Lathe.

Legal

Privacy Policy

Effective date: 13 June 2026

1. Who we are

This Privacy Policy applies to Lathe Labs Ltd (“Lathe”, “we”, “us”, “our”), a company registered in England and Wales. Our website is lathelabs.dev.

We are the data controller for personal data we process about you. Questions about this policy: contact@lathelabs.dev.

2. Data we collect and why

Contact form submissions

Name, email address, company name, project description, and budget range — collected when you complete our contact form. Used to respond to your enquiry and assess project fit. Legal basis: legitimate interests (pre-contractual).

Analytics data

Page views, referrer URLs, device type and approximate location (country-level). Collected via Vercel Analytics — no cookies, no cross-site tracking. Legal basis: legitimate interests (improving our site).

Client project data

Data necessary to deliver contracted services — code repositories, access credentials, project communications. Processed under the terms of our engagement contract. Legal basis: contract performance.

AI chat interactions

Messages you send to our AI assistant are processed via the Anthropic API to generate responses. We do not store chat histories on our servers. Anthropic's data handling applies to API traffic. Legal basis: legitimate interests (providing the service you requested).

3. How we use your data

  • To respond to enquiries and manage client relationships
  • To deliver contracted development and hosting services
  • To send project-related communications (no marketing without consent)
  • To send invoices and manage payments
  • To improve our website and services based on aggregate analytics

4. Who we share data with

We do not sell your data. We share data only with third-party processors necessary to operate our services:

  • VercelWebsite hosting and analytics — servers in US/EU
  • ResendTransactional email delivery — EU data residency
  • AnthropicAI assistant API — data processed under Anthropic's enterprise terms
  • Cal.comMeeting scheduling — if you book a call

5. Data retention

Contact enquiries: retained for 2 years or until the relationship ends, whichever is later. Client project data: retained for the duration of the engagement plus 6 years (UK contract law limitation period). Analytics data: aggregated and anonymised — no individual retention.

6. Your rights under GDPR

If you are in the UK or EU, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure ('right to be forgotten') where no legal basis to retain exists
  • Object to processing based on legitimate interests
  • Request restriction of processing
  • Data portability (receive your data in a structured format)
  • Withdraw consent where processing is consent-based

To exercise any of these rights, email contact@lathelabs.dev. We respond within one calendar month. You also have the right to lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.

7. Cookies

This website does not use tracking cookies. Vercel Analytics operates without cookies — it uses a privacy-preserving approach based on request metadata, not persistent identifiers.

8. Security

We implement appropriate technical and organisational measures to protect your data: HTTPS everywhere, encrypted storage, access controls, and regular dependency security reviews. No system is 100% secure — if you believe a security incident has occurred, contact contact@lathelabs.dev immediately.

9. Changes to this policy

We update this policy when our data practices change. Material changes will be flagged on this page with an updated effective date. Continued use of our services after a change constitutes acceptance.

Contact us about privacy

Lathe Labs Ltd · contact@lathelabs.dev

Related: Terms & Conditions