Voidlabs is a digital product studio. When you visit voidlabs.studio, send us a message, or enter a contract with us, we may process personal data about you. This policy is written for people in the United Kingdom and the European Economic Area. It is meant to be readable, not theatrical. If something here is unclear, email contact@voidlabs.studio.
Effective date: . This policy should be read with our Cookie Policy and Terms and Conditions.
1. Who we are
We trade as Voidlabs. The legal name we use is Void Labs. We operate the website at https://voidlabs.studio and the email address contact@voidlabs.studio. We are based in the United Kingdom.
Our registered office and company number will be provided on request and on any formal proposal or invoice. Until a contract is signed, treat contact@voidlabs.studio as the correct channel for privacy requests.
2. Scope
This policy covers personal data we process as a controller when you:
- browse or use voidlabs.studio
- submit the contact form or email the studio
- manage cookie preferences
- receive a proposal, invoice, or project communication from us
- exercise a data protection right
If we process personal data on a client’s instructions during a project (for example, access to a CMS, analytics account, or customer list), we do so as a processor. That processing is governed by the contract with that client, not by this public policy alone. We still apply appropriate security in either role.
This policy does not apply to third-party websites we link to. Those services have their own policies.
3. Data controller
For website enquiries, cookie consent records, and studio administration, Void Labs (trading as Voidlabs) is the data controller. That means we decide why and how that personal data is processed.
We have not appointed a statutory Data Protection Officer. Privacy requests go to contact@voidlabs.studio and are handled by the studio.
4. What we collect
Identity and contact
Name, email address, and any other details you choose to include in a message.
Enquiry content
The body of your message, files you attach by email, and follow-up correspondence. Please do not send special category data (health, politics, religion, biometrics, and similar) unless we have asked for it in writing for a specific purpose.
Technical data
Internet protocol (IP) address, approximate location derived from IP, browser type and version, device type, operating system, referring URL, pages viewed, and timestamps. We may see this in server logs kept by our hosting provider.
Consent records
Your cookie choices, the time they were saved, and the fact that necessary cookies were always on. We store this in a first-party cookie on your device so we can respect the choice on later visits.
Project and billing data
If we work together: billing name and address, payment references, VAT numbers where relevant, statements of work, and project communications. Payment card details are processed by our payment provider if we use one; we do not store full card numbers on our systems.
We do not buy marketing lists. We do not scrape contact details to cold-email you from this site.
5. How we collect it
- Directly from you, via the form, email, or calls
- Automatically, via necessary cookies, server logs, and security tooling
- From you later, if a project goes ahead (contracts, kickoff, tools we both use)
- Rarely, from a referrer who introduces you — we will say if that is how we got your details
6. Lawful bases
UK GDPR requires a lawful basis for each purpose. We rely on the following.
| Purpose | Basis |
|---|---|
| Responding to enquiries | Legitimate interests (Art. 6(1)(f)) — to reply to people who contact us. Where you tick the form consent box, we also treat that as consent to use those details for that reply. |
| Preparing and performing a contract | Contract (Art. 6(1)(b)) |
| Invoicing, tax, accounting | Legal obligation (Art. 6(1)(c)) |
| Necessary cookies and security logs | Legitimate interests; PECR exemption for cookies that are strictly necessary |
| Optional analytics or marketing cookies | Consent (Art. 6(1)(a) and PECR) |
| Establishing, exercising, or defending legal claims | Legitimate interests |
You may object to legitimate interests processing. We will stop unless we have compelling grounds or the data is needed for a legal claim. Consent can be withdrawn at any time without affecting processing that already happened.
7. How we use data
- To read, assess, and reply to project enquiries
- To schedule calls and send proposals
- To deliver, invoice, and support contracted work
- To keep the website secure, debug faults, and prevent abuse of the form
- To remember cookie preferences
- To meet accounting, tax, and legal duties
- To improve the site, but only with analytics if you opted in
We do not sell personal data. We do not use enquiry messages to train public generative AI models. If we use private tools to draft a reply, we take reasonable steps not to feed confidential briefs into services that claim a right to train on that content.
8. Contact form
The form on this site is sent to contact@voidlabs.studio using an email delivery provider. Fields include name, email, and your message. A timestamp and technical signals (such as IP, used only to limit abuse) may be processed to reduce spam. Cloudflare Turnstile is used to check that a submission is from a person before the message is emailed to us.
A hidden field is present to catch bots. Humans should leave it blank. Submitting the form is not a contract. It is a way to reach the studio.
9. Cookies and similar technologies
Cookies, local storage, and similar technologies are described in full in our Cookie Policy. In short:
- Strictly necessary cookies do not need consent under PECR
- Analytics and marketing cookies are off until you opt in
- You can change your mind at any time from the Cookie Policy page
10. Sharing and processors
We share personal data only with people who need it to provide our service, including:
- Hosting and content delivery — Vercel, Inc., which hosts this website and related serverless functions
- Email delivery — Google (Gmail SMTP) to send form submissions to us
- Captcha — Cloudflare Turnstile, used to check that a form submission is from a person
- Professional advisers — accountants, insurers, or lawyers, when required
- Authorities — if the law requires it, or to protect rights, safety, or the studio
Processors are bound by contract to use data only on our instructions and to apply appropriate security. If we add a new processor that materially changes how enquiry data is handled, we will update this policy.
If a project requires shared tools (Figma, GitHub, Notion, Slack, and similar), those providers process data under their own terms. We will tell you which tools we intend to use before a kickoff.
11. International transfers
Some processors are in the United States or other countries outside the UK. Where we transfer personal data internationally, we use a lawful mechanism such as:
- the UK Extension to the EU-US Data Privacy Framework, where the importer is certified
- the UK International Data Transfer Agreement, or the Addendum to the EU SCCs
- an adequacy regulation made by the UK government
Vercel and common email APIs may process data in the US. You can ask us for more detail about the mechanism in force for a given provider.
12. Retention
| Record | Typical period |
|---|---|
| Unsuccessful enquiries | Up to 24 months, then deleted or anonymised, unless you ask us to delete sooner |
| Successful enquiries that become a project | Kept with the project file for the life of the contract plus 6 years (limitation and tax) |
| Invoices and accounting records | 6 years from the end of the relevant financial year, or longer if the law requires |
| Server and security logs | Usually 30–90 days, unless needed to investigate an incident |
| Cookie consent | Up to 12 months on your device, then we ask again |
We may keep data longer if it is needed for a dispute, to meet a legal duty, or if you ask us to retain a file.
13. Security
We use HTTPS, access controls, least-privilege hosting, and rate limiting on the contact form. No method of transmission or storage is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the ICO and, where the law requires, you.
14. Your rights
Under UK GDPR you may have the right to:
- Access — a copy of personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete data in certain cases
- Restriction — ask us to pause processing in certain cases
- Portability — receive data you provided in a structured format, where the basis is consent or contract and the processing is automated
- Objection — object to processing based on legitimate interests, including profiling
- Withdraw consent — where processing is based on consent
- Complain — to the Information Commissioner’s Office
These rights are not absolute. We will explain if an exemption applies (for example, we must keep invoices).
15. How to exercise your rights
Email contact@voidlabs.studio with the subject line “Privacy request”. Tell us which right you want to use and enough information to find your data (usually the email you used to contact us). We may need to verify your identity. We will respond within one month, or explain if we need more time (up to two further months for complex requests).
There is no fee unless a request is manifestly unfounded or excessive.
16. Automated decision-making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects about you. Spam filters and rate limits may automatically hold or reject a form submission. That is abuse-prevention, not a decision about a contract.
17. Children
This site and our services are aimed at adults acting in a business capacity. We do not knowingly collect data from children under 18. If you believe we have, email us and we will delete it.
18. Third-party links
If this site links out, we are not responsible for those destinations. Check their privacy information before you share data with them.
19. Changes
We will update this page when our processing changes in a meaningful way. The date at the top is the latest version. If a change is material and we have your email from an active project, we may also notify you directly.
20. Complaints
Please contact us first so we can try to fix the issue. You also have the right to complain to the UK regulator:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk
Helpline: 0303 123 1113
If you live in the EEA, you may also complain to your local supervisory authority.
21. Contact
Privacy questions and requests: contact@voidlabs.studio
Or use the contact form.
