Who we are
Tasin Labs is a software studio and IT services practice. In this policy, “we”, “us” and “our” mean Tasin Labs.
Tasin Labs is a trading name rather than a registered company. The person responsible for the personal data described here — the data controller under the UK and EU General Data Protection Regulation — is [CONTROLLER NAME], trading as Tasin Labs.
You can reach us about anything in this policy at hello@tasinlabs.com.
What this policy covers
This policy applies to personal data we handle as a controller — that is, where we decide why and how it is used:
- Visitors to this website.
- People who contact us through the enquiry form or by email.
- Clients and prospective clients, and the individuals we deal with at those organisations.
- People who use software we operate ourselves, including our own SaaS product.
It does not cover personal data we handle on behalf of a client while building or supporting their systems. There we act as a processor: the client decides what is collected and why, their own privacy notice applies, and our handling is governed by the data processing terms in our contract with them.
What we collect
When you browse this website
This site is static and carries no analytics, no advertising and no third-party scripts. Fonts are served from our own domain rather than a font provider, so simply loading a page does not send your details to anyone else.
Our hosting provider records standard server logs — IP address, timestamp, the page requested, and your browser's user-agent string — for security and to keep the service running. We do not use those logs to build a profile of you.
When you contact us
The enquiry form on this site does not transmit anything on its own: submitting it opens a draft in your own email application with the fields filled in, and nothing reaches us until you choose to send it. Once you do, we receive the name, email address, company, project type, budget range and message you provided, together with anything else you write.
We also receive whatever you send us directly by email, and we keep the correspondence so we can pick up the thread later.
When you become a client
- Contact and billing details for the people we work with at your organisation.
- Records of the work: proposals, scopes, invoices, tickets and correspondence.
- Credentials and access you grant us to your systems. We ask for the least access that does the job, and we ask you to revoke it when the work ends.
When you use software we operate
For our own SaaS product we hold the account details you register, your subscription and payment status, the content you put into the product, and operational logs used for security, billing accuracy and debugging. Card details are handled by our payment provider — we never see or store full card numbers.
Why we use it, and our lawful basis
Under the UK and EU GDPR we must have a lawful basis for each use. Ours are:
- To answer your enquiry and prepare a proposal — our legitimate interest in responding to people who approach us, and taking steps at your request before entering a contract.
- To deliver the work and run your account — performance of our contract with you.
- To invoice, take payment and chase late payment — performance of our contract, and our legitimate interest in being paid.
- To keep systems secure and available — our legitimate interest in protecting our services and our clients' systems from abuse.
- To meet accounting and tax obligations — compliance with a legal obligation.
- To send occasional updates about our services — your consent, which you can withdraw at any time. We do not sell or rent contact details to anyone, ever.
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and you can object at any time using the details below.
International transfers
We work with clients and providers in several countries, so personal data may be transferred outside the UK or the European Economic Area. Where it is, we rely on an adequacy decision covering the destination country, or on the UK International Data Transfer Agreement / EU Standard Contractual Clauses with the recipient, together with any additional safeguards those require.
You can ask us for details of the safeguards applying to a specific transfer.
How long we keep it
- Enquiries that do not become work — up to 24 months, in case you come back to us, then deleted.
- Client records and correspondence — for the duration of our relationship and for 6 years afterwards, which covers the period in which a contractual claim could be brought.
- Invoices and accounting records — for as long as tax law requires, typically 6 years.
- SaaS account data — while your account is active, and for 90 days after cancellation so you can change your mind, after which it is deleted or irreversibly anonymised.
- Server logs — a rolling window, typically no more than 90 days.
Credentials you give us for your own systems are removed from our password manager when the engagement ends, and we will ask you to revoke them at your end too.
Your rights
If the UK or EU GDPR applies to you, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where we no longer have grounds to keep it.
- Restriction — have us pause our use of your data while a dispute is resolved.
- Portability — receive data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time, which we will always honour.
- Withdraw consent — where we relied on consent, without affecting what came before.
To exercise any of these, email hello@tasinlabs.com. We respond within one month and will not charge you for it. We may need to confirm your identity first, so that we do not hand your data to someone else.
If you are unhappy with our response you can complain to your local data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the supervisory authority of the country you live or work in. We would rather you came to us first so we can put it right.
How we protect it
We keep access to the least number of people who need it, use a password manager with multi-factor authentication, encrypt data in transit, prefer managed services with tested backups, and scan dependencies for known vulnerabilities. No system is perfectly secure, but we do not treat security as something to be added later.
If a breach affects your personal data and is likely to pose a risk to you, we will notify the relevant supervisory authority within 72 hours where required, and tell you without undue delay.
Children's data
Our services are provided to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We update this policy when how we work changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights, we will tell you directly rather than relying on you to notice.
Contact us
For any privacy question, request or complaint, email hello@tasinlabs.com, addressed to [CONTROLLER NAME], trading as Tasin Labs.
Written notices can be sent to [POSTAL ADDRESS].
Questions about this document?
Email hello@tasinlabs.com and a person will answer.