Latonis Technologies Ltd
Latonis Technologies Ltd ("Latonis", "we", "us", "our") is a software development and digital marketing agency incorporated in England and Wales under company number 16798861, with its registered office at Sterling House, Suite 310e East Wing, Langston Road, Loughton, Essex, United Kingdom, IG10 3TS. We also trade under the names "Latonis", "Latonis Studios", and "Latpax". Personal data collected through our Latpax digital products platform is governed by the separate Latpax Privacy Policy published on that website.
Except where Section 2 provides otherwise, Latonis is the data controller of the personal data described in this policy. We process personal data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018"), and the Privacy and Electronic Communications Regulations 2003 ("PECR"). Where we process the personal data of individuals located in the European Economic Area, the EU GDPR applies to that processing.
This policy applies to visitors to our website(s), prospective, current, and former clients and their personnel, suppliers, contractors, and freelancers, applicants for roles or engagements with us, and anyone else who communicates or interacts with us.
Because Latonis is a business-to-business services company, we handle personal data in two distinct capacities, and it is important to understand which one applies to you.
(a) Latonis as controller. When we collect and use personal data for our own purposes — operating our website, responding to enquiries, marketing our services, managing client relationships, invoicing, recruitment, and complying with our own legal obligations — we act as a data controller, and this policy governs that processing.
(b) Latonis as processor. When we deliver services to a client — for example, developing, hosting, maintaining, or operating a software platform, or running a marketing campaign — we may process personal data contained in the client's systems (such as the client's end users, customers, or community members). In that context, our client is the controller and Latonis acts only as a processor, on the client's documented instructions and under a written data processing agreement that complies with Article 28 UK GDPR. The client's own privacy notice governs that data, not this policy. If your personal data is held in a platform or service that we build or operate on behalf of a client, please direct any privacy request to that client in the first instance; if we receive such a request directly and can identify the relevant client, we will forward it to them without undue delay and provide reasonable assistance.
You can reach our privacy team through any of the following channels. We are not legally required to appoint a statutory Data Protection Officer, but we have designated a privacy lead responsible for data protection compliance.
Email: Support@latonis.app
Post: Privacy Team, Latonis Technologies Ltd, Sterling House, Suite 310e East Wing, Langston Road, Loughton, Essex, United Kingdom, IG10 3TS
We collect only the personal data we genuinely need. Depending on your relationship with us, this may include the following categories.
We do not intentionally collect special category data (such as data about health, religion, or ethnicity) or data relating to criminal convictions, and we ask that you do not send such data to us unless it is strictly necessary and lawful for you to do so.
We collect personal data directly from you when you contact us, complete a form on our website, negotiate or enter into a contract with us, or communicate with us during a project. We collect data automatically through cookies and similar technologies when you visit our website (see Section 7). We also receive data from third parties, including your organisation or colleagues when they nominate you as a contact; publicly available sources such as Companies House, LinkedIn, and professional portfolio platforms; marketplaces and platforms through which you engage us (for example Fiverr, Upwork, Behance, or Dribbble); referrals; and our service providers (for example analytics providers).
We only process personal data where we have a lawful basis under Article 6 UK GDPR. The list below summarises our processing activities, the typical data involved, and the lawful basis we rely on.
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests are not overridden by your rights and freedoms. You may request further information about these assessments using the contact details in Section 3.
Our website uses strictly necessary cookies to function, and, with your consent where required by PECR, analytics and marketing cookies to understand how the site is used and to improve it. You can manage non-essential cookies through our cookie banner and through your browser settings. Refusing non-essential cookies will not prevent you from using the website.
We send direct marketing only where the law permits: with your consent, or to corporate subscribers and existing business contacts under the applicable PECR rules, always in relation to services similar to those you have engaged with. Every marketing message we send includes a simple way to unsubscribe, and you can opt out at any time by contacting us. When you opt out, we retain a minimal suppression record (typically just your email address) so that we can honour your objection permanently. Opting out of marketing does not affect service communications that are necessary to deliver a contract, such as invoices or project updates.
We never sell personal data. We share it only as follows, and only to the extent necessary.
Latonis operates internationally. Our team members, contractors, service providers, and clients may be located outside the United Kingdom, including in South Asia, the Middle East, the European Economic Area, and the United States, so your personal data may be transferred to and processed in those locations.
Whenever we transfer personal data outside the UK (or the EEA, where EU GDPR applies), we ensure an equivalent level of protection through one or more of the following safeguards: transfer to a country covered by UK adequacy regulations; the ICO's International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum; and supplementary technical and organisational measures such as encryption and access controls where appropriate. You may request a copy of the relevant safeguards (redacted where commercially sensitive) using the contact details in Section 3.
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and, where appropriate, at rest; role-based access controls and the principle of least privilege; multi-factor authentication on core systems; secure credential and secret management; code review and automated vulnerability scanning in our development pipelines; due diligence on vendors and subprocessors; and confidentiality obligations for all personnel and contractors.
No system can be guaranteed to be completely secure. If a personal data breach occurs, we will act in accordance with Articles 33 and 34 UK GDPR, including notifying the Information Commissioner's Office within 72 hours where required and informing affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We keep personal data only for as long as necessary for the purposes described in this policy, after which it is securely deleted or irreversibly anonymised. Our standard retention periods are set out below; specific records may be kept for longer where the law requires it or where they are relevant to an active or reasonably anticipated legal claim.
Subject to the conditions and exemptions in data protection law, you have the following rights in respect of personal data for which Latonis is the controller.
Exercising your rights is free of charge in almost all cases (see Section 15).
We treat erasure requests as a priority and have designed our systems and vendor relationships so that deletion can be carried out thoroughly, including across large or complex environments.
You may ask us to erase your personal data where: the data is no longer necessary for the purposes for which it was collected; you withdraw consent and no other lawful basis applies; you object to processing based on legitimate interests and there are no overriding legitimate grounds, or you object to direct marketing; the data has been unlawfully processed; erasure is required to comply with a legal obligation; or the data was collected from a child in connection with online services.
Send your request to the contact details in Section 3, ideally with the subject line "Erasure Request", describing the data or context concerned (for example, "newsletter subscriber", "project contact for X engagement"). You do not need to use any particular form, cite any legal provision, or give a reason. We may ask for proportionate information to verify your identity, solely to ensure we do not delete or disclose data at the request of the wrong person; we will not use that information for any other purpose.
We will acknowledge your request within 5 working days and complete it within one calendar month of receipt. For particularly complex or numerous requests we may extend this by up to two further months, in which case we will tell you within the first month and explain why. When we action an erasure request we will: delete or irreversibly anonymise your personal data across our live production systems, CRM, mailing lists, and internal records; instruct our processors and subprocessors holding the data to erase it as well; notify each recipient to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort, and tell you about those recipients if you ask; and, where we have made the data public, take reasonable steps, taking account of available technology and cost, to inform other controllers processing it that you have requested erasure of any links to, or copies of, that data. We will confirm to you in writing when erasure is complete.
Erased data may persist for a limited period in encrypted backups maintained for disaster recovery. Backups are isolated, access-restricted, and never used for active processing. Erased data is purged from backups on a rolling cycle of no more than 90 days, and if a backup containing erased data ever has to be restored, the erasure is re-applied immediately as part of the restoration procedure.
The right to erasure is not absolute, and there are limited situations, recognised by UK GDPR, in which we may retain some data despite a request. We rely on these exemptions narrowly and at our reasonable, documented discretion, and only where one of the following applies:
Where we rely on an exemption, we will still erase everything the exemption does not cover, restrict the retained data so it is used only for the exempt purpose, tell you which exemption we are relying on and why, and remind you of your right to complain to the ICO and to seek a judicial remedy.
If a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable administrative fee or refuse to act on it. If we do, we will explain our reasons and you may challenge the decision through the routes in Section 20.
Where the data concerned is held in a platform or environment that we operate as a processor for a client (Section 2(b)), the decision on your request legally belongs to that client as controller. We will forward your request to the client without undue delay, assist them in fulfilling it, and carry out any deletion they instruct.
All rights requests are free of charge unless manifestly unfounded or excessive. We may need to verify your identity before acting, and we will respond within one calendar month, extendable by up to two further months for complex or numerous requests with an explanation. If someone makes a request on your behalf, we will ask for evidence of their authority. If we decline a request in whole or in part, we will tell you why and inform you of your right to complain to the ICO and to a judicial remedy.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Any analytics or profiling we carry out (for example, understanding how visitors use our website) is limited in scope and does not have such effects.
Our services are provided to businesses and are not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will delete it.
Our website and communications may contain links to third-party websites, plug-ins, and applications. We do not control those third parties and are not responsible for their privacy practices. Please review their privacy notices before providing them with personal data.
We may update this policy from time to time to reflect changes in our practices or in the law. The "Last updated" date at the top shows when it was last revised. Where a change is material, we will take reasonable steps to bring it to your attention, for example by email or a prominent website notice.
If you have any concern about how we handle your personal data, please contact us first using the details in Section 3 — we take every concern seriously and will do our best to resolve it. You also have the right to lodge a complaint at any time with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Telephone: 0303 123 1113
Website: ico.org.uk
If you are located in the European Economic Area, you may instead lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
This policy is provided under, and shall be interpreted in accordance with, the laws of England and Wales, without prejudice to any mandatory data protection rights you enjoy under the law applicable to you.
Latonis Technologies Ltd · Company No. 16798861 · Registered in England and Wales
Registered office: Sterling House, Suite 310e East Wing, Langston Road, Loughton, Essex, United Kingdom, IG10 3TS