We use essential cookies to run our website and optional cookies to improve your experience. Please accept optional cookies or choose to continue with essential only. See our Cookie Policy for more details.

// Privacy Policy

Privacy Policy

Last updated on

Introduction

Welcome to Metron Labs Limited ("we", "us", "our"). We are committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains how we collect, use, store, and share your personal information when you visit metronlabs.ai, join a waiting list, contact us, or use our software (the “Services”).

We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

When you provide us with your personal data, for example by using our contact form, we will process it in accordance with this Privacy Policy and applicable data protection laws.

Who We Are

  • Company name: Metron Labs Limited
  • Company number: 16422712
  • Registered address: 124-128 City Road, London, England, EC1V 2NX
  • Privacy contact: [email protected]

We are the data controller responsible for your personal data.

Please use the email address above for all privacy enquiries.

The Data We Collect

We collect and process the following categories of personal data:

a) Information you provide directly

When you:

  • Contact us via our website or email — we collect your name, email address, and any other information you include in your message.
  • Join our waiting list — we collect your name and email address to keep you informed about our product launch and related updates.
  • Create an account / subscribe to our software — we collect details necessary to deliver our Services, including:
    • Full name
    • Email address
    • Password (stored securely in salted and hashed form)
    • Company name and role (if applicable)
    • Billing and payment information

b) Information we collect automatically

When you visit our website or use our software, we automatically collect:

  • Technical data: IP address, browser type/version, operating system, and time-zone setting.
  • Usage data: how you interact with our site and product (pages viewed, session duration, features used).
  • Cookie data: as explained in section 5 below.

How and Why We Use Personal Data

We only use your personal data when the law allows us to. The table below summarises how we use your data and our lawful bases.

PurposeType of dataLawful basis
Responding to your enquiriesName, email, messageLegitimate interests
Managing waiting list and updatesName, emailConsent
Creating and managing user accountsName, email, login detailsPerformance of a contract
Processing paymentsBilling and payment informationPerformance of a contract and legal obligation
Sending marketing communicationsName, emailConsent
Improving and securing our website/softwareTechnical and usage dataLegitimate interests
Compliance with legal requirementsAll relevant dataLegal obligation

We send marketing communications in accordance with the Privacy and Electronic Communications Regulations (PECR).

You can unsubscribe or change your marketing preferences at any time.

We do not use your data for automated decision-making or profiling that has legal or similarly significant effects.

Cookies

We use mandatory cookies for the operation of our website, they are set automatically and do not require your consent under the Privacy and Electronic Communications Regulations (PECR). We also use optional analytics cookies. Please visit our Cookie Policy for details.

Sharing Your Personal Data

We do not sell your personal data. We may share limited information with trusted third-party processors who help us provide our Services, such as:

  • Payment processors: e.g. Stripe Payments UK Ltd - to securely process payments
  • Cloud hosting providers: e.g. Amazon Web Services (AWS) - to host our software and store data securely
  • Email and communication platforms: e.g. SendGrid or Mailchimp - to send product updates and communications

All processors are contractually required to keep your data secure and process it only under our instructions, in accordance with UK GDPR.

International Data Transfers

Some of our service providers may be located outside the UK (for example, in the EEA or the US). When personal data is transferred internationally, we ensure appropriate safeguards are in place, such as:

  • An adequacy decision (where the destination country provides equivalent protection), or
  • The UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) approved by the ICO.

You can request details of these safeguards by contacting [email protected]

Data Security

We use industry-standard technical and organisational measures to protect your data, including:

  • Encryption of data in transit (TLS) and at rest where appropriate
  • Role-based access control and authentication
  • Regular access reviews and vulnerability assessments
  • Secure processor contracts and internal data-handling policies

While we take reasonable precautions, no system is completely secure; we cannot guarantee absolute security of data transmitted over the internet.

Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy or to meet legal, accounting, or reporting requirements.

Data typeRetention period
Contact form enquiriesUp to 12 months after resolution
Waiting list recordsUntil unsubscribe or up to 24 months after last contact
Account and billing dataWhile account is active and up to 7 years after closure
Analytics and logsUp to 24 months, then anonymised or deleted

After retention periods expire, data is securely deleted or anonymised.

Your Data Protection Rights

Under UK data protection law, you have the following rights:

  • Access - request a copy of your personal data.
  • Rectification - correct inaccurate or incomplete data.
  • Erasure - ask us to delete your data in certain circumstances.
  • Restriction - limit processing in some cases.
  • Objection - object to processing based on legitimate interests or direct marketing.
  • Data portability - request transfer of your data to you or another provider.
  • Withdrawal of consent - withdraw consent at any time where applicable.

We will respond without undue delay and within one month (or within three months for complex requests).

We do not carry out automated decision-making or profiling.

To exercise your rights, please contact [email protected]

Data Breaches

We maintain an incident-response process. If a personal data breach occurs that is likely to result in a risk to individuals’ rights and freedoms, we will:

  • Notify the Information Commissioner’s Office (ICO) within 72 hours, where feasible; and
  • Inform affected individuals without undue delay if there is a high risk to their rights or freedoms.

Children’s Privacy

Our website and Services are not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. If you believe a child has provided us with personal data, please contact [email protected], and we will delete it promptly.

How to Complain

If you are unhappy with how we have used your personal data, please contact us first at [email protected] so we can address your concern.

If you remain dissatisfied, you may complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: www.ico.org.uk

Changes to This Policy

We may update this Privacy Policy from time to time. Any updates will appear on this page with a revised “Last Updated” date.

If the changes are significant, we may notify you by email. We encourage you to review this Policy periodically to stay informed about how we protect your data.