This policy explains what personal data Gateway Labs Ltd collects, why we hold it, how long we keep it, and the rights you have over it under the UK GDPR and the Data Protection Act 2018.
1 · Who we are
Gateway Labs Ltd is the data controller for the personal data described in this policy. We are registered in England & Wales under company number 17357186 and based in London.
Company number 17357186, England & Wales.
Write to us with any question or request about your data.
2 · What we collect
This website has no contact forms, no account system and no advertising. Almost all the personal data we hold arrives because someone chose to email us.
Your name, email address, employer, role and whatever you tell us in the message — including details about your company's commercial position if you share them.
For clients and portfolio companies: contract details, contacts at the company, notes and deliverables produced during the work, and billing information.
Our hosting provider records standard server logs — IP address, request time, page requested, browser type — for security and reliability. We do not use these to identify or profile visitors.
No analytics, no advertising or tracking pixels, no social media trackers, and no special category data. We never sell personal data or share it for marketing.
3 · Cookies and storage
We set no cookies. The site stores one item in your browser's local storage: whether you switched background motion on or off using the control in the footer. It is strictly necessary to honour that preference, contains no identifier, is never sent to us, and is removed if you clear site data for this domain. Because no non-essential cookies or trackers are used, there is no consent banner.
Fonts are served by Google Fonts, which receives your IP address in order to deliver the font files. If you prefer to avoid that, browser extensions and privacy settings can block third-party font loading; the site remains readable without it.
4 · Why, and our legal basis
Answering enquiries
Replying to you, assessing whether an engagement makes sense, and keeping a record of the conversation.
Delivering the work
Performing a diagnostic, sprint or operating engagement, and managing the contract behind it.
Accounting and compliance
Invoices, statutory accounts, tax records and anti-money-laundering checks where they apply.
Site security
Keeping the website available and protecting it from abuse, using our host's server logs.
5 · Who sees it
Personal data stays with us and with a small number of service providers acting as our processors under written terms: our email and document providers, our website host, and our accounting software. We also share data with our accountants and, where necessary, our legal advisers.
Some of these providers process data outside the United Kingdom. Where they do, transfers are covered by UK adequacy regulations or by the International Data Transfer Agreement or Addendum, with additional safeguards where required. We will disclose data to a public authority only where the law obliges us to.
6 · How long we keep it
Enquiries that did not become an engagement, measured from our last exchange.
Engagement files and correspondence after the work ends, matching the limitation period for contractual claims.
Invoices and accounting records, as required by UK company and tax law.
Server logs held by our hosting provider.
7 · Your rights
Under the UK GDPR you can ask us to
- Give you access — a copy of the personal data we hold about you.
- Correct it — fix anything inaccurate or incomplete.
- Erase it — delete it where we have no overriding reason or legal duty to keep it.
- Restrict processing — pause our use of it while a question is resolved.
- Object — to processing we base on legitimate interests.
- Port it — receive it in a portable format, or have it sent elsewhere.
Email admin@gatewaylabs.org and we will respond within one month. Exercising any of these rights is free, and we will not treat you differently for it.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first, but you do not have to.
8 · Security and changes
Data is held in reputable cloud services with encryption in transit and at rest, multi-factor authentication on every account, and access limited to the people who need it. No system is perfect; if a breach ever affects your rights we will notify you and the ICO as the law requires.
We update this policy when our practices or the law change. The version and date at the top of the page tell you which edition you are reading, and material changes will be summarised here.