use for.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights, we will report it to the ICO within 72 hours and tell you without undue delay where the risk to you is high.
12. Children
Our website and services are intended for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us their data, contact us and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we use your personal data, we will take reasonable steps to tell you directly. Previous versions are available on request.
14. Contact us
Letrix Labs is a trading name of Dime Corporation Ltd (13175488), registered in England and Wales, 124 City Road, London, EC1V 2NX, United Kingdom. ICO registration ZC094825.
For any question or request about this policy, email hello@letrixlabs.com.