Data Protection & Governance

Privacy Policy (UK GDPR Compliant)

Last updated: 28 September 2026. Watling Labs is committed to absolute transparency, privacy-by-design, and zero intrusive commercial surveillance.

1. Data Controller Information

The Data Controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) is:
Watling Labs (Independent UK Software Studio, operated by Alex Watling)
Jurisdiction: England & Wales
Privacy & Data Protection Officer Contact: [email protected]

2. Core Data Privacy Principles

We operate under strict privacy-by-design principles:
• Zero Third-Party Advertising: We do not sell, rent, or monetize your personal data.
• Zero Tracking Cookies: Our website contains no Google Analytics, Meta Pixels, or cross-site tracking scripts.
• Data Minimization: We collect only the data strictly necessary to fulfill your order, issue statutory invoices, or deliver technical subscriptions.

3. Data We Collect & Lawful Bases

Category Data Elements Lawful Basis (UK GDPR)
Commercial Orders Name, email, billing address, VAT/tax identifier. Performance of Contract (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c))
Statutory BACS Orders Council name, clerk email, council PO number. Performance of Contract (Art. 6(1)(b))
Subscription Feeds Email address, practitioner firm name. Performance of Contract (Art. 6(1)(b))
Edge Security Logs IP address, user agent, requested URL (retained max 30 days). Legitimate Interests (Art. 6(1)(f) - network security & DDoS prevention)

4. Authorized Sub-Processors

We partner exclusively with enterprise-grade sub-processors that maintain strict UK and EU GDPR compliance:

  • Cloudflare, Inc.: Global edge network, DDoS protection, and static hosting (UK/EU data processing agreements in place).
  • Lemon Squeezy, LLC: Merchant of Record managing PCI-DSS compliant checkout and tax reporting.
  • Stripe Payments Europe, Ltd.: Payment gateway for direct transactions.
  • Resend, Inc.: Transactional email service for order delivery and statutory invoices.

5. Data Retention Periods

Financial and invoicing records (including BACS invoices and Lemon Squeezy order manifests) are retained for six (6) years in compliance with HMRC statutory accounting regulations. Technical diagnostic logs and temporary edge access logs are automatically pruned after 30 days.

6. Your Statutory Rights Under UK GDPR

As an individual in the United Kingdom, you possess statutory rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data where no overriding statutory retention obligation exists.
  • Right to Restriction & Objection: Object to specific processing activities.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.

To exercise any of these rights, email our Data Protection Officer at [email protected]. We respond to all verified statutory requests within 30 calendar days at zero cost.

7. Complaints to the Supervisory Authority

If you believe our data processing fails to comply with the UK GDPR or Data Protection Act 2018, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Website: https://ico.org.uk | Helpline: 0303 123 1113.